VLDB 2026 Research / reviewers in the wild / expert
Hui Ma 0002
dblp:46/5778-2
· DBLP profile ↗
38ranked-venue papers
6as first author
22since 2021 · last 2026
0000-0001-8359-5158ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 5 first-author · 14 since 2021Systems, architecture and hardware · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Securing leakage and collusion attacks on encrypted cloud storage using memorizable passwordsabstractAbstract Encryption is the most direct technique to protect data confidentiality when users outsource their data to the cloud. Typically, ciphertexts are stored in the cloud, while cryptographic keys are managed by a key management server (KMS). However, this approach introduces new challenges in securely managing both keys and ciphertexts. Specifically, two crucial issues remain unresolved. One is that the simultaneous leakage of data encryption key and ciphertexts stored in cloud can directly compromise user data. Another is that if the cloud and KMS collude, they can trivially retrieve user data. In this work, we propose a Password-protected Encrypted Cloud Storage scheme PECS that is resilient to the aforementioned leakage and collusion attacks. In PECS, the users can encrypt/decrypt their data using only a password without storing any key material, and neither the cloud nor KMS learns any information about the user data or keys. Technically, we introduce a re-encryption mechanism performed by the cloud to prevent an adversary from obtaining the original ciphertexts. Furthermore, the user encrypts key wrap before sending it to the cloud, under a pair of password-derived secret and public key. Both the data encryption keys and password are protected from being exposed by the servers through an oblivious pseudorandom function (OPRF). Provable security and efficiency of PECS are demonstrated through comprehensive analyses. Shihan Qin, Rui Zhang 0002, Hui Ma 0002 |
Cybersecur. | 3 |
| 2026 | A Practical Dynamic Searchable Symmetric Encryption Scheme With Trusted Hardware-Assisted
Yang Yang 0192, Tianming Hou, Haihui Fan, Bo Li 0063, Xiaoyan Gu 0001, Jinchao Zhang 0002, Hui Ma 0002, Weiping Wang 0005 |
IEEE Trans. Computers | 7 |
| 2026 | MithrilRB: Resource-Efficient Redactable Blockchain With Single-Use AuthorizationabstractRedactable blockchains preserve the integrity of hash links while enabling authorized redactions to comply with regulatory requirements. However, existing permissioned solutions suffer from three severe issues. First, fine-grained privilege control incurs significant storage overhead, especially in the case of single-use authorization. Second, the reliance on bilinear pairings in chameleon hash leads to significant performance degradation when handling large-scale redaction requests. Finally, multiple incorporated components often unconsciously introduce centralized entities, undermining the decentralized nature. In this paper, we propose MithrilRB, a resource-efficient and decentralized redactable blockchain with single-use authorization. Specifically, we introduce a privilege control mechanism with our proposed multi-authority attribute-based signature (MA-ABS) and the threshold BLS signature, achieving fine-grained single-use authorization and direct user revocation without extra ciphertext storage. We also design a pairing-free non-interactive threshold chameleon hash (PNITCH), which enhances efficiency and is better suited for large-scale redaction requests. Moreover, MithrilRB eliminates centralized trust points that hold secret information, ensuring fully decentralization-compatible functional integration in redactable blockchains. Finally, we implement MithrilRB, and the experimental results demonstrate that MithrilRB significantly outperforms existing solutions in both computational efficiency and storage requirements. Tianming Hou, Hui Ma 0002, Jinchao Zhang 0002, Yang Li 0192, Bo Li 0063, Weiping Wang 0005 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Efficient Privacy-Preserving Image Retrieval With User Revocation in Mobile CloudabstractAs image data outsourcing to mobile cloud grows, data privacy has become a major concern. Privacy-preserving image retrieval aims to search over encrypted data without requiring decryption. However, existing schemes face three critical challenges: struggle to balance accuracy, efficiency, and security; limited scalability for large-scale image retrieval in multi-user settings; and vulnerability to security threats arising from user permission changes or key compromises. In this paper, we propose ELSEIR, a novel framework for accurate, efficient, and privacy-preserving image retrieval. ELSEIR leverages a deep hashing model to extract image feature vectors and designs an irreversible random hash code generation module that combines secure permutation keys with two differential privacy methods for privacy protection. To enable accurate searches in multi-user settings, ELSEIR introduces a key conversion protocol that allows the cloud to unify ciphertexts encrypted under different user keys via corresponding switch keys. Furthermore, we extend the framework to ABE-ELSEIR, which supports immediate and efficient user revocation. We further provide formal security proofs demonstrating that the proposed frameworks are resilient against known-plaintext and key collusion attacks. Extensive experiments on real-world datasets show that our scheme achieves accuracy comparable to the unprotected baseline, while surpassing existing approaches in both retrieval accuracy and efficiency. Haihui Fan, Hui Ma 0002, Shuaishuai Chang, Xiaoyan Gu 0001, Zhangjie Fu 0001, Bo Li 0063 |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | ShieldIR: Privacy-Preserving Unsupervised Cross-Domain Image Retrieval via Dual Protection TransformationabstractUnsupervised cross-domain image retrieval (UCDIR) aims to retrieve images across different domains without the guidance of labels. However, existing UCDIR methods assume that data can be shared across domains in plaintext, which is often impractical due to strict data privacy protection policies. In this paper, we propose ShieldIR, a novel privacy-preserving unsupervised cross-domain image retrieval framework that enhances the retrieval performance across two domains while safeguarding data privacy. ShieldIR unifies intra-domain and cross-domain representation learning through a Dual Protection Transformation (DPT) module, which introduces a structured feature space via orthogonal projection and ensures data privacy by adding calibrated differential privacy noise. This transformation allows ShieldIR to preserve semantic structure while formally protecting private data. For intra-domain representation learning, ShieldIR enhances discriminability by using DPT to map prototypes into an independent feature space and subsequently aligning the resulting dual-protected prototypes with instance-level features. For cross-domain alignment, ShieldIR maps intra-domain features and cross-domain prototypes into a shared structured space using DPT, achieving semantic alignment under privacy constraints. Extensive experiments on real-world datasets demonstrate that our ShieldIR outperforms state-of-the-art methods while effectively protecting data privacy. Haihui Fan, Jinchao Zhang 0002, Hui Ma 0002, Xiaoyan Gu 0001, Bo Li 0063, Weiping Wang 0005 |
ACM Multimedia | 4 |
| 2025 | Enabling efficient and accurate semantic search over encrypted cloud data
Haihui Fan, Xiaoyan Gu 0001, Hui Ma 0002, Athanasios V. Vasilakos, Bo Li 0063 |
Inf. Sci. | 5 |
| 2025 | RevokAll: Hardware-Assisted Revocable Data Sharing Framework for Full Data Traffic With Rapid Deployment in Cloud-EdgeabstractSecure cloud-edge data sharing has been researched recently to provide high quality on-demand data service. Attribute-based encryption (ABE) is a promising solution that achieves data confidentiality and flexible access control simultaneously. But three major issues remain when adapting ABE in cloud-edge, namely reliable user revocation, high performance on devices, and trust issues of public cloud. First, existing direct user revocation mechanisms focus on preventing a revoked user from decrypting header ciphertexts even when key exposure occurs, but ignore the payload security. Second, how to conveniently apply deployment on diverse platforms and run programs on resource-constrained devices with high efficiency is a challenge. Finally, no universal guarantee of cloud computation and management tasks, thus lazy or malicious cloud may not follow the protocol and perform improper actions on purpose. In this work, we propose a Hardware-Assisted Hybrid Fully Outsourced Revocable Attribute-Based Proxy Re-Encryption (H²O-RABPRE) scheme that supports reliable user revocation for full data traffic and hardware-assisted fully outsourced computation. Moreover, we design a hardware-assisted data-sharing framework with rapid deployment for cloud-edge, which integrates the developed SGX-MCL to protect outsourced tasks executed by cloud/edge devices against malicious behaviors and utilizes the enhanced WebAssembly runtime, WasmCrypto, a unified deployment approach for IoT devices with near-native performance. We implement the scheme on an SGX cloud server, a laptop, a Raspberry Pi, and an ESP32 board, and the results indicate that the proposed scheme is practical. Shuaishuai Chang, Hui Ma 0002, Jianting Ning, Yuzhe Li 0001, Bo Li 0063, Weiping Wang 0005 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Hodor: Robust Fine-Grained Information Flow Control With Full Data Traffic Protection for Cloud-Edge ComputingabstractCloud-edge computing has been widely-adopted for large-scale data sharing and processing. In practical data sharing systems, data are very sensitive and typically encrypted, such as health records. Unauthorized users may attempt to decrypt ciphertexts to recover the data. Due to mistakes or malice, some users might try to share sensitive information with others who do not have access. Clearly, strong access control should be employed to restrict the read and write privilege of users. There was a rich literature on mandatory fine-grained information flow control for such scenarios, but three important issues remain. First, payload privacy was often neglected. Most of the known solutions focused on the protection ciphertext header, but ignored the payload, i.e. encrypted data, which may leak information by a malicious sender. Second, no guarantee of the encrypted data. Ill-formed ciphertexts, e.g. encrypted garbage data, can pass the global policy check, causing decryption failures or disseminating bad information, hence are incapable of content distribution. Finally, the heavy computation cost of sender authentication impedes the practical deployment. In this work, we introduce Hodor, a robust fine-grained information flow control scheme that not only guards the transmission channel with mandatory fine-grained access control for massive data, but also protects whole data traffic, checks ciphertext well-formedness, and efficiently authenticates the sender. In particular, Hodor considers full data traffic protection of both the ciphertext header and encrypted payload to resist information leakage, completely verifies the consistency between the claimed access structure and the actual access structure, and achieves efficient sender authentication with a succinct challenge-response protocol. We present a formal model and give detailed proofs. We also implement and evaluate Hodor using various optimization techniques to boost its performance. The results demonstrate the efficiency and practicality of Hodor for cloud-edge data sharing. Yansen Xin, Hui Ma 0002, Rui Zhang 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | SMSSE: Size-Pattern Mitigation Searchable Symmetric EncryptionabstractSearchable Symmetric Encryption (SSE) enables clients to make confidential queries over encrypted data while revealing some formally-defined leakage profiles. Despite the promising performance and application prospects of SSE, the recent leakage-abuse attacks show that a passive adversary can recover queries by exploiting patterns about data disclosed from leakage profiles. Among those attacks, the size pattern is a frequently exploited leakage. Although several countermeasures have been proposed, they can provide neither sufficient protection to mitigate size pattern leakage, nor sufficient scalability for large-scale databases. To address those challenges, we present an SGX-based size-pattern mitigation SSE schemeSMSSEwith two tailored response padding approaches and an I/O efficient disk-based index construction. In addition, we evaluate the size pattern leakage after padding through conditional entropy and differential privacy. Furthermore, we demonstrate the scalability robustness ofSMSSEon different databases by theoretically deducing the approximate boundary of index reading efficiency under a reasonable query distribution. Experiment results on representative real-world datasets show thatSMSSEcan provide high utility and strong protection against newly size pattern-based leakage-abuse attacks. Yang Yang 0192, Haihui Fan, Jinchao Zhang 0002, Bo Li 0063, Hui Ma 0002, Xiaoyan Gu 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | $ \mathsf{GPABE} $GPABE: GPU-Based Parallelization Framework for Attribute-Based Encryption SchemesabstractAttribute-based encryption (ABE) has emerged as a new paradigm for access control in cloud computing. However, despite the many promising features of ABE, its deployment in real-world systems is still limited, partially due to the expensive cost of its underlying mathematical operations, which often grow linearly with the size and complexity of the system's security policies. This becomes particularly challenging in data-intensive applications, where multiple users may simultaneously access and manipulate large volumes of data, resulting in high levels of concurrency and demand for computing resources, which are too heavy even for high-end servers. Further exacerbating the issues are the functionality and security requirements of a cloud, as they introduce additional computations to both the client and the server. Therefore, in this work, we introduce$ \mathsf{GPABE} $, the first GPU-based parallelization framework for ABE to facilitate its batch processing in cloud computing. By analyzing ABE's major computational workload, we identify multiple arithmetic modules that are common in the design of pairing-based ABEs. Based on the analysis, we further propose to decompose the ABE algorithm into computation graph, which can be efficiently implemented on the GPU platform. Our graph representation bridges the gap between ABE's high-level design and their low-level implementation on GPUs, and is applicable to a variety of popular schemes in the realm of ABE. We then implement$ \mathsf{GPABE} $as a heterogeneous computing server, with several optimization techniques to improve its throughput. Finally, we evaluate the GPU implementation of several ABE schemes using$ \mathsf{GPABE} $. The results show a speedup of least 51.0× and at most 253.6× for the throughput of ABE algorithms, compared to their state-of-the-art CPU implementations, which preliminarily demonstrated the effectiveness of$ \mathsf{GPABE} $. Hui Ma 0002, Rui Zhang 0002 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2024 | GAPS: GPU-accelerated processing service for SM9abstractAbstract SM9 was established in 2016 as a Chinese official identity-based cryptographic (IBC) standard, and became an ISO standard in 2021. It is well-known that IBC is suitable for Internet of Things (IoT) applications, since a centralized processing of client data (e.g. IoT cloud) is often done by gateways. However, due to limited computation resources inside IoT devices, the performance of SM9 becomes a bottleneck in practical usage. The existing SM9 implementations are often CPU-based, with relatively low latency and low throughput. Consequently, a pivotal challenge for SM9 in large-scale applications is how to reduce the latency while maximizing throughput for numerous concurrent inputs. After a systematic analysis of the SM9 algorithms, we apply optimization techniques including precomputation, resource caching and parallelization to reduce the overhead of SM9. In this work, we introduce the first practical implementation of SM9 and its underlying curve on GPU. Our GPU implementation combines multiple algorithms and low-level optimizations tailored for GPU’s single instruction, multiple threads architecture in order to achieve high throughput for SM9. Based on these, we propose , a high-performance Cryptography as a Service (CaaS) for SM9. adopts a heterogeneous computing architecture that flexibly schedules the inputs across two implementation platforms: a CPU for the low-latency processing of sporadic inputs, and a GPU for the high-throughput processing of batch inputs. According to our benchmark, only takes a few milliseconds to process a single SM9 request in idle mode. Moreover, when operating in its batch processing mode, can generate 2,038,071 private keys, 248,239 signatures or 238,001 ciphertexts per second. The results show that scales seamlessly across inputs of different sizes, preliminarily demonstrating the efficacy of our solution. Hui Ma 0002, Rui Zhang 0002 |
Cybersecur. | 2 |
| 2024 | Gringotts: An Encrypted Version Control System With Less Trust on ServersabstractVersion Control System (VCS) plays an essential role in software supply chain, as it manages code projects and enables efficient collaboration. For a private repository, where source code is a high-profile asset and needs to be protected, VCS’ security is extremely important. Traditional (unencrypted or encrypted) VCS solutions rely on a trusted service provider to host the code and enforce access control, which is not realistic enough for real-world threats. If the service provider peep in or the hackers break into the repository, the read & write privilege to the sensitive code is totally lost. Therefore, we consider whether one can relax the assumption on the server by introducing acovert adversary, namely, it may act maliciously, but will not misbehave if it can be caught doing so. However, protecting sensitive code and enforcing access control on a covert adversarial server is a challenging task. Existing encryption-based VCS solutions failed to address this challenge, as they offered limited access control functionalities, introduced heavy key management overhead or storage overhead. Moreover, the crucial feature of compression of the source files were missing in an encrypted and versioned storage. To address these problems, we introduceGringotts, an end-to-end encrypted VCS, tailored for read & write access control, version control and source file compression. We present a formal model and propose a scheme with detailed analysis. We also implement and evaluateGringottson top-10 most starred code projects on GitHub. The results demonstrate thatGringottsintroduces low latency (less than 0.3 s) for commit encryption and decryption, supports fine-grained access control and rich version control functionalities with practical performance. Hui Ma 0002, Zishuai Song, Rui Zhang 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Flexible and Controllable Access Policy Update for Encrypted Data Sharing in the CloudabstractAbstract As a promising service paradigm, cloud computing has attracted lots of enterprises and individuals to outsource big data to public cloud. To facilitate secure data using and sharing, ciphertext-policy attribute-based encryption (CP-ABE) is a suitable solution, which can provide fine-grained access control and encryption functionalities simultaneously. However, some serious challenges are still remaining toward achieving flexible and controllable access policy update in CP-ABE, which essentially impede the powerful access control ability of CP-ABE from long-term and large-scale deployment in real systems. In this work, we propose a novel scheme named policy updatable CP-ABE for encrypted data sharing scenes. The proposed scheme features the following achievements: (i) it supports fine-grained update algorithms with no restriction on update time; (ii) the cloud server can effectively verify update ciphertexts, so the integrity of original data would not be compromised intentionally or accidentally during the update and (iii) most operations of encryption and policy update are securely outsourced to cloud servers, leaving extremely low overheads for data owners and users. We formally define its security model and prove it is adaptively secure. Also, we implement the proposed scheme using the Charm framework. The experiment results demonstrate that it is efficient and practical. Ti Wang, Yongbin Zhou, Hui Ma 0002, Rui Zhang 0002 |
Comput. J. | 3 |
| 2023 | Rainbow: reliable personally identifiable information retrieval across multi-cloudabstractPersonally identifiable information (PII) refers to any information that links to an individual. Sharing PII is extremely useful in public affairs yet hard to implement due to the worries about privacy violations. Building a PII retrieval service over multi-cloud, which is a modern strategy to make services stable where multiple servers are deployed, seems to be a promising solution. However, three major technical challenges remain to be solved. The first is the privacy and access control of PII. In fact, each entry in PII can be shared to different users with different access rights. Hence, flexible and fine-grained access control is needed. Second, a reliable user revocation mechanism is required to ensure that users can be revoked efficiently, even if few cloud servers are compromised or collapse, to avoid data leakage. Third, verifying the correctness of received PII and locating a misbehaved server when wrong data are returned is crucial to guarantee user's privacy, but challenging to realize. In this paper, we propose Rainbow, a secure and practical PII retrieval scheme to solve the above issues. In particular, we design an important cryptographic tool, called Reliable Outsourced Attribute Based Encryption (ROABE) which provides data privacy, flexible and fine-grained access control, reliable immediate user revocation and verification for multiple servers simultaneously, to support Rainbow. Moreover, we present how to build Rainbow with ROABE and several necessary cloud techniques in real world. To evaluate the performance, we deploy Rainbow on multiple mainstream clouds, namely, AWS, GCP and Microsoft Azure, and experiment in browsers on mobile phones and computers. Both theoretical analysis and experimental results indicate that Rainbow is secure and practical. Zishuai Song, Hui Ma 0002, Shuzhou Sun, Yansen Xin, Rui Zhang 0002 |
Cybersecur. | 2 |
| 2023 | Wolverine: A Scalable and Transaction-Consistent Redactable Permissionless BlockchainabstractThe immutability of blockchains is critical for cryptocurrencies, but an imperative need arises for the redaction of on-chain data due to privacy-protecting laws like GPDR. Recently, Ateniese et al. (EuroS&P 2017) proposed an elegant solution to this problem based on chameleon hash functions, followed by many subsequent works. While these works offered a solution to the permissioned blockchain, the approaches were not efficient enough for the permissionless setting, in terms of either security (which may cause inconsistent historical transactions) or performance (only up to a few hundred nodes). In this paper, we investigate this problem and present Wolverine, a redactable permissionless blockchain. First, we present a formal redactable blockchain model, carefully considering transaction consistency. Next, towards a practical scheme, we introduce the novel concept of non-interactive chameleon hash (NITCH). NITCHs dynamically distribute a trapdoor key among a group and each party in the group can compute its partial share without communicating with others. Anyone who possesses enough shares can then find a valid hash collision. To prevent the static group from being compromised after a sufficiently long time, we provide a generic transform from NITCHs to decentralized random beacons (DRBs) and design a committee evolution protocol based on DRBs that refresh the group after every fixed interval of time. Based on NITCH and the committee evolution protocol, we construct Wolverine which offers important features such as scalability, transaction consistency, and public accountability. Finally, we demonstrate the practicality of Wolverine by giving a proof-of-concept implementation based on Bitcoin in Golang. Hui Ma 0002, Jiabei Wang, Zishuai Song, Rui Zhang 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Everything Under Control: Secure Data Sharing Mechanism for Cloud-Edge ComputingabstractCloud-edge computing is a new paradigm for data sharing. Many computation tasks are assigned to multiple edge nodes to mitigate the computing burden of the cloud and data is also outsourced to them to provide real-time services for IoT devices. However, two major issues remain, namely data privacy and real-world deployment. According to the data privacy rights and principles that stated by General Data Protection Regulation (GDPR), data access control, restriction of data processing and finding inaccuracy data are critical issues that should be tackled in cloud-edge computing. Besides, since there are various types of devices and many of them are resource-constrained, how to efficiently apply deployment in cloud-edge computing is challenging for practice. In this work, we propose a new cryptographic primitive Controllable Outsourced Attribute-Based Proxy Re-Encryption (COAB-PRE) and a universal WebAssembly-based implementation framework for cross-platform deployment. In particular, COAB-PRE achieves bilateral and distributed access control whereby data producers and data consumers can both specify policies the other party must satisfy without a centralized access control server. The property, that we called controllable delegation, restricts the data processing on the edge nodes. COAB-PRE also supports comprehensive verifiability to find out a wrong result produced by the edge nodes and locate the misbehaved one. Moreover, we further discussed the potential property of COAB-PRE and put forward an improved scheme with high efficiency on devices. We also implemented our scheme using the approach and deployed it on different devices for experiment. All theoretical and experimental results indicate that our solution is secure and practical, and our implementation is suitable for cloud-edge computing. Zishuai Song, Hui Ma 0002, Rui Zhang 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | WebCloud: Web-Based Cloud Storage for Secure Data Sharing Across PlatformsabstractWith more and more data moving to the cloud, privacy of user data have raised great concerns. Client-side encryption/decryption seems to be an attractive solution to protect data security, however, the existing solutions encountered three major challenges: low security due to encryption with low-entropy PIN, inconvenient data sharing with traditional encryption algorithms, and poor usability with dedicated software/plugins that require certain types of terminals. This work designs and implements WebCloud, a practical browser-side encryption solution, leveraging modern Web technologies. It solves all the above three problems while achieves several additional remarkable features: robust and immediate user revocation, fast data processing with offline encryption and outsourced decryption. Notably, our solution works on any device equipped with a Web user agent, including Web browsers, mobile and PC applications. We implement WebCloud based on ownCloud for basic file management utility, and utilize WebAssembly and Web Cryptography API for complex cryptographic operations integration. Finally, comprehensive experiments are conducted with many well-known browsers, Android and PC applications, which indicates that WebCloud is cross-platform and efficient. As an interesting by-product, the design of WebCloud naturally embodies a dedicated and practical ciphertext-policy attribute-based key encapsulation mechanism (CP-AB-KEM) scheme, which can be useful in other applications. Shuzhou Sun, Hui Ma 0002, Zishuai Song, Rui Zhang 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | SeUpdate: Secure Encrypted Data Update for Multi-User EnvironmentsabstractSearchable Symmetric Encryption (SSE) is a key tool for secure data processing. To date, most of the SSEs were studied alone, while an SSE supporting update operations over encrypted data remained a challenging problem due to various statistical attacks and multi-user environments. In this article, we proposeSeUpdate, the first SSE scheme that simultaneously achieves keyword search and controlled update over encrypted data, with flexible read (search) and write (update) access control policies among multiple users. InSeUpdate, users do not need to share secret keys and a single query enables one to efficiently search all his authorized data. We formally define a security model, and prove our scheme have both forward and backward security. We note that the write permission of an SSE is realized for the first time. We further extend the basic scheme with dynamic access policy update and support of a large number of files. We also implementSeUpdateand some related work. The theoretical and experimental analyses demonstrate our scheme and its extension are practical and efficient. Jiabei Wang, Rui Zhang 0002, Hui Ma 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2022 | Server-Aided Fine-Grained Access Control Mechanism with Robust Revocation in Cloud ComputingabstractAs an innovative technique for cloud storage services, attribute based encryption (ABE) enables fine-grained access control over encrypted data in many cloud computing applications. However, there exist two main drawbacks that restrict the development of ABE. One is that most of the existing user revocation mechanisms cannot achieve high efficiency, immediacy and robustness simultaneously. Another is that the decryption of ABE contains expensive pairing operations which often grow with the complexity of access policy. In this work, we propose a practical server-aided revocable fine-grained access control mechanism with the help of cloud’s storage, computing and management capabilities, which not only achieves efficient fine-grained attribute based access control, but also actualizes immediate and robust user revocation. Moreover, most of the complicated operations in decryption are outsourced to the public cloud server, leaving one exponentiation for the users. At last, we implement our proposed mechanism with$\mathsf{Charm}$Charmframework. The benchmark results demonstrate the high efficiency and practicality of our proposed mechanism. Hui Ma 0002, Rui Zhang 0002, Shuzhou Sun, Zishuai Song, Gaosheng Tan |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | Modular Design of Role-Symmetric Authenticated Key Exchange Protocols
Rui Zhang 0002, Hui Ma 0002 |
ASIACRYPT (4) | 3 |
| 2021 | Hashing multiple messages with SM3 on GPU platforms
Shuzhou Sun, Rui Zhang 0002, Hui Ma 0002 |
Sci. China Inf. Sci. | 3 |
| 2021 | Fully Accountable Data Sharing for Pay-as-You-Go Cloud ScenesabstractMany enterprises and individuals prefer to outsource data to public cloud via various pricing approaches. One of the most widely-used approaches is the pay-as-you-go model, where the data owner hires public cloud to share data with data consumers, and only pays for the actually consumed services. To realize controllable and secure data sharing, ciphertext-policy attribute-based encryption (CP-ABE) is a suitable solution, which can provide fine-grained access control and encryption functionalities simultaneously. But there are some serious challenges when applying CP-ABE in pay-as-you-go. First, the decryption cost in ABE is too heavy for data consumers. Second, ABE ciphertexts probably suffer distributed denial of services (DDoS) attacks, but there is no solution that can eliminate the security risk. At last, the data owner should audit resource consumption to guarantee the transparency of charge, while the existing method is inefficient. In this work, we propose a general construction named fully accountable ABE (FA-ABE), which simultaneously solves all the challenges by supporting all-sided accountability in the pay-as-you-go model. We formally define the security model and prove the security in the standard model. Also, we implement an instantiate construction with the self-developed library$\mathsf{ libabe}$. The experiment results indicate the efficiency and practicality of our construction. Ti Wang, Hui Ma 0002, Yongbin Zhou, Rui Zhang 0002, Zishuai Song |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | An Efficient CCA-Secure Access Control Encryption for Any Policy
Gaosheng Tan, Rui Zhang 0002, Hui Ma 0002, Yang Tao 0001 |
Inscrypt | 3 |
| 2020 | Fully Secure ABE with Outsourced Decryption against Chosen Ciphertext Attack
Ti Wang, Yongbin Zhou, Hui Ma 0002, Yuejun Liu, Rui Zhang 0002 |
Inscrypt | 3 |
| 2020 | Tightly Secure Two-Pass Authenticated Key Exchange Protocol in the CK Model
Rui Zhang 0002, Hui Ma 0002 |
CT-RSA | 3 |
| 2020 | Server-aided immediate and robust user revocation mechanism for SM9abstractAbstract As the only approved Identity-Based Encryption scheme in China that is also standardized by ISO, SM9-IBE has been widely adopted in many real-world applications. However, similar to other IBE standard algorithms, SM9-IBE currently lacks revocation mechanism, which is vital for a real system. Worse still, we find that existing revocable techniques may not be suitable and efficient when applying to SM9-IBE. Given the widespread use of SM9-IBE, an efficient and robust user revocation mechanism becomes an urgent issue.In this work, we propose a dedicated server-aided revocation mechanism, which for the first time achieves the secure, immediate and robust user revocation for SM9-IBE. Provided with a compact system model, the proposed method leverages an existing server to perform all heavy workloads during user revocation, thus leaving no communication and computation costs for the key generation center and users. Moreover, the mechanism supports key-exposure resistance, meaning the user revocation mechanism is robust even if the revocation key leaks. We then formally define and prove the security. At last, we present theoretical comparisons and an implementation in terms of computational latency and throughput. The results indicate the efficiency and practicability of the proposed mechanism. Shuzhou Sun, Hui Ma 0002, Rui Zhang 0002 |
Cybersecur. | 2 |
| 2020 | Efficient Fine-Grained Data Sharing Mechanism for Electronic Medical Record Systems with Mobile DevicesabstractSharing digital medical records on public cloud storage via mobile devices facilitates patients (doctors) to get (offer) medical treatment of high quality and efficiency. However, challenges such as data privacy protection, flexible data sharing, efficient authority delegation, computation efficiency optimization, are remaining toward achieving practical fine-grained access control in the Electronic Medical Record (EMR) system. In this work, we propose an innovative access control model and a fine-grained data sharing mechanism for EMR, which simultaneously achieves the above-mentioned features and is suitable for resource-constrained mobile devices. In the model, complex computation is outsourced to public cloud servers, leaving almost no complex computation for the private key generator (PKG), sender and receiver. Additionally, the communication cost of the PKG and users is optimized. Moreover, we develop an extensible library called libabe that is compatible with Android devices, and the access control mechanism is actually deployed on realistic environment, including public cloud servers, a laptop and an inexpensive mobile phone with constrained resources. The experimental results indicate that the mechanism is efficient, practical and economical. Hui Ma 0002, Rui Zhang 0002, Guomin Yang, Zishuai Song |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Efficient Parallelism of Post-Quantum Signature Scheme SPHINCSabstractSPHINCS was recently proposed as a stateless, quantum-resilient hash-based signature scheme. However, one possible limitation of SPHINCS is its signing speed, namely, the best known implementation merely produces a few hundred of signatures per second, which is not good enough, e.g., for a social website with a huge amount of users. Aiming at improving the singing throughput, we present highly parallel and optimized implementations of SPHINCS, which can be deployed on various multi-core platforms. As a first step, we give an elementary implementation on ×86/64 processors, which proves the effectiveness and correctness of our implementations. To obtain a significantly higherthroughput, we implement SPHINCS on Graphics Processing Units (GPUs). Furthermore, we develop a few general and hardware-specific techniques to take full advantage of the computing power of targeted platforms. We instantiate the underlying hash functions with three primitives. Our comprehensive benchmark shows that our work outperforms all the state-of-the-art implementations of SPHINCS regarding throughput with reasonable latency, and has scalability on multiple cores and multiple GPU cards. For instance, forthe key generation algorithm instantiated with ChaCha running on a GeForce GTX 1080, we obtain 5152 signatures per second which is 7.88x speedup fasterthan a recent FPGA implementation. When upgrade to TITAN Xp, 6,651 signatures are generated in one second. With four TITAN Xp GPUs, the obtained throughput satisfies vast majority scenarios. Shuzhou Sun, Rui Zhang 0002, Hui Ma 0002 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2019 | Efficient Multi-Factor Authenticated Key Exchange Scheme for Mobile CommunicationsabstractAuthenticated key exchange (AKE) is one of the most important applications in applied cryptography, where a user interacts with a server to set up a session key where pre-registered information (aka. authentication factor), such as a password or biometrics, of the user is stored. While single-factor AKE is widely used in practice, higher security concerns call for multi-factor AKE (MFAKE) schemes, e.g., combining both passwords and biometrics simultaneously. However, in some casually designed schemes, security is even weakened in the sense that leakage of one authentication factor will defeat the whole MFAKE protocol. Furthermore, an inevitable by-product arise that the usability of the protocol often drop greatly. To summarize, the existing multi-factor protocols did not provide enough security and efficiency simultaneously. In this paper, we make one step ahead by proposing a very efficient MFAKE protocol. We define the security model and give the according security analysis. We also implement our protocol on a smartphone and a cloud server. The theoretic comparisons and the experimental results show that our scheme achieves both security and usability. Rui Zhang 0002, Shuzhou Sun, Hui Ma 0002 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2018 | Concessive Online/Offline Attribute Based Encryption with Cryptographic Reverse Firewalls - Secure and Efficient Fine-Grained Access Control on Corrupted Machines
Hui Ma 0002, Rui Zhang 0002, Guomin Yang, Zishuai Song, Shuzhou Sun |
ESORICS (2) | 1 |
| 2018 | Certifying Variant of RSA with Generalized Moduli
Yao Lu 0002, Noboru Kunihiro, Rui Zhang 0002, Liqiang Peng, Hui Ma 0002 |
ICICS | 5 |
| 2018 | Auditable σ-Time Outsourced Attribute-Based Encryption for Access Control in Cloud ComputingabstractAs a sophisticated mechanism for secure finegrained access control over encrypted data, ciphertext-policy attribute-based encryption (CP-ABE) is one of the highly promising candidates for cloud computing applications. However, there exist two main long-lasting open problems of CP-ABE that may limit its wide deployment in commercial applications. One is that decryption yields expensive pairing cost which often grows with the increase of access policy size. The other is that one is granted access privilege for unlimited times as long as his attribute set satisfies the access policy of a given ciphertext. Such powerful access rights, which are provided by CP-ABE, may be undesirable in real-world applications (e.g., pay-as-youuse). To address the above drawbacks, in this paper, we propose a new notion called auditable σ-time outsourced CF-ABE, which is believed to be applicable to cloud computing. In our notion, expensive pairing operation incurred by decryption is offloaded to cloud and meanwhile, the correctness of the operation can be audited efficiently. Moreover, the notion provides σ-time fine-grained access control. The cloud service provider may limit a particular set of users to enjoy access privilege for at most σ times within a specified period. As of independent interest, the notion also captures key-leakage resistance. The leakage of a user's decryption key does not help a malicious third party in decrypting the ciphertexts belonging to the user. We design a concrete construction (satisfying our notion) in the key encapsulation mechanism setting based on Rouselakis and Waters (prime order) CP-ABE, and further present security and extensive experimental analysis to highlight the scalability and efficiency of our construction. Jianting Ning, Zhenfu Cao, Xiaolei Dong, Kaitai Liang, Hui Ma 0002, Lifei Wei |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2017 | Provably secure cloud storage for mobile networks with less computation and smaller overhead
Rui Zhang 0002, Hui Ma 0002, Yao Lu 0002, Yang Li 0192 |
Sci. China Inf. Sci. | 2 |
| 2017 | Fine-grained access control system based on fully outsourced attribute-based encryption
Rui Zhang 0002, Hui Ma 0002, Yao Lu 0002 |
J. Syst. Softw. | 2 |
| 2017 | Verifiable and Exculpable Outsourced Attribute-Based Encryption for Access Control in Cloud ComputingabstractWe propose two ciphertext-policy attribute-based key encapsulation mechanism (CP-AB-KEM) schemes that for the first time achieve both outsourced encryption and outsourced decryption in two system storage models and give corresponding security analysis. In our schemes, heavy computations are outsourced to Encryption Service Providers (ESPs) or Decryption Service Providers (DSPs), leaving only one modular exponentiation computation for the sender or the receiver. Moreover, we propose a general verification mechanism for a wide class of ciphertext-policy (cf. key-policy) AB-KEM schemes, which can check the correctness of the outsourced encryption and decryption efficiently. Concretely, we introduce a stronger version of verifiability (cf. [1] ) and a new security notion for outsourced decryption called exculpability, which guarantees that a user cannot accuse DSP of returning incorrect results while it is not the case. With all these mechanisms, any dispute between a user and an outsource computation service provider can be easily resolved, furthermore, a service provider will be less motivated to give out wrong results. Finally, we implement our schemes in Charm [2] , and the results indicate that the proposed schemes/mechanisms are efficient and practical. Hui Ma 0002, Rui Zhang 0002, Zhiguo Wan, Yao Lu 0002, Suqing Lin |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | Comments on "Control Cloud Data Access Privilege and Anonymity With Fully Anonymous Attribute-Based Encryption"abstractMost of the known attribute-based encryption (ABE) schemes focused on the data contents privacy and the access control, but less attention was paid to the privilege control and the identity privacy problem. Recently in IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY (TIFS) (DOI:10.1109/TIFS.2014.2368352), Junget al.proposed an anonymous attribute-based encryption scheme for access privilege and anonymity, which exhibited a lot of interesting ideas and gave the proof in the standard model. However, after carefully revisiting the scheme, we found that any valid user can compute the system-wide master key and their proof has some mistakes, hence, it fails to meet their security definitions. Hui Ma 0002, Rui Zhang 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Secure Cloud Storage for Dynamic Group: How to Achieve Identity Privacy-Preserving and Privilege Control
Hui Ma 0002, Rui Zhang 0002 |
NSS | 1 |
| 2015 | Revisiting Attribute-Based Encryption With Verifiable Outsourced DecryptionabstractAttribute-based encryption (ABE) is a promising technique for fine-grained access control of encrypted data in a cloud storage, however, decryption involved in the ABEs is usually too expensive for resource-constrained front-end users, which greatly hinders its practical popularity. In order to reduce the decryption overhead for a user to recover the plaintext, Green et al. suggested to outsource the majority of the decryption work without revealing actually data or private keys. To ensure the third-party service honestly computes the outsourced work, Lai et al. provided a requirement of verifiability to the decryption of ABE, but their scheme doubled the size of the underlying ABE ciphertext and the computation costs. Roughly speaking, their main idea is to use a parallel encryption technique, while one of the encryption components is used for the verification purpose. Hence, the bandwidth and the computation cost are doubled. In this paper, we investigate the same problem. In particular, we propose a more efficient and generic construction of ABE with verifiable outsourced decryption based on an attribute-based key encapsulation mechanism, a symmetric-key encryption scheme and a commitment scheme. Then, we prove the security and the verification soundness of our constructed ABE scheme in the standard model. Finally, we instantiate our scheme with concrete building blocks. Compared with Lai et al.'s scheme, our scheme reduces the bandwidth and the computation costs almost by half. Suqing Lin, Rui Zhang 0002, Hui Ma 0002, Suqing Wang |
IEEE Trans. Inf. Forensics Secur. | 3 |