Yong Yu 0002

dblp:43/5685-2 · DBLP profile ↗
← Back
123ranked-venue papers
25as first author
56since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 53 · 10 first-author · 24 since 2021Computer networks · 26 · 2 first-author · 17 since 2021Systems, architecture and hardware · 17 · 5 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 4 first-author · 2 since 2021Databases, data management, data science and information retrieval · 9 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 Provably Secure Authentication Protocol for Emergency Vehicles Avoidance in VANETs
abstract
In Vehicular Ad-hoc Networks (VANETs), the ability of emergency vehicles (EVs) to reach their destinations quickly can maximize the protection of people’s lives and property safety, and minimize the losses and impacts caused by various emergencies. In this endeavor, the emergency vehicle avoidance protocol is of paramount importance. However, the existing authentication protocol is vulnerable to side-channel attacks, Roadside Units (RSUs) captured attacks, as well as untraceability, etc. Therefore, for wider and more practical realizability, we propose an efficient and secure authentication scheme based on Elliptic Curves Cryptography (ECC), fuzzy extraction algorithm and Physical Unclonable Function (PUF) for EVs avoidance. In the protocols, PUF and biometric key are used for protecting RSUs’ and EVs’ privacy information respectively. Additionally, a conditional privacy-preserving and traceable message authentication strategy is designed for emergency messages propagation, the avoidance messages can be forwarded to ordinary vehicles before the EVs arriving. Compared with related EVs avoidance protocols, our protocol can resist side-channel attacks and other various known attacks. In our scheme, the first authentication efficiencies have increased by 11.72% and the subsequent authentication increased by 25.99% than the previous protocols in the same scenario. Security and performance analysis demonstrate that the proposed scheme is secure, efficient, and practical.
Qi Xie 0001, Juanjuan Huang, Yong Yu 0002
IEEE Internet Things J.3
2026 EVMKA: Efficient and Verifiable Multikey Aggregation for Privacy-Preserving Federated Learning in Internet of Things
Xiaoyi Yang 0001, Xing Zou, Yanqi Zhao, Yong Yu 0002, Jiguo Yu
IEEE Internet Things J.5
2026 Fuzzy Matching Data Sharing With Equality Test for Internet of Medical Things
abstract
The contemporary healthcare ecosystem is being radically reshaped by the burgeoning deployment of Internet of Medical Things (IoMT) technologies; however, this ubiquity inevitably expands the attack surface regarding data confidentiality and user privacy. To mitigate the risk of sensitive physiological data leakage, this paper introduces a novel cryptographic primitive: Fuzzy Matching Data Sharing with Equality Test (FMDS-ET), optimized for the constraints of IoMT environments. Distinct from traditional approaches, our construction enforces a bilateral fine-grained access control mechanism. Specifically, decryption is authorized if and only if the cardinality of the intersection between the attribute sets and access policies of both the transmitter and the recipient surpasses a predefined threshold. This design not only bolsters the resilience of mutual authentication but also facilitates secure data dissemination and ciphertext equality test. Furthermore, it provides a viable solution for privacy-preserving data classification and record linkage. We provide a formal definition of the system syntax and prove its semantic security in the random oracle model. Comprehensive performance evaluations confirm that the proposed scheme maintains low computational overhead, rendering it highly feasible for resource-constrained medical sensors.
Yinghui Zhang 0002, Yong Yu 0002, Qiuxia Zhao, Dong Zheng 0001
IEEE Internet Things J.3
2026 Splight: A Lightweight Block Cipher for Resource-Constrained Embedded Devices
Chengzhe Lai, Yong Yu 0002
IEEE Trans. Computers4
2026 An Auction-Based Bilateral Bidding Privacy Protection Scheme in Multi-Platform MCS
abstract
With the advancement of smart terminals and communication technologies, the emergence of heterogeneous Service Subscribers (SSs) and diverse sensing demands has facilitated the development of multi-platform Mobile CrowdSensing (MCS) scenarios. However, unlike traditional single-platform scenarios, Mobile Users' (MUs) bidding privacy is hard to protect in multi platform MCS. Additionally, the privacy disclosure issue of SSs has not been well addressed. To tackle these issues, in this paper, we propose a bilateral, auction-based scheme to preserve bidding privacy in multi-platform MCS, thereby protecting the interests of both SSs and MUs. Specifically, since SSs and MUs strategically choose one another to maximize their utility, we construct the corresponding selection processes for both sides by taking advantage of auction pricing theory. We firstly design a user-oriented forward auction that integrates the 0-1 knapsack problem with the Paillier encryption algorithm to protect the bidding information of both SSs and MUs. Then, we employ the Chinese Remainder Theorem (CRT) to design a reverse auction that hides the bidding behaviors of MUs. Theoretical analysis demonstrates that our scheme can protect the bidding privacy of both parties while ensuring economic robustness. Extensive experiments on a real dataset demonstrate that, compared with existing works, our scheme enables both SSs and MUs to achieve satisfactory utility while maintaining low computational overhead.
Bin Luo 0006, Yong Yu 0002, Xinghua Li 0001, Yanbing Ren, Zhe Ren, Yuchao Yao
IEEE Trans. Dependable Secur. Comput.2
2026 Verifiable Privacy-Preserving Retrieval Service for Large-Scale Image in Cloud Computing
abstract
The vigorous development of the Internet of Things and cloud computing is driving resource-limited smart devices to outsource large-scale images to cloud servers for storage and retrieval. Privacy-preserving image retrieval addresses the threat of data privacy leakage without affecting the searchability of images. Existing privacy-preserving retrieval schemes use the approximate nearest neighbor search to improve the retrieval efficiency of large-scale images on the cloud server. However, these schemes suffer from reduced retrieval accuracy, difficulties in constructing encrypted index structures, and a lack of result verification support. To tackle these problems, we propose a verifiable privacy-preserving retrieval scheme for large-scale images (VPIRL) in cloud servers. We use learning with errors (LWE) theory to protect image features, achieving distance and angle preservation between encrypted features. This enables the cloud server to construct an encrypted satellite system graph for efficient and accurate retrieval of large-scale images. We also propose a privacy-preserving data verification method based on the Merkle Hash Tree and cuckoo hash to detect dishonest behaviors of the cloud server and verify the correctness and completeness of the approximate nearest neighbor retrieval results. Experimental results show that this scheme achieves retrieval and verification in milliseconds for millions of images, confirming its practicality for large-scale image retrieval.
Yuejing Yan, Yanyan Xu 0003, Yong Yu 0002
IEEE Trans. Dependable Secur. Comput.3
2026 EvaFL: An Efficient Verifiable Privacy-Preserving Federated Learning Against Malicious Servers
abstract
Federated Learning (FL) preserves client data privacy by distributing model training but remains vulnerable to inference attacks (e.g., gradient inversion). Existing secure aggregation schemes mitigate basic privacy threats, but most of them are under the semi-honest server assumption. Malicious servers can corrupt the global model through forging aggregation results. Moreover, the high interaction rounds and communication complexity of the existing schemes still constrain their feasibility in large-scale distributed deployment scenarios. To tackle these challenges, we propose EvaFL, an efficient verifiable privacy-preserving federated learning against malicious servers, which reduces the communication overhead and privacy threats from malicious severs. We propose the system model of EvaFL and give the concrete protocol. We leverage the linear homomorphism property of Shamir secret sharing under discrete logarithm assumption to reuse the mask seed shares, which avoids the communication overhead caused by share distribution in multiple rounds of iterations. In addition, by integrating consistency checking into the unmasking step, we further reduce one round interaction. To resist malicious servers, we adopt linear homomorphic hash to realize the correctness verification of the aggregation results. Finally, we implement and evaluate our EvaFL based on MNIST and CIFAR10 datasets to show its feasibility for privacy training. The single round aggregation completion time of EvaFL is reduced by 69% compared to BBGLR (CCS 2020) and by 11% compared to Flamingo (S&P 2023).
Xiaoyi Yang 0001, Xing Zou, Qian Chen 0032, Baodong Qin, Yanqi Zhao, Yong Yu 0002
IEEE Trans. Dependable Secur. Comput.7
2026 User-Side Pairing-Free Lightweight Distributed Anonymous Counting Tokens
abstract
Centralized issuer in Anonymous Counting Tokens (ACT) is prone to single-point failure and imposes prohibitive computational overhead on resource-constrained IoT devices, hindering practical deployment. To overcome these limitations, we propose a user-side pairing-free lightweight distributed anonymous counting tokens protocol called LDACT. LDACT enables efficient issuance within a distributed environment and ensures that each client receives at most one valid token per message without disclosing their identity. LDACT eliminates pairing operations for user-side, enhancing scalability for source-constrained scenarios. Additionally, the tokens are publicly verifiable, allowing any party to verify their validity without compromising user anonymity. We conduct security analysis that LDACT satisfies unforgeability and unlinkability. We evaluate the computational overhead of LDACT on both Ubuntu and Raspberry Pi system, and compare it with other schemes. The result of the experiment demonstrates that LDACT achieves computational overhead in milliseconds for source-constrained IoT devices.
Yanqi Zhao, Minghong Sun, Xiaoyi Yang 0001, Yong Yu 0002
IEEE Trans. Dependable Secur. Comput.5
2026 Two Heads Are Not Better Than One: Continual Learning From Multiple Models for Encrypted Traffic Analysis
Qingjun Yuan, Weina Niu, Jian Chai, Yong Yu 0002
IEEE Trans. Inf. Forensics Secur.7
2026 AC-BaaS: An Asynchronous Cross-Blockchain as a Service for the Internet of Things
abstract
Cross-chain techniques improve blockchain scalability and interoperability, providing decentralized exchange and cross-chain collaboration services for Internet of Things (IoT) data across various domains. However, current state-of-the-art (SOTA) solutions for cross-chain data exchange across multiple domains are constrained by synchronous networks, hindering efficient data exchange in intermittent network environments. Furthermore, there is a lack of research on asynchronous cross-chain transaction pool mechanisms, which are crucial for optimizing system utility. In this paper, we propose AC-BaaS, anasynchronouscross-blockchainasaservice framework tailored for the multi-domain IoT. Built upon a specially designed asynchronous sidechain architecture, the system leverages a committee to provide AC-BaaS for data exchange across multiple IoT domains. To fulfill the need for asynchronous and efficient data exchange, we combine the ideas of aggregate signatures and verifiable delay functions to devise a novel cryptographic primitive called delayed aggregate signature (DAS), which constructs asynchronous cross-chain proofs (ACPs) that ensure the security of cross-chain interactions. To ensure the consistency of asynchronous transactions, we propose a multilevel buffered transaction pool that guarantees the transaction sequencing. We further propose a heuristic for optimizing the utility of the buffer pool mechanism to strike a balance between performance and resource consumption. We also examine DAS delay size settings to trade-off security and efficiency. We analyze and prove the security of AC-BaaS, simulate asynchronous communication environments under various security levels, and conduct a comprehensive evaluation. The results show that AC-BaaS outperforms SOTA schemes, improving throughput by an average of 1.71 to 5.09 times, reducing transaction latency by 64.36% to 85.49%, and maintaining comparable resource overhead.
Lingxiao Yang, Xuewen Dong, Zhiguo Wan, Sheng Gao 0002, Wei Tong 0003, Yong Yu 0002, Yulong Shen 0001
IEEE Trans. Serv. Comput.6
2025 R+R: Anonymous Authentication and Key Agreement, Revisited
abstract
In NDSS 2024, Yu et al. proposed AAKA, an Anonymous Authentication and Key Agreement scheme designed to protect users' privacy from mobile tracking by Mobile Network Operators (MNOs). AAKA aims to provide both anti-tracking privacy and traceability (lawful de-anonymization), allowing subscribers to access the network via anonymous proofs while enabling a Law Enforcement Agency (LEA) to trace the real identity if misbehaviors are detected. However, we identify that the AAKA scheme in NDSS 2024 is insecure since the subscriber's identity is exposed within the protocol, thereby failing to achieve the claimed privacy and traceability. Building on the repair of AAKA, we propose AAKA +, Anonymous Authentication and Key Agreement with Verifier-Local Revocation, a new mobile authentication scheme, to ensure privacy against mobile tracking. In addition to the privacy and traceability introduced in NDSS 2024, AAKA + additionally allows the MNO to immediately assert whether the associated subscriber has been traced and revoked upon receiving an anonymous proof We formally define the syntax and the security model of AAKA + and propose two concrete schemes, AAKA+BB andAAKA+PS, based on the Boneh-Boyen signature and the Pointcheval-Sanders signature schemes, respectively. Both AAKA+BB and AAKA+PS are pairing-free on the user equipment side and compatible with existing cellular infrastructure. Experimental results show that our schemes are practical, with anonymous proof generation taking approximately 18 milliseconds for a constrained device.
Yanqi Zhao, Xiaoyi Yang 0001, Jianting Ning, Baodong Qin, Yong Yu 0002
ACSAC8
2025 Lightweight Transparent Zero-Knowledge Proofs for Cross-Domain Statements
Zhengzhou Tu, Yong Yu 0002, Zoe Lin Jiang
ICICS (1)4
2025 When There Is No Decoder: Removing Watermarks from Stable Diffusion Models in a No-Box Setting
Xiangman Li, Jianbing Ni, Yong Yu 0002
ICICS (3)5
2025 Threshold Anonymous Counting Tokens with Batch Proofs for Online Paywalls
abstract
As online application services evolve, an increasing number of users are opting for subscription-based or paywall models to access high-quality content. Anonymous counting tokens (ACTs), which regulate user access while protecting user privacy, are widely adopted in the online paywall model. However, the centralized server of ACT may lead to a single point of failure, thereby exposing users’ privacy. To address this challenge, in this paper, we propose threshold anonymous counting tokens with batch proofs (ThrACT) that balance privacy preservation and access count limitation for online paywalls. We define the system model for ThrACT and provide its concrete construction. We utilize the threshold Boneh-Boyen signature to facilitate distributed issuance of anonymous tokens and enable batch issuance. In addition, our ThrACT employs non-interactive zero-knowledge proofs to verify the label and token requests while allowing the correctness of multiple blind token shares to be validated simultaneously. We also prove that ThrACT satisfies unforgeable and unlinkable security properties. Finally, we evaluate the computational cost of our ThrACT and compare it with other schemes. The experiment result demonstrates that ThrACT not only supports distributed issuance, batch verification, and counting functionalities but also achieves computational overhead in milliseconds. In particular, when the threshold is set to (3,5), the token issuance time is approximately 9 milliseconds.
Yanqi Zhao, Minghong Sun, Xiaoyi Yang 0001, Yong Yu 0002
IWCMC5
2025 Redactable Blockchain from Accountable Weight Threshold Chameleon Hash
abstract
The redactable blockchain provides the editability of blocks, which guarantees the data immutability of blocks while removing illegal content on the blockchain. However, the existing redactable blockchain relies on trusted assumptions regarding a single editing authority. Ateniese et al. (EuroS&P 2017) and Li et al. (TIFS 2023) proposed solutions by using threshold chameleon hash functions, but these lack accountability for malicious editing. This paper delves into this problem and proposes an accountability weight threshold blockchain editing scheme. Specifically, we first formalize the model of a redactable blockchain with accountability. Then, we introduce the novel concept of the Accountable Weight Threshold Chameleon Hash Function (AWTCH). This function collaboratively generates a chameleon hash trapdoor through a weight committee protocol, where only sets of committees meeting the weight threshold can edit data. Additionally, it incorporates a tracer to identify and hold accountable any disputing editors, thus enabling supervision of editing rights. We propose a generic construction for AWTCH. Then, we introduce an efficient construction of AWTCH and develop a redactable blockchain scheme by leveraging AWTCH. Finally, we demonstrate our scheme’s practicality. The editing efficiency of our scheme is twice that of Tian et al. (TIFS 2023) with the same number of editing blocks.
Yanqi Zhao, Xiaoyi Yang 0001, Yong Yu 0002
High Confid. Comput.6
2025 Less leakage and more precise: Efficient wildcard keyword search over encrypted data
abstract
Wildcard searchable encryption allows the server to efficiently perform wildcard-based keyword searches over encrypted data while maintaining data privacy. A promising solution to achieve wildcard SSE is to extract the characteristics of the queried keyword and check the existence based on a membership test structure. However, existing schemes have false positives of character order, that is, the server cannot identify the order between the first and the last wildcard character. Besides, the schemes also suffer from characteristic matching pattern leakage due to the one-by-one membership testing. In this paper, we present the first efficient wildcard SSE scheme to eliminate the false positives of character order and characteristic matching pattern leakage. To this end, we design a novel characteristic extraction technique that enables the client to exact the characteristics of the queried keyword maintaining the order between the first and the last wildcard character. Then, we utilize the primitive of Symmetric Subset Predicate Encryption, which supports checking if one set is a subset of another in one shot to reduce the characteristic matching pattern leakage. Finally, by performing a formal security analysis and implementing the scheme on a real-world database, we demonstrate that the desired security properties are achieved with high performance.
Yunling Wang, Chenyang Gao, Yong Yu 0002
High Confid. Comput.5
2025 Linkable group signatures against malicious regulators for regulated privacy-preserving cryptocurrencies
abstract
With the emergence of illegal behaviors such as money laundering and extortion, the regulation of privacy-preserving cryptocurrency has become increasingly important. However, existing regulated privacy-preserving cryptocurrencies usually rely on a single regulator, which seriously threatens users’ privacy once the regulator is corrupt. To address this issue, we propose a linkable group signature against malicious regulators (ALGS) for regulated privacy-preserving cryptocurrencies. Specifically, a set of regulators work together to regulate users’ behavior during cryptocurrencies transactions. Even if a certain number of regulators are corrupted, our scheme still ensures the identity security of a legal user. Meanwhile, our scheme can prevent double-spending during cryptocurrency transactions. We first propose the model of ALGS and define its security properties. Then, we present a concrete construction of ALGS, which provides CCA-2 anonymity, traceability, non-frameability, and linkability. We finally evaluate our ALGS scheme and report its advantages by comparing other schemes. The implementation result shows that the runtime of our signature algorithm is reduced by 17% compared to Emura et al. (2017) and 49% compared to KSS19 (Krenn et al. 2019), while the verification time is reduced by 31% compared to Emura et al. and 47% compared to KSS19.
Yanqi Zhao, Lingyue Zhang, Yong Yu 0002
High Confid. Comput.5
2025 A logarithmic size revocable linkable ring signature for privacy-preserving blockchain transactions
abstract
Monero uses ring signatures to protect users’ privacy. However, Monero’s anonymity covers various illicit activities, such as money laundering, as it becomes difficult to identify and punish malicious users. Therefore, it is necessary to regulate illegal transactions while protecting the privacy of legal users. We present a revocable linkable ring signature scheme (RLRS), which balances the privacy and supervision for privacy-preserving blockchain transactions. By setting the role of revocation authority, we can trace the malicious user and revoke it in time. We define the security model of the revocable linkable ring signature and give the concrete construction of RLRS. We employ accumulator and ElGamal encryption to achieve the functionalities of revocation and tracing. In addition, we compress the ring signature size to the logarithmic level by using non-interactive sum arguments of knowledge (NISA). Then, we prove the security of RLRS, which satisfies anonymity, unforgeability, linkability, and non-frameability. Lastly, we compare RLRS with other ring signature schemes. RLRS is linkable, traceable, and revocable with logarithmic communication complexity and less computational overhead. We also implement RLRS scheme and the results show that its verification time is 1.5s with 500 ring members.
Yanqi Zhao, Xiaoyi Yang 0001, Minghong Sun, Yong Yu 0002
High Confid. Comput.6
2025 Privacy Protection Distributed Spatial Cloaking Scheme Based on Certified Reputation in Industrial Internet of Things
abstract
As a typical application in Industrial Internet of Things (IIoT), Location-Based Service (LBS) are experiencing rapid development. To address the issue of user location privacy leakage during LBS, distributed spatial cloaking attracts considerable attention from researchers. This approach not only provides users with precise query results but also enhances their control over personal information, allowing users to independently decide whether to participate in constructing Anonymous Cloaking Regions (ACRs). However, existing LBS schemes are unable to effectively prevent malicious behavior by requesters or cooperators, leading to user privacy leakage. To resolve this issue, we propose a novel privacy-preserving LBS scheme that incorporates a Certified Reputation (CR) mechanism. The proposal integrates user-owned CRs with preset trust thresholds, forming an innovative interactive verification mechanism. This mechanism enhances user privacy while establishing a trustworthy framework, within which each user individually manages their CR information. It not only adapts to fully distributed scenarios but also supports cross-regional trust evaluation. Meanwhile, the scheme establishes trust relationships among users, ensuring that only mutually trusted users can collaborate to construct ACRs. Security analysis and extensive experiments demonstrate that the proposed scheme effectively regulates user behavior during the construction of ACRs. Furthermore, it imposes minimal computational and communication overhead, highlighting its efficiency and practicality.
Jianyong Fan, Bin Luo 0006, Yong Yu 0002
IEEE Internet Things J.4
2025 Crowd-BT: A Bilateral Trustworthy Ensured Scheme for Blockchain-Assisted Mobile Crowdsensing
abstract
Blockchain-based distributed mobile crowdsensing (MCS) has been widely adopted in areas, such as the Industrial Internet of Things (IIoT) to transform traditional data collection methods. However, existing works lack a theory-driven quantitative utility analysis and precise reward and punishment measures that effectively deter malicious behavior. This deficiency hinders the ability to constrain rational participants’ behavior, thereby compromising the trustworthiness of MCS implementations. To address the issue above, this article proposes Crowd-BT: a bilateral trustworthy ensured scheme for blockchain assisted MCS. Specifically, Crowd-BT first devises reward and punishment measures based on participants’ short-term utility analysis for an unrestricted context in the ideal case. Then, for the more practical situation, Crowd-BT designs blocklist punishment measures for participants, ensuring self-containment based on long-term utility analysis. Finally, leveraging the practical blocklist punishment measures and the devised anonymity behavior record certificates (ABRCs) using the message-hidden signature, Crowd-BT details the implementation steps for MCS under the blockchain. Theoretical analysis shows that Crowd-BT achieves both utility and security goals. Extensive experiments illustrate that Crowd-BT effectively constrains participant behavior. Compared to the existing works, it significantly enhances the trustworthiness of MCS.
Bin Luo 0006, Yong Yu 0002, Zoe Lin Jiang, Yuchao Yao, Jianyong Fan
IEEE Internet Things J.2
2025 MRDT: An Enhanced Multireceiver Secure Data Transmission Protocol for WBANs
abstract
Wireless Body Area Networks (WBANs) have gained significant attention due to their numerous advantages in healthcare monitoring and applications. However, WBANs also face challenges related to data transmission security and privacy protection. Many researchers have proposed solutions to address these issues, but most of them are based on one-to-one communication models, which suffer from security vulnerabilities. Hence, we first review the previous protocol and show potential attack scenarios. Building upon their work, we propose an enhanced certificateless multi-receiver secure data transmission protocol for WBANs. Our proposal addresses security concerns and improves the efficiency and practicality of data transmission in WBANs. The security analysis and performance evaluation demonstrate that the proposed protocol achieves higher security levels, increases efficiency, and enhances practicality compared to existing approaches. Furthermore, our protocol provides a reliable framework for secure data transmission in WBANs, ensuring the privacy of users and maintaining the integrity and confidentiality of sensitive medical information.
Zirui Qiao, Yanwei Zhou, Yong Yu 0002, Dong Zheng 0001
IEEE Internet Things J.4
2025 TRACE: Trusted Return-Path Authentication via Context and Lightweight Encryption for IoT Devices
abstract
Return-Oriented Programming (ROP) attacks pose a significant threat to the control-flow integrity of Internet of Things (IoT) devices, which operate in resource-constrained environments with limited memory isolation and runtime protection. Existing defenses, such as shadow stacks and message authentication code (MAC)-based schemes, face key limitations in IoT: shadow stacks depend on trusted hardware often absent in lightweight devices, while message authentication code (MAC) schemes lack semantic binding to the call path, making them vulnerable to replay attacks during recursion or stack reuse. To address these challenges, this paper proposes TRACE, a lightweight return-path authentication mechanism with path-semantic awareness, designed for IoT devices. TRACE dynamically encodes the function call context into an evolving path-state vector, which is then combined with the return address and cryptographically processed to generate a semantically unique authentication tag. At each function return, TRACE reconstructs the path state and verifies the tag to enforce precise runtime control-flow integrity. We evaluate TRACE in both synthetic and real-world attack scenarios. With the RIPE test suite, we demonstrate its robustness across five representative attack dimensions. Additionally, we identify a stack overflow vulnerability in the widely used libmodbus v2.9.3 protocol stack, construct a complete attack chain in a realistic IoT context, and validate TRACE’s effectiveness in mitigating such attacks. Experimental results show that TRACE reliably detects return-path tampering even without Address Space Layout Randomization (ASLR) or stack protections and incurs only a 5.3% runtime overhead, offering strong security with lightweight performance suitable for resource-constrained IoT deployments.
Rongkuan Ma, Yong Yu 0002, Siqi Lu, Yongjuan Wang
IEEE Internet Things J.3
2025 PINQ: Privacy-Preserving Influential Nodes Query Over Encrypted Distributed Networks
abstract
Identifying influential nodes in complex networks is crucial for information dissemination, epidemic control, and supply chain management, etc. As the scale of networks increases, data owners prefer to outsource identifying influential nodes to cloud servers. To protect data privacy, network data needs to be encrypted before being outsourced. So identifying influential nodes on encrypted data is necessary. Furthermore, many sensitive networks are distributed among different data owners. To identify the influential nodes in such networks, it is necessary to first obtain the whole network and then outsource the whole network to supply identify influential nodes service. Currently, there is only one scheme that supports privacy-preserving identification of influential nodes in distributed private networks, but it works on a wrong whole network, it leaks some topological characteristics of the whole network, can only support influential nodes identifying, and cannot support private querying for any influential nodes. To address these issues, we propose PINQ (Privacy-preserving Any Influential Node Query Scheme), the first general scheme that supports any influential node queries in private distributed networks. PINQ can query the top-k most influential nodes, the bottom k influential nodes, or nodes with influence at a specific rank. PINQ uses encryption-selection-re-randomization techniques to correctly generate the privacy whole network within distributed private networks, securely ranking the importance of nodes without leaking any network topology information, and supporting any influential node privacy queries. Additionally, PINQ uses blockchain to achieve fair data query transactions. Theoretical analysis and experimental simulation results show that PINQ is secure, feasible and efficient.
Jingjuan Yu, Yong Yu 0002, Jiawei Dou
IEEE Internet Things J.3
2025 How to reduce the number of steps for (multi-valued validated) Byzantine agreement?
Baohan Huang, Chao Liu 0039, Shengli Liu 0001, Yong Yu 0002, Fangguo Zhang, Liehuang Zhu
J. Parallel Distributed Comput.5
2025 Accountable Many-to-One Signature With Short Verification Key for Self-Sovereign Identity
abstract
Self-Sovereign Identity (SSI) shifts identity management authority from central institutions to users, enhancing privacy protections. However, malicious identity providers may collude with users to issue credentials that pass verification but contain false information. While multi-signature schemes enable joint credential issuance by multiple identity providers to mitigate this risk, they result in a linear increase in the size of signatures within credentials and verification keys as the number of identity providers grows, leading to substantial storage overhead for both users and verifiers. Furthermore, malicious verifiers may leak users' credentials to third parties or unlawfully duplicate them, causing users to lose control over the distribution of their credentials. To address these challenges, we propose the Accountable Many-to-One Signature Scheme with Short Verification Key (ASVK-MOSS), a multi-signature scheme with designated verifiers and accountability that ensures fixed sizes for both the verification key and the signature. We prove the security of the proposed ASVK-MOSS under the random oracle model. Building on ASVK-MOSS, we design a novel SSI system, namedMO-SSI, in which multiple identity providers jointly sign the user's personal information to generate a credential with fixed sizes. Service providers only need to store a minimal, fixed-size verification key to validate the credentials from any set of identity providers. Additionally, the designated verifier and accountability mitigate risks posed by malicious service providers and identity providers within MO-SSI. The theoretical analysis and experimental results demonstrate its effectiveness and feasibility.
Yong Yu 0002, Haochen Yang 0001, Yannan Li 0001, Xiaojiang Du
IEEE Trans. Dependable Secur. Comput.1
2025 FDAAC-CR: Practical Delegatable Attribute-Based Anonymous Credentials With Fine-Grained Delegation Management and Chainable Revocation
Peichen Ju, Yanqi Zhao, Zoe Lin Jiang, Man Ho Au, Yong Yu 0002, Xuan Wang 0002
IEEE Trans. Inf. Forensics Secur.7
2025 Everything Distributed and Asynchronous: A Practical System for Key Management Service
abstract
A key management service (KMS) is vital to modern mission-critical systems. At the core of KMS are the key generation process and the key refresh process. In this paper, we design and implement a purely asynchronous system for completely distributed KMS supporting traditional applications such as threshold cryptosystems and multiparty computation (MPC) as well as emerging blockchains and Web3 applications. In this system, we have built a number of new asynchronous distributed key generation (ADKG) protocols and their corresponding asynchronous distributed key refresh (ADKR) protocols. We have demonstrated that our ADKG and ADKR protocols in the standard model outperform existing ones of the same kind, while our protocols in the random oracle model (ROM) are more efficient than other protocols with small and medium-sized networks.
Zhaoyang Xie, Sisi Duan, Chao Liu 0039, Shengli Liu 0001, Xuanji Meng, Yong Yu 0002, Fangguo Zhang, Boxin Zhao, Liehuang Zhu, Tianqing Zhu
IEEE Trans. Parallel Distributed Syst.7
2025 Calling Out Trustless Users: A Trust Propagation Scheme for Decentralized Trust Management
abstract
Trust management has been widely employed to determine a user's trustworthiness based on evaluations from other entities, and trustless users are those with low trustworthiness due to dishonest or malicious behaviors. To overcome the defects of traditional centralized trust management, decentralized trust management has been proposed, leveraging blockchain to store trust data, e.g., user interaction evaluations, securely. However, blockchain-based decentralized trust management usually suffers from throughput limitation, hindering timely record users' trust data, delaying expose trustless users. As a result, trustless users may still interact with others in the system with the outdated trustworthiness, undermining the reliability and fairness of the system. Furthermore, decentralized pseudonymous networks suffer from a trust cold-start problem due to lacking users' prior interaction history or endorsements from trusted third parties, making it hard for newly joined users to assess the trustworthiness. To address these issues, we propose TUES in this paper, an efficient Trustless User Exposure Scheme. TUES stores trust data in a trust blockchain collectively maintained by all users. To efficiently expose trustless users, we design a dynamic consensus mechanism for TUES. This dynamic consensus mechanism integrates three novel consensus algorithms, efficiently utilizing network throughput to record trust data of trustless users and ensure the consistency of the blockchain. Additionally, TUES includes a multi-signature-based scheme to allocate initial trust values to users, thus resolving the trust cold-start problem in decentralized pseudonymous networks. Analysis and experiments show that TUES improves the efficiency of exposing trustless users while maintaining the consistency of the trust blockchain. It also increases the cost for adversaries conducting Sybil, whitewashing and Byzantine attacks.
Yong Yu 0002, Haochen Yang 0001, Yannan Li 0001, Robert H. Deng
IEEE Trans. Serv. Comput.1
2024 GAN Augmentation-Based Continuous Authentication for Vehicular Digital Twin
abstract
In this paper, to secure the communication between autonomous vehicle and its digital representative in the vehicular digital twin system, we propose a GAN augmentation-based continuous authentication scheme. Specifically, in the proposed scheme, we first introduce a data augmentation technique based Generative Adversarial Network (GAN) that provides the augmentation of raw data from vehicle sensors. We then present the efficient authentication: 1) We train a Convolutional Neural Network (CNN) using raw and augmented data; 2) Deep features are extracted through a combination of Principal Component Analysis (PCA) and CNN; 3) We train the OC-SVM classifier during the registration to ensure the legality of vehicle in the authentication phase. Performance evaluations via extensive simulations demonstrate the efficiency and effectiveness of the proposed scheme in terms of GAN loss and accuracy.
Chengzhe Lai, Xinwei Zhang 0008, Guanjie Li, Yong Yu 0002, Dong Zheng 0001
ICC5
2024 Chronos: An Efficient Asynchronous Byzantine Ordered Consensus
abstract
Abstract Byzantine ordered consensus, introduced by Zhang et al. (OSDI 2020), is a new consensus primitive that additionally guarantees a correctness specification of transaction order, allowing nodes to assign fairly an ordering indicator to the committed transaction. Zhang et al. also presented a concrete Byzantine ordered consensus protocol called Pompē in the partially synchronous network model. However, Pompē cannot prevent an adversary from manipulating message delivery time. In this paper, we present Chronos, the first Byzantine ordered consensus protocol in the asynchronous network model, where an adversary can arbitrarily manipulate message delivery time. To construct Chronos, we propose a variant of asynchronous common subset called signal asynchronous common subset protocol, which guarantees the liveness of Chronos. We implement both Chronos and its baseline HoneyBadgerBFT using Go language and deploy them on 100 Amazon t3.medium instances distributed throughout 10 regions across the world. The experimental results show that Chronos is more efficient than HoneyBadgerBFT for small network, achieving peak throughput of 59 368 tx/s when the batch size is 100 000 and the number of nodes is 4, while the peak of HoneyBadgerBFT is 57 077 tx/s.
Zongyang Zhang, Lingyue Zhang, Rongxing Lu, Yong Yu 0002
Comput. J.6
2024 iPMRSS: An Improved privacy-preserving medical record searching scheme for intelligent diagnosis in IoMT
Guishan Dong, Yong Yu 0002
Expert Syst. Appl.4
2024 Identity-based threshold (multi) signature with private accountability for privacy-preserving blockchain
abstract
Identity-based threshold signature (IDTHS) allows a threshold number of signers to generate signatures to improve the deterministic wallet in the blockchain . However, the IDTHS scheme cannot determine the identity of malicious signers in case of misinformation . To solve this challenge, we propose an identity-based threshold (multi) signature with private accountability (for short AIDTHS) for privacy-preserving blockchain . From the public perspective, AIDTHS is completely private and no user knows who participated in generating the signature. At the same time, when there is a problem with the transaction, a trace entity can trace and be accountable to the signers. We formally define the syntax and security model of AIDTHS. To address the issue of identifying malicious signers, we improve upon traditional identity-based threshold signatures by incorporating zero-knowledge proofs as part of the signature and leveraging a tracer holding tracing keys to identify all signers. Additionally, to protect the privacy of signers, the signature is no longer achievable by anyone, which requires a combiner holding the keys to produce a valid signature. We give a concrete construction of AIDTHS and prove its security. Finally, we implement the AIDTHS scheme and compare it with existing schemes. The key distribution algorithm of AIDTHS takes 13.04 ms and the signature algorithm takes 34.60 μ s . The verification algorithm takes 1 s , which is one-third of the time the TAPS scheme uses.
Yanqi Zhao, Xiaoyi Yang 0001, Yong Yu 0002
High Confid. Comput.6
2024 Security Analysis of Large Language Models on API Misuse Programming Repair
abstract
Application programming interface (API) misuse refers to misconceptions or carelessness in the anticipated usage of APIs, threatening the software system’s security. Moreover, API misuses demonstrate significant concealment and are challenging to uncover. Recent advancements have explored enhanced LLMs in a variety of software engineering (SE) activities, such as code repair. Nonetheless, the security implications of using LLMs for these purposes remain underexplored, particularly concerning the issue of API misuse. In this paper, we present an empirical study to observe the bug‐fixing capabilities of LLMs in addressing API misuse related to monitoring resource management (MRM API misuse). Initially, we propose APImisRepair, a real‐world benchmark for repairing MRM API misuse, including buggy programs, corresponding fixed programs, and descriptions of API misuse. Subsequently, we assess the performance of several LLMs using the APImisRepair benchmark. Findings reveal the vulnerabilities of LLMs in repairing MRM API misuse and find several reasons, encompassing factors such as fault localization and a lack of awareness regarding API misuse. Additionally, we have insights on improving LLMs in terms of their ability to fix MRM API misuse and introduce a crafted approach, APImisAP. Experimental results demonstrate that APImisAP exhibits a certain degree of improvement in the security of LLMs.
Rui Zhang 0106, Ziyue Qiao, Yong Yu 0002
Int. J. Intell. Syst.3
2024 TBSCrowd: A Blockchain-Assisted Privacy-Preserving Mobile Crowdsourcing Scheme From Threshold Blind Signatures
abstract
Mobile crowdsourcing is the practice of hiring a number of people (workers) at a low cost to complete tasks that are typically difficult to complete individually. However, in the IoT era, how to achieve lightweight privacy preservation and evaluate the trust of human mobility are crucial matters. Therefore, this article proposes a blockchain assisted Privacy-Preserving mobile crowdsourcing scheme based on threshold blind signatures (TBSCrowd for short). We design a blockchain assisted Privacy-Preserving mobile crowdsourcing scheme which can preserve security, robustness, fairness while reducing computation and communication overheads of scheme. To achieve the properties of privacy, unforgeability and robustness, we propose robust asynchronous ECC threshold signatures. Simulations are conducted to show the performance of the TBSCrowd scheme, and the experiment results demonstrate that our construction significantly outperforms some related schemes in security and other related aspects.
Shunyu Dong, Jiaming Wen 0001, Yong Yu 0002
IEEE Internet Things J.5
2024 BSCDA: Blockchain-Based Secure Cross-Domain Data Access Scheme for Internet of Things
abstract
In the current hypergrowth phase of the Internet of Things, cross-domain data access becomes more and more frequently. Whereas, the lack of trust between domains makes cross-domain data access extremely hard. Traditional schemes typically depend on a third party to establish trust between data accessing entities, which can easily result in single point of failure. To conquer the aforementioned challenge, this paper proposes BSCDA, a blockchain-based cross-domain data access scheme designed to enable secure data transmission across domains. The decentralization, transparency, and anti-tampering features of blockchain perfectly solve the issue of single point of failure and foster trust among various domains. Specifically, a certificate management method is developed to address the certificate storage issue by leveraging a mapping table to store the revocation certificate index on the blockchain. This method not only ensures the verifiability of the certificate but also reduces the storage overhead. Additionally, a four-party key agreement mechanism is designed to guarantee the secure data transmission during the process of cross-domain data access. Security analysis prove the feasibility of our proposed scheme. Extensive experiments demonstrate the superiority of our scheme in cross-domain data access.
Baobao Chai, Jiguo Yu, Biwei Yan, Yong Yu 0002, Shengling Wang 0001
IEEE Trans. Netw. Serv. Manag.4
2023 Practical Asynchronous Distributed Key Generation: Improved Efficiency, Weaker Assumption, and Standard Model
abstract
Distributed key generation (DKG) allows bootstrapping threshold cryptosystems without relying on a trusted party, nowadays enabling fully decentralized applications in blockchains and multiparty computation (MPC). While we have recently seen new advancements for asynchronous DKG (ADKG) protocols, their performance remains the bottleneck for many applications, with only one protocol being implemented (DYX+ ADKG, IEEE S&P 2022). DYX+ ADKG relies on the Decisional Composite Residuosity assumption (being expensive to instantiate) and the Decisional Diffie-Hellman assumption, incurring a high latency (more than 100s with a failure threshold of 16). Moreover, the security of DYX+ ADKG is based on the random oracle model (ROM) which takes hash function as an ideal function; assuming the existence of random oracle is a strong assumption, and up to now, we cannot find any theoretically-sound implementation. Furthermore, the ADKG protocol needs public key infrastructure (PKI) to support the trustworthiness of public keys. The strong models (ROM and PKI) further limit the applicability of DYX+ ADKG, as they would add extra and strong assumptions to underlying threshold cryptosystems. For instance, if the original threshold cryptosystem works in the standard model, then the system using DYX+ ADKG would need to use ROM and PKI. In this paper, we design and implement a modular ADKG protocol that offers improved efficiency and stronger security guarantees. We explore a novel and much more direct reduction from ADKG to the underlying blocks, reducing the computational overhead and communication rounds of ADKG in the normal case. Our protocol works for both the low-threshold and high-threshold scenarios, being secure under the standard assumption (the well-established discrete logarithm assumption only) in the standard model (no trusted setup, ROM, or PKI).
Sisi Duan, Chao Liu 0039, Boxin Zhao, Xuanji Meng, Shengli Liu 0001, Yong Yu 0002, Fangguo Zhang, Liehuang Zhu
DSN7
2023 A post quantum secure multi-party collaborative signature with deterability in the Industrial Internet of Things
abstract
Industrial Internet-of-Things (IIoT for short) which is the basis of Industry 4.0, extends Internet connectivity beyond traditional computing devices, for example, smartphones, computers, laptops, webcams, etc., to the physical world for improving accuracy and efficiency while reducing the production cost. However, there exists large numbers of security threats, such as data leakage and privacy threats. To solve these issues, we first present a system model, security requirements and then proposed a post quantum secure multi-party collaborative signature with deterability in the IIoT environment. In this scheme, formal security proofs are given in the random oracle assuming that AMLWE and AMSIS problem are hard. We also demonstrate the potential utility of our proposed scheme by evaluating its performance.
Jiaming Wen 0001, Shunyu Dong, Yong Yu 0002
Future Gener. Comput. Syst.6
2023 Trustworthy decentralized collaborative learning for edge intelligence: A survey
abstract
Edge intelligence is an emerging technology that enables artificial intelligence on connected systems and devices in close proximity to the data sources. Decentralized Collaborative Learning (DCL) is a novel edge intelligence technique that allows distributed clients to cooperatively train a global learning model without revealing their data. DCL has a wide range of applications in various domains, such as smart city and autonomous driving. However, DCL faces significant challenges in ensuring its trustworthiness, as data isolation and privacy issues make DCL systems vulnerable to adversarial attacks that aim to breach system confidentiality, undermine learning reliability or violate data privacy. Therefore, it is crucial to design DCL in a trustworthy manner, with a focus on security, robustness, and privacy. In this survey, we present a comprehensive review of existing efforts for designing trustworthy DCL systems from the three key aformentioned aspects: security, robustness, and privacy. We analyze the threats that affect the trustworthiness of DCL across different scenarios and assess specific technical solutions for achieving each aspect of Trustworthy DCL (TDCL). Finally, we highlight open challenges and future directions for advancing TDCL research and practice.
Dongxiao Yu, Zhenzhen Xie 0002, Yuan Yuan 0014, Shuzhen Chen 0001, Jing Qiao, Yong Yu 0002, Yifei Zou, Xiao Zhang 0015
High Confid. Comput.7
2023 Privacy-Preserving Cross-Silo Federated Learning Atop Blockchain for IoT
abstract
Cross-silo federated learning (FL) is promising in facilitating data collaboration across various organizations, which greatly alleviates the information silo problem in industries and promotes the data intelligence of Internet of Things. With the advances of decentralized FL, the higher requirements of trust and privacy are put forward. Traditional FL heavily relies on a central coordinating server, which suffers from single points of failure and lacks trust in the correctness of aggregation results. What is more, the intrinsic privacy issues of FL have aroused public attention, such as gradient inversion attack in local gradients. However, the privacy of quantized gradients remains serious and lacks attention, especially the most extremely 1-bit quantization in sign-based FL. In this article, we demonstrate the potential privacy risk in sign-based FL by presenting a new gradient inversion attack, which successfully restores the original data from sign-based quantized gradients. And then we tackle the above two challenges via constructing a self-aggregation privacy-preserving FL atop blockchain, which takes advantage of a variant of ElGamal encryption to protect the privacy of local sign-based quantized gradients, and leverages the smart contract to achieve secure self-aggregation for participants without involving a centralized server. Moreover, we analyze that the proposed protocol achieves privacy and public verifiability. Finally, we evaluate the performance of the proposed protocol with a real deep learning model, and the results show that our protocol is resilient against gradient inversion attack in a decentralized environment without sacrificing learning accuracy.
Yu Sun 0015, Yong Yu 0002, Dawei Li 0009, Zhenyu Guan 0002, Jianwei Liu 0001
IEEE Internet Things J.3
2023 Trustworthy sealed-bid auction with low communication cost atop blockchain
Yong Yu 0002, Jiguo Yu, Lei Wang 0118
Inf. Sci.2
2023 Cross-Channel: Scalable Off-Chain Channels Supporting Fair and Atomic Cross-Chain Operations
abstract
Cross-chain technology facilitates the interoperability among isolated blockchains on which users can freely communicate and transfer values. Existing cross-chain protocols suffer from the scalability problem when processing on-chain transactions. Off-chain channel, as a promising blockchain scaling technique, can enable micro-payment transactions without involving on-chain transaction settlement. However, existing channel schemes can only be applied to operations within a single blockchain, failing to support cross-chain services. Therefore in this paper, we propose$\mathsf {Cross}$-$\mathsf {Channel}$, the first off-chain channel to support cross-chain services. We introduce a novel hierarchical channel structure with a hierarchical interaction protocol, a new hierarchical settlement protocol, and a smart general fair exchange protocol, to ensure scalability, fairness, and atomicity of cross-chain interactions. Besides,$\mathsf {Cross}$-$\mathsf {Channel}$provides strong security and practicality by avoiding high latency in asynchronous networks.Through a 50-instance deployment of$\mathsf {Cross}$-$\mathsf {Channel}$on AliCloud, we demonstrate that$\mathsf {Cross}$-$\mathsf {Channel}$is well-suited for processing cross-chain transactions in high-frequency and large-scale, and brings a significantly enhanced throughput with a small amount of gas and delay overhead.
Minghui Xu 0001, Dongxiao Yu, Yong Yu 0002, Rajiv Ranjan 0001, Xiuzhen Cheng
IEEE Trans. Computers4
2023 HyperMaze: Towards Privacy-Preserving and Scalable Permissioned Blockchain
abstract
Blockchain systems face two emergent problems, namely scalability and privacy, each of which has been addressed independently. However, how to achieve privacy and scalability simultaneously remains a challenging problem for blockchains. In this article, we propose a privacy-preserving and scalable permissioned blockchain system called HyperMaze employing the zero knowledge proof technique and a hierarchical system architecture. It gains scalability by adopting a hierarchy of multiple blockchains that processes transactions in parallel. We design anID-based dual-balance account modelwhere an identity-based account is associated with two types of balances–a plaintext balance and a private (zero-knowledge) balance. Furthermore, we design a two-phase cross-chain transaction mechanism (2PXT) to achieve transaction privacy for both intra-chain and cross-chain transactions. We rigorously formulate a security model for HyperMaze under the universal composability framework, and then provide a simulation-based security proof. A prototype of HyperMaze is implemented and a series of experiments are conducted over up to 2,600 nodes to evaluate its performance. The experimental results show that a 4-level, (7,10)-threshold, 6-ary HyperMaze system can reach 19,440 TPS and the transaction confirmation latency is only 9.5 seconds. To our best knowledge, HyperMaze is the first high-throughput privacy-preserving blockchain whose throughput is over 19,000 TPS.
Wei Liu 0149, Zhiguo Wan, Jun Shao 0001, Yong Yu 0002
IEEE Trans. Dependable Secur. Comput.4
2022 Your Breath Doesn't Lie: Multi-user Authentication by Sensing Respiration Using mmWave Radar
abstract
User authentication is critical to privacy preservation. Most of the existing works focus on single-user authentication, which may not work efficiently and practically in multi-user scenarios. To this end, we present a Multi-user Authentication system (M-Auth) that employs a single COTS mmWave radar to capture the user's unique breathing pattern. It exploits the phenomenon that radio frequency (RF) signals are affected by chest displacements due to breathing. We specifically design an auxiliary rotating gadget to dynamically adjust radar orientation, making it more effective in capturing respiration signals from multiple users. To profile individual components from the entangled RF signals, we leverage mmWave's high directivity to locate each user and separately focus on reflections from different positions. We propose a signal energy comparison method to eliminate the irrelevant body movements for preserving fine-grained respiration traits. Afterward, we develop a feature selection pipeline to elicit the most informative features and train a machine learning-based classifier to identify each user. M-Auth is practical due to its non-contact and passive nature, and it is secure as respiration is unique and difficult-to-forge. Extensive experiments involving 37 participants demonstrate that M-Auth is effective in verifying legitimate users and thwarting spoofing attacks, with an authentication accuracy of over 96 % and an attack detection rate of over 95%.
Yao Wang 0005, Tao Gu 0001, Tom H. Luan, Yong Yu 0002
SECON4
2022 Post quantum secure fair data trading with deterability based on machine learning
Yong Yu 0002, Hongliang Bi, Yanqi Zhao, Huanguo Zhang
Sci. China Inf. Sci.2
2022 Privacy protection in social applications: A ciphertext policy attribute-based encryption with keyword search
abstract
In a highly evolved big data era, intelligent data analysis can improve social operation efficiency and save resources. However, it also brings masses of conflicts, such as malicious mining and abuse of personal privacy information. This paper introduces a privacy protection scheme for social applications. In this scheme, attribute based searchable encryption is used to defend the security of confidential data and ensure the availability of data. Moreover, the access control structure of ciphertext strategy can meet the needs of data sharing in social applications. Security analysis shows that the scheme does not disclose privacy information in index ciphertext, search trapdoor, and equality test. Compared with plaintext information upload and sharing, the additional performance overhead caused by the scheme is acceptable. The scheme can be actually deployed in social applications.
Junbin Shi, Qiming Yu, Yong Yu 0002, Lianhai Wang
Int. J. Intell. Syst.3
2022 Blockchain-Based Auditable Privacy-Preserving Data Classification for Internet of Things
abstract
Internet of Things (IoT) connects massive physical devices to capture and collect useful data, which are used to make accurate decisions by taking advantage of the machine learning techniques. However, the collected data may contain users’ sensitive information. When guaranteeing the utility of data, we need to consider privacy of users’ data. To balance the utility and the privacy of data, the existing approaches usually adopt the privacy-preserving signature technology, where the privacy-preserving data are classified by a designated converter (data processor) interacting with a semihonest verifier (data center). However, for the malicious behavior of the data center and data processor, this kind of approach is insufficient. To prevent the malicious data center/data processor while guaranteeing the utility and privacy of data, we propose blockchain-based auditable privacy-preserving data classification (PPDC) scheme for IoT. We put forth a new controllably linkable group signature (CL-GS) to balance the utility and privacy of data and take advantage of blockchain to audit the correctness of privacy-preserving data classification against malicious data processor/data center. We formalize the system model of the auditable privacy-preserving data classification in the blockchain setting and its security model. Then, we present a concrete construction and prove its security in the random oracle model. Finally, we deploy a prototype system to evaluate the performance ofPPDC.
Yanqi Zhao, Xiaoyi Yang 0001, Yong Yu 0002, Baodong Qin, Xiaojiang Du, Mohsen Guizani
IEEE Internet Things J.3
2022 Lattice-Based Self-Enhancement Authorized Accessible Privacy Authentication for Cyber-Physical Systems
abstract
Healthcare cyber-physical system significantly facilitates healthcare services and patient treatment effectiveness by analyzing patients’ health information data conveniently. Nevertheless, it also develops the threats to the confidentiality of health information, patients’ privacy, and decidability of medical disputes. And, with the advances of quantum computing technology, most existing anonymous authentication schemes are becoming a growing threat to traditional cryptosystems. To address these problems, for healthcare cyber-physical systems, we propose a new lattice-based self-enhancement authorized accessible privacy authentication scheme by using a strong designated verifier double-authentication-preventing signature technique, called SEAPA. The SEAPA achieves three security and privacy requirements including unforgeability, anonymity for patients’ information, and self-enhancement for patients themselves. A detailed security proof shows our proposal achieves those required security goals. Finally, our construction is demonstrated by parameter analysis and performance evaluation to have reasonable efficiency.
Yong Yu 0002, Huanguo Zhang
Secur. Commun. Networks2
2022 A Blockchain-Based Self-Tallying Voting Protocol in Decentralized IoT
abstract
The Internet of Things (IoT) is experiencing explosive growth and has gained extensive attention from academia and industry in recent years. However, most of the existing IoT infrastructures are centralized, which may cause the issues of unscalability and single-point-of-failure. Consequently, decentralized IoT has been proposed by taking advantage of the emerging technology called blockchain. Voting systems are widely adopted in IoT, for example a leader election in wireless sensor networks. Self-tallying voting systems are alternatives to unsuitable, traditional centralized voting systems in decentralized IoT. Unfortunately, self-tallying voting systems inherently suffer from fairness issues, such as adaptive and abortive issues caused by malicious voters. To address these issues, in this article, we introduce a framework of the self-tallying voting system in decentralized IoT based on blockchain. We propose a concrete construction and prove that the proposed system satisfies all the security requirements, including fairness, dispute-freeness, and maximal ballot secrecy. We simulate the algorithms on a laptop, an Android phone, and a Raspberry Pi to test the time consumption and evaluate the gas cost of each algorithm in a private blockchain as well. The implementation results demonstrate the practicability of our system.
Yannan Li 0001, Willy Susilo, Guomin Yang, Yong Yu 0002, Dongxi Liu, Xiaojiang Du, Mohsen Guizani
IEEE Trans. Dependable Secur. Comput.4
2022 Identity-Based Provable Data Possession From RSA Assumption for Secure Cloud Storage
abstract
As cloud storage services have become popular nowadays, the integrity of outsourced data stored at untrusted servers received increased attention. Provable data possession (PDP) provides an effective and efficient solution for cloud data integrity by asking the cloud server to prove that the stored data are not tampered with or maliciously discarded without returning the actual data to users. In this article, we propose an efficient identity-based privacy-preserving provable data possession scheme (ID-P$^3$DP) based on the RSA assumption for secure cloud storage. In ID-P$^3$DP, a cloud user takes the outsourcing file and a global parameter in a time period as inputs to generate identity-based homomorphic authenticators, and any third-party auditor (TPA) can check the integrity of the outsourced file by verifying the validity of homomorphic authenticators. The distinguished feature of ID-P$^3$DP is to support the aggregation of identity-based homomorphic authenticators generated by different users under the RSA assumption, which is an open problem in provable data possession. Specifically, we transfer the identity-based homomorphic authenticators generated in distinct time periods into those with the same period parameter, and the cloud can compress the homomorphic authenticators of different users to generate a data possession proof for integrity verification. Besides, by exploiting zero-knowledge proof, the leakage of outsourced data to TPA can be prevented. The soundness of ID-P$^3$DP is proved based on the RSA assumption, and the privacy against TPA is perfectly preserved. Finally, we demonstrate ID-P$^3$DP is more efficient on integrity verification than the existing BLS-based schemes, and cross-user aggregate verification can significantly reduce computational and communication overhead for TPA.
Jianbing Ni, Kuan Zhang 0001, Yong Yu 0002, Tingting Yang 0001
IEEE Trans. Dependable Secur. Comput.3
2021 Concise Mercurial Subvector Commitments: Definitions and Constructions
Yannan Li 0001, Willy Susilo, Guomin Yang, Tran Viet Xuan Phuong, Yong Yu 0002, Dongxi Liu
ACISP5
2021 Non-Equivocation in Blockchain: Double-Authentication-Preventing Signatures Gone Contractual
abstract
Equivocation is one of the most fundamental problems that need to be solved when designing distributed protocols. Traditional methods to defeat equivocation rely on trusted hardware or particular assumptions, which may hinder their adoption in practice. The advent of blockchain and decentralized cryptocurrencies provides an auspicious breakthrough paradigm to resolve the problem above. In this paper, we propose a blockchain-based solution to address contractual equivocation, which supports user-defined fine-grained policy-based equivocation. Specifically, users will be de-incentive if the statements they made breach the predefined access rules. The core of our solution is a newly introduced primitive named Policy-Authentication-Preventing Signature (PoAPS), which combined with a deposit mechanism allows a signer to make conflict statements corresponding to a policy to be penalized. We present a generic construction of PoAPS based on Policy-Based Verifiable Secret Sharing (PBVSS) and demonstrate its practicality via a concrete implementation in the blockchain. Compared with the existing solutions that only handle specific types of equivocation, our proposed approach is more generic and can be instantiated to deal with various kinds of equivocation.
Yannan Li 0001, Willy Susilo, Guomin Yang, Yong Yu 0002, Tran Viet Xuan Phuong, Dongxi Liu
AsiaCCS4
2021 Post-Quantum Secure Ring Signatures for Security and Privacy in the Cybertwin-Driven 6G
abstract
Cybertwin-driven-based network architecture for sixth generation (6G) is a new cloud-centric network architecture, which was put forward to address challenges of 6G, such as scalability, security, mobility, and availability. As more and more users’ data are obtained and converted into other digital asset by the cybertwin, relevant techniques of data management to enhance privacy and security becomes a key challenge for Cybertwin-driven 6G. The double authentication preventing ring signature (DAPRS) is a cryptographic primitive that meets requirements of authenticity, anonymity of users’ private data, and linkability of users’ misbehavior, so it is suitable for monitoring behaviors of risky users. In this article, we propose a post-quantum secure ring signature to enhance security and privacy in Cybertwin-driven 6G (PRSG). In the PRSG, we first put forward an accumulator based on a chameleon hash function that allows to efficiently prove knowledge of an accumulated value. Then, we construct a DAPRS based on the accumulator and the zero-knowledge argument of knowledge. Finally, we present how to use the DAPRS to build a secure and efficient privacy-preserving scheme in the Cybertwin-driven 6G. Security proof shows that this scheme achieves anonymity, unforgeability, as well as double signature extractability. Also, we make some security analysis and performance evaluation to demonstrate that the PRSG has low communication complexity, high performance, and privacy preservation in the cybertwin-driven 6G.
Yong Yu 0002
IEEE Internet Things J.2
2021 DRBFT: Delegated randomization Byzantine fault tolerance consensus protocol for blockchains
Baocang Wang, Rongxing Lu, Yong Yu 0002
Inf. Sci.4
2021 Traceable Monero: Anonymous Cryptocurrency with Enhanced Accountability
abstract
Monero provides a high level of anonymity for both users and their transactions. However, many criminal activities might be committed with the protection of anonymity in cryptocurrency transactions. Thus, user accountability (or traceability) is also important in Monero transactions, which is unfortunately lacking in the current literature. In this paper, we fill this gap by introducing a new cryptocurrency named Traceable Monero to balance the user anonymity and accountability. Our framework relies on a tracing authority, but is optimistic, in that it is only involved when investigations in certain transactions are required. We formalize the system model and security model of Traceable Monero. We present a detailed construction of Traceable Monero by overlaying Monero with two types of tracing mechanisms, tracing the one-time addresses with money flows and tracing the long-term addresses. We prove the security of Traceable Monero and implement a prototype of the system, which demonstrates that Traceable Monero incurs merely a very small overhead in generating and verifying a transaction compared to Monero transactions.
Yannan Li 0001, Guomin Yang, Willy Susilo, Yong Yu 0002, Man Ho Au, Dongxi Liu
IEEE Trans. Dependable Secur. Comput.4
2021 Time-Efficient Ensemble Learning with Sample Exchange for Edge Computing
abstract
In existing ensemble learning algorithms (e.g., random forest), each base learner’s model needs the entire dataset for sampling and training. However, this may not be practical in many real-world applications, and it incurs additional computational costs. To achieve better efficiency, we propose a decentralized framework:Multi-Agent Ensemble.The framework leverages edge computing to facilitate ensemble learning techniques by focusing on the balancing of access restrictions (small sub-dataset) and accuracy enhancement. Specifically, network edge nodes (learners) are utilized to model classifications and predictions in our framework. Data is then distributed to multiple base learners who exchange data via an interaction mechanism to achieve improved prediction. The proposed approach relies on a training model rather than conventional centralized learning. Findings from the experimental evaluations using 20 real-world datasets suggest that Multi-Agent Ensemble outperforms other ensemble approaches in terms of accuracy even though the base learners require fewer samples (i.e., significant reduction in computation costs).
Wu Chen 0005, Yong Yu 0002, Keke Gai, Jiamou Liu, Kim-Kwang Raymond Choo
ACM Trans. Internet Techn.2
2021 PrivCrowd: A Secure Blockchain-Based Crowdsourcing Framework with Fine-Grained Worker Selection
abstract
Blockchain‐based crowdsourcing systems can mitigate some known limitations of the centralized crowdsourcing platform, such as single point of failure and Sybil attacks. However, blockchain‐based crowdsourcing systems still endure the issues of privacy and security. Participants’ sensitive information (e.g., identity, address, and expertise) have the risk of privacy disclosure. Sensitive crowdsourcing tasks such as location‐based data collection and labeling images including faces also need privacy‐preserving. Moreover, current work fails to balance the anonymity and public auditing of workers. In this paper, we present a secure blockchain‐based crowdsourcing framework with fine‐grained worker selection, named PrivCrowd which exploits a functional encryption scheme to protect the data privacy of tasks and to select workers by matching the attributes. In PrivCrowd, requesters and workers can achieve both exchange and evaluation fairness by calling smart contracts. Solutions collection also can be done in a secure, sound, and noninteractive way. Experiment results show the feasibility, usability, and efficiency of PrivCrowd.
Qiliang Yang, Tao Wang 0039, Bo Yang 0003, Yong Yu 0002, Zirui Qiao
Wirel. Commun. Mob. Comput.5
2020 Blockchain-Based Dynamic Provable Data Possession for Smart Cities
abstract
Smart cities have experienced rapid development with the advances of information and communication technologies such as Internet of Things (IoT). To tackle the data storage issues raised by large-scale data generated by IoT devices, an increasing number of enterprises and individuals prefer to outsource their data to cloud, where data integrity becomes a concern to cloud users. A variety of provable data possession (PDP) protocols have been proposed for centralized cloud storage scenarios so far. However, a centralized cloud relies too much on the trust of the central servers and, thus, is prone to the single point of failure. In this article, we describe a blockchain-based PDP model to realize the decentralized outsourcing storage framework, and then present a concrete construction of decentralized PDP by using multireplica storage tricks. Moreover, our protocol provides dynamic operations for outsourced data and at the same time, guarantees the fairness of all parties involved. We provide a detailed security proof for the proposed protocol and deploy a smart contract for the protocols as well. We finally evaluate the algorithms and the implementation results demonstrate the practicability of the proposed protocol.
Yannan Li 0001, Yong Yu 0002, Xiaofeng Chen 0001, Willy Susilo
IEEE Internet Things J.3
2020 Improved Security of a Pairing-Free Certificateless Aggregate Signature in Healthcare Wireless Medical Sensor Networks
abstract
Certificateless aggregate signature (CLAS) schemes reduce the trust on the key generation center of identity-based signatures and thus partially address the inherent key escrow issue in identity-based cryptosystems while retaining the advantage of implementation efficiency. In the past few years, a number of new CLAS schemes were proposed to overcome the communicational and computational limitations of sensors and attain integrality, validity, and availability of patients' medical data in healthcare wireless medical sensor networks (HWMSNs). However, many of these schemes do not provide enough security guarantees. In this article, we first review a most recent CLAS scheme for HWMSNs and show that it is insecure for medical applications by presenting attacks due to a type I adversary and a type II adversary. Then, we put forth an improved construction which is provably secure under the CLAS security model in the random oracle model. Our detailed analyses demonstrate that the proposed scheme not only overcomes the security flaws but also has higher implementation efficiency and lower communication cost.
Lianhai Wang, Yong Yu 0002
IEEE Internet Things J.3
2020 IntegrityChain: Provable Data Possession for Decentralized Storage
abstract
Outsourced storage enables data owners to host their data on remote storage resources without keeping a local copy so as to target their core business. However, a serious problem is data integrity in the sense that data owners lose their physical control over the remote-stored data. Existing provable data possession protocols are overwhelmingly designed for centralized storage such as cloud, in which the server is assumed dishonest but the client is reliable. Moreover, the centralized storage suffers single-point-of-failure threat. In this paper, to deal with these issues, we propose the notion of IntegrityChain, a decentralized storage framework supporting provable data possession (PDP) based on blockchain. We formalize the system model, in which a data owner can store files to the peers in a blockchain network and check the integrity of the outsourced data periodically by paying some cryptocurrencies while the hosts can earn money if honestly provide storage service and will be punished by losing the pre-made deposit if data loss happens. In the security model, we consider the fairness in trading between a host and a data user and the soundness of the underlying decentralized PDP in this system. We come up with a concrete construction by borrowing the idea of multi-replica PDP and proof-of-retrievability and present the security analysis of the proposal. The evaluation for the construction contain two segments: the offchain part, in which we implement the algorithms locally to test the time consumption, and onchain part, in which we program a smart contract and launch it in a test network to test the gas cost for the functions.
Yannan Li 0001, Yong Yu 0002, Xiaojiang Du, Mohsen Guizani
IEEE J. Sel. Areas Commun.2
2020 Key-Policy Attribute-Based Encryption With Keyword Search in Virtualized Environments
abstract
Cloud computing is a model for convenient, on-demand network access to virtualized environments of configurable computing resources. It is challenging to search data encrypted and stored in cloud storage servers. Searchable encryption enables data users to search on ciphertext without leaking any information about keywords and the plaintext of the data. Currently, a number of searchable encryption schemes have been proposed, but most of them provide unlimited search privileges to data users, which is not desirable in certain scenarios. In this paper, we propose a new construction of searchable encryption with fine-grained access control by using key-policy attribute-based cryptography to generate trapdoors to support AND, OR and threshold gates. The main idea is that the data owner encrypts the index keywords according to the specified access policy. The data user can generate a trapdoor to search on data, if and only if the attributes of the data user satisfy the access policy. We provide formal security proofs for the scheme, including the indistinguishability of ciphertexts and the indistinguishability of trapdoors, which are used to resist the chosen keyword attack and the keyword guessing attack of external adversaries. Comprehensive security analysis and implementation results show that the proposed scheme is provably secure and feasible in real-world applications.
Yong Yu 0002, Junbin Shi, Yannan Li 0001, Xiaojiang Du, Mohsen Guizani
IEEE J. Sel. Areas Commun.1
2020 Providing Task Allocation and Secure Deduplication for Mobile Crowdsensing via Fog Computing
abstract
Mobile crowdsensing enables a crowd of individuals to cooperatively collect data for special interest customers using their mobile devices. The success of mobile crowdsensing largely depends on the participating mobile users. The broader participation, the more sensing data are collected; nevertheless, the more replicate data may be generated, thereby bringing unnecessary heavy communication overhead. Hence it is critical to eliminate duplicate data to improve communication efficiency, a.k.a., data deduplication. Unfortunately, sensing data is usually protected, making its deduplication challenging. In this paper, we propose a fog-assisted mobile crowdsensing framework, enabling fog nodes to allocate tasks based on user mobility for improving the accuracy of task assignment. Further, a fog-assisted secure data deduplication scheme (Fo-SDD) is introduced to improve communication efficiency while guaranteeing data confidentiality. Specifically, a BLS-oblivious pseudo-random function is designed to enable fog nodes to detect and remove replicate data in sensing reports without exposing the content of reports. To protect the privacy of mobile users, we further extend the Fo-SDD to hide users' identities during data collection. In doing so, Chameleon hash function is leveraged to achieve contribution claim and reward retrieval for anonymous mobile users. Finally, we demonstrate that both schemes achieve secure, efficient data deduplication.
Jianbing Ni, Kuan Zhang 0001, Yong Yu 0002, Xiaodong Lin 0001, Xuemin Shen
IEEE Trans. Dependable Secur. Comput.3
2020 Blockchain-Based Anonymous Authentication With Selective Revocation for Smart Industrial Applications
abstract
Personal privacy disclosure is one of the most serious challenges in smart industrial applications. Anonymous authentication is an effective solution to protect personal privacy. However, the existing anonymous credential protocols are not perfectly suitablefor smart industrial environments such as smart vehicles in the sense that the credential revocation issue is not well-solved. In this article, we propose a Blockchain-based Anonymous authentication with Selective revocation for Smart industrial applications (BASS) for smart industrial applications supporting attribute privacy, selective revocation, credential soundness, and multishowing-unlinkability. Specifically, an efficient selective revocation mechanism is proposed based on dynamic accumulators and the signature algorithm due to Pointcheval and Sanders as the overlay of the BASS. According to the diverse demands of credential authorities, BASS can selectively provide revocation of credentials or revocation of users. We extend BASS from single-attribute privacy to multiattribute privacy as well. Finally, we implement a prototype to evaluate the cryptographic core primitives of BASS by deploying smart contracts in Ethereum to demonstrate the validity of BASS in smart industrial applications.
Yong Yu 0002, Yanqi Zhao, Yannan Li 0001, Xiaojiang Du, Lianhai Wang, Mohsen Guizani
IEEE Trans. Ind. Informatics1
2019 Anonymous Asynchronous Payment Channel from k-Time Accountable Assertion
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Nan Li 0007, Yong Yu 0002
CANS5
2019 Lattice Based Verifiably Encrypted Double Authentication Preventing Signatures
Yong Yu 0002
NSS2
2019 Leakage Resilient CCA Security in Stronger Model: Branch Hidden ABO-LTFs and Their Applications
abstract
Lossy trapdoor functions (LTFs) have already found various applications in cryptography with many priorities. But constructing leakage resilient (LR) CCA secure PKE schemes through this way received less attention. Existing works could only be proven secure in a weakened model due to the power of leakage attack. To address this problem, we introduce a new variant of ABO-LTF which is called branch hidden ABO-LTF (BHABO-LTF) in this paper. This primitive provides protection for the information of evaluated branches rather than lossy branches, which means even an adversary knows the information of the set of lossy branches, it can still not determine whether the output is evaluated on an injective or a lossy branch as long as the inversion key is kept secret. We observe that if this primitive has Chameleon property, we could present a generic construction of CCA secure PKE schemes. Due to the transparency of lossy branches of the primitive, we find that our construction can naturally be extended to accommodate leakage resilience. We give a generic construction with a realization of LR-BHABO-LTFs under the decisional composite residuosity assumption. This construction can be proved secure in a well-accepted security model rather than existing LTF-based ones in weak key-leakage model. Besides, without the need to hide the information of lossy branches, a Chameleon BHABO-LTF can be constructed by additively homomorphic CPA secure PKE alone. So our work can also be viewed as an interesting progress to give a construction of CCA secure PKE from additively homomorphic CPA secure PKE with certain properties as well as their LR counterparts, which has been a longstanding problem.
Yi Zhao 0011, Yong Yu 0002, Bo Yang 0003
Comput. J.2
2019 An efficient linkable group signature for payer tracing in anonymous cryptocurrencies
Lingyue Zhang, Yannan Li 0001, Yong Yu 0002, Man Ho Au, Baocang Wang
Future Gener. Comput. Syst.4
2019 LRCoin: Leakage-Resilient Cryptocurrency Based on Bitcoin for Data Trading in IoT
abstract
Currently, the number of Internet of Things (IoT) devices making up the IoT is more than 11 billion and this number has been continuously increasing. The prevalence of these devices leads to an emerging IoT business model called Device-as-a-service, which enables sensor devices to collect data disseminated to all interested devices. The devices sharing data with other devices could receive some financial reward, such as Bitcoin. However, side-channel attacks, which aim to exploit some information leaked from the IoT devices during data trade execution, are possible since most of the IoT devices are vulnerable to be hacked or compromised. Thus, it is challenging to securely realize data trading in IoT environment due to the information leakage, such as leaking the private key for signing a Bitcoin transaction in Bitcoin system. In this paper, we propose LRCoin, a kind of leakage-resilient cryptocurrency based on bitcoin in which the signature algorithm used for authenticating bitcoin transactions is leakage-resilient. LRCoin is suitable for the scenarios where information leakage is inevitable, such as IoT applications. Our core contribution is proposing an efficient bilinear-based continual-leakage-resilient ECDSA signature. We prove the proposed signature algorithm is unforgeable against adaptively chosen messages attack in the generic bilinear group model under the continual leakage setting. Both the theoretical analysis and the implementation demonstrate the practicability of the proposed scheme.
Yong Yu 0002, Yujie Ding, Yanqi Zhao, Yannan Li 0001, Yi Zhao 0011, Xiaojiang Du, Mohsen Guizani
IEEE Internet Things J.1
2019 Efficient attribute-based encryption with attribute revocation for assured data deletion
Yong Yu 0002, Yannan Li 0001, Man Ho Au, Xiaojiang Du, Bo Yang 0003
Inf. Sci.2
2019 Machine learning based privacy-preserving fair data trading in big data market
Yanqi Zhao, Yong Yu 0002, Yannan Li 0001, Xiaojiang Du
Inf. Sci.2
2019 Blockchain based privacy-preserving software updates with proof-of-delivery for Internet of Things
Yanqi Zhao, Aikui Tian, Yong Yu 0002, Xiaojiang Du
J. Parallel Distributed Comput.4
2019 An Approach Enabling Various Queries on Encrypted Industrial Data Stream
abstract
Massive data are generated and collected by devices in the industrial Internet of Things. Data sources would encrypt the data and send them to the data center through the gateway. For some supervision purpose, the gateway needs to observe the encrypted data stream and label the suspicious data. Instead of decrypting ciphertext at the gateway, which is not efficient, this paper presents a Φ -searchable functional encryption scheme that supports inner product evaluations on encrypted data. Based on this scheme, an approach enabling various queries on the encrypted industrial data stream is proposed. The adaptive security of our proposed underlying functional encryption scheme can be proven under general subgroup decision assumptions, and our scheme has the smaller public key, the smaller secret key, and the smaller ciphertext size compared to the related schemes. In addition, the experimental results show that our proposed scheme is efficient. Especially for the gateway, querying on the encrypted data only needs less than 20ms, which is practical for industrial data stream auditing scenario.
Tao Wang 0039, Bo Yang 0003, Guoyong Qiu, Lina Zhang 0003, Yong Yu 0002, Yanwei Zhou, Juncai Guo 0001
Secur. Commun. Networks5
2019 An alternative approach to public cloud data auditing supporting data dynamics
Tao Wang 0039, Bo Yang 0003, Yong Yu 0002, Guoyong Qiu, Zhe Xia
Soft Comput.4
2019 Fuzzy Identity-Based Data Integrity Auditing for Reliable Cloud Storage Systems
abstract
Data integrity, a core security issue in reliable cloud storage, has received much attention. Data auditing protocols enable a verifier to efficiently check the integrity of the outsourced data without downloading the data. A key research challenge associated with existing designs of data auditing protocols is the complexity in key management. In this paper, we seek to address the complex key management challenge in cloud data integrity checking by introducing fuzzy identity-based auditing, the first in such an approach, to the best of our knowledge. More specifically, we present the primitive of fuzzy identity-based data auditing, where a user's identity can be viewed as a set of descriptive attributes. We formalize the system model and the security model for this new primitive. We then present a concrete construction of fuzzy identity-based auditing protocol by utilizing biometrics as the fuzzy identity. The new protocol offers the property of error-tolerance, namely, it binds with private key to one identity which can be used to verify the correctness of a response generated with another identity, if and only if both identities are sufficiently close. We prove the security of our protocol based on the computational Diffie-Hellman assumption and the discrete logarithm assumption in the selective-ID security model. Finally, we develop a prototype implementation of the protocol which demonstrates the practicality of the proposal.
Yannan Li 0001, Yong Yu 0002, Geyong Min, Willy Susilo, Jianbing Ni, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.2
2018 Anonymous Identity-Based Hash Proof System from Lattices in the Standard Model
Qiqi Lai, Bo Yang 0003, Yong Yu 0002, Yuan Chen 0008, Liju Dong
ACISP3
2018 An Efficient Anonymous Authentication Scheme Based on Double Authentication Preventing Signature for Mobile Healthcare Crowd Sensing
Yong Yu 0002, Yannan Li 0001, Yanqi Zhao, Xiaojiang Du
Inscrypt2
2018 A Bignum Network Coding Scheme for Multipath Transmission in Vehicular Networks
abstract
The multipath transmission scheme in vehicular networks has become a hot topic. It is a great challenge to overcome the unreliability of wireless network in multipath transmission. Recently, scholars propose a lot of network coding schemes to solve this problem. These schemes implement network coding algorithms by bitwise X O R or Galois Field arithmetic. However, these schemes cannot take into account both coding flexibility and computational complexity. Therefore, we propose a BigNum Network Coding (BNNC) scheme. The core idea of the BNNC scheme is to treat a packet as an integer and implement the network coding through linear operations on the integer set. It replaces bitwise XOR and Galois Field arithmetic with integer arithmetic that guarantees high coding flexibility and low computational complexity. In this paper, first, we propose the BNN C scheme that can effectively improve the reliability of multipath transmission in vehicular networks with lower computational complexity than current network coding scheme. Second, we design the Independent Matrix that enables the coding process to improve coding efficiency without independent check. Third, we compare BNNC scheme with Earliest Completion First (ECF) and Galois Field network coding scheme through a lot of simulations and real tests. The results show that the BNN C scheme is significantly superior to the Galois Field network coding schemes in terms of computational performance. And in terms of the network performance, the BNNC scheme can overcome the unreliability of links in multipath transmission.
Yong Yu 0002, Xiaojiang Du, Hongbin Luo, Tao Zheng 0003, Mohsen Guizani
GLOBECOM3
2018 DSH: Deniable Secret Handshake Framework
Yangguang Tian, Yingjiu Li, Yinghui Zhang 0002, Nan Li 0007, Guomin Yang, Yong Yu 0002
ISPEC6
2018 An Efficient Privacy Preserving Batch Authentication Scheme with Deterable Function for VANETs
Yong Yu 0002, Yanqi Zhao, Jianwei Jia
NSS2
2018 Novel Smooth Hash Proof Systems Based on Lattices
abstract
As a basic and important primitive, hash proof system can be used to construct many cryptographic schemes and protocols. Therefore, it is significant to instantiate more efficient hash proof systems from various assumptions. Although there are many hash proof systems based on various classical assumptions, only a handful of efficient hash proof systems are known based on post-quantum assumptions. In this paper, we present several new hash proof systems based on the standard learning with errors (LWE) problem, which is at least as hard as standard worst-case lattice problems. Comparing with other existing constructions based on lattices, our main advantages are 2-fold: much simpler and more efficient. And our constructions can be easily extended to be identity-based ones and updatable ones. Throughout the paper, our main idea is to base hash proof systems on a new subset indistinguishability problem related to LWE, and employ the property of smooth parameter of q-ary orthogonal lattices to ensure smoothness.
Qiqi Lai, Bo Yang 0003, Yong Yu 0002, Yuan Chen 0008
Comput. J.3
2018 Structural Key Recovery of Simple Matrix Encryption Scheme Family
abstract
Advances in quantum computers threaten the security of public-key cryptosystems whose security is based on the hardness of factoring or on the discrete logarithm problem. Multivariate encryption schemes are promising alternatives to traditional cryptosystems. Tao et al. proposed a new Multivariate Public-Key Cryptosystem for encryption called simple matrix encryption scheme (ABC for short). Further, they proposed an improved simple matrix encryption schemes and a cubic simple matrix encryption scheme. In this paper, we show that the three schemes are vulnerable to a structural key recovery attack by tensor and vectorization notation and associated algebraic re-writing rules. We derive a set of linear equations from the public key whose solution yields an equivalent key pair that hide the central map. The proposed cryptanalysis approaches require polynomial computational complexity to achieve some equivalent keys from associated public keys. In addition, we provide an example to illustrate feasibility of proposed analysis method.
Yong Yu 0002, Bo Yang 0003, Jianwei Jia
Comput. J.2
2018 Privacy preserving cloud data auditing with efficient key update
Yannan Li 0001, Yong Yu 0002, Bo Yang 0003, Geyong Min, Huai Wu
Future Gener. Comput. Syst.2
2018 Updatable Identity-Based Hash Proof System Based on Lattices and Its Application to Leakage-Resilient Public-Key Encryption Schemes
Qiqi Lai, Bo Yang 0003, Yong Yu 0002, Zhe Xia, Yanwei Zhou, Yuan Chen 0008
J. Comput. Sci. Technol.3
2018 Assured Data Deletion With Fine-Grained Access Control for Fog-Based Industrial Applications
abstract
The advances of cloud computing, fog computing, and Internet of things (IoT) make industries more prosperous than ever. A wide range of industrial systems such as transportation and manufacturing systems have been developed by integrating cloud computing, fog computing, and IoT infrastructure successfully. However, in this sophisticated system, security and privacy issues are major concerns that hinder the widespread adoptions of these novel techniques. In this paper, we focus on assured data deletion, an issue that is important but received less attention in academia and industry. We first propose a framework to integrate the cloud, the fog, and the things together to manage stored data from industries or individuals. We then focus on secure data deletion in this framework by proposing an assured data deletion scheme that fulfills verifiable data deletion as well as flexible access control over sensitive data. Only data owners and fog devices are involved when deleting cloud data and validating the deletion of these data, which makes the protocol practical due to the features of low latency as well as real-time interaction with fog. The proposed protocol takes advantage of the attribute-based encryption, whose security can be proved under the standard model. The theoretical analysis shows good performance and functionality requirements while the implementation results demonstrate the feasibility of our proposal.
Yong Yu 0002, Yannan Li 0001, Xiaojiang Du, Mohsen Guizani, Bo Yang 0003
IEEE Trans. Ind. Informatics1
2017 Privacy-Preserving k-time Authenticated Secret Handshakes
Yangguang Tian, Shiwei Zhang 0003, Guomin Yang, Yi Mu 0001, Yong Yu 0002
ACISP (2)5
2017 Privacy-Preserving Extraction of HOG Features Based on Integer Vector Homomorphic Encryption
Haomiao Yang, Yunfan Huang, Yong Yu 0002, Mingxuan Yao, Xiaosong Zhang 0001
ISPEC3
2017 Improved dynamic remote data auditing protocol for smart city security
Li Zang, Yong Yu 0002, Yannan Li 0001, Yujie Ding, Xiaoling Tao
Pers. Ubiquitous Comput.2
2017 EACSIP: Extendable Access Control System With Integrity Protection for Enhancing Collaboration in the Cloud
abstract
It is widely acknowledged that the collaborations with more users increase productivity. Secure cloud storage is a promising tool to enhance such a collaboration. Access control system can be enabled with attribute-based encryption. In this system, a user encrypts and uploads his/her data to the cloud with an access policy, such that only people who satisfy that access policy can decrypt the data. When a recipient would like to enable another person who is originally unauthorized by the original access policy, this recipient will need to extend the access policy by adding a new policy that includes the new person hence, the notion of extendable access control system. Admitting new users to access the uploaded data is an important requirement in enhancing collaborations. The main issue is with regards to the integrity protection during the process of extending the access policy. When a new access policy is added, the cloud has to be sure that the extended access policy remains guarding the same encrypted data as the original access policy, even though the cloud cannot decrypt this ciphertext, which is a challenging problem to solve. In this paper, we answer the above problem affirmatively by introducing an extendable access control system with Integrity Protection (EACSIP), which is suitable to enhance collaboration in the cloud. The construction of EACSIP is built on top of a novel cryptographic primitive, namely functional key encapsulation with equality testing. The security proof and the performance evaluation of EACSIP are provided in this paper.
Willy Susilo, Peng Jiang 0007, Fuchun Guo, Guomin Yang, Yong Yu 0002, Yi Mu 0001
IEEE Trans. Inf. Forensics Secur.5
2017 Identity-Based Remote Data Integrity Checking With Perfect Data Privacy Preserving for Cloud Storage
abstract
Remote data integrity checking (RDIC) enables a data storage server, say a cloud server, to prove to a verifier that it is actually storing a data owner's data honestly. To date, a number of RDIC protocols have been proposed in the literature, but most of the constructions suffer from the issue of a complex key management, that is, they rely on the expensive public key infrastructure (PKI), which might hinder the deployment of RDIC in practice. In this paper, we propose a new construction of identity-based (ID-based) RDIC protocol by making use of key-homomorphic cryptographic primitive to reduce the system complexity and the cost for establishing and managing the public key authentication framework in PKI-based RDIC schemes. We formalize ID-based RDIC and its security model, including security against a malicious cloud server and zero knowledge privacy against a third party verifier. The proposed ID-based RDIC protocol leaks no information of the stored data to the verifier during the RDIC process. The new construction is proven secure against the malicious server in the generic group model and achieves zero knowledge privacy against a verifier. Extensive security analysis and implementation results demonstrate that the proposed protocol is provably secure and practical in the real-world applications.
Yong Yu 0002, Man Ho Au, Giuseppe Ateniese, Xinyi Huang 0001, Willy Susilo, Yuan-Shun Dai, Geyong Min
IEEE Trans. Inf. Forensics Secur.1
2016 Public Cloud Data Auditing with Practical Key Update and Zero Knowledge Privacy
Yong Yu 0002, Yannan Li 0001, Man Ho Au, Willy Susilo, Kim-Kwang Raymond Choo, Xinpeng Zhang 0001
ACISP (1)1
2016 Secure and Deduplicated Spatial Crowdsourcing: A Fog-Based Approach
abstract
With the proliferation of mobile devices, spatial crowdsourcing is rising as a new paradigm that enables individuals to participate in tasks related to some locations in the physical world. Nevertheless, how to allocate these tasks to proper mobile users and improve communication efficiency are critical in spatial crowdsourcing. In this paper, we propose Fo-DSC, a fog-based deduplicated spatial crowdsourcing framework to achieve precise task allocation and secure data deduplication. Specifically, by integrating fog computing, we design a two-step task allocation mechanism to improve the accuracy of tasks allocation in spatial crowdsourcing. The fog nodes can detect and erase the repeated data in crowdsensing reports without learning any information about the reports. Furthermore, Fo-DSC efficiently records the contributions of mobile users whose data are reduplicated and deleted. As a result, these users do not become discouraged. Finally, we demonstrate that Fo-DSC satisfies the properties of fog-based task allocation and secure data deduplication with low computational and communication overheads.
Jianbing Ni, Xiaodong Lin 0001, Kuan Zhang 0001, Yong Yu 0002
GLOBECOM4
2016 One-Round Attribute-Based Key Exchange in the Multi-party Setting
Yangguang Tian, Guomin Yang, Yi Mu 0001, Kaitai Liang, Yong Yu 0002
ProvSec5
2016 Cloud-Based Privacy-Preserving Parking Navigation Through Vehicular Communications
Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Yong Yu 0002, Xuemin Shen
SecureComm4
2016 Recent advances in security and privacy in large-scale networks
abstract
We are pleased to present to you 13 technical papers dealing with cutting-edge research and technology related to this topic. These papers were selected out of the significantly extended versions of the 149 submissions from 18 countries in the 3rd IEEE International Workshop on Large-Scale Network Security (LSNS 2014) and a large number of open submissions. The selection has been very rigorous, and only the best papers were selected. In the first paper, ‘An Error-Tolerant Keyword Search Scheme Based on Public-Key Encryption in Secure Cloud Computing’ 1, Yang et al. first present a general framework for searching on error-tolerant keywords based on a public-key encryption scheme. Then a concrete scheme is proposed based on the Cramer–Shoup cryptosystem. The scheme is chosen ciphertext attack secure, and suitable for all similarity metrics including Hamming distance metric, edit distance metric, and set difference metric. Because it does not require the user to construct and store anything in advance, very different from those cryptosystems used to calculate the trapdoor of keywords and to encrypt data documents, the new scheme tremendously eases the users' burden. In the second paper, ‘A Lightweight Privacy-Preserving Scheme with Data Integrity for Smart Grid Communications’ 2, Bao and Chen propose a lightweight data report scheme for smart grid communications, which can achieve privacy preservation and data integrity simultaneously. Specifically, an efficient pseudonym identity-based privacy-preserving report approach is proposed for the control center to obtain the fine-grained usage data of all the users while protecting user's privacy. An online/offline hash tree-based mechanism is also designed to check and assure data integrity of communications. Furthermore, a topology-independent data report architecture is also structured, which is adaptable for dynamic residential users to spontaneously form clusters and efficiently report data in flocks. Extensive performance evaluation demonstrates that the proposed scheme can achieve less communication overhead and dramatically reduce computational cost in comparison with the existing schemes. Secure biometric authentication aims to replace an encryption key or an identity certificate with biometrics to complete authentication. In the third paper, ‘A Secure Biometric Authentication Based on PEKS’ 3, Zhang et al. present a generic transformation from searchable encryption to secure biometric authentication and construct a specific secure biometric authentication scheme based on public key encryption with keyword search. Compared with some existing authentication schemes, the proposed scheme is more efficient in the practical application. Furthermore, the transformation from searchable encryption to secure biometric authentication presents a new direction of constructing authentication scheme. Certificateless aggregate signature schemes are required to satisfy the applications in certificateless environment. In the fourth paper, ‘A New Certificateless Signature with Enhanced Security and Aggregation Version’ 4, Deng et al. present an improved certificateless signature scheme and use it to construct a new certificateless signature scheme with enhanced security and aggregation. Compared with other schemes, the proposed scheme is more suitable for realistic applications. In the fifth paper, ‘Worm Propagation Model in Mobile Network’ 5, Chen et al. focus on mobile worm propagation model that allows to control and detect potential worm threat, according to the characteristics of worm's outbreak. Chen et al. put forward a worm propagation model based on the mobile network environment. After analyzing the model, it gives the simulation for controlling factors affecting worm propagation. This model allows us to have a certain understanding for the spread on the size and speed of the mobile worm, providing effective methods to control the spread of the mobile worm. In the sixth paper, ‘Efficient Privacy-Preserving Temporal and Spacial Data Aggregation for Smart Grid Communications’ 6, Dong et al. propose an efficient privacy-preserving temporal and spacial data aggregation from one-way functions in smart grid communications, which also allows special data aggregation from multiple users. The proposed construction can guarantee the unconditional security of users' metering power data privacy from the community gateway and the operation center, and the adaptive chosen ciphertext attack security of the aggregation result that can only be accessed by the authorized operation center. Both temporal and spacial data aggregation only require computing the underlying one-way function once. The provable multiple-replication data-possession protocol with full dynamics aims to realize efficient integrity verification and full dynamic data updates for cloud storage. In the seventh paper, ‘Provable Multiple Replication Data Possession with Full Dynamics for Secure Cloud Storage’ 7, Zhang et al. present a new multiple replication data possession scheme with full dynamics, in which a novel multiple replication Merkle hash tree with rank is used. The proposed scheme improves the efficiency of verifying updates for cloud storage with multiple replicas, which satisfies robust security properties. The eighth paper, ‘Efficient Group Key Management for Secure Big Data in Predictable Large-scale Networks’ 8, by He et al. focuses on secure group communication in large-scale social networks in which the entire social network may have millions of users but a concrete group is usually small. The paper proposes a new dynamic group key agreement protocol by using a novel dual-ring approach in which two rings of nodes are established, one active and one dummy. When some nodes leave, the remaining nodes can replace these nodes with dummy nodes, minimizing the required communications and computations after the protocol is set up and thus provides significant advantage over existing group key management protocols. The thorough analysis by the authors demonstrates provable security of the protocol and the superiority of computation and communication overload. The ninth paper, ‘Delegation of Signing Rights for Emerging 5G Networks’ 9, Ge et al. address the issue of delegating authentication in 5G networks by proposing a new proxy signature scheme. In their proposal, the original signer delegates his or her signing right by signing an exposure-free chameleon hash value as a warrant, and the proxy signer can generate a proxy signature on a message only by finding a chameleon hash collision instead of calculating a new digital signature, which can dramatically reduce computation cost of the proxy signer. With the emergence of cloud storage, searchable encryption technique that enables cloud clients to securely search over ciphertext through keywords and selectively retrieve records of interest has been extensively studied in both industry and academia. Unfortunately, most of the existing searchable encryption schemes cannot preserve keyword privacy and user privacy in multi-user setting simultaneously. For this end, in the 10th paper, ‘Revocable and Anonymous Searchable Encryption in Multi-user Setting’ 10, Miao et al. designed a secure and scalable cryptographic primitive based on identity-based encryption. As a further contribution, this proposed scheme can effectively resist decryption key exposure threat and achieve anonymous-revocable-ID-chosen plaintext attack (CPA) secure in the standard model. The location-based service (LBS) privacy protection scheme aims to solve the user's location privacy disclosure issue when the user initiates an LBS request. In the 11th paper, ‘DALP: A Demand-aware Location Privacy Protection Scheme in Continuous Location-based Services’ 11, Li et al. present a new anonymity-based scheme for continuous LBS queries, which allows a user to customize not only location privacy but also QoS requirement. The proposed scheme can maximize the demands-aware query sequence and minimize the constructed cloaking regions, thereby reducing the query latency and the server's workload. In the 12th paper, ‘Security Analysis of a Privacy-preserving Decentralized Ciphertext-Policy Attribute-based Encryption Scheme’ 12, Wang et al. point out the security weakness of a privacy-preserving decentralized ciphertext-policy attribute-based encryption scheme proposed 13, by Han et al. in ESORICS 2014. They present a collusion attack on the underlying decentralized ciphertext policy attribute based encryption (CP-ABE) scheme and additionally show that the privacy protection of attributes in the privacy-preserving key extraction protocol cannot be provided. The 13th paper, ‘Partner Selection of Agricultural Products Supply Chain Based on Data Mining’ 14, puts forward supply chain partner selection model and partner evaluation index system. With BP neural network, the agricultural products' supply chain partner-selection example analysis is made. The results show that the established supply chain partner-selection model has better generalization ability and can be effectively used to supply chain partner selection. We sincerely hope that you will enjoy reading these papers in this special issue. We thank all the international reviewers for their professional services. We deeply thank Professor Geoffrey Fox, the Editor-in-Chief, for providing this opportunity to publish this special issue. With his continuous support, encouragement, and guidance throughout this publishing project, this special issue has been very successful.
Yong Yu 0002, Yi Mu 0001, Rongxing Lu, Jian Ren 0001
Concurr. Comput. Pract. Exp.1
2016 SDIVIP2: shared data integrity verification with identity privacy preserving in mobile clouds
abstract
Summary Mobile networks integrate cloud computing to impair the weaknesses of the mobile terminals. With mobile cloud storage, mobile users can fully enjoy the advantages from both mobile networks and cloud storage. However, a major concern of mobile users is how to guarantee the integrity of their outsourced data. Taking into account the mobility of mobile devices, in this paper, we propose a shared data integrity verification protocol with identity privacy preserving, named SDIVIP2, for mobile cloud storage. In the construction of SDIVIP2, the dynamic group key agreement technique is employed for key sharing among a group of mobile users and the proxy re‐signature mechanism is utilized to update tags efficiently when users in the group change. In this new protocol, a third party auditor is able to verify the correctness of cloud data without the knowledge of mobile users' identities during the data integrity checking process. Performance analysis demonstrates that SDIVIP2outperforms the existing schemes in the sense that it can significantly enhance the efficiency of mobile users' joining and leaving a group. Copyright © 2015 John Wiley & Sons, Ltd.
Yong Yu 0002, Jianbing Ni, Qi Xia 0001, Haomiao Yang, Xiaosong Zhang 0001
Concurr. Comput. Pract. Exp.1
2016 Provable multiple replication data possession with full dynamics for secure cloud storage
abstract
Summary Cloud storage has been gaining tremendous popularity among individuals and corporations because of its low maintenance cost and on‐demand services for the clients. To improve the availability and the reliability of critical data, storing multiple replicas on multiple servers is a commonly used strategy. Currently, several provable data possession (PDP) protocols for multiple replicas of dynamic data have been proposed to ensure the integrity of outsourced multi‐copy data, but the efficiency of these protocols on verifying multiple replicas one by one is not satisfactory. In this paper, we propose a provable multiple replication data possession protocol with full dynamics, named MR‐DPDP. In MR‐DPDP, we utilize a novel authenticated data structure called Merkle hash tree with rank to support both full dynamic data updates and efficient integrity verification. In addition, our construction with RSA signature can support both variable‐sized file blocks and public verification. Through security proof and performance evaluation, we demonstrate that MR‐DPDP not only is sound but also incurs less communication overhead when updating data blocks as well as verifying a proof of the integrity of multiple replicas. Copyright © 2015 John Wiley & Sons, Ltd.
Yafang Zhang, Jianbing Ni, Xiaoling Tao, Yong Wang 0031, Yong Yu 0002
Concurr. Comput. Pract. Exp.5
2016 Cloud data integrity checking with an identity-based auditing mechanism from RSA
Yong Yu 0002, Man Ho Au, Willy Susilo, Jianbing Ni, Yafang Zhang, Athanasios V. Vasilakos, Jian Shen 0001
Future Gener. Comput. Syst.1
2016 Survey on key revocation mechanisms in wireless sensor networks
Kim-Kwang Raymond Choo, Huai Wu, Yong Yu 0002
J. Netw. Comput. Appl.4
2016 Comments on "Public Integrity Auditing for Dynamic Data Sharing With Multiuser Modification"
abstract
Recently, a practical public integrity auditing scheme supporting multiuser data modification (IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, DOI 10.1109/TIFS.2015.2423264) was proposed. Although the protocol was claimed secure, in this paper, we show that the proposal fails to achievesoundness, the most essential property that an auditing scheme should provide. Specifically, we show that a cloud server can collude with a revoked user to deceive a third-party auditor (TPA) that a stored file keeps virgin even when the entire file has been deleted.
Yong Yu 0002, Yannan Li 0001, Jianbing Ni, Guomin Yang, Yi Mu 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.1
2015 Provably Secure Identity Based Provable Data Possession
Yong Yu 0002, Yafang Zhang, Yi Mu 0001, Willy Susilo
ProvSec1
2015 On Indistinguishability in Remote Data Integrity Checking
abstract
With a rapid growth of data storage in the cloud, data integrity checking in a remote data storage system has become an important issue. A number of protocols, which allow remote integrity checking by a third party, have been proposed. Although those protocols are provably secure, the data privacy issues in those protocols have not been considered. We believe that these issues are equally important since the communication flows of integrity proofs from the cloud server should not reveal any useful information of the stored data. In this paper, we introduce a new definition of data privacy called ‘IND-Privacy’ by an indistinguishability game. It is found that many existing remote integrity proofs are insecure under an IND-Privacy game. It is also found that by adopting witness indistinguishable proofs, the IND-Privacy is achievable. We provide an instantiation that captures data integrity, soundness and IND-privacy.
Guomin Yang, Yi Mu 0001, Yong Yu 0002
Comput. J.4
2015 Secure Delegation of Signing Power from Factorization
abstract
Delegation of signing is a working way common in office automation work, and is also an important approach to establish trust. Proxy signature is an important cryptographic primitive for delegating signing powers and it has found many real-world applications. The existing proxy signature schemes from factorization assumption are either insecure or inefficient. In this paper, we propose a novel, efficient and provably secure proxy signature scheme from factorization. Our construction makes use of a factorization-based key exposure-free chameleon hash function in the delegation phase and the proxy signer needs only to find a collision to a chameleon hash value to generate a valid proxy signature. As a result, our scheme is highly efficient in terms of the computation of a proxy signature. We also provide a formal security proof by classifying the adversaries into three categories. Comparisons demonstrate that the new scheme outperforms the known ones in terms of security, computational efficiency and the length of the public key.
Yong Yu 0002, Man Ho Au, Yi Mu 0001, Willy Susilo, Huai Wu
Comput. J.1
2015 A secure and efficient Ciphertext-Policy Attribute-Based Proxy Re-Encryption for cloud data sharing
Kaitai Liang, Man Ho Au, Joseph K. Liu, Willy Susilo, Duncan S. Wong, Guomin Yang, Yong Yu 0002, Anjia Yang
Future Gener. Comput. Syst.7
2015 Remote data possession checking with enhanced security for cloud storage
Yong Yu 0002, Yafang Zhang, Jianbing Ni, Man Ho Au, Lanxiang Chen
Future Gener. Comput. Syst.1
2015 Advanced security analysis of a signature scheme with message recovery
abstract
Chang et al. proposed a new digital signature scheme with message recovery. However, several forgery attacks demonstrated that Chang et al.'s construction without using one-way hash functions and message redundancy is insecure. Nevertheless, it is unclear to see how to achieve the attacks. In this paper, more general forgery attacks are described to show clearly how to obtain these attacks. It is interesting that our general forgery covers all the known attacks.
Lei Niu, Changqing Zhang 0007, Qi Xia 0001, Yong Yu 0002
Int. J. Inf. Comput. Secur.4
2015 Comments on a Public Auditing Mechanism for Shared Cloud Data Service
abstract
Recently, a public auditing protocol for shared data called Panda (IEEE Transactions on Services Computing, doi: 10.1109/TSC.2013.2295611) was proposed to ensure the correctness of the outsourced data. A distinctive feature of Panda is the support of data sharing and user revocation. Unfortunately, in this letter, we show that Panda is insecure in the sense that a cloud server can hide data loss without being detected. Specifically, we show that even some stored file blocks have been lost, the server is able to generate a valid proof by replacing a pair of lost data block and its signature with another block and signature pair. We also provide a solution to the problem while preserving all the desirable features of the original protocol.
Yong Yu 0002, Jianbing Ni, Man Ho Au, Yi Mu 0001, Boyang Wang 0001, Hui Li 0006
IEEE Trans. Serv. Comput.1
2014 New Insight to Preserve Online Survey Accuracy and Privacy in Big Data Era
Joseph K. Liu, Man Ho Au, Xinyi Huang 0001, Willy Susilo, Jianying Zhou 0001, Yong Yu 0002
ESORICS (2)6
2014 An Adaptively CCA-Secure Ciphertext-Policy Attribute-Based Proxy Re-Encryption for Cloud Data Sharing
Kaitai Liang, Man Ho Au, Willy Susilo, Duncan S. Wong, Guomin Yang, Yong Yu 0002
ISPEC6
2014 Improvement of a Remote Data Possession Checking Protocol from Algebraic Signatures
Yong Yu 0002, Jianbing Ni, Jian Ren 0001, Wei Wu 0001, Lanxiang Chen, Qi Xia 0001
ISPEC1
2014 Identity Privacy-Preserving Public Auditing with Dynamic Group for Secure Mobile Cloud Storage
Yong Yu 0002, Yi Mu 0001, Jianbing Ni, Jiang Deng, Ke Huang 0002
NSS1
2014 Improved security of a dynamic remote data possession checking protocol for cloud storage
Yong Yu 0002, Jianbing Ni, Man Ho Au, Chunxiang Xu
Expert Syst. Appl.1
2014 On the security of auditing mechanisms for secure cloud storage
Yong Yu 0002, Lei Niu, Guomin Yang, Yi Mu 0001, Willy Susilo
Future Gener. Comput. Syst.1
2014 Security pitfalls of an efficient threshold proxy signature scheme for mobile agents
Yong Yu 0002, Yi Mu 0001, Willy Susilo, Man Ho Au
Inf. Process. Lett.1
2014 Efficient public key encryption with revocable keyword search
abstract
ABSTRACT Public key encryption with keyword search is a novel cryptographic primitive enabling one to search on the encrypted data directly. In the known schemes, once getting a trapdoor, the server can search associated data without any restrictions. However, in reality, it is sometimes essential to prevent the server from searching the data all the time because the server is not fully trusted. In this paper, we propose the notion of public key encryption with revocable keyword search to address the issue. We also develop a concrete construction by dividing the whole life of the system into distinct times to achieve our goals. The proposed scheme achieves the properties of the indistinguishability of ciphertexts against an adaptive chosen keywords attack security under the co‐decisional bilinear Diffie–Hellman assumption in our security model. Compared with two somewhat schemes, ours offers much better performance in terms of computational cost. Copyright © 2013 John Wiley & Sons, Ltd.
Yong Yu 0002, Jianbing Ni, Haomiao Yang, Yi Mu 0001, Willy Susilo
Secur. Commun. Networks1
2014 On the Security of an Efficient Dynamic Auditing Protocol in Cloud Storage
abstract
Using cloud storage, data owners can remotely store their data and enjoy the on-demand high quality cloud services without the burden of local data storage and maintenance. However, this new paradigm does trigger many security concerns. A major concern is how to ensure the integrity of the outsourced data. To address this issue, recently, a highly efficient dynamic auditing protocol (IEEE Transactions on Parallel and Distributed Systems, doi:10.1109/TPDS.2013.199) for cloud storage was proposed which enjoys many desirable features. Unfortunately, in this letter, we demonstrate that the protocol is insecure when an active adversary is involved in the cloud environment. We show that the adversary is able to arbitrarily modify the cloud data without being detected by the auditor in the auditing process. We also suggest a solution to fix the problem while preserving all the properties of the original protocol.
Jianbing Ni, Yong Yu 0002, Yi Mu 0001, Qi Xia 0001
IEEE Trans. Parallel Distributed Syst.2
2013 A Secure Scalar Product Protocol Against Malicious Adversaries
Bo Yang 0003, Yong Yu 0002, Chung-Huang Yang
J. Comput. Sci. Technol.2
2012 Improved certificateless signature scheme provably secure in the standard model
abstract
Certificateless cryptography shares many features of identity-based cryptography and partially solves the problem of key escrow. Three certificateless signature schemes without random oracles were found in the literature. However, all the schemes suffer from some common drawbacks. First, by obtaining a signature on a message and replacing the public key of a signer, an adversary can forge valid signatures on the same message under the replaced public key. Secondly, all the schemes require a relatively large size of public parameters. The authors propose a new certificateless signature scheme, which exhibits an improvement on the existing schemes. Compared with the previous schemes, the proposed scheme offers stronger security, shorter system parameters and higher computational efficiency.
Yong Yu 0002, Yi Mu 0001, Guilin Wang, Qi Xia 0001, Bo Yang 0003
IET Inf. Secur.1
2011 Cryptanalysis of an Off-Line Electronic Cash Scheme Based on Proxy Blind Signature
abstract
Proxy blind signature is an important cryptographic primitive and plays an essential role in construction of the electronic cash (e-cash). Recently, Tan (2001, An offline electronic cash scheme based on proxy blind signature. Comput. J., 54, 505–512) proposed a new proxy blind signature scheme and applied it to electronic cash. The scheme was claimed as being provably secure under the Discrete Log assumption, DBDH assumption and Chosen–Target CDH assumption in the random oracle model. In this paper, we show that Tan's proxy blind signature scheme is insecure by demonstrating several attacks in which a malicious original signer can forge both valid proxy signature keys of arbitrary proxy signers and a proxy blind signature on an arbitrary message with respect to any proxy signer directly. We also discuss some weaknesses in the e-cash scheme proposed by Tan.
Yong Yu 0002, Yi Mu 0001, Guilin Wang
Comput. J.1
2011 Improvement of a proxy multi-signature scheme without random oracles
Chunxiang Xu, Yong Yu 0002, Bo Yang 0003
Comput. Commun.3
2011 Strongly unforgeable proxy signature scheme secure in the standard model
Chunxiang Xu, Yong Yu 0002, Yi Mu 0001
J. Syst. Softw.3
2009 Identity Based Multi-proxy Multi-signcryption Scheme for Electronic Commerce
abstract
A new concept called multi-proxy multi-signcryption is introduced in this paper. In a multi-proxy multi-signcryption scheme, a group of original signcrypters can authorize a group of proxy signcrypters under the agreement of all signcrypters in the original group. Then only the cooperation of all signcrypters in the proxy group could generate a multi-proxy multi-signcryption. We propose a multi-proxy multi-signcryption scheme based on bilinear pairings. The proposed scheme has the following characteristics: (i) the size of multi-proxy multi-signcryption is independent of the number of original and proxy signcrypters. (ii) it provides the fair protection for the original signcrypter group and the proxy group.(iii) the key management problem is simplified because of using ID-based cryptography. Finally, we give an application of the proposed scheme in electronic commerce.
Chunxiang Xu, Fagen Li, Yong Yu 0002
IAS4
2009 Analysis and Improvement of a Proxy Blind Multi-signature Scheme without a Secure Channel
abstract
Proxy blind signature is a cryptographic research hotspot, and has been applied in many occasions. Many proxy blind signature schemes were proposed, however, all the schemes rely on secure channels to transmit proxy secret key. Therefore, Lu, Cao and Zhou proposed a new proxy blind multi-signature scheme recently, which does not need a secure channel and is provably secure under the random oracle model. In this letter, however, we show that their scheme is not secure against the original signer's forgery attack. Moreover, we give four improved proxy key generation algorithms to counter this attack.
Chunxiang Xu, Qi Xia 0001, Yong Yu 0002
IAS4
2007 Provably Secure Identity-Based Threshold Unsigncryption Scheme
Bo Yang 0003, Yong Yu 0002, Fagen Li
ATC2
2007 Efficient Identity-Based Signcryption Scheme for Multiple Receivers
Yong Yu 0002, Bo Yang 0003, Xinyi Huang 0001, Mingwu Zhang
ATC1