Yang Yang 0026

dblp:48/450-26 · DBLP profile ↗
← Back
64ranked-venue papers
28as first author
39since 2021 · last 2026
0000-0002-7891-2670ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 11 first-author · 19 since 2021Systems, architecture and hardware · 16 · 7 first-author · 9 since 2021Computer networks · 6 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 5 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-authorArtificial intelligence and machine learning · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-authorTheory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 QuantumQA: Enhancing Scientific Reasoning via Physics-Consistent Dataset and Verification-Aware Reinforcement Learning
abstract
Songxin Qu, Tai-Ping Sun, Yun-Jie Wang, Huan-Yu Liu, Cheng Xue, Xiao-Fan Xu, Han Fang, Yang Yang, Yu-Chun Wu, Guo-Ping Guo, Zhao-Yun Chen. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Songxin Qu, Tai-Ping Sun, Yun-Jie Wang, Huan-Yu Liu, Xiao-Fan Xu, Yang Yang 0026, Yu-Chun Wu, Guo-Ping Guo, Zhao-Yun Chen
ACL (1)8
2026 PriSrv+: Privacy and Usability-Enhanced Wireless Service Discovery with Fast and Expressive Matchmaking Encryption
Yang Yang 0026, Guomin Yang, Yingjiu Li, Pengfei Wu 0003, Minming Huang, Jian Weng 0001, HweeHwa Pang, Robert H. Deng
NDSS1
2026 A Novel Privacy-Preserving user information queries scheme with functional policy
Yuhang Lei, Yang Yang 0026, Chunjie Cao, Huamin Feng
J. Inf. Secur. Appl.3
2026 Hardware Security Meets Incomplete Netlists: Insights Into Trojan Detection via Structural Reasoning
abstract
In order to better utilize the achievements of various countries and lower costs, the integrated circuit (IC) design and manufacturing process is based on a global supply chain model, highly relying on untrusted third parties, such as intellectual property (IP) cores, electronic design automation (EDA) tools, and employees. This globalized model creates lots of opportunities for the prosperity of hardware Trojans (HTs). However, existing countermeasures were all accomplished under some assumptions, such as finding HTs in a complete netlist. In practical industry scenarios, netlists may be obtained through reverse engineering, which has inherent limitations, including imaging resolution and inaccurate recognition of interconnections, making it almost impossible to obtain a complete netlist to detect whether HTs exist. Evidently, studying how to find HTs from incomplete netlists should be a reasonable, notable, critical and practical issue for the IC security research community. Addressing this problem entails substantial challenges. This paper is the first to propose the problem of detecting HTs with incomplete netlists, and also presents an effective approach named HTINS, which infers and completes incomplete circuit structures and utilizes the completed information for HTs detection. The method leverages GraphVAE to reconstruct incomplete netlist components and performs circuit feasibility validation on the reconstructed components. Local features are then extracted from the completed circuits and classified via a graph neural network. In the experiments, netlist components are randomly removed to set netlists with 1%, 5%, and 10% missing ratios, and the performance of HT detection on the completed netlists is evaluated under these conditions. Experimental results demonstrate that the proposed method can effectively reconstruct incomplete netlists and significantly improve HT detection performance.
Decheng Qiu, Chen Dong 0002, Yang Yang 0026
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2026 FEAC: A New Construction of Fast and Expressive Anonymous Credential for Cloud Service
abstract
Anonymous credentials are an essential cryptography primitive to protect user privacy and provide fine-grained access control for proving ownership and rights of specific credentials. There are currently two roadmaps to designing anonymous credentials: one is signature credentials, which are constructed by signature with efficient protocols and non-interactive zero-knowledge proofs, and the other is functional credentials, which are transformed from predicate encryption schemes. However, none of the existing instances of anonymous credentials support$expressive$access policies expressed as conjunction, disjunction, or arbitrary Boolean formulas, which are particularly useful for cloud services. In this paper, we propose a new fast and expressive anonymous credential, called FEAC. It is constructed with the unique$dual$$randomness$$splitting$technique, which combines the most efficient anonymous key-policy attribute-based encryption (USENIX 24) and short randomizable signature (CT-RSA 18) to balance efficiency, expressiveness, and security, demonstrating a new way to instantiate anonymous credentials. Furthermore, our credential presentation protocol offloads most of the time-consuming computation to the cloud server (11 pairing) to reduce the computational burden on the user side (2 pairing). We propose formal definitions and formal security proofs of FEAC. We provide implementations and evaluate the performance of FEAC, comparing it to state-of-the-art work.
Huamin Feng, Chunjie Cao, Yang Yang 0026, Baitao Zhang, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.4
2026 LatInc: A Practical Lattice-Based Privacy-Preserving Incentive System
abstract
Incentive (or point) systems are widely deployed across industries such as retail, tourism, and finance to enhance customer loyalty and create benefits for service providers. However, their operation typically requires the collection and processing of sensitive customer data, leading to significant privacy concerns. Existing privacy-preserving incentive systems predominantly rely on bilinear pairings and the discrete logarithm assumption, which, while efficient in classical settings, are vulnerable to quantum adversaries and thus lack long-term security guarantees. To address this limitation, we present LatInc, a practical lattice-based privacy-preserving incentive system. LatInc integrates state-of-the-art lattice-based signatures with efficient protocols, the ABDLOP commitment, and efficient lattice zero-knowledge proofs, achieving a robust balance between post-quantum security and efficiency. Relying on the hardness of the MLWE and MSIS problems, we formally prove that LatInc achieves unforgeability, anonymity, and framing-resistance in the random oracle model. We implement a demo of the system and evaluate its performance on a standard laptop platform. Experimental results show that the communication overheads for the Earning and Spending protocols are approximately 99 KB and 140 KB, respectively, with execution times of 610 ms and 900 ms, highlighting significant efficiency gains over previous lattice-based incentive constructions.
Huamin Feng, Yang Yang 0026, Zhen Guo 0003, Chunjie Cao, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.3
2026 Hecate: Threshold Anonymous Credentials With Private Verifiers and Issuer-Hiding
Huamin Feng, Yang Yang 0026, Yingjiu Li, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.3
2026 FlyCred: Contractual Anonymous Credentials Based on Oracles and Events
abstract
In a scenario where an issuer wishes to issue an attribute-based anonymous credential to a user, this issuance is conditional on a number of real-world outcomes. These outcomes involve multiple entrusted oracles confirming the occurrence of several events, after which the issuance can proceed successfully. Such contractual credentials can serve as an important building block for blockchain-based Web 3.0 systems and can be used in real-world applications that require privacy-preserving, prescheduled authorization. However, there is currently no work that enables the pre-issuance of credentials based on oracles and events. In this work, we propose contractual anonymous credentials, called FlyCred, to fill this gap. With FlyCred, the issuer can issue an encrypted credential to a user, controlled by a dual-layer authorization policy consisting of oracle-based and event-based expressive policies. As core building blocks, we introduce two novel cryptographic primitives: the Adaptor Anonymous Credential and ABE-based Signature Witness Encryption with Tags, which can serve as independent interests. We provide efficient instantiations of these primitives and evaluate their performance under different security levels and system parameters on a laptop, showing that the computation and communication overhead of the credential pre-issuance is less than 85.8 seconds and 8.7 MB, respectively.
Yang Yang 0026, Huamin Feng, Yingjiu Li, Chunjie Cao, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.2
2025 Defense in the Reverse Fragment: RL-Based Partial Netlist Hardware Trojan Detection
abstract
The globalization of integrated circuit design and manufacturing has brought about extremely dangerous hardware Trojans (HT). One critical HT detection method is reverse engineering, which is used to restore design files to detect HTs. However, whether current reverse engineering can accurately reconstruct detailed design information, including partial netlists, remains uncertain. Meanwhile, numerous current HT detection methods based on machine learning are generally based on the ideal assumption that "the netlist is complete and available". This makes such models significantly reduce the detection accuracy and stability when facing practical applications due to the interference of part of the netlist. Therefore, exploring HT detection of partial netlists is cutting-edge. To address the above issues, we propose RE-PNRL, a Reinforcement Learning-based framework for reconstructing Partial Netlists using node-level transition probabilities. We also introduce a clustering-based hardware Trojan detection method that uses the complete netlist to identify potential threats. Experiments show that our method achieves average TPR and TNR of 66.39% and 73.72%, respectively, while the clustering-based detection achieves 96.80% TPR and 94.80% TNR, outperforming state-of-the-art approaches. Further validation on Trojan benchmarks confirms its effectiveness under different levels of netlist missingness.
Chen Dong 0002, Decheng Qiu, Yang Yang 0026
ICCAD5
2025 AKMA+: Security and Privacy-Enhanced and Standard-Compatible AKMA for 5G Communication
Yang Yang 0026, Guomin Yang, Yingjiu Li, Minming Huang, Zilin Shen, Imtiaz Karim, Ralf Sasse, David A. Basin, Elisa Bertino, Jian Weng 0001, HweeHwa Pang, Robert H. Deng
USENIX Security Symposium1
2025 GNN4HT: A Two-Stage GNN-Based Approach for Hardware Trojan Multifunctional Classification
abstract
Due to the complexity of integrated circuit design and manufacturing process, an increasing number of third parties are outsourcing their untrusted Intellectual Property (IP) cores to pursue greater economic benefits, which may embed numerous security issues. The covert nature of hardware Trojans (HTs) poses a significant threat to cyberspace, and they may lead to catastrophic consequences for the national economy and personal privacy. To deal with HTs well, it is not enough to just detect whether they are included, like the existing studies. Same as malware, identifying the attack intentions of HTs, that is, analyzing the functions they implement, is of great scientific significance for the prevention and control of HTs. Based on the fined detection, for the first time, this paper proposes a two-stage Graph Neural Network model for HTs’ multifunctional classification, GNN4HT. In the first stage, GNN4HT localizes HTs, achieving a notable True Positive Rate (TPR) of 94.28 the Trust-Hub dataset and maintaining high performance on the TRTC-IC dataset. GNN4HT further transforms the localization results into HT Information Graphs (HTIGs), representing the functional interaction graphs of HTs. In the second stage, the dataset is augmented through logical equivalence for training and HT functionalities are classified based on the extracted HTIG from the first stage. For the multifunctional classification of HTs, the correct classification rate reached as high as 80.95% at gate-level and 62.96% at RTL. This paper marks a breakthrough in HT detection, and it is the first to address the multifunctional classification issue, holding significant practical importance and application prospects.
Chen Dong 0002, Qiaowen Wu, Ximeng Liu, Hao Zhang 0078, Yang Yang 0026
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.8
2025 AccCred: Improved Accountable Anonymous Credentials With Dynamic Triple-Hiding Committees
abstract
Accountable anonymous credentials protect user privacy while holding the accountability of ill-intentioned individuals, which is a critical feature for applications such as online payments and other financial services. Existing accountable anonymous credentials rely on a public committee of trustworthy members who are assumed not to collude and are well protected to perform privacy revocation. However, this assumption is unsound in blockchain-based cryptocurrency systems because the selected committees may involve nodes with significant stakes, and public nodes serving as committee members are vulnerable against targeted attacks from high-computing power adversaries. In this paper, we propose an improved accountable anonymous credential called AccCred, allowing users and issuers to randomly select a hidden committee within a set of authenticated candidates for privacy revocation. No one except the members with corresponding private keys knows their identity, preventing proactive attacks. As a core component, we introduce the primitive of dynamic triple-hiding committees (DTHC), which achieves authentication, dynamic join/delete, random selection, and strong anonymity of committee members. As a building block of DTHC, we design a shuffle protocol to provide efficient shuffle proof of randomized public keys. We formally prove our scheme and compare its performance with previous work for demonstration of practicality.
Sijiang Xie, Yang Yang 0026, Huiqin Xie, Yingjiu Li, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.3
2025 Forward-Secure Hierarchical Delegable Signature for Smart Homes
abstract
Aiming to provide people with great convenience and comfort, smart home systems have been deployed in thousands of homes. In this paper, we focus on handling the security and privacy issues in such a promising system by customizing a new cryptographic primitive to provide the following security guarantees: 1) fine-grained, privacy-preserving authorization for smart home users and integrity protection of communication contents; 2) flexible self-sovereign permission delegation; 3) forward security of previous messages. To our knowledge, no previous system has been designed to consider these three security and privacy requirements simultaneously. To tackle these challenges, we put forward the first-ever efficient cryptographic primitive called the Forward-secure Hierarchical Delegable Signature (FS-HDS) scheme for smart homes. Specifically, we first propose a new primitive, efficient Hierarchical Delegable Signature (HDS) scheme, which is capable of supporting partial delegation capability while realizing privacy-preserving authorization and integrity guarantee. Then, we present an FS-HDS for smart homes with the efficient HDS as the underlying building block, which not only inherits all the desirable features of HDS but also ensures that the past content integrity is not affected even if the current secret key is compromised. We provide comprehensively strict security proofs to prove the security of our proposed solutions. Its performance is also validated via experimental simulations to showcase its practicability and effectiveness.
Jianfei Sun, Guowen Xu, Yang Yang 0026, Xuehuan Yang, Xiaoguo Li, Cong Wu 0003, Zhen Liu 0008, Guomin Yang, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.3
2025 DkvSSO: Delegatable Keyed-Verification Credentials for Efficient Anonymous Single Sign-On
abstract
Anonymous single sign-on (ASSO) is an anonymous multi-service authentication method for end users. However, existing ASSO schemes suffer from heavy ticket requesting and verifying overheads, limiting their applications in large-scale settings. To address this problem, we propose a novel concept called keyed-verification anonymous credentials with disposable delegation (KVAC-DD) in the multi-verifier setting. Next, we extend KVAC-DD to build an efficient ASSO system, dubbed DkvSSO. The construction of DkvSSO can be instantiated in efficient prime-order groups, avoiding costly operations required in previous ASSO systems. We formally prove the security of our proposed constructions. Extensive experiments show that DkvSSO is significantly more efficient than existing ASSO schemes, making it suitable to be deployed in large-scale settings.
Wenyi Xue, Yang Yang 0026, Minming Huang, Yingjiu Li, HweeHwa Pang, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.2
2025 DISC: Decentralized Identity System With Self-Sovereign Credential Aggregation
abstract
The evolution of decentralized identity (DID) and self-sovereign identity (SSI) frameworks, as endorsed by W3C Verifiable Credentials (VC) and eIDAS 2.0, underscores the need for secure, efficient, and privacy-preserving credential management. However, existing credential systems often depend on centralized issuers, lack efficient aggregation mechanisms, or fail to ensure unlinkability across authentication sessions. To address these challenges, we propose DISC (Decentralized Identity System with Self-Sovereign Credential Aggregation), a novel credential system that enables multi-authority credential issuance, user-controlled credential aggregation, and unlinkable authentication. DISC allows users to aggregate credentials from multiple issuers while maintaining constant-size authentication tokens and supporting batch verification for scalable authentication. Additionally, DISC ensures unlinkability of aggregated authentication tokens, preventing verifiers from correlating sessions even when credentials share attributes. Security analysis proves DISC’s unforgeability, anonymity, and unlinkability, while experimental results confirm its efficiency in credential issuance, aggregation, and verification. Compared to existing schemes, DISC offers a scalable, privacy-preserving, and efficient decentralized identity solution, making it well-suited for real-world applications requiring secure and privacy-preserving identity verification.
Yang Yang 0026, Wai Keung Ching, Minming Huang, Supachate Innet, Guomin Yang, HweeHwa Pang, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.1
2024 CRNG-PBFT: An Efficient PBFT Algorithm Based on Comprehensive Reputation and Node Grouping for Data Sharing in Digital Twins
abstract
Data sharing helps the digital twin builders obtain the necessary data to construct a virtual replica of the physical entity. The consortium blockchain is one of the effective ways to solve the lack of trust among these participants, but the traditional PBFT cannot distinguish abnormal nodes and has poor scalability. We propose an efficient PBFT algorithm based on comprehensive reputation and node grouping for data sharing in digital twins. First, we design a comprehensive reputation evaluation mechanism to distinguish normal and abnormal nodes according to their behavior in the processes of data sharing and consensus. Secondly, a node grouping algorithm is proposed, in which nodes with high reputation form a committee, while other nodes are randomly assigned to different groups. Finally, we design consensus processes separately for the group and committee. Each transaction is recorded in the consortium blockchain when the group and committee have reached a consensus on it in sequence. Experimental results show that the CRNG-PBFT algorithm can effectively identify abnormal nodes, reduce transaction delay, and improve throughput.
Qihua Hu, Hongju Cheng, Yang Yang 0026, Longfei Guo
MSN3
2024 PriSrv: Privacy-Enhanced and Highly Usable Service Discovery in Wireless Communications
Yang Yang 0026, Robert H. Deng, Guomin Yang, Yingjiu Li, HweeHwa Pang, Minming Huang, Jian Weng 0001
NDSS1
2024 A certificateless designated verifier sanitizable signature in e-health intelligent mobile communication system
Yonghua Zhan, Yang Yang 0026, Bixia Yi, Xianghan Zheng
Comput. Commun.2
2024 AnoPas: Practical anonymous transit pass from group signatures with time-bound keys
Yang Yang 0026, Yingjiu Li, Huamin Feng, HweeHwa Pang, Robert H. Deng
J. Syst. Archit.2
2024 M$^{3}$SA: Multimodal Sentiment Analysis Based on Multi-Scale Feature Extraction and Multi-Task Learning
abstract
Sentiment analysis plays an indispensable part in human-computer interaction. Multimodal sentiment analysis can overcome the shortcomings of unimodal sentiment analysis by fusing multimodal data. However, how to extracte improved feature representations and how to execute effective modality fusion are two crucial problems in multimodal sentiment analysis. Traditional work uses simple sub-models for feature extraction, and they ignore features of different scales and fuse different modalities of data equally, making it easier to incorporate extraneous information and affect analysis accuracy. In this paper, we propose a Multimodal Sentiment Analysis model based on Multi-scale feature extraction and Multi-task learning (M$^{3}$SA). First, we propose a multi-scale feature extraction method that models the outputs of different hidden layers with the method of channel attention. Second, a multimodal fusion strategy based on the key modality is proposed, which utilizes the attention mechanism to raise the proportion of the key modality and mines the relationship between the key modality and other modalities. Finally, we use the multi-task learning approach to train the proposed model, ensuring that the model can learn better feature representations. Experimental results on two publicly available multimodal sentiment analysis datasets demonstrate that the proposed method is effective and that the proposed model outperforms baselines.
Changkai Lin, Hongju Cheng, Qiang Rao, Yang Yang 0026
IEEE ACM Trans. Audio Speech Lang. Process.4
2024 Double Issuer-Hiding Attribute-Based Credentials From Tag-Based Aggregatable Mercurial Signatures
abstract
Attribute-based anonymous credentials offer users fine-grained access control in a privacy-preserving manner. However, in such schemes obtaining a user's credentials requires knowledge of the issuer's public key, which obviously reveals the issuer's identity that must be hidden from users in certain scenarios. Moreover, verifying a user's credentials also requires the knowledge of issuer's public key, which may infer the user's private information from their choice of issuer. In this paper, we introduce the notion of double issuer-hiding attribute-based credentials (${\sf DIHAC}$) to tackle these two problems. In our model, a central authority can issue public-key credentials for a group of issuers, and users can obtain attribute-based credentials from one of the issuers without knowing which one it is. Then, a user can prove that their credential was issued by one of the authenticated issuers without revealing which one to a verifier. We provide a generic construction, as well as a concrete instantiation for${\sf DIHAC}$based on structure-preserving signatures on equivalence classes (JOC's 19) and a novel primitive which we calltag-based aggregatable mercurial signatures. Our construction is efficient without relying on zero-knowledge proofs. We provide rigorous evaluations on personal laptop and smartphone platforms, respectively, to demonstrate its practicability.
Yang Yang 0026, Yingjiu Li, Huamin Feng, Guozhen Shi, HweeHwa Pang, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.2
2024 AnoPay: Anonymous Payment for Vehicle Parking With Updatable Credential
abstract
Many existing anonymous parking payment schemes lack high efficiency and flexibility. For instance, the calculation and communication costs involved in payment may linearly increase with the payment amount. In this paper, we propose an anonymous payment system (dubbed AnoPay) for vehicle parking, which leverages updatable attribute-based anonymous credentials and efficient zero-knowledge proof (ZKP) to achieve user anonymity and constant overhead for parking fee payment. To further improve the efficiency, we design a secure parking fee aggregation protocol based on linear homomorphic encryption to aggregate parking transactions, where the amount of each parking transaction is hidden and the privacy of the parking lot in terms of its revenue is guaranteed. AnoPay achieves both unlinkability and accountability, malicious payments can be efficiently traced when it is necessary. We provide a security model and rigorous proof for each security property of AnoPay. Extensive experiments and comparisons demonstrate the efficiency and practicality of the system.
Yang Yang 0026, Wenyi Xue, Yonghua Zhan, Minming Huang, Yingjiu Li, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.1
2024 PkT-SIN: A Secure Communication Protocol for Space Information Networks With Periodic k-Time Anonymous Authentication
abstract
Space Information Network (SIN) enables universal Internet connectivity for any object, even in remote and extreme environments where deploying a cellular network is difficult. Access authentication is crucial for ensuring user access control in SIN and preventing unauthorized entities from gaining access to network services. However, due to the complex communication environment in SIN, including exposed links and higher signal delay, designing a secure and efficient authentication scheme presents a significant challenge. In this paper, we propose a secure communication protocol for SIN with periodick-time anonymous authentication (named PkT-SIN) that allows satellite users to anonymously authenticate to ground stations at mostktimes in each single time period. An efficient handover mechanism is designed to ensure seamless communication for satellite users to communicate with different satellites and ground stations, taking into account the dynamic topology of SIN. As a core component of PkT-SIN, we propose a novel primitive, periodick-time keyed-verification anonymous credential (PkT-KVAC), that enables users to derivektokens from a credential for anonymous and unlinkable authentication. On the other hand, a verifier can always recognize a reused token from a dishonest user. PkT-KVAC is of independent contribution to anonymous authentication in pay-per-use business scenarios. Formal security proofs confirm that PkT-SIN and PkT-KVAC have desired security features. The supremacy of their computing features is demonstrated through comprehensive comparison and rigorous performance analysis.
Yang Yang 0026, Wenyi Xue, Jianfei Sun, Guomin Yang, Yingjiu Li, HweeHwa Pang, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.1
2024 PIAS: Privacy-Preserving Incentive Announcement System Based on Blockchain for Internet of Vehicles
abstract
More vehicles are connecting to the Internet of Things (IoT), transforming Vehicle Ad hoc Networks (VANETs) into the Internet of Vehicles (IoV), providing a more environmentally friendly and safer driving experience. Vehicular announcement networks show promise in vehicular communication applications. However, two major issues arise when establishing such a system. First, user privacy cannot be guaranteed when messages are forwarded anonymously, thus the reliability of these messages is in question. Second, users often lack interest in responding to announcements. To address these problems, we introduce a Blockchain-based incentive announcement system called PIAS. This system enables anonymous message commitment in a semi-trusted environment and encourages witnesses to respond to requests for traffic information. Additionally, PIAS uses blockchain accounts as identities to participate in the system with incentives, ensuring privacy in anonymous announcements. PIAS successfully protects the privacy of participants and motivates witnesses to respond to requests. Furthermore, our assessment of security and compatibility shows that PIAS can maintain privacy and incentivization while being compatible with both the Bitcoin and Ethereum blockchains. Further evaluation has confirmed the system's efficiency in terms of performance.
Yonghua Zhan, Yang Yang 0026, Hongju Cheng, Xiangyang Luo 0001, Zhangshuang Guan, Robert H. Deng
IEEE Trans. Serv. Comput.2
2023 Toward data privacy preservation with ciphertext update and key rotation for IoT
abstract
Abstract Fine‐grained access control become a research spotlight in the scenario of the smart home with Internet‐of‐Things (IoTs). However, most of the existing works could only realize ciphertext outsourcing with an unchangeable encryption key in the cloud. That is because the trivial solution needs great communication overhead. To overcome this challenge, we propose an updatable encryption based on SM9 (SM9‐UE) scheme for the IoT smart home scenario, where SM9 is an identity and cryptographic standard adopted by GM/T0044. SM9‐UE realizes secure and lightweight ciphertext updating through using the token generated by the data owner, which is information independent with the plaintext. We give the formal security definition and prove it to be adaptive update indistinguishability (IND‐UPD) secure. Theoretical comparison and analysis show that our scheme is efficient in computation and storage overhead. Experimental results also indicate that SM9‐UE can be practically applied to IoT smart home.
Shuaiyong Shen, Yang Yang 0026, Ximeng Liu
Concurr. Comput. Pract. Exp.2
2023 PriRPT: Practical blockchain-based privacy-preserving reporting system with rewards
Yang Yang 0026, Huamin Feng, Huiqin Xie
J. Syst. Archit.2
2023 A privilege-constrained sanitizable signature scheme for e-health systems
Yonghua Zhan, Bixia Yi, Yang Yang 0026, Chen Dong 0002, Minming Huang
J. Syst. Archit.3
2023 Multimodal Sentiment Analysis Based on Attentional Temporal Convolutional Network and Multi-Layer Feature Fusion
abstract
Multimodal sentiment analysis aims to extract and integrate information from different modalities to accurately identify the sentiment expressed in multimodal data. How to effectively capture the relevant information within a specific modality and how to fully exploit the complementary information among multiple modalities are two major challenges in multimodal sentiment analysis. Traditional approaches fail to obtain the global contextual information of long time-series data when extracting unimodal temporal features, and they usually fuse the features from multiple modalities with the same method and ignore the correlation between different modalities when modeling inter-modal interactions. In this paper, we first propose an Attentional Temporal Convolutional Network (ATCN) to extract unimodal temporal features for enhancing the feature representation ability, then introduce a Multi-layer Feature Fusion (MFF) model to improve the effectiveness of multimodal fusion, which fuses the different-level features by different methods according to the correlation coefficient between the features, and cross-modal multi-head attention is used to fully explore the potential relationship between the low-level features. The experimental results on SIMS and CMU-MOSI datasets show that the proposed model achieves superior performance on sentiment analysis tasks compared to state-of-the-art baselines.
Hongju Cheng, Zizhen Yang, Yang Yang 0026
IEEE Trans. Affect. Comput.4
2023 Dual Traceable Distributed Attribute-Based Searchable Encryption and Ownership Transfer
abstract
In this article, we proposedualtraceabledistributedattributebasedencryption withsubsetkeywordsearch system (DT-DABE-SKS, abbreviated as$\mathcal {DT}$) to simultaneously realize data source trace (secure provenance) and user trace (traitor trace) and flexible subset keyword search from polynomial interpolation. Leveraging non-interactive zero-knowledge proof technology,$\mathcal {DT}$preserves privacy for both data providers and users in normal circumstances, but a trusted authority can disclose their real identities if necessary, such as the providers deceitfully uploading false data or users maliciously leaking secret attribute key. Next, we introduce the new conception of updatable and transferable message-lock encryption (UT-MLE) for block-level dynamic encrypted file update, where the owner does not have to download the whole ciphertext, decrypt, re-encrypt and upload for minor document modifications. In addition, the owner is permitted to transfer file ownership to other system customers with efficient computation in an authenticated manner. A nontrivial integration of$\mathcal {DT}$and UT-MLE lead to the distributed ABSE with ownership transfer system ($\mathcal {DTOT}$) to enjoy the above merits. We formally define$\mathcal {DT}$, UT-MLE, and their security model. Then, the instantiations of$\mathcal {DT}$and UT-MLE, and the formal security proof are presented. Comprehensive comparison and experimental analysis based on real dataset affirm their feasibility.
Yang Yang 0026, Robert H. Deng, Wenzhong Guo, Hongju Cheng, Xiangyang Luo 0001, Xianghan Zheng, Chunming Rong
IEEE Trans. Cloud Comput.1
2023 ACB-Vote: Efficient, Flexible, and Privacy- Preserving Blockchain-Based Score Voting With Anonymously Convertible Ballots
abstract
Blockchain has emerged as a decentralized platform for e-voting. Among various blockchain-based voting systems, score voting provides flexible choices and better reflects public opinions. However, existing blockchain-based score voting systems suffer from heavy range proof overheads, and are much inefficient compared with other blockchain-based voting systems. Besides, voter anonymity in these systems is not rigorously addressed. In this paper, we propose an efficient, flexible and privacy-preserving score voting system, named ACB-Vote, from anonymously convertible ballots. ACB-Vote achieves voting anonymity with BBS+ signature and signature of knowledge. Driven by convertibly linkable signatures (CLS), ACB-Vote allows cast ballots to be converted, where the conversion mechanism prevents anonymous voters from multiple voting. Besides, the proposed system avoids heavy range proofs, enables batch ballot verification and facilitates flexible tallying methods. We formally define a security model for ACB-Vote and provide rigorous security proofs. Experiments show that the efficiency of ACB-Vote is competitive compared with the previous score voting systems and is affordable in blockchain environments.
Wenyi Xue, Yang Yang 0026, Yingjiu Li, HweeHwa Pang, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.2
2023 Threshold Attribute-Based Credentials With Redactable Signature
abstract
Threshold attribute-based credentials are suitable for decentralized systems such as blockchains as such systems generally assume that authenticity, confidentiality, and availability can still be guaranteed in the presence of a threshold number of dishonest or faulty nodes. Coconut (NDSS’19) was the first selective disclosure attribute-based credentials scheme supporting threshold issuance. However, it does not support threshold tracing of user identities and threshold revocation of user credentials, which is desired for internal governance such as identity management, data auditing, and accountability. The communication and computation complexities of Coconut for verifying credentials are linear in the number of each user's attributes and thus costly. Addressing these issues, we propose a novel efficient threshold attribute-based anonymous credential scheme. While retaining all the features of Coconut, our scheme supports threshold tracing of user identities and threshold revocation of user credentials, and it significantly reduces the computational and communication complexities of credential verification. In addition, we prove that our scheme enjoys strong security features, including anonymity, blindness, traceability, and non-frameability.
Huamin Feng, Yang Yang 0026, Yingjiu Li, HweeHwa Pang, Robert H. Deng
IEEE Trans. Serv. Comput.3
2023 Time Controlled Expressive Predicate Query With Accountable Anonymity
abstract
Many existing searchable encryption schemes are inflexible in retrieval patterns. The data usage authorization is almost permanent valid as long as the user is not revoked. This “all-or-nothing” authorization mode is not compatible with the “pay-as-you-use” commercial billing model. In this article, we propose a new notion called time controlled expressive predicate query with accountable anonymity. It realizes time controlled data query, where a time server issues time token to authorize search privilege in designated time period. The data users can anonymously query on encrypted data and the anonymity is accountable in a way that the trusted authority is able to deanonymize data users if they misbehave in the system. The underlying techniques are anonymous credential, Pederson commitment and non-interactive zero-knowledge proof. We firstly design an efficient expressive predicate query (EPQ) scheme, which is proved secure to protect the privacy of expressive search predicate. Based on EPQ, we present a concrete system instantiation, which realizes key-escrow free and time token nontransferability. The formal definition and security models are given out. The system is formally proved indistinguishable against chosen keyword-set attacks, unforgeable of time tokens and accountable of anonymous users. The comparison and experiment results demonstrate its scalability and efficiency.
Yang Yang 0026, Chunming Rong, Xianghan Zheng, Hongju Cheng, Victor Chang 0001, Xiangyang Luo 0001
IEEE Trans. Serv. Comput.1
2022 Trusted Resource Allocation Based on Smart Contracts for Blockchain-Enabled Internet of Things
abstract
By sharing resources between edge servers and end users, edge-end cooperation is one important way to support various applications in Internet of Things, which have critical resource requirements on computing, storage, or bandwidth. How to price these resources and how to evaluate the service quality of edge servers are two key issues to support trusted resource allocation for blockchain-enabled Internet of Things. In this article, we provide a trusted resource allocation mechanism based on smart contracts, in which a group-buying pricing mechanism (GBPM) and a reputation evaluation mechanism (REM) are proposed to effectively address the problems existing in resources pricing and service quality evaluation of edge servers. In the trusted resource allocation mechanism, end users can choose a purchase mode from four pricing schemes in terms of actual demands on delay and price, and smart contracts can match end users with high-reputation edge servers automatically. Moreover, end users can submit reputation evaluations to smart contracts based on the behaviors of edge servers. Simulation results show the GBPM can provide differentiated prices and optimize the utility of end users accordingly, while the REM is more sensitive to edge servers with irregular behaviors and quickly reduces their reputations so that the success rate of transactions is improved.
Hongju Cheng, Qiaohong Hu, Zhiyong Yu 0001, Yang Yang 0026, Naixue Xiong
IEEE Internet Things J.5
2022 Privacy-Preserving Medical Treatment System Through Nondeterministic Finite Automata
abstract
In this article, we propose a privacy-preserving medical treatment system using nondeterministic finite automata (NFA), hereafter referred to as P-Med, designed for remote medical environment. P-Med makes use of the nondeterministic transition characteristic of NFA to flexibly represent medical model, which includes illness states, treatment methods and state transitions caused by exerting different treatment methods. A medical model is encrypted and outsourced to cloud to deliver telemedicine service. Using P-Med, patient-centric diagnosis and treatment can be made on-the-fly while protecting the confidentiality of patient’s illness states and treatment recommendation results. Moreover, a new privacy-preserving NFA evaluation method is given in P-Med to get a confidential match result for the evaluation of an encrypted NFA and an encrypted data set, which avoids the cumbersome inner state transition determination. We demonstrate that P-Med realizes treatment procedure recommendation without privacy leakage to unauthorized parties. We conduct extensive experiments and analysis to evaluate the efficiency.
Yang Yang 0026, Robert H. Deng, Ximeng Liu, Yongdong Wu, Jian Weng 0001, Xianghan Zheng, Chunming Rong
IEEE Trans. Cloud Comput.1
2022 BlockMaze: An Efficient Privacy-Preserving Account-Model Blockchain Based on zk-SNARKs
abstract
The disruptive blockchain technology is expected to have broad applications in many areas due to its advantages of transparency, fault tolerance, and decentralization, but the open nature of blockchain also introduces severe privacy issues. Since anyone can deduce private information about relevant accounts, different privacy-preserving techniques have been proposed for cryptocurrencies under the UTXO model, e.g., Zerocash and Monero. However, it is more challenging to protect privacy for account-model blockchains (e.g., Ethereum) since it is much easier to link accounts in the account-model blockchain. In this article, we proposeBlockMaze, an efficient privacy-preserving account-model blockchain based on zk-SNARKs. Along with dual-balance model, BlockMaze achieves strong privacy guarantees by hiding account balances, transaction amounts, and linkage between senders and recipients. Moreover, we provide formal security definitions and prove the security ofBlockMaze. Finally, we implement a prototype ofBlockMazebased on Libsnark and Go-Ethereum, and conduct extensive experiments to evaluate its performance. Our 300-node experiment results show that BlockMaze has high efficiency in computation and transaction throughput: one transaction verification takes about 14.2 ms, one transaction generation takes 6.1-18.6 seconds, and its throughput is around 20 TPS.
Zhangshuang Guan, Zhiguo Wan, Yang Yang 0026, Butian Huang
IEEE Trans. Dependable Secur. Comput.3
2022 Lightweight Privacy-Preserving GAN Framework for Model Training and Image Synthesis
abstract
Generative adversarial network (GAN) has excellent performance for data generation and is widely used in image synthesis. Outsourcing GAN to cloud platform is a popular way to save local computation resources and improve the efficiency, but it still faces the privacy leakage concerns: (1) the sensitive information of the training dataset may be disclosed in the cloud; (2) the trained model may reveal the privacy of training samples since it extracts the characteristics from the data. In this paper, we propose a lightweight privacy-preserving GAN framework (LP-GAN) for model training and image synthesis based on secret sharing scheme. Specifically, we design a series of efficient secure interactive protocols for different layers (convolution, batch normalization, ReLU, Sigmoid) of neural network (NN) used in GAN. Our protocols are scalable to build secure training or inference tasks for NN-based applications. We utilize edge computing to reduce the latency and all the protocols are executed on two edge servers collaboratively. Compared with the existing schemes, the proposed solution greatly improves efficiency, reduces communication overhead, and guarantees the privacy. We prove the correctness and security of LP-GAN by theoretical analysis. Extensive experiments on different real-world datasets demonstrate the effectiveness, accuracy, and efficiency of our scheme.
Yang Yang 0026, Ke Mu, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.1
2021 Secure and verifiable outsourced data dimension reduction on dynamic data
Zhenzhu Chen, Anmin Fu, Robert H. Deng, Ximeng Liu, Yang Yang 0026, Yinghui Zhang 0002
Inf. Sci.5
2021 PriScore: Blockchain-Based Self-Tallying Election System Supporting Score Voting
abstract
Election and voting play crucial roles in democratic society for an elactorate to make a collective decision. E-voting is one of the most challenging problems in cryptographic research to provide multiple dimensions security assurances. In this paper, we study an important voting paradigm, score voting, with privacy protection, which has not been investigated in previous work. We propose a blockchain based self-tallying election system to support score voting, dubbed “PriScore”, where the ballots are recorded on blockchain to prevent vote forgery or tampering. PriScore makes it possible for each voter to assign different evaluation scores (within a certain range) for the candidates as ranked-choice, where the sum of the scores in each ballot should be a predefined constant, and the evaluation scores are encrypted to maintain confidentiality. A major challenge in score voting is to simultaneously prove two constraint conditions: range proof and sum proof. We introduce a new technique, called dual zero-knowledge proof (dual-ZKP), to prove the scores satisfying two crucial requirements, which integrates “1-out-of-$K$” proof and distributed ElGamal crypto in a non-trivial way. The self-tallying mechanism in PriScore enables any party in the system to calculate and verify the election result, which provides fairness, dispute-freeness. The security analysis demonstrates that PriScore achieves completeness, soundness, eligibility, universal/individual verifiability and multiple-voting detection. We evaluate the performance of PriScore on modern workbench to test the performance, and also on a blockchain platform to measure the resource consumption. The experiments show that PriScore preserves privacy of score voting with reasonable overheads.
Yang Yang 0026, Zhangshuang Guan, Zhiguo Wan, Jian Weng 0001, HweeHwa Pang, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.1
2021 Privacy-Preserving Outsourced Clinical Decision Support System in the Cloud
abstract
In this paper, we propose a privacy-preserving clinical decision support system using Naïve Bayesian (NB) classifier, hereafter referred to as Peneus, designed for the outsourced cloud computing environment. Peneus allows one to use patient health information to train the NB classifier privately, which can then be used to predict a patient's (undiagnosed) disease based on his/her symptoms in a single communication round. Specifically, we design secure Single Instruction Multiple Data (SIMD) integer circuits using the fully homomorphic encryption scheme, which can greatly increase the performance compared with the original secure integer circuit. Then, we present a privacy-preserving historical Personal Health Information (PHI) aggregation protocol to allow different PHI sources to be securely aggregated without the risk of compromising the privacy of individual data owner. Also, secure NB classifier is constructed to achieve secure disease prediction in the cloud without the help of an additional non-colluding computation server. We then demonstrate that Peneus achieves the goal of patient health status monitoring without privacy leakage to unauthorized parties, as well as the utility and the efficiency of Peneus using simulations and analysis.
Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang 0026
IEEE Trans. Serv. Comput.4
2020 Lightning-fast and privacy-preserving outsourced computation in the cloud
abstract
Abstract In this paper, we propose a framework for lightning-fast privacy-preserving outsourced computation framework in the cloud, which we refer to as LightCom. Using LightCom, a user can securely achieve the outsource data storage and fast, secure data processing in a single cloud server different from the existing multi-server outsourced computation model. Specifically, we first present a general secure computation framework for LightCom under the cloud server equipped with multiple Trusted Processing Units (TPUs), which face the side-channel attack. Under the LightCom, we design two specified fast processing toolkits, which allow the user to achieve the commonly-used secure integer computation and secure floating-point computation against the side-channel information leakage of TPUs, respectively. Furthermore, our LightCom can also guarantee access pattern protection during the data processing and achieve private user information retrieve after the computation. We prove that the proposed LightCom can successfully achieve the goal of single cloud outsourced data processing to avoid the extra computation server and trusted computation server, and demonstrate the utility and the efficiency of LightCom using simulations.
Ximeng Liu, Robert H. Deng, Pengfei Wu 0003, Yang Yang 0026
Cybersecur.4
2020 Multimedia access control with secure provenance in fog-cloud computing networks
Yang Yang 0026, Ximeng Liu, Wenzhong Guo, Xianghan Zheng, Chen Dong 0002, Zhiquan Liu 0001
Multim. Tools Appl.1
2020 Privacy-Preserving Outsourced Support Vector Machine Design for Secure Drug Discovery
abstract
In this paper, we propose a framework for privacy-preserving outsourced drug discovery in the cloud, which we refer to as POD. Specifically, POD is designed to allow the cloud to securely use multiple drug formula providers' drug formulas to train Support Vector Machine (SVM) provided by the analytical model provider. In our approach, we design secure computation protocols to allow the cloud server to perform commonly used integer and fraction computations. To securely train the SVM, we design a secure SVM parameter selection protocol to select two SVM parameters and construct a secure sequential minimal optimization protocol to privately refresh both selected SVM parameters. The trained SVM classifier can be used to determine whether a drug chemical compound is active or not in a privacy-preserving way. Lastly, we prove that the proposed POD achieves the goal of SVM training and chemical compound classification without privacy leakage to unauthorized parties, as well as demonstrating its utility and efficiency using three real-world drug datasets.
Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang 0026
IEEE Trans. Cloud Comput.4
2020 Efficient Traceable Authorization Search System for Secure Cloud Storage
abstract
Secure search over encrypted remote data is crucial in cloud computing to guarantee the data privacy and usability. To prevent unauthorized data usage, fine-grained access control is necessary in multi-user system. However, authorized user may intentionally leak the secret key for financial benefit. Thus, tracing and revoking the malicious user who abuses secret key needs to be solved imminently. In this paper, we propose an escrow free traceable attribute based multiple keywords subset search system with verifiable outsourced decryption (EF-TAMKS-VOD). The key escrow free mechanism could effectively prevent the key generation centre (KGC) from unscrupulously searching and decrypting all encrypted files of users. Also, the decryption process only requires ultra lightweight computation, which is a desirable feature for energy-limited devices. In addition, efficient user revocation is enabled after the malicious user is figured out. Moreover, the proposed system is able to support flexible number of attributes rather than polynomial bounded. Flexible multiple keyword subset search pattern is realized, and the change of the query keywords order does not affect the search result. Security analysis indicates that EF-TAMKS-VOD is provably secure. Efficiency analysis and experimental results show that EF-TAMKS-VOD improves the efficiency and greatly reduces the computation overhead of users' terminals.
Yang Yang 0026, Ximeng Liu, Xianghan Zheng, Chunming Rong, Wenzhong Guo
IEEE Trans. Cloud Comput.1
2020 Efficient Regular Language Search for Secure Cloud Storage
abstract
Cloud computing provides flexible data management and ubiquitous data access. However, the storage service provided by cloud server is not fully trusted by customers. Searchable encryption could simultaneously provide the functions of confidentiality protection and privacy-preserving data retrieval, which is a vital tool for secure storage. In this paper, we propose an efficient large universe regular language searchable encryption scheme for the cloud, which is privacy-preserving and secure against the off-line keyword guessing attack (KGA). A notable highlight of the proposal over other existing schemes is that it supports the regular language encryption and deterministic finite automata (DFA) based data retrieval. The large universe construction ensures the extendability of the system, in which the symbol set does not need to be predefined. Multiple users are supported in the system, and the user could generate a DFA token using his own private key without interacting with the key generation center. Furthermore, the concrete scheme is efficient and formally proved secure in standard model. Extensive comparison and simulation show that this scheme has function and performance superior than other schemes.
Yang Yang 0026, Xianghan Zheng, Chunming Rong, Wenzhong Guo
IEEE Trans. Cloud Comput.1
2020 Lightweight Sharable and Traceable Secure Mobile Health System
abstract
Mobile health (mHealth) has emerged as a new patient centric model which allows real-time collection of patient data via wearable sensors, aggregation and encryption of these data at mobile devices, and then uploading the encrypted data to the cloud for storage and access by healthcare staff and researchers. However, efficient and scalable sharing of encrypted data has been a very challenging problem. In this paper, we propose a Lightweight Sharable and Traceable (LiST) secure mobile health system in which patient data are encrypted end-to-end from a patient's mobile device to data users. LiST enables efficient keyword search and fine-grained access control of encrypted data, supports tracing of traitors who sell their search and access privileges for monetary gain, and allows on-demand user revocation. LiST is lightweight in the sense that it offloads most of the heavy cryptographic computations to the cloud while only lightweight operations are performed at the end user devices. We formally define the security of LiST and prove that it is secure without random oracle. We also conduct extensive experiments to access the system's performance.
Yang Yang 0026, Ximeng Liu, Robert H. Deng, Yingjiu Li
IEEE Trans. Dependable Secur. Comput.1
2020 Privacy-Preserving Outsourced Calculation Toolkit in the Cloud
abstract
In this paper, we propose a privacy-preserving outsourced calculation toolkit, Pockit, designed to allow data owners to securely outsource their data to the cloud for storage. The outsourced encrypted data can be processed by the cloud server to achieve commonly-used plaintext arithmetic operations without involving additional servers. Specifically, we design both signed and unsigned integer circuits using a fully homomorphic encryption (FHE) scheme, construct a new packing technique (hereafter referred to as integer packing), and extend the secure circuits to its packed version. This achieves significant improvements in performance compared with the original secure signed/unsigned integer circuit. The secure integer circuits can be used to construct a new data mining application, which we refer to as secure k-nearest neighbours classifier, without compromising the privacy of original data. Finally, we prove that the proposed Pockit achieves the goal of secure computation without privacy leakage to unauthorized parties, and demonstrate the utility and efficiency of Pockit.
Ximeng Liu, Robert H. Deng, Kim-Kwang Raymond Choo, Yang Yang 0026, HweeHwa Pang
IEEE Trans. Dependable Secur. Comput.4
2020 Multi-User Multi-Keyword Rank Search Over Encrypted Data in Arbitrary Language
abstract
Multi-keyword rank searchable encryption (MRSE) returns the top-k results in response to a data user's request of multi-keyword search over encrypted data, and hence provides an efficient way for preserving data privacy in cloud storage systems while without loss of data usability. Many existing MRSE systems are constructed based on an algorithm which we term as k-nearest neighbor for searchable encryption (KNN-SE). Unfortunately, KNN-SE has a number of shortcomings, which limit its practical applications. In this paper, we propose a new MRSE system which overcomes almost all the defects of the KNN-SE based MRSE systems. Specifically, our new system does not require a predefined keyword set and supports keywords in arbitrary languages, is a multi-user system which supports flexible search authorization and time-controlled revocation, and it achieves better data privacy protection since even the cloud server is not able to tell which documents are the top-k results returned to a data user. We also conduct extensive experiments to demonstrate the efficiency of the new system.
Yang Yang 0026, Ximeng Liu, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.1
2020 Flexible Wildcard Searchable Encryption System
abstract
Searchable encryption is an important technique for public cloud storage service to provide user data confidentiality protection and at the same time allow users performing keyword search over their encrypted data. Previous schemes only deal with exact or fuzzy keyword search to correct some spelling errors. In this paper, we propose a new wildcard searchable encryption system to support wildcard keyword queries which has several highly desirable features. First, our system allows multiple keywords search in which any queried keyword may contain zero, one or two wildcards, and a wildcard may appear in any position of a keyword and represent any number of symbols. Second, it supports simultaneous search on multiple data owner's data using only one trapdoor. Third, it provides flexible user authorization and revocation to effectively manage search and decryption privileges. Fourth, it is constructed based on homomorphic encryption rather than Bloom filter and hence completely eliminates the false probability caused by Bloom filter. Finally, it achieves a high level of privacy protection since matching results are unknown to the cloud server in the test phase. The proposed system is thoroughly analyzed and is proved secure. Extensive experimental results indicate that our system is efficient compared with other existing wildcard searchable encryption schemes in the public key setting.
Yang Yang 0026, Ximeng Liu, Robert H. Deng, Jian Weng 0001
IEEE Trans. Serv. Comput.1
2019 Privacy-Preserving Compressive Sensing for Traffic Estimation
abstract
Traffic estimation is a popular approach to acquire traffic conditions in urban areas. At present, using the traffic data to realize the low-cost traffic estimation has already been widely favored. Although those data include various sensitive element, people ignore the harm caused by information leakage while the data are used. Additionally, the transmission of vehicle data also requires a very large communication bandwidth. To address those problems, we focus on the privacy-preserving vehicle data and reducing the amount of ciphertext data to achieve a city-scale traffic estimation. Meanwhile, we present a novel framework that integrates compressive sensing (CS) technology into privacy- preserving vehicle data. Furthermore, outsourcing vehicle data to the cloud is adopted to overcome the limitations of the in-vehicle sensors. In particular, we present a feasible computational scheme for traffic estimation, further improve the capacity of privacy- preserving and decrease system energy consumption. Finally, we validate the effectiveness of the scheme proposed through the real-world dataset.
Wenzhong Guo, Zhuo Ma 0001, Xianjia Meng, Yang Yang 0026, Ximeng Liu
GLOBECOM5
2019 Privacy-preserving smart IoT-based healthcare big data storage and self-adaptive access control system
Yang Yang 0026, Xianghan Zheng, Wenzhong Guo, Ximeng Liu, Victor Chang 0001
Inf. Sci.1
2019 Clustering based interest prediction in social networks
Xianghan Zheng, Wenfei Zheng, Yang Yang 0026, Wenzhong Guo, Victor Chang 0001
Multim. Tools Appl.3
2018 Cross-domain dynamic anonymous authenticated group key management with symptom-matching for e-health social system
Yang Yang 0026, Xianghan Zheng, Ximeng Liu, Shangping Zhong, Victor Chang 0001
Future Gener. Comput. Syst.1
2018 Hybrid privacy-preserving clinical decision support system in fog-cloud computing
Ximeng Liu, Robert H. Deng, Yang Yang 0026, Ngoc Hieu Tran, Shangping Zhong
Future Gener. Comput. Syst.3
2018 Privacy-preserving fusion of IoT and big data for e-health
Yang Yang 0026, Xianghan Zheng, Wenzhong Guo, Ximeng Liu, Victor Chang 0001
Future Gener. Comput. Syst.1
2018 Expressive query over outsourced encrypted data
Yang Yang 0026, Ximeng Liu, Robert H. Deng
Inf. Sci.1
2018 Lattice assumption based fuzzy information retrieval scheme support multi-user for secure multimedia cloud
Yang Yang 0026, Xianghan Zheng, Victor Chang 0001, Shaozhen Ye, Chunming Tang 0003
Multim. Tools Appl.1
2018 Region-Aware Image Denoising by Exploring Parameter Preference
abstract
The goal of an image denoising algorithm is to preserve the details of clean images while reducing the noise in noisy images. Some existing image denoising algorithms preserve the details by using external information. However, external information needs to be obtained from external images or regions similar to the noisy images or regions. In this letter, we propose a region-aware image denoising algorithm (RAID) by exploring parameter preference. The proposed RAID algorithm is based on the observation that different regions of noisy images prefer denoised results that differ due to being obtained with different denoising parameters. The RAID algorithm, first, measures the extent of preferences of denoising parameters for different image regions. Then, it combines the denoised results obtained by using the various denoising parameters according to the extent of preferences determined in the previous step to get the final denoised image. Experimental results show that the proposed RAID algorithm can be combined with some existing image denoising algorithms to improve their denoising performance. Our denoised results are better at preserving the details while reducing the noise than existing algorithms which use the same parameter for the whole image.
Yuzhen Niu, Yang Yang 0026, Wenzhong Guo, Lening Lin
IEEE Trans. Circuits Syst. Video Technol.2
2018 Lightweight Break-Glass Access Control System for Healthcare Internet-of-Things
abstract
Healthcare Internet-of-things (IoT) has been proposed as a promising means to greatly improve the efficiency and quality of patient care. Medical devices in healthcare IoT measure patients' vital signs and aggregate these data into medical files which are uploaded to the cloud for storage and accessed by healthcare workers. To protect patients' privacy, encryption is normally used to enforce access control of medical files by authorized parties while preventing unauthorized access. In healthcare, it is crucial to enable timely access of patient files in emergency situations. In this paper, we propose a lightweight break-glass access control (LiBAC) system that supports two ways for accessing encrypted medical files: attribute-based access and break-glass access. In normal situations, a medical worker with an attribute set satisfying the access policy of a medical file can decrypt and access the data. In emergent situations, the break-glass access mechanism bypasses the access policy of the medical file to allow timely access to the data by emergency medical care or rescue workers. LiBAC is lightweight since very few calculations are executed by devices in the healthcare IoT network, and the storage and transmission overheads are low. LiBAC is formally proved secure in the standard model and extensive experiments are conducted to demonstrate its efficiency.
Yang Yang 0026, Ximeng Liu, Robert H. Deng
IEEE Trans. Ind. Informatics1
2018 Security and Privacy Challenges for Internet-of-Things and Fog Computing
Ximeng Liu, Yang Yang 0026, Kim-Kwang Raymond Choo, Huaqun Wang
Wirel. Commun. Mob. Comput.2
2017 Semantic keyword searchable proxy re-encryption for postquantum secure cloud storage
abstract
Summary With the advent of cloud computing, more and more consumers prefer to use the cloud services with the pay‐as‐you‐consume mode. The cloud storage brings about great convenience to users, who store data in cloud and access to it using the smart devices anytime and anywhere. Consumers' information should be encrypted to guarantee the data privacy. Flexible searching on ciphertext is a critical challenge to be solved for effective data utilization. In this paper, we propose a novel semantic keyword searchable proxy re‐encryption scheme for secure cloud storage. A highlight of this work is that the scheme is quantum attack resistant, while most of the available searchable encryption schemes are not. It supports not only exact keyword search but also synonym keyword search. Moreover, the data owner is capable to delegate his search right to another user using the proxy re‐encryption mechanism. In the generation process of re‐encryption key, the delegator and delegatee do not need to be interactive with each other. The scheme is also collusion resistant. Under the learning with errors hardness problem, this scheme is proved secure in standard model.
Yang Yang 0026, Xianghan Zheng, Victor Chang 0001, Chunming Tang 0003
Concurr. Comput. Pract. Exp.1
2017 Lightweight distributed secure data management system for health internet of things
Yang Yang 0026, Xianghan Zheng, Chunming Tang 0003
J. Netw. Comput. Appl.1
2014 Broadcast encryption based non-interactive key distribution in MANETs
Yang Yang 0026
J. Comput. Syst. Sci.1
2012 A Communication Efficient Group Key Distribution Scheme for MANETs
Yang Yang 0026
NSS1
2011 CCA2 secure biometric identity based encryption with constant-size ciphertext
abstract
We propose a new biometric identity based encryption scheme (Bio-IBE), in which user biometric information is used to generate the public key with a fuzzy extractor. This is the first Bio-IBE scheme that achieves constant size ciphertext. This is also a scheme that is secure against the adaptive chosen ciphertext attack (CCA2). Details are presented along with a discussion of Shamir’s threshold secret sharing and fuzzy extraction of biometrics, which is based on error correction codes. We also define a security model and prove that the security of the proposed scheme is reduced to the decisional bilinear Diffie-Hellman (DBDH) assumption. The comparison shows that the proposed scheme has better efficiency and stronger security compared with the available Bio-IBE schemes.
Yang Yang 0026, Yupu Hu, Leyou Zhang, Chun-hui Sun
J. Zhejiang Univ. Sci. C1