Qi Jiang 0001

dblp:48/5579-1 · DBLP profile ↗
← Back
54ranked-venue papers
6as first author
27since 2021 · last 2026
0000-0002-0894-4992ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 21 · 4 first-author · 11 since 2021Security and privacy · 14 · 1 first-author · 9 since 2021Systems, architecture and hardware · 7 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 3Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Reliable location selection and hierarchical interleaved bloom filter based iris template protection
Guichuan Zhao, Youliang Tian, Qi Jiang 0001, Jianfeng Ma 0001
Comput. Secur.3
2026 PAMA: Provable-Secure Anonymous Multifactor Authentication With Postquantum Security for IoT-Enabled E-Healthcare Systems
abstract
The booming technologies of the Internet of Things (IoT) enable various applications and develop well. E-healthcare system is one of the successful examples, where people manage their healthcare information, diagnosis data, physical examination results, and so on. These types of sensitive information cause crucial security risks, posing threats to the security of the lives and property of the people. Given this concern, safeguard measures, such as authentication and encryption, are necessary. However, due to the openness of the wireless networks, authentication protocols for IoT-enabled e-healthcare systems are usually vulnerable to serious attacks. Furthermore, the quantum era is around the corner, urging authentication protocols to possess post-quantum security properties. In this paper, we propose a multi-factor password authentication scheme, named PAMA, with post-quantum security for the e-healthcare system. The lattice cryptography is adopted for post-quantum security. We formally prove the proposed PAMA scheme to be secure, and also informally verify the security against common attacks. Furthermore, we compare the performance of the communication efficiency of the PAMA scheme with other related works from both theoretical and experimental aspects. The efficiency comparison results demonstrate that our PAMA scheme approximately reduces the computation cost by 37.59% and the energy consumption by 37.5%, compared to the related post-quantum schemes. In summary, the PAMA scheme has a great advantage in secure authentication and agreement on a session key in the e-healthcare system.
Yuqian Ma, Yongliu Ma, Zhiquan Liu 0001, Qi Jiang 0001, Qingfeng Cheng
IEEE Internet Things J.4
2025 Publicly Verifiable and Fault-Tolerant Privacy-Preserving Aggregation for Federated Learning
abstract
Publicly verifiable privacy-preserving aggregation is widely regarded as an effective approach to protect user privacy and ensure the integrity of the aggregated model published by the aggregator in Federated Learning (FL). State-of-the-art solutions either fail to guarantee unforgeability when the aggregator colludes with malicious users or require costly cryptographic operations during the online aggregation phase and lack fault tolerance. In this work, we propose eVTPA, the first online-efficient, publicly verifiable, and fault-tolerant privacy-preserving aggregation protocol considering malicious users and aggregators for FL. We introduce a novel collusion-resistant symmetric masking technique to conceal users' local gradients while ensuring the correctness of the aggregated model through a publicly verifiable aggregation signature algorithm. To improve the efficiency of online signature generation, we design a specialized precomputation-based acceleration method and leverage the randomness of masking to enable batch processing. Furthermore, eVTPA adopts a dynamic mask update mechanism that tolerates user dropouts without affecting the validation of the aggregated model. Security analysis shows that eVTPA meets FL's confidentiality, integrity, and authenticity requirements. Experimental results demonstrate that our scheme maintains model classification accuracy while achieving at least a 7.85× faster online aggregation than related solutions at the same security level.
Guohao Li 0004, Qi Jiang 0001, Li Yang 0005
CIKM2
2025 PQ3FAKE: Postquantum Three-Factor Authentication Against Server Compromise in Mobile Cloud Computing
abstract
The rapid advancement of mobile cloud computing has prompted users and commercial entities to increasingly access and utilize cloud resources for executing resource-intensive operations, which requires strong three-factor authentication and key exchange (3FAKE) protocols to ensure secure interactions in cloud environments. However, the current 3FAKE protocols not only primarily rely on traditional public-key cryptosystems that are vulnerable to quantum attacks, but lack sufficient protection for sensitive information of cloud users as well. To this end, this paper proposes a post-quantum 3FAKE (PQ3FAKE) protocol employing identity-based oblivious pseudorandom function (IBOPRF). Specifically, an IBOPRF from module learning with errors is instantiated to achieve a better balance between efficiency and security. Next, PQ3FAKE is built upon this IBOPRF to protect password from server compromise. We conduct an extensive evaluation and comparison with existing typical protocols in terms of computational overhead and security, demonstrating that the proposed PQ3FAKE achieves higher security while maintaining expected performance.
Xue Yang 0017, Qi Jiang 0001, Meng Li 0006, Meijia Xu, Ding Wang 0002, Jianfeng Ma 0001
IEEE Internet Things J.2
2025 Electrocardiogram-to-Pair (E2P): A Secure Group Pairing Protocol for WBAN Devices
abstract
In a wireless body area network (WBAN), group pairing among multiple wearable devices enables efficient and secure broadcasting group messages. Existing pairing methods that rely on trusted concentrators, active participation of users, or homogeneous environments are vulnerable to single point of failure and have restricted practicality. In this article, we propose Electrocardiogram-to-Pair (E2P), an electrocardiogram (ECG)-based secure group pairing protocol for WBAN devices that allows the establishment of a shared group key among multiple devices without requiring the user involvement or the central device. First, all wearable devices worn by the same user simultaneously collect ECG signals, which are then pre-processed through filtering and alignment to minimize the effect of noise on the pairing. Next, an adaptive quantization method is designed to reliably quantize the pre-processed ECG signals to generate initial keys. This method is ingenious as it relies on feature transformation and dynamic thresholds generation in the quantization process, which effectively ensures the security of biometrics and increases the key generation rate. Then, the group key is established among devices with initial keys through an improved Cascade method. The simulation results demonstrate that E2P achieves an effective balance the reliability and efficiency in group pairing, with outstanding performance in both security and key generation rate.
Guichuan Zhao, Youliang Tian, Qi Jiang 0001, Jianfeng Ma 0001
IEEE Internet Things J.3
2025 Multi-factor single-registration authentication and key exchange protocol for IIoT
Qi Jiang 0001, Zengwen Yu, XinDi Ma, Xinghua Li 0001
J. Syst. Archit.3
2025 Repairing Backdoor Model With Dynamic Gradient Clipping for Intelligent Vehicles
abstract
The backdoor attack has emerged as a prevalent threat that affects the effectiveness of machine learning models in intelligent vehicles. While such attacks may not impair the normal performance of the trained model, they can be exploited by malicious entities to manipulate model inferences, resulting in serious problems. In this paper, we design a dynamic gradient clipping (DGC) method aimed at rectifying backdoor models by eliminating the underlying backdoor trigger. Firstly, we construct a repair dataset fused by some clean samples and few-shot backdoor samples to amplify the backdoor behavior when we only obtain limited backdoor samples. Subsequently, we introduce sample states to characterize the backdoor behavior of the target model, determined by the model's inference outcome. Finally, we devise the DGC method to clip parameter gradients at varying degrees, effectively eliminating the backdoor trigger within the target model. Through the evaluation, the simulation results demonstrate that our DGC method exhibits robust defense capabilities against four contemporary state-of-the-art backdoor attacks, reducing the attack success rate by 95% with only$0.1\% \sim 4.8\%$model accuracy loss.
XinDi Ma, Xinfu Li, Zhuo Ma 0001, Qi Jiang 0001, Ximeng Liu, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.5
2025 Three Birds With One Arrow: Symmetric Two-Factor Authentication Protocol Based on Puncturable Pseudorandom Function
abstract
The combination of smart cards and passwords has given birth to one of the most prevalent two-factor authentication (2FA) approaches. Numerous 2FA schemes have been proposed, nevertheless, most of them either do not possess critical security properties or are not efficient for implementation on smart cards. It is generally considered that asymmetric cryptographic primitives are indispensable to achieve security goals, which are burdensome for resource-limited devices. That is, the literature is being stuck with the security-efficiency tension. In this paper, we propose a 2FA protocol only resorting to symmetric primitives. Specifically, with the puncturable pseudorandom function, the proposed protocol hits three birds: it achieves three subtle security goals, i.e., resisting offline password guessing attacks, perfect forward secrecy and anonymity. It alleviates the long-standing security-efficiency conflict that is considered intractable in the literature. The proposed protocol is provably secure within the harshest adversary model to date. Furthermore, the evaluation results demonstrate that our protocol is the optimal choice when considering both security and efficiency.
Qi Jiang 0001, Meng Li 0006, XinDi Ma, Jianfeng Ma 0001
IEEE Trans. Inf. Forensics Secur.2
2025 FedWiper: Federated Unlearning via Universal Adapter
abstract
Privacy preservation are becoming increasingly significant in machine learning, with recent privacy regulations requiring the deletion of personal data and its impact on models. Although erasing data from storage is simple, removing the influence of data on models remains a challenge. Federated unlearning is an emerging paradigm that aims to forget the knowledge contributed by some specific data to the federated model. In this paper, we design a novel federated unlearning strategy, named FedWiper, which enables exact unlearning in federated learning by erasing specific data and its impact from the federated model. Specifically, based on the granularity of the dataset, we propose training multiple federated submodels to construct a federated unlearning framework, thereby narrowing the scope of the impact of wiped data. Furthermore, the proposed Uni-Adapter structure effectively mitigates the negative impact on model performance from diminishing the dataset scale, while also reducing communication cost. Rather than focusing solely on achieving indistinguishability unlearning of the model for classification task, we extend FedWiper to unlearning for multiple types of tasks and achieve the exact unlearning. Experiments demonstrate that FedWiper can not only accelerate federated unlearning, but also achieve exact unlearning across multiple types of tasks in federated learning while ensuring minimal loss of model performance. Our Code: https://github.com/grey1989/FedWiper.
XinDi Ma, Qi Jiang 0001, Zhuo Ma 0001, Sheng Gao 0002, Zuobin Ying, Jianfeng Ma 0001
IEEE Trans. Inf. Forensics Secur.4
2024 DP-CLMI:Differentially Private Contrastive Learning Against Membership Inference Attack
Yiwen Xia, XinDi Ma, Qi Jiang 0001, Ning Xi 0002, Di Lu 0001, Pengbin Feng, Sheng Gao 0002, Jianfeng Ma 0001
ICA3PP (5)4
2024 Deep Hashing Based Cancelable Multi-Biometric Template Protection
abstract
The increasing use of multi-biometric authentication has raised concerns about the security of biometric templates. Many template protection methods based on convolutional neural network have been presented, but most involve a trade-off between authentication accuracy and template security. In this paper, we present a cancelable multi-biometric template protection scheme that combines deep hashing with cancelable distance-preserving encryption (CDPE), which provides high template security without degrading the authentication performance. Specifically, a deep hashing based architecture that minimizes the quantization loss is designed to map face and iris traits to binary codes. Next, CDPE is proposed to generate a protected template given the face binary code and a user-specific key obtained from the iris binary code, which preserves the distance between original templates in the protected domain to ensure authentication performance equivalent to unprotected systems. Digital lockers instead of the key are stored to further enhance the security, which can be unlocked with genuine biometric traits to get the correct key during authentication. Theoretical and experimental results on real face and iris datasets show that our scheme can achieve equal error rate of 0.23% and genuine accept rate of 97.54%, while guaranteeing irreversibility, revocability and unlinkability of protected templates.
Guichuan Zhao, Qi Jiang 0001, Ding Wang 0002, XinDi Ma, Xinghua Li 0001
IEEE Trans. Dependable Secur. Comput.2
2024 Cross-Modal Learning Based Flexible Bimodal Biometric Authentication With Template Protection
abstract
Face and voice are two of the most popular traits used for authentication tasks in daily life, as they can be easily captured using low-cost visual and audio sensors on smartphones, laptops, tablets,etc. Many bimodal biometric authentication schemes based on these two traits have been presented to provide higher accuracy than unimodal systems. However, these schemes are inflexibility due to the requirement of submitting two traits simultaneously, and they lack template protection, which may lead to biometric data leakage. We present a cross-modal learning based bimodal biometric authentication scheme, which improves the flexibility of existing schemes while ensuring the biometric template security. We integrate cross-modal learning into the feature extraction to obtain a bimodal biometric shared representation given input face images and voice clips. In order to enhance biometric template security without sacrificing authentication accuracy, a residual network and polar codes based template protection method is proposed, which can eliminate the noise in shared representations due to intra-user variations and generate protected templates. We have evaluated the efficacy of the bimodal biometric scheme using a real video dataset containing face images and voice clips. Experimental results demonstrate that our scheme can achieve flexible authentication with high accuracy no matter the probe input is a face image, a voice clip or a combination of them. Furthermore, the security analysis demonstrates that our scheme provides irreversibility, unlinkability and revocability of protected templates.
Qi Jiang 0001, Guichuan Zhao, XinDi Ma, Meng Li 0006, Youliang Tian, Xinghua Li 0001
IEEE Trans. Inf. Forensics Secur.1
2023 Anonymous Lightweight Authenticated Key Agreement Protocol for Fog-Assisted Healthcare IoT System
abstract
The impact of fog-assisted healthcare Internet of Things (H-IoT) system is immense. The smart H-IoT equipments can upload healthcare information to fog nodes with low latency and high mobility. To facilitate secure interactions among three parties, including smart H-IoT equipments, fog nodes, and a cloud server, over the public and insecure channels, a few authenticated key agreement (AKA) protocols are proposed. However, existing works are constructed based on expensive cryptographic primitives (e.g., bilinear pairing), which lead to high computation costs. Besides, the anonymity of H-IoT users is failed to be provided. To tackle these issues, an anonymous and lightweight three-party AKA protocol (ALAKAP) is proposed, which leverages an efficient cryptographic primitive (i.e., Chebyshev chaotic map operation) to generate a shared session key among three parties and achieve security (anonymity and other six properties) and efficiency simultaneously. It then formally proves the security of ALAKAP under the broadly accepted Burrows–Abadi–Needham (BAN) logic model and demonstrates how the proposed protocol satisfies the desired requirements in the fog-assisted H-IoT system. Finally, the performance of ALAKAP is validated by conducting the experiments on Amazon EC2 and Raspberry Pi. The results show that our work can achieve at least 44% higher improvement than the state-of-the-art works.
Xuewen Dong, Qi Jiang 0001, Siqi Ma 0001, Chao Liu 0039, Ning Xi 0002, Yulong Shen 0001
IEEE Internet Things J.3
2023 Verifiable and Dynamic Multi-Keyword Search Over Encrypted Cloud Data Using Bitmap
abstract
Searchable Symmetric Encryption (SSE), which enables users to search over encrypted data without decryption, has gained increasing attention from both academic and industrial fields. However, existing SSE schemes either have low search efficiency or cannot support multi-keyword search, dynamic updates, and result verification simultaneously. To solve these problems, we propose a Verifiable and Dynamic Multi-keyword Search (VDMS) scheme over encrypted data by using the bitmap and RSA accumulator, which provides multi-keyword search over encrypted data in an efficient, verifiable and updated way. The bitmap is used as a data structure to build the indexes, which improves the search efficiency and reduces the storage space of the indexes. The RSA accumulator and bitmap are combined to verify the correctness of results. Formal security analysis proves that our VDMS is adaptively secure against Chosen-Keyword Attacks (CKA), and empirical experiments using a real-world dataset demonstrate that our VDMS is efficient and feasible in practical applications.
Feng Li 0041, Jianfeng Ma 0001, Yinbin Miao, Qi Jiang 0001, Ximeng Liu, Kim-Kwang Raymond Choo
IEEE Trans. Cloud Comput.4
2023 Learning in Your "Pocket": Secure Collaborative Deep Learning With Membership Privacy
abstract
Organizations tend to collaboratively train the deep learning model over their combined datasets for a common benefit (e.g., better-trained model or learning a complicated model). However, due to the consideration about privacy leakage, organizations cannot share their data directly, especially related to sensitive domains. In this paper, a privacy-preserving collaborative deep learning mechanism, namely Sigma, is designed to allow participating organizations to train a collective model without exposing their local training data to the others. Specifically, a single-server-aided private collaborative architecture is introduced to achieve the private collaborative learning, which protects organizations’ data even if$n-1$out of$n$participants colluded. We also design a practical protocol to perform the secure model training, which can resist the typical inference attack through the sharing information. After that, we propose a fair model releasing mechanism for participants and introduce differential privacy to prevent model stealing and membership inference attack. Furthermore, we prove that Sigma can ensure participants’ privacy preservation and analyze the communication overhead in theory. To evaluate the effectiveness and efficiency of Sigma, we conduct an experiment over two real-world datasets and the simulation results demonstrate that Sigma can efficiently achieve the collaborative model training and effectively resist the membership inference attack.
XinDi Ma, Qi Jiang 0001, Ximeng Liu, Qingqi Pei, Jianfeng Ma 0001, Wenjing Lou
IEEE Trans. Dependable Secur. Comput.2
2023 DisBezant: Secure and Robust Federated Learning Against Byzantine Attack in IoT-Enabled MTS
abstract
With the intelligentization of Maritime Transportation System (MTS), Internet of Thing (IoT) and machine learning technologies have been widely used to achieve the intelligent control and routing planning for ships. As an important branch of machine learning, federated learning is the first choice to train an accurate joint model without sharing ships' data directly. However, there are still many unsolved challenges while using federated learning in IoT-enabled MTS, such as the privacy preservation and Byzantine attacks. To surmount the above challenges, a novel mechanism, namely DisBezant, is designed to achieve the secure and Byzantine-robust federated learning in IoT-enabled MTS. Specifically, a credibility-based mechanism is proposed to resist the Byzantine attack in non-iid (not independent and identically distributed) dataset which is usually gathered from heterogeneous ships. The credibility is introduced to measure the trustworthiness of uploaded knowledge from ships and is updated based on their shared information in each epoch. Then, we design an efficient privacy-preserving gradient aggregation protocol based on a secure two-party calculation protocol. With the help of a central server, we can accurately recognise the Byzantine attackers and update the global model parameters privately. Furthermore, we theoretically discussed the privacy preservation and efficiency of DisBezant. To verify the effectiveness of our DisBezant, we evaluate it over three real datasets and the results demonstrate that DisBezant can efficiently and effectively achieve the Byzantine-robust federated learning. Although there are 40% nodes are Byzantine attackers in participants, our DisBezant can still recognise them and ensure the accurate model training.
XinDi Ma, Qi Jiang 0001, Mohammad Shojafar, Mamoun Alazab, Sachin Kumar 0002, Saru Kumari
IEEE Trans. Intell. Transp. Syst.2
2023 Electrocardiogram Based Group Device Pairing for Wearables
abstract
The widespread usage of wearables to provide healthcare services prompts the need for secure group communication among multiple devices using group keys. Gait-based group key establishment schemes are either vulnerable to video attacks, or fail to offer a secure group key update mechanism when group device changes. In this paper, we present an electrocardiogram (ECG) signals based group device pairing protocol, which can strengthen the security and reduce the overhead of wearables. Specifically, we first design a robust and lightweight fuzzy extractor that supports secure and efficient group device association between wearables. Meanwhile, we propose Improved Martingale Randomness Extraction (IMRE) algorithm, which utilizes the trend of InterPulse Interval (IPI) from ECG signal to extract high-entropy keys. Then we present a membership management mechanism that enables group key dynamic update when group device changes. Finally, we simulate our protocol and evaluate the accuracy and efficiency by various experiments. The experimental results demonstrate that the proposed work is robust and efficient, and the threat model-based security analysis shows that the proposed protocol can prevent both active and passive attacks.
Guichuan Zhao, Qi Jiang 0001, Ximeng Liu, XinDi Ma, Ning Zhang 0007, Jianfeng Ma 0001
IEEE Trans. Mob. Comput.2
2022 Blockchain-Based Encrypted Image Storage and Search in Cloud Computing
Yingying Li 0001, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Qi Jiang 0001
DASFAA (1)5
2022 Reliable PUF-based mutual authentication protocol for UAVs towards multi-domain environment
Chuang Tian 0001, Qi Jiang 0001, Teng Li 0003, Junwei Zhang 0008, Ning Xi 0002, Jianfeng Ma 0001
Comput. Networks2
2022 NOSnoop: An Effective Collaborative Meta-Learning Scheme Against Property Inference Attack
abstract
Collaborative learning has been used to train a joint model on geographically diverse data through periodically sharing knowledge. Although participants keep the data locally in collaborative learning, the adversary can still launch inference attacks through participants’ shared information. In this article, we focus on the property inference attack during model training and design a novel defense mechanism, namely, NOSnoop, to defend such an attack. We propose a collaborative meta-learning architecture to learn the common knowledge over all participants and utilize the natural advantage of meta-learning to hide the sensitive property data. We consider both irrelevant property and relevant property preservation in NOSnoop. For irrelevant property preservation, we utilize the inherent advantage of meta-learning to hide the sensitive property data in meta-training support data set. Thus, the adversary cannot capture the key information related to the sensitive properties and cannot infer victim’s private property successfully. For relevant property preservation, an adversarial game is further proposed to reduce the inference success rate of the adversary. We conduct comprehensive experiments to evaluate the effectiveness of NOSnoop. When hiding the sensitive property data in meta-training support data set, NOSnoop achieves an inference AUC score as low as 0.4984 for irrelevant property preservation, meaning the adversary cannot distinguish whether the training batch has the sensitive property data or not. When preserving the relevant property, NOSnoop is able to achieve an inference AUC score of 0.5091 without compromising model utility.
XinDi Ma, Baopu Li, Qi Jiang 0001, Yimin Chen 0004, Sheng Gao 0002, Jianfeng Ma 0001
IEEE Internet Things J.3
2022 A geometric approach to analysing the effects of time delays on stability of vehicular platoons with ring interconnections
XinDi Ma, Qi Jiang 0001
Peer-to-Peer Netw. Appl.3
2021 Three-factor authentication protocol using physical unclonable function for IoV
Qi Jiang 0001, Ning Zhang 0007, Youliang Tian, XinDi Ma, Jianfeng Ma 0001
Comput. Commun.1
2021 Secure and Usable Handshake Based Pairing for Wrist-Worn Smart Devices on Different Users
Guichuan Zhao, Qi Jiang 0001, Xiaohan Huang 0002, XinDi Ma, Youliang Tian, Jianfeng Ma 0001
Mob. Networks Appl.2
2021 An efficient three-factor remote user authentication protocol based on BPV-FourQ for internet of drones
Naijian Zhang, Qi Jiang 0001, XinDi Ma, Jianfeng Ma 0001
Peer-to-Peer Netw. Appl.2
2021 Fast and Universal Inter-Slice Handover Authentication with Privacy Protection in 5G Network
abstract
In a 5G network-sliced environment, mobility management introduces a new form of handover called inter-slice handover among network slices. Users can change their slices as their preferences or requirements vary over time. However, existing handover-authentication mechanisms cannot support inter-slice handover because of the fine-grained demand among network slice services, which could cause challenging issues, such as the compromise of service quality, anonymity, and universality. In this paper, we address these issues by introducing a fast and universal inter-slice (FUIS) handover authentication framework based on blockchain, chameleon hash, and ring signature. To address these issues, we introduce an anonymous service-oriented authentication protocol with a key agreement for inter-slice handover by constructing an anonymous ticket with the trapdoor collision property of chameleon hash functions. In order to reduce the computation overhead of the user side in the process of authentication, a privacy-preserving ticket validation with a ring signature is designed to finish in the consensus phase of the blockchain in advance. Thanks to the edge computing capabilities in 5G, distributed edge nodes help to store the anonymous ticket information, which guarantees that the legal users can finish authentication swiftly during handover. Our scheme's performance is evaluated through simulation experiments to testify the efficiency and feasibility in a 5G network-sliced environment. The results show that compared to other authentication schemes of the same type, the overall inter-slice handover delay has been reduced by 97.94%.
Zhe Ren, Xinghua Li 0001, Qi Jiang 0001, Qingfeng Cheng, Jianfeng Ma 0001
Secur. Commun. Networks3
2021 Efficient Hierarchical and Time-Sensitive Data Sharing with User Revocation in Mobile Crowdsensing
abstract
Recently, cloud-based mobile crowdsensing (MCS) has developed into a promising paradigm which can provide convenient data sensing, collection, storage, and sharing services for resource-constrained terminates. Nevertheless, it also inflicts many security concerns such as illegal access toward user secret and privacy. To protect shared data against unauthorized accesses, many studies on Ciphertext-Policy Attribute-Based Encryption (CP-ABE) have been proposed to achieve data sharing granularity. However, providing a scalable and time-sensitive data-sharing scheme across hierarchical users with compound attribute sets and revocability remains a big issue. In this paper, we investigate this challenge and propose a hierarchical and time-sensitive CP-ABE scheme, named HTR-DAC, which is characteristics of time-sensitive data access control with scalability, revocability, and high efficiency. Particularly, we propose a time-sensitive CP-ABE for hierarchical structured users with recursive attribute sets. Moreover, we design a robust revocable mechanism to achieve direct user revocation in our scheme. We also integrate verifiable outsourced decryption to improve efficiency and guarantee correctness in decryption procedure. Extensive security and performance analysis is presented to demonstrate the security requirement satisfaction and high efficiency for our data-sharing scheme in MCS.
Jiawei Zhang 0011, Jianfeng Ma 0001, Teng Li 0003, Qi Jiang 0001
Secur. Commun. Networks4
2021 PDLM: Privacy-Preserving Deep Learning Model on Cloud with Multiple Keys
abstract
Deep learning has aroused a lot of attention and has been used successfully in many domains, such as accurate image recognition and medical diagnosis. Generally, the training of models requires large, representative datasets, which may be collected from a large number of users and contain sensitive information (e.g., users' photos and medical information). The collected data would be stored and computed by service providers (SPs) or delegated to an untrusted cloud. The users can neither control how it will be used, nor realize what will be learned from it, which make the privacy issues prominent and severe. To solve the privacy issues, one of the most popular approaches is to encrypt users' data with their public keys. However, this technique inevitably leads to another challenge that how to train the model based on multi-key encrypted data. In this paper, we propose a novel privacy-preserving deep learning model, namely PDLM, to apply deep learning over the encrypted data under multiple keys. In PDLM, lots of users contribute their encrypted data to SP to learn a specific model. We adopt an effective privacy-preserving calculation toolkit to achieve the training process based on stochastic gradient descent (SGD) in a privacy-preserving manner. We also prove that our PDLM can achieve users' privacy preservation and analyze the efficiency of PDLM in theory. Finally, we conduct an experiment to evaluate PDLM over two real-world datasets and empirical results demonstrate that our PDLM can effectively and efficiently train the model in a privacy-preserving way.
XinDi Ma, Jianfeng Ma 0001, Hui Li 0005, Qi Jiang 0001, Sheng Gao 0002
IEEE Trans. Serv. Comput.4
2020 Usable and Secure Pairing Based on Handshake for Wrist-Worn Smart Devices on Different Users
Xiaohan Huang 0002, Guichuan Zhao, Qi Jiang 0001, XinDi Ma, Youliang Tian, Jianfeng Ma 0001
CollaborateCom (1)3
2020 BUA: A Blockchain-based Unlinkable Authentication in VANETs
abstract
Authentication with unlinkability is one of the critical requirements for the security of VANETs. Unlinkability prevents attackers from linking multiple messages to infer vehicular privacy. Pseudonymous authentication schemes are widely adopted to achieve unlinkable authentication. However, they need multiple interactions with a trusted third-party to update pseudonym as well as the attached information. In order to address this issue and provide effective services in distributed systems, we propose a blockchain-based unlinkable authentication protocol called BUA, where Service Manager (SM) of each domain acts as the nodes of consortium blockchain to construct a distributed system. Each SM covers a certain logical area and maintains a sequence of consistent blocks, which hold vehicular registration data. Based on the system, vehicles use homomorphic encryption to self-generate any number of pseudonyms to achieve unlinkability. Pseudonymous validity and ownership can be verified locally by each SM. Performance evaluation results of the proposed scheme show that our protocol provides stronger security with less computation and communication overhead.
Jiao Liu 0002, Xinghua Li 0001, Qi Jiang 0001, Mohammad S. Obaidat, Pandi Vijayakumar
ICC3
2020 A Traceable and Revocable Multiauthority Attribute-Based Encryption Scheme with Fast Access
abstract
Multiauthority ciphertext-policy attribute-based encryption (MA-CP-ABE) is a promising technique for secure data sharing in cloud storage. As multiple users with same attributes have same decryption privilege in MA-CP-ABE, the identity of the decryption key owner cannot be accurately traced by the exposed decryption key. This will lead to the key abuse problem, for example, the malicious users may sell their decryption keys to others. In this paper, we first present a traceable MA-CP-ABE scheme supporting fast access and malicious users’ accountability. Then, we prove that the proposed scheme is adaptively secure under the symmetric external Diffie–Hellman assumption and fully traceable under the q -Strong Diffie–Hellman assumption. Finally, we design a traceable and revocable MA-CP-ABE system for secure and efficient cloud storage from the proposed scheme. When a malicious user leaks his decryption key, our proposed system can not only confirm his identity but also revoke his decryption privilege. Extensive efficiency analysis results indicate that our system requires only constant number of pairing operations for ciphertext data access.
Kai Zhang 0044, Yanping Li 0001, Yun Song, Laifeng Lu, Tao Zhang 0029, Qi Jiang 0001
Secur. Commun. Networks6
2020 Attribute-Based Keyword Search over Hierarchical Data in Cloud Computing
abstract
Searchable encryption (SE) has been a promising technology which allows users to perform search queries over encrypted data. However, the most of existing SE schemes cannot deal with the shared records that have hierarchical structures. In this paper, we devise a basic cryptographic primitive called as attribute-based keyword search over hierarchical data (ABKS-HD) scheme by using the ciphertext-policy attribute-based encryption (CP-ABE) technique, but this basic scheme cannot satisfy all the desirable requirements of cloud systems. The facts that the single keyword search will yield many irrelevant search results and the revoked users can access the unauthorized data with the old or outdated secret keys make this basic scheme not scale well in practice. To this end, we also propose two improved schemes (ABKS-HD-I, ABKS-HD-II) for the sake of supporting multi-keyword search and user revocation, respectively. In contrast with the state-of-the-art attribute-based keyword search (ABKS) schemes, the computation overhead of our schemes almost linearly increases with the number of users' attributes rather than the number of attributes in systems. Formal security analysis proves that our schemes are secure against both chosen-plaintext attack (CPA) and chosen-keyword attack (CKA) in the random oracle model. Furthermore, empirical study using a real-world dataset shows that our schemes are feasible and efficient in practical applications.
Yinbin Miao, Jianfeng Ma 0001, Ximeng Liu, Xinghua Li 0001, Qi Jiang 0001, Junwei Zhang 0001
IEEE Trans. Serv. Comput.5
2020 A Mobile Intelligent Terminal Based Anonymous Authenticated Key Exchange Protocol for Roaming Service in Global Mobility Networks
abstract
With the rapid development of mobile intelligent terminals, users can conveniently enjoy ubiquitous services in global mobility networks. User authentication and user privacy protection are two important issues for providing secure roaming service in global mobility networks. Until now, many authentication protocols for roaming service with user anonymity are proposed. Unfortunately, most of the existing protocols only have heuristic informal security arguments. Moreover, current works only achieve weak anonymity. A user's identity is only anonymous against eavesdroppers and is known to the home agent and sometimes even the foreign agent. In order to overcome these weaknesses, we propose a privacy-preserving password-authenticated key exchange protocol for roaming service in global mobility networks. The proposed protocol is proven secure in the random oracle model under the CDH and the q-SDH assumptions. Our protocol achieves stronger user anonymity than other related protocols. The performance comparison shows that our protocol is more efficient in terms of on-line computation and enjoys optimal communication complexity. Consequently, it is more suitable for real applications in global mobility networks.
Fushan Wei, Pandi Vijayakumar, Qi Jiang 0001
IEEE Trans. Sustain. Comput.3
2020 Provably Secure Crossdomain Multifactor Authentication Protocol for Wearable Health Monitoring Systems
abstract
Wearable health monitoring systems (WHMSs) have become the most effective and practical solutions to provide users with low-cost, noninvasive, long-term continuous health monitoring. Authentication is one of the key means to ensure physiological information security and privacy. Although numerous authentication protocols have been proposed, few of them cater to crossdomain WHMSs. In this paper, we present an efficient and provably secure crossdomain multifactor authentication protocol for WHMSs. First, we propose a ticket-based authentication model for multidomain WHMSs. Specifically, a mobile device of one domain can request a ticket from the cloud server of another domain with which wearable devices are registered and remotely access the wearable devices with the ticket. Secondly, we propose a crossdomain three-factor authentication scheme based on the above model. Only a doctor who can present all three factors can request a legitimate ticket and use it to access the wearable devices. Finally, a comprehensive security analysis of the proposed scheme is carried out. In particular, we give a provable security analysis in the random oracle model. The comparisons of security and efficiency with the related schemes demonstrate that the proposed scheme is secure and practical.
Hui Zhang 0084, Yuanyuan Qian, Qi Jiang 0001
Wirel. Commun. Mob. Comput.3
2019 Shake to Communicate: Secure Handshake Acceleration-Based Pairing Mechanism for Wrist Worn Devices
abstract
With the booming penetration of wrist worn smart devices in daily lives, a wide range of applications have been enabled, such as exchanging social information, sharing sports data, and sending messages. Securing data exchange between these devices has become a challenging issue, considering the high security requirements and low computation capabilities of these wrist worn devices. In this paper, we propose a secure wrist worn smart device pairing scheme by exploiting the motion signal of the devices generated by the handshake to negotiate a reliable key between users. To ensure the security of key negotiation, a novel fuzzy cryptography algorithm is further developed. Compared with existing algorithms, the proposed algorithm avoids complicated error correction algorithms and has low requirements for data coincidence on the premise of individual differentiation. At the same time, the security is guaranteed by feature reordering and protection of auxiliary data. Extensive experimental results are provided, which demonstrate that the proposed handshake acceleration-based pairing scheme is robust, secure, and efficient.
Qi Jiang 0001, Xiaohan Huang 0002, Ning Zhang 0007, Kuan Zhang 0001, XinDi Ma, Jianfeng Ma 0001
IEEE Internet Things J.1
2019 Pruneable sharding-based blockchain protocol
Xiaoqin Feng, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Qi Jiang 0001, Hui Li 0006
Peer-to-Peer Netw. Appl.6
2018 Updatable Block-Level Deduplication with Dynamic Ownership Management on Encrypted Data
abstract
Deduplication is becoming increasingly important in that it can effectively reduce the storage space in the cloud server. Unfortunately the static file- level deduplication only supports limited data updatability and low deduplication ratio. In this paper, we show that by using updatable block-level deduplication (UBLDe) on encrypted data, all these issues can be addressed. In addition, this approach can also protect the user data privacy. However, updatable block-level dedeplication also faces several challenges. First, block-level deduplication should be achieved across different encrypted files. Second, an updatable authenticated data structure has to be designed for proof of file ownership. Finally, file ownership revocation has to be dealt with for forward secrecy. While the first challenge can be addressed by message-locked encryption, the last two challenges have not been solved yet. To address these two issues, we present a new UBLDe protocol on encrypted data with dynamic ownership management. Specifically, we design a new authenticated data structure for Proof of Ownership, named DBSL, to support update operations with low computation cost. We also propose a dynamic file ownership management scheme based on a novel lightweight MIX algorithm to protect forward secrecy. The security analysis and experimental results show that the proposed UBLDe protocol is secure and efficient.
Maozhen Liu 0001, Chao Yang 0016, Qi Jiang 0001, Xiaofeng Chen 0001, Jianfeng Ma 0001, Jian Ren 0001
ICC3
2018 ARMOR: A trust-based privacy-preserving framework for decentralized friend recommendation in online social networks
XinDi Ma, Jianfeng Ma 0001, Hui Li 0006, Qi Jiang 0001, Sheng Gao 0002
Future Gener. Comput. Syst.4
2018 A provably secure biometrics-based authenticated key agreement scheme for multi-server environments
Saru Kumari, Ashok Kumar Das, Xiong Li 0002, Fan Wu 0003, Muhammad Khurram Khan, Qi Jiang 0001, SK Hafizul Islam
Multim. Tools Appl.6
2018 AGENT: an adaptive geo-indistinguishable mechanism for continuous location-based service
XinDi Ma, Jianfeng Ma 0001, Hui Li 0006, Qi Jiang 0001, Sheng Gao 0002
Peer-to-Peer Netw. Appl.4
2018 User Authentication in the IoE Era: Attacks, Challenges, Evaluation, and New Designs
abstract
We are venturing into the new era of Internet of Everything (IoE) where smaller and smarter computing devices have begun to be integrated into our environments.Despite its great potential, IoE also exposes devices to new security and privacy threats, such as the exposure of devices to attacks emanating from the Internet.User authentication, as a first line of defense, has been widely deployed to prevent unauthorized access, and, in many cases, it is also the primary line of defense.However, conventional user authentication mechanisms are not capable of dealing with this new situation.Firstly, it is not possible to directly utilize Internet-centric security solutions because of the inherently heterogeneous characteristics of IoE devices (e.g., the limited computational capabilities and power supply).Secondly, constrained devices may lack conventional user interfaces, such as keyboard, mice, and touch screen.In summary, the subjects of authentication in IoE are compelling yet largely unexploited, as well as unexplored topics that are in need of more intense interest and research from both the industry and academia.This special issue aims to provide a forum for researchers to publish and exchange their recent research ideas and results about authentication in IoE.In response to the call for papers, after rigorous review and careful revision, the following 5 papers were included in this special issue, ranging from novel understanding of traditional textual passwords, new cryptographic primitives for user authentication, and privacy-preserving biometric authentication to interesting contemporary key users authentication in microblogging.
Ding Wang 0002, Shujun Li 0001, Qi Jiang 0001
Secur. Commun. Networks3
2017 A client-based secure deduplication of multimedia data
abstract
The replication and dissemination of multimedia data become increasingly convenient and efficient, so a lot of redundant multimedia data, especially image files, have been generated and stored on the Internet. Therefore, it is necessary to perform deduplication of images. However, the existing deduplication methods of regular files are hash-based, which cannot be applied to the deduplication of images. The deduplication of images faces following three challenges: it needs to check duplicates fuzzily; it needs to verify the ownership of similar images; it needs perceptual image quality assessment. Aiming at these challenges, we propose a scheme named the Client-based Security Provable Deduplication of Multimedia Data (CSPD). The proposed CSPD scheme is capable of responding to the above challenges. Furthermore, it meets provable security requirements. Our extensive simulation and performance analysis show that the CSPD can check duplicates accurately and assess the perceptual quality of distorted images. Moreover, the proposed CSPD is more efficient than the existing schemes in communication bandwidth and storage spaces.
Danping Li, Chao Yang 0016, Chengzhou Li, Qi Jiang 0001, Xiaofeng Chen 0001, Jianfeng Ma 0001, Jian Ren 0001
ICC4
2017 APPLET: a privacy-preserving framework for location-aware recommender system
XinDi Ma, Hui Li 0006, Jianfeng Ma 0001, Qi Jiang 0001, Sheng Gao 0002, Ning Xi 0002, Di Lu 0001
Sci. China Inf. Sci.4
2017 VCKSM: Verifiable conjunctive keyword search over mobile e-health cloud in shared multi-owner settings
Yinbin Miao, Jianfeng Ma 0001, Ximeng Liu, Qi Jiang 0001, Junwei Zhang 0001, Zhiquan Liu 0001
Pervasive Mob. Comput.4
2017 Zero knowledge based client side deduplication for encrypted files of secure cloud storage in smart cities
Chao Yang 0016, Qi Jiang 0001, Junwei Zhang 0001, Danping Li, Jianfeng Ma 0001, Jian Ren 0001
Pervasive Mob. Comput.3
2016 An untraceable temporal-credential-based two-factor authentication scheme using ECC for wireless sensor networks
Qi Jiang 0001, Jianfeng Ma 0001, Fushan Wei, Youliang Tian, Jian Shen 0001
J. Netw. Comput. Appl.1
2016 Single round-trip SIP authentication scheme with provable security for Voice over Internet Protocol using smart card
Saru Kumari, Fan Wu 0003, Xiong Li 0002, Mohammad Sabzinejad Farash, Qi Jiang 0001, Muhammad Khurram Khan, Ashok Kumar Das
Multim. Tools Appl.5
2016 A robust and privacy-preserving aggregation scheme for secure smart grid communications in digital communities
abstract
ABSTRACT By offering indisputable advantages over traditional grid including remote readings and load balancing, smart grid is regarded as the modernization of the electricity delivery system. In this paper, we propose a privacy‐preserving and secure multi‐dimensional aggregation scheme for smart grid communications in digital communities. By integrating privacy homomorphism encryption with aggregation signature scheme, data authentication and integrity protection are performed and proved without disclosing any fine‐grained user consumption data. The construction of member list allows the fault tolerance of our scheme against accidental errors. In addition, the batch verification technique is adopted to reduce the computation cost of the operation center, and each user's computation cost is independent of the number of collected data types. Security analysis and performance evaluation demonstrate that the proposed scheme can resist various security threats and preserve identity privacy and has significantly less communication overhead and computation cost than other existing approaches. Copyright © 2015 John Wiley & Sons, Ltd.
Jianfeng Ma 0001, Qi Jiang 0001
Secur. Commun. Networks4
2016 A privacy preserving three-factor authentication protocol for e-Health clouds
Qi Jiang 0001, Muhammad Khurram Khan, Xiang Lu 0004, Jianfeng Ma 0001, Debiao He
J. Supercomput.1
2015 Bayesian mechanism for rational secret sharing scheme
Youliang Tian, Changgen Peng, Dongdai Lin, Jianfeng Ma 0001, Qi Jiang 0001, Wenjiang Ji
Sci. China Inf. Sci.5
2015 A delegation based cross trusted domain direct anonymous attestation scheme
Li Yang 0005, Jianfeng Ma 0001, Wenjing Lou, Qi Jiang 0001
Comput. Networks4
2015 An efficient two-factor user authentication scheme with unlinkability for wireless sensor networks
Qi Jiang 0001, Jianfeng Ma 0001, Xiang Lu 0004, Youliang Tian
Peer-to-Peer Netw. Appl.1
2013 Fair (t, n) threshold secret sharing scheme
abstract
In the setting of secret sharing, a group of parties wish to run a protocol for recovering the secret when they input their shares. The security requirement include privacy, correctness and others. One desirable property is fairness, which guarantees that if either party gets the secret, then the other party does too. However, basic secret sharing schemes, verifiable secret sharing schemes and publicly verifiable secret sharing schemes do not satisfy the fairness. Moreover, fairness is a central objective of the rational secret sharing scheme. In this work, the authors study the fairness problem of secret reconstruction in a ( t , n ) secret sharing scheme. They use a new approach to achieve the fairness of the protocol. They first define the fair notion of secret sharing probabilistically. Using the definition, a fair ( t , n ) secret sharing scheme is proposed, its security and fairness are shown against three different attack types. The proposed scheme is an extension of basic model of secret sharing (Shamir's scheme) and the approach of fairness of Dov Gordon et al.(STOC2008). Theoretical analysis shows that the proposed scheme is more efficient.
Youliang Tian, Jianfeng Ma 0001, Changgen Peng, Qi Jiang 0001
IET Inf. Secur.4
2012 Security analysis of Kulseng et al.'s mutual authentication protocol for RFID systems
abstract
The authors describe three attacks against an efficient lightweight mutual authentication protocol recently proposed by Kulseng et al. These attacks are unique as they are closely related and must be performed in order, one after another. They break the untraceability, confidentiality and mutual authentication properties of the protocol, and show, for the first time, that breaking the privacy property may lead to attacks on the security properties of radio frequency identification (RFID) authentication protocols. Finally, we present a countermeasure to fix the flaws and make a brief security analysis of the improved protocol.
J. Gu, C. Lv, Qi Jiang 0001, W. Ma
IET Inf. Secur.4
2011 A novel re-authentication scheme based on tickets in wireless local area networks
Guangsong Li, Jianfeng Ma 0001, Qi Jiang 0001
J. Parallel Distributed Comput.3