Yunlei Zhao

dblp:51/2976 · DBLP profile ↗
← Back
90ranked-venue papers
8as first author
36since 2021 · last 2026
0000-0002-2623-9170ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 61 · 6 first-author · 20 since 2021Theory of computation · 15 · 2 first-author · 4 since 2021Systems, architecture and hardware · 5 · 5 since 2021Computer networks · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Post-quantum Internet Key Exchange via Authenticated Forward-Secure KEM
Yunlei Zhao, Biming Zhou, Zhixiang Zhao, Haodong Jiang
CRYPTO (10)1
2026 Post-quantum TLS 1.3 Handshake from CPA-Secure KEMs with Tighter Reductions
Jinrong Chen, Biming Zhou, Rongmao Chen, Haodong Jiang, Yi Wang 0055, Xinyi Huang 0001, Yunlei Zhao, Moti Yung
EUROCRYPT (2)7
2026 BW-KEM: Robust and Versatile MLWE-Based KEM with Barnes-Wall Lattices
Hengchuan Zou, Shiyu Shen 0001, Yunlei Zhao
PKC (1)5
2026 Optimizing CTRU for TLS 1.3 on Edge Platforms
abstract
The rise of quantum computing necessitates post-quantum cryptography (PQC) to secure Internet communications on edge platforms. CTRU is an NTRU-based key encapsulation mechanism (KEM) that features a small modulus and an efficient scaledE8lattice encoding, offering strong security and performance. However, two critical gaps impede its deployment for Internet of Things (IoT) edge platforms: the absence of an optimized implementation for ARMv8 devices, which dominate the mobile and embedded IoT ecosystems, and a lack of integration and evaluation in practical protocols such as Transport Layer Security (TLS) 1.3. To address these challenges, we present the first NEON-optimized CTRU implementation for ARMv8-A. Our implementation reduces CPU cycles by 3.24×, 2.62×, and 2.99× in key generation (KeyGen), encapsulation (Encaps), and decapsulation (Decaps) compared to the reference C (REF-C) implementation, while lowering energy consumption by 55.2%. Among all evaluated KEMs, it achieves the lowest energy consumption and a competitive memory footprint. We further design a batch key generation scheme that boosts KeyGen throughput by 3.73×. Finally, we integrate CTRU into TLS 1.3 to enable post-quantum (PQ) key exchange. Comprehensive benchmarks show that CTRU outperforms all evaluated KEMs and classical key exchange scheme Elliptic Curve Diffie-Hellman Secp384r1 (ECDH P384) on ARMv8-A platform. Specifically, it achieves lower TLS handshake latency and higher throughput under ideal network conditions, and its handshake latency distribution is superior to that of all alternatives under Narrow Band IoT (NB-IoT) constraints. These results demonstrate CTRU’s practical suitability for real-world deployment on IoT edge platforms.
Zhuo Zhang 0027, Jieyu Zheng, Hanyu Wei, Yunlei Zhao
IEEE Internet Things J.6
2026 Enhancing Redactable Blockchain With Robust and Efficient Threshold Redaction
abstract
Blockchain technology, known for its decentralized and tamper-resistant nature, offers strong auditing guarantees across a wide range of applications. However, its inherent immutability presents challenges when correcting erroneous transactions or removing sensitive information is necessary. To address this, the concept of redactable blockchain has emerged, aiming to improve adaptability to real-world regulatory and operational needs. Yet, existing designs often suffer from limitations in decentralization, security, or efficiency. This paper introduces an Enhanced Threshold Chameleon Hash (ETCH) scheme as a foundational building block for redactable blockchains. ETCH enables redactions only when a predefined threshold of nodes collaborates to generate trapdoor shares, preserving decentralization. It also enhances collision resistance, overcoming key security flaws in prior schemes, and incorporates a periodic trapdoor refresh mechanism to improve long-term robustness. Experimental results show that ETCH reduces computational overhead by 50% in Hash and Verify phases and by 22.26% in the Adapt phase. The prototype implementation of the ETCH-based redactable blockchain further confirms ETCH's effectiveness in supporting low-latency redactions and mitigating blockchain state growth. Overall, ETCH improves both the security and efficiency of redactable blockchains, broadening their applicability in privacy-sensitive and regulated scenarios.
Zhaoman Liu, Biming Zhou, Yunlei Zhao
IEEE Trans. Dependable Secur. Comput.3
2026 An Insider Attack Resistant Threshold Anonymous Traffic Violation Reporting Scheme for Fog-Assisted VANETs
abstract
Traffic violation reporting schemes for fog-assisted vehicular ad hoc networks are generally designed to support traffic management centers (TMCs) in detecting traffic violations so that appropriate actions can be taken against the involved vehicle owners. However, there are ongoing challenges such as ensuring accuracy or accountability with minimal privacy dis closure (e.g., accurate and reliable detection of traffic violations without disclosing the contents of the incident, achieving identity authentication while protecting the privacy of reporters), and how to guarantee the reports are correctly processed complicate the design of such schemes. To address these challenges, we propose a threshold anonymous traffic violation reporting (TATVR) scheme under the assumptions that the fog nodes (i.e., roadside units) and the TMC are semi-trusted, and the number of colluding vehicles is limited. We then extend the TATVR scheme (i.e., extended TATVR or E-TATVR) that does not rely on these assumptions. We explain how TMC can process the received reports more efficiently using the proposed E-TATVR scheme. We also evaluate the security of both proposed schemes and demonstrate that they simultaneously support (strong) confidentiality, non-frameability, conditional unlinkability, unforgeability, and conditional anonymity. In particular, we show that both schemes guarantee strong confidentiality, and the E-TATVR scheme additionally supports report traceability.
Yafang Yang, Lei Zhang 0009, Yunlei Zhao, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.3
2026 cuFalcon: An Adaptive Parallel GPU Implementation for High-Performance Falcon Acceleration
Hanyu Wei, Shiyu Shen 0001, Hao Yang 0062, Wangchen Dai, Yunlei Zhao
IEEE Trans. Parallel Distributed Syst.6
2025 PIsignHD: A New Structure for the SQIsign Family with Flexible Applicability
Kaizhan Lin, Weize Wang, Changan Zhao, Yunlei Zhao
SAC4
2025 Efficient NTTRU TLS 1.3 for IoT Devices
abstract
In 1994, Shor’s algorithm was introduced, which exploits the capabilities of quantum computers (QCs) to solve integer factorization and discrete logarithm problems, posing a significant threat to traditional public-key cryptosystems based on these problems. The widely used Internet security protocol, TLS, relies on ECC as one of its cryptographic primitives. As quantum computing continues to advance, there is an urgent need to replace the cryptographic primitives used in TLS with post-quantum cryptographic (PQC) algorithms that can resist quantum attacks. Given the proliferation of IoT devices, the security of IoT embedded systems has become a critical concern. In this article, we present an optimized implementation of PQC algorithms on IoT embedded devices, introducing the first implementation of the NTTRU key encapsulation mechanism (KEM) based on the ARMv8 architecture. ARMv8 is the dominant processor architecture in current mobile phones and tablets. By utilizing the NEON engine of the ARMv8 architecture, we have accelerated the performance bottlenecks in the NTTRU algorithm, achieving an overall speedup of 2.85 to 3.27 times. Moreover, we propose a detailed design and implementation of a hybrid migration of NTTRU KEM into TLS 1.3 on embedded platforms, and we perform experimental and comparative analysis of the TLS 1.3 handshake performance with other standardized KEMs. Our experimental results demonstrate that the hybrid migration of our NEON-optimized NTTRU implementation significantly enhances TLS handshake performance compared to its C implementation, while also outperforming other PQC KEMs.
Zhuo Zhang 0027, Jieyu Zheng, Yunlei Zhao
IEEE Internet Things J.4
2025 OSKR/OKAI: Systematic Optimization of Key Encapsulation Mechanisms from Module Lattice
Shiyu Shen 0001, Zhichuang Liang, Jieyu Zheng, Hanyu Wei, Yang Wang 0050, Zhenfeng Zhang, Yunlei Zhao
J. Comput. Sci. Technol.9
2025 Sign-then-encrypt with security enhancement and compressed ciphertext
Yanbo Chen 0002, Yunlei Zhao
Theor. Comput. Sci.2
2025 cuML-DSA: Optimized Signing Procedure and Server-Oriented GPU Design for ML-DSA
abstract
The threat posed by quantum computing has precipitated an urgent need for post-quantum cryptography. Recently, the post-quantum digital signature draft FIPS 204 has been published, delineating the details of the ML-DSA, which is derived from the CRYSTALS-Dilithium. Despite these advancements, server environments, especially those equipped with GPU devices necessitating high-throughput signing, remain entrenched in classical schemes. A conspicuous void exists in the realm of GPU implementation or server-specific designs for ML-DSA. In this paper, we propose the first server-oriented GPU design tailored for the ML-DSA signing procedure in high-throughput servers. We introduce several innovative theoretical optimizations to bolster performance, including depth-prior sparse ternary polynomial multiplication, the branch elimination method, and the rejection-prioritized checking order. Furthermore, exploiting server-oriented features, we propose a comprehensive GPU hardware design, augmented by a suite of GPU implementation optimizations to further amplify performance. Additionally, we present variants for sampling sparse polynomials, thereby streamlining our design. The deployment of our implementation on both server-grade and commercial GPUs demonstrates significant speedups, ranging from 284.9× to 485.3× against the CPU baseline, and an improvement of up to 60.9% compared to related work, affirming the effectiveness and efficiency of the proposed GPU architecture for ML-DSA signing procedure.
Shiyu Shen 0001, Hao Yang 0062, Yunlei Zhao
IEEE Trans. Dependable Secur. Comput.4
2025 Optimized Vectorization Implementation of CRYSTALS-Dilithium
abstract
CRYSTALS-Dilithium is a lattice-based signature scheme that is being standardized by NIST as the primary post-quantum signature algorithm. In this work, we present a comprehensive study of optimizing the implementation of Dilithium using Advanced Vector Extensions (AVX), specifically AVX2 and the latest AVX-512. We begin by introducing an enhanced parallel small polynomial multiplication with tailored early evaluation (PSPM-TEE) to accelerate the signing process. We provide both AVX2 and AVX-512 implementations of PSPM-TEE, demonstrating that our PSPM algorithm outperforms the traditional NTT by 47%-66% on these platforms. Next, we propose a tailored reduction method that is simpler and faster than Montgomery reduction. By leveraging AVX-512IFMA, we further minimize the CPU cycles required for the tailored reduction. Finally, we present a fully vectorized implementation of Dilithium using AVX-512, carefully optimizing most of the Dilithium functions to improve both time and space efficiency simultaneously. As a result of these optimizations, our AVX-512 implementation achieves performance improvements of 2.25×/2.07×/2.20× in key generation, 2.07×/2.13×/2.36× in signing, and 2.20×/2.36×/2.46× in verification for the Dilithium2/3/5 parameter sets, respectively compared to the state-of-the-art AVX2 implementation.
Jieyu Zheng, Haoliang Zhu, Yunlei Zhao
IEEE Trans. Dependable Secur. Comput.5
2024 CPA-Secure KEMs are also Sufficient for Post-quantum TLS 1.3
Biming Zhou, Haodong Jiang, Yunlei Zhao
ASIACRYPT (3)3
2024 Faster Post-quantum TLS 1.3 Based on ML-KEM: Implementation and Assessment
Jieyu Zheng, Haoliang Zhu, Yafang Yang, Yunlei Zhao
ESORICS (2)7
2024 Generalized splitting-ring number theoretic transform
Zhichuang Liang, Yunlei Zhao, Zhenfeng Zhang
Frontiers Comput. Sci.2
2024 Leveraging GPU in Homomorphic Encryption: Framework Design and Analysis of BFV Variants
abstract
Homomorphic Encryption (HE) enhances data security by enabling computations on encrypted data, advancing privacy-focused computations. The BFV scheme, a promising HE scheme, raises considerable performance challenges. Graphics Processing Units (GPUs), with considerable parallel processing abilities, offer an effective solution. In this work, we present an in-depth study on accelerating and comparing BFV variants on GPUs, including Bajard-Eynard-Hasan-Zucca (BEHZ), Halevi-Polyakov-Shoup (HPS), and recent variants. We introduce a universal framework for all variants, propose optimized BEHZ implementation, and first support HPS variants with large parameter sets on GPUs. We also optimize low-level arithmetic and high-level operations, minimizing instructions for modular operations, enhancing hardware utilization for base conversion, and implementing efficient reuse strategies and fusion methods to reduce computational and memory consumption. Leveraging our framework, we offer comprehensive comparative analyses. Performance evaluation shows a 31.9$\times$speedup over OpenFHE running on a multi-threaded CPU and 39.7% and 29.9% improvement for tensoring and relinearization over the state-of-the-art GPU BEHZ implementation. The leveled HPS variant records up to 4$\times$speedup over other variants, positioning it as a highly promising alternative for specific applications.
Shiyu Shen 0001, Hao Yang 0062, Wangchen Dai, Lu Zhou 0002, Zhe Liu 0001, Yunlei Zhao
IEEE Trans. Computers6
2024 Fully anonymous identity-based broadcast signcryption with public verification
Zhaoman Liu, Yanbo Chen 0002, Jianting Ning, Yunlei Zhao
Theor. Comput. Sci.4
2024 Phantom: A CUDA-Accelerated Word-Wise Homomorphic Encryption Library
abstract
Homomorphic encryption (HE) is a promising technique for privacy-preserving computations, especially the word-wise HE schemes that allow batching. However, the high computational overhead hinders the deployment of HE in real-word applications. GPUs are often used to accelerate execution, but a comprehensive performance comparison of different schemes on the same platform is still missing. In this work, we fill this gap by implementing three word-wise HE schemes BGV, BFV, and CKKS on GPU, with both theoretical and engineering optimizations. We enhance the hybrid key-switching technique, significantly reducing the computational and memory overhead. We explore several kernel fusing strategies to reuse data, resulting in reduced memory access and IO latency, and enhancing the overall performance. By comparing with the state-of-the-art works, we demonstrate the effectiveness of our implementation. Meanwhile, we introduce a unified framework that finely integrates our implementation of the three schemes, covering almost all scheme functions and homomorphic operations. We optimize the management of pre-computation, RNS bases, and memory in the framework, to provide efficient and low-latency data access and transfer. Based on this framework, we provide a thorough benchmark of the three schemes, which can serve as a reference for scheme selection and implementation in constructing privacy-preserving applications.
Hao Yang 0062, Shiyu Shen 0001, Wangchen Dai, Lu Zhou 0002, Zhe Liu 0001, Yunlei Zhao
IEEE Trans. Dependable Secur. Comput.6
2024 cuXCMP: CUDA-Accelerated Private Comparison Based on Homomorphic Encryption
abstract
Private comparison schemes constructed on homomorphic encryption offer the noninteractive and parallelizable features, and have advantages in communication bandwidth and performance. In this work, we propose cuXCMP, an extension of the privacy comparison scheme XCMP (AsiaCCS 2018). We address the relatively small input domain and the incompletely expressible output of XCMP, by modifying the encoding method and devising a constant term extraction (CTX) approach. Then, we describe a method for constructing privacy-preserving decision tree (PPDT) using this scheme. Considering the high computational overhead of CTX, we exploit the massive parallelism of the GPU to accelerate this function. Based on the results of the kernel profiling, we utilize several optimization techniques to improve the performance, including using multiple CUDA streams, reducing the grid dimension, kernel fusion, etc. By accelerating this function, we boost the execution time of the scheme and demonstrate 130× and 1.9× speedups for CTX and cuXCMP, respectively, as well as a 35% reduction in the evaluation time of PPDT.
Hao Yang 0062, Shiyu Shen 0001, Zhe Liu 0001, Yunlei Zhao
IEEE Trans. Inf. Forensics Secur.4
2024 Rebuttal to "On the Unforgeability of 'Privacy-Preserving Aggregation-Authentication Scheme for Safety Warning System in Fog-Cloud Based VANET"'
abstract
Lin recently claimed that the privacy-preserving aggregation authentication scheme (PPAAS) based on a certificateless aggregation signcryption scheme (CASS) proposed in our paper (IEEE Transactions on Information Forensics and Security, vol.17, pp.317-331, Jan.2022) suffers from a forgery attack from type II adversary. In this paper, we show that this attack is not valid since the adversary outputs a trivial forged ciphertext. Specifically, the adversary has the master secret key and randomly selects the secret values of all users.
Yafang Yang, Lei Zhang 0009, Yunlei Zhao, Kim-Kwang Raymond Choo, Yan Zhang 0103
IEEE Trans. Inf. Forensics Secur.3
2024 High-Throughput GPU Implementation of Dilithium Post-Quantum Digital Signature
abstract
Digital signatures are fundamental building blocks in various protocols to provide integrity and authenticity. The development of the quantum computing has raised concerns about the security guarantees afforded by classical signature schemes. CRYSTALS-Dilithium is an efficient post-quantum digital signature scheme based on lattice cryptography and has been selected as the primary algorithm for standardization by the National Institute of Standards and Technology. In this work, we present a high-throughput GPU implementation of Dilithium. For individual operations, we employ a range of computational and memory optimizations to overcome sequential constraints, reduce memory usage and IO latency, address bank conflicts, and mitigate pipeline stalls. This results in high and balanced compute throughput and memory throughput for each operation. In terms of concurrent task processing, we leverage task-level batching to fully utilize parallelism and implement a memory pool mechanism for rapid memory access. We propose a dynamic task scheduling mechanism to improve multiprocessor occupancy and significantly reduce execution time. Furthermore, we apply asynchronous computing and launch multiple streams to hide data transfer latencies and maximize the computing capabilities of both CPU and GPU. Across all three security levels, our GPU implementation achieves over 160× speedups for signing and over 80× speedups for verification on both commercial and server-grade GPUs. This achieves microsecond-level amortized execution times for each task, offering a high-throughput and quantum-resistant solution suitable for a wide array of applications in real systems.
Shiyu Shen 0001, Hao Yang 0062, Wangchen Dai, Zhe Liu 0001, Yunlei Zhao
IEEE Trans. Parallel Distributed Syst.6
2023 Efficient NTTRU Implementation on ARMv8
abstract
To tackle the challenges introduced by quantum computers to traditional public key cryptography, the domain of post-quantum cryptography (PQC) has taken center stage. Within this domain, the evaluation of computational performance emerges as a pivotal yardstick. Notably, NTTRU stands for one of the most efficient PQC schemes for key encapsulation mechanisms (KEM). This paper introduces the first optimized implementation of NTTRU on ARMv8 architecture. By leveraging the capabilities of the NEON engine, we strategically optimize the core modules of NTTRU: NTT/INTT, polynomial base case multiplication, and polynomial inversion. These optimizations have resulted in remarkable performance gains of 7.37×, 6.10×, 5.91×, and 4.43×, respectively when compared to the reference implementation. For the whole implementation, we achieve performance improvement of 2.85×, 2.36×, and 3.27× in key generation, encapsulation, and decapsulation respectively.
Zhuo Zhang 0027, Jieyu Zheng, Yunlei Zhao
ICPADS3
2023 Efficient and Strong Symmetric Password Authenticated Key Exchange With Identity Privacy for IoT
abstract
Password authenticated key exchange (PAKE) allows two parties with a shared password to establish a session key. In order to provide secure and private communication between devices in an Internet of Things (IoT) environment, the PAKE protocol is considered one of the most common and promising security methods. However, many existing PAKE proposals still face challenges in security and efficiency. First, both the terminals of participants may suffer from the compromise attack and precomputation attack, which will lead to the leakage of password. Second, the majority of the existing schemes cannot guarantee participants’ identity privacy. Third, most PAKE protocols are not suitable for IoT devices with limited computing capability because of a large number of exponential and pairing operations. To address these issues, we propose a strong symmetric PAKE protocol for IoT devices, which only requires 3 exponentiations per party. The proposed scheme can protect both parties from compromise and precomputation attacks, in which the password file relies on the identity and random salt. What’s more, our protocol guarantees the identity privacy, that is, the transmitted record and password file will not reveal the identity information. We further present a new security model for our protocol, and prove that the proposed scheme is secure under this model. Finally, we show the practicality of our PAKE via experiments and efficiency analysis.
Huanhuan Lian, Yafang Yang, Yunlei Zhao
IEEE Internet Things J.3
2023 CARM: CUDA-Accelerated RNS Multiplication in Word-Wise Homomorphic Encryption Schemes for Internet of Things
abstract
Homomorphic encryption (HE), which allows computation over encrypted data, has often been used to preserve privacy. However, the computationally heavy nature and complexity of network topologies make the deployment of HE schemes in the Internet of Things (IoT) scenario difficult. In this work, we propose CARM, the first optimized GPU implementation that covers BGV, BFV and CKKS, targeting for accelerating homomorphic multiplication using GPU in heterogeneous IoT systems. Our solution is suitable for accelerating RNS homomorphic multiplication on both high-performance and embedded GPUs, as it is a parametric and generic design and offers various trade-offs between resource and efficiency. We offer constant-time low-level arithmetic with minimum instructions and memory usage, as well as performance- and memory-prior configurations. Through this, we can provide more real-time evaluation results and relieve the computational pressure on cloud devices. We deploy our implementations on two GPUs. Compared to the CPU implementation, we achieve up to$378.4\times$,$234.5\times$, and$287.2\times$speedup for homomorphic multiplication of BGV, BFV, and CKKS on Tesla V100S, and$8.8\times$,$9.2\times$, and$10.3\times$on Jetson AGX Xavier, respectively.
Shiyu Shen 0001, Hao Yang 0062, Zhe Liu 0001, Yunlei Zhao
IEEE Trans. Computers5
2022 Parallel Small Polynomial Multiplication for Dilithium: A Faster Design and Implementation
abstract
The lattice-based signature scheme CRYSTALS-Dilithium is one of the two signature finalists in the third round NIST post-quantum cryptography (PQC) standardization project. For applications of low-power Internet-of-Things (IoT) devices, recent research efforts have been focusing on the performance optimization of PQC algorithms on embedded systems. In particular, performance optimization is more demanding for PQC signature algorithms that are usually significantly more time-consuming than PQC public-key encryption counterparts. For most cryptographic algorithms based on algebraic lattices including Dilithium, the fundamental and most time-consuming operation is polynomial multiplication over rings. For this computational task, number theoretic transform (NTT) is the most efficient multiplication method for NTT-friendly rings, and is now the typical technique for performing fast polynomial multiplications when implementing lattice-based PQC algorithms.
Jieyu Zheng, Shiyu Shen 0001, Chenxi Xue, Yunlei Zhao
ACSAC5
2022 Half-Aggregation of Schnorr Signatures with Tight Reductions
Yanbo Chen 0002, Yunlei Zhao
ESORICS (2)2
2022 Tight Analysis of Decryption Failure Probability of Kyber in Reality
Boyue Fang, Weize Wang, Yunlei Zhao
ICICS3
2022 Identity-based authenticated encryption with identity confidentiality
Shiyu Shen 0001, Yunlei Zhao
Theor. Comput. Sci.3
2022 Fine-Grained and Controllably Editable Data Sharing With Accountability in Cloud Storage
abstract
With the increasing cloud storage service, users can enjoy non-interactive data sharing. Nonetheless, the data owner cannot timely update the shared data all the while. To ensure the timeliness and the authoritative source of the data, some users should be allowed to update the data on behalf of an authoritative data owner without changing data source. However, this allows harmful information to be injected into the data unnoticeably. How to efficiently realize editable cloud-based data sharing supporting malicious user tracing has not been fully explored. To address the problem, we propose a fine-grained and controllably editable cloud-based data sharing scheme with malicious user accountability. The data owner only needs to sign the shared data before uploading it and can specify a fine-grained access control policy about who can update the data and which portions of the data can be updated. The authorized users non-interactively convert signatures of original data into new ones for the updated data, which are indistinguishable from the original signatures. The proposed scheme also supports malicious user accountability in the sense that malicious users who post harmful information can be traced. We demonstrate the security and practicality of our scheme via formal security analysis and extensive experiments.
Huiying Hou, Jianting Ning, Yunlei Zhao, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.3
2022 Privacy-Preserving Aggregation-Authentication Scheme for Safety Warning System in Fog-Cloud Based VANET
abstract
As cities become smarter, the importance of vehicular ad hoc networks (VANETs) will be increasingly pronounced. To support latency- and time-sensitive applications, there have been attempts to utilize fog-cloud computing in VANETs. There are, however, a number of limitations in existing fog-cloud based VANET deployments, ranging from computation and communication bottlenecks to privacy leakage to costly certificate/ pseudonym management to key escrow, and so on. Therefore, in this paper we propose a privacy-preserving aggregation authentication scheme (PPAAS). The scheme is designed for deployment in a safety warning system for fog-cloud based VANETs. Specifically, the PPAAS scheme is realized using a novel efficient anonymous certificateless aggregation signcryption scheme (CASS) proposed in this paper, and allows a fog node to aggregate signcrypted traffic-related messages from surrounding vehicles into an aggregated ciphertext and unsigncrypt them in a batch. We then evaluate the security of PPAAS and demonstrate that it supports confidentiality, authentication, and (efficient) conditional privacy, and key escrow freeness. In particular, our scheme is the first in the literature to achieve efficient conditional privacy, which avoids the need for costly pseudonym management. We also demonstrate that the scheme is practical, based on our simulation results.
Yafang Yang, Lei Zhang 0009, Yunlei Zhao, Kim-Kwang Raymond Choo, Yan Zhang 0103
IEEE Trans. Inf. Forensics Secur.3
2022 Compact and Flexible KEM From Ideal Lattice
abstract
A remarkable breakthrough in mathematics in recent years is the proof of the long-standing conjecture: sphere packing in the$E_{8}$lattice is optimal in the sense of the best density for sphere packing in$\mathbb {R}^{8}$. In this work, we design a mechanism for asymmetric key consensus from noise (AKCN), referred to as AKCN-E8, for error correction and key consensus. As a direct application, we present a practical key encapsulation mechanism (KEM) from the ideal lattice based on the ring learning with errors (RLWE) problem. Compared with NewHope-KEM that was the second round candidate of the National Institute of Standards and Technology (NIST) post-quantum cryptography (PQC) standardization, our AKCN-E8 KEM scheme overcomes some limitations and shortcomings of NewHope-KEM. Compared with some other dominating KEM schemes based on the variants of LWE, specifically Kyber and Saber, AKCN-E8 has a comparable performance but enjoys much flexible shared-key sizes. Specifically, the key encapsulated by AKCN-E8-512 (resp., 768, 1024) has the size of 256 (resp., 384, 512) bits. Flexible key size renders us stronger security against quantum attacks, more powerful and economic ability of key transportation, and better matches the demand in interactive protocols like TLS where parties need to negotiate the security parameters including the shared key length.
Zhengzhong Jin, Shiyu Shen 0001, Yunlei Zhao
IEEE Trans. Inf. Theory3
2022 A Traitor-Resistant and Dynamic Anonymous Communication Service for Cloud-Based VANETs
abstract
Cloud-based VANETs are designed to enable communication between high-speed vehicles. In such a highly dynamic environment, how to provide secure and anonymous communication service is a challenge. In this article, we affirmatively address the challenge by proposing a traitor-resistant and dynamic anonymous communication framework (TD-ACF) for cloud-based VANETs, which supports several advantageous features. In TD-ACF, each vehicle is represented by a set of attributes instead of its real identity, and the driving data is transmitted in encrypted form. Therefore, the anonymous authentication and the confidentiality of driving data are achieved in this way. Meanwhile, TD-ACF supports two practical requirements in cloud-based VANETs: the revocation and the traceability of traitor. For the former, TD-ACF can force a vehicle to exit the communication network at any moment. We employ an efficient binary tree algorithm to reduce the size of key updates for revocation from the traditional linear to the logarithmic level. For the latter, we overcome the barrier of the one-to-many relationship between a vehicle and the shared set of attributes to support traitor tracing. In TD-ACF, unlike most existing schemes, the Semi-Trusted Cloud (STC) can directly capture and punish a traitor instead of querying all the records in the list of unrevoked vehicles. In addition, we solve the key escrow problem that plagues most existing attribute-based schemes. The theoretical analysis and experimental simulation show that the proposed scheme is feasible and effective.
Huiying Hou, Jianting Ning, Yunlei Zhao, Robert H. Deng
IEEE Trans. Serv. Comput.3
2021 Identity-Based Identity-Concealed Authenticated Key Exchange
Huanhuan Lian, Tianyu Pan 0002, Huige Wang, Yunlei Zhao
ESORICS (2)4
2021 Order-Revealing Encryption: File-Injection Attack and Forward Security
Xing-Chen Wang, Yunlei Zhao
J. Comput. Sci. Technol.4
2021 Fine-Grained and Controllably Redactable Blockchain with Harmful Data Forced Removal
abstract
Notoriously, immutability is one of the most striking properties of blockchains. As the data contained in blockchains may be compelled to redact for personal and legal reasons, immutability needs to be skillfully broken. In most existing redactable blockchains, fine-grained redaction and effective deletion of harmful data are mutually exclusive. To close the gap, we propose a fine-grained and controllably redactable blockchain with harmful data forced removal. In the scheme, the originator of the transaction has fine-grained control over who can perform the redaction and which portions of the transaction can be redacted. The redaction transaction is performed after collecting enough votes from miners. All users can provide the index of the block containing the harmful data to receive rewards, which are borne by the malicious user who initially posted the data. Miners can forcibly remove the harmful data based on the index. The malicious user will be blacklisted if the reward is not paid within a period of time, and any transaction about such user will not be performed later. In addition, the scheme supports the redaction of additional data and unexpended transaction output (UTXO) simultaneously. We demonstrate that the scheme is secure and feasible via formal security analysis and proof-of-concept implementation.
Huiying Hou, Shidi Hao, Jiaming Yuan, Shengmin Xu, Yunlei Zhao
Secur. Commun. Networks5
2020 SKCN: Practical and Flexible Digital Signature from Module Lattice
Boru Gong, Leixiao Cheng, Yunlei Zhao
ACISP3
2020 Number Theoretic Transform: Generalization, Optimization, Concrete Analysis and Applications
Zhichuang Liang, Shiyu Shen 0001, Yuantao Shi, Dongni Sun, Chongxuan Zhang, Guoyun Zhang, Yunlei Zhao, Zhixiang Zhao
Inscrypt7
2020 Identity-Based Authenticated Encryption with Identity Confidentiality
Yunlei Zhao
ESORICS (2)1
2020 Functional encryption with application to machine learning: simple conversions from generic functions to quadratic functions
Huige Wang, Kefei Chen, Yuan Zhang 0006, Yunlei Zhao
Peer-to-Peer Netw. Appl.4
2020 Practical CCA-Secure Functional Encryptions for Deterministic Functions
abstract
Functional encryption (FE) can implement fine-grained control to encrypted plaintext via permitting users to compute only some specified functions on the encrypted plaintext using private keys with respect to those functions. Recently, many FEs were put forward; nonetheless, most of them cannot resist chosen-ciphertext attacks (CCAs), especially for those in the secret-key settings. This changed with the work, i.e., a generic transformation of public-key functional encryption (PK-FE) from chosen-plaintext (CPA) to chosen-ciphertext (CCA), where the underlying schemes are required to have some special properties such as restricted delegation or verifiability features. However, examples for such underlying schemes with these features have not been found so far. Later, a CCA-secure functional encryption from projective hash functions was proposed, but their scheme only applies to inner product functions. To construct such a scheme, some nontrivial techniques will be needed. Our key contribution in this work is to propose CCA-secure functional encryptions in the PKE and SK environment, respectively. In the existing generic transformation from (adaptively) simulation-based CPA- (SIM-CPA-) secure ones for deterministic functions to (adaptively) simulation-based CCA- (SIM-CCA-) secure ones for randomized functions, whether the schemes were directly applied to CCA settings for deterministic functions is not implied. We give an affirmative answer and derive a SIM-CCA-secure scheme for deterministic functions by making some modifications on it. Again, based on this derived scheme, we also propose an (adaptively) indistinguishable CCA- (IND-CCA-) secure SK-FE for deterministic functions. The final results show that our scheme can be instantiated under both nonstandard assumptions (e.g., hard problems on multilinear maps and indistinguishability obfuscation (IO)) and under standard assumptions (e.g., DDH, RSA, LWE, and LPN).
Huige Wang, Kefei Chen, Tianyu Pan 0002, Yunlei Zhao
Secur. Commun. Networks4
2019 Generic and Practical Key Establishment from Lattice
Zhengzhong Jin, Yunlei Zhao
ACNS2
2019 Delegatable Order-Revealing Encryption
abstract
Order-revealing encryption (ORE) is a basic cryptographic primitive for ciphertext comparisons based on the order relationship of plaintexts while maintaining the privacy of them. In the data era we are experiencing, cross-dataset transactions become ubiquitous in practice. However, almost all the previous ORE schemes can only support comparisons on ciphertexts from the same user, which does not meet the requirement for the multi-user environment. In this work, we introduce and design ORE schemes with delegation functionality, which is referred to as delegatable ORE (DORE). The "delegation" here is an authorization that allows for efficient ciphertext comparisons among different users. To the best of our knowledge, it is the first ORE that allows an user to delegate the comparison privilege for his ciphertexts, which also opens the door for future explorations. At the heart of the construction and analysis of DORE is a new building tool proposed in this work, named delegatable equality-revealing encoding (DERE), which might be of independent interest.
Yunlei Zhao
AsiaCCS3
2019 Practical Aggregate Signature from General Elliptic Curves, and Applications to Blockchain
abstract
Aggregate signature (AS) allows non-interactively condensing multiple individual signatures into a compact one. Besides faster verification, it is useful to reduce storage and bandwidth, and is especially attractive for blockchain and cryptocurrency. In this work, we first demonstrate the subtlety of achieving AS from general groups, by a concrete attack that actually works against the natural implementations of AS based on almost all the variants of DSA and Schnorr's. Then, we show that aggregate signature can be de- rived from the -signature scheme proposed by Yao, et al. To the best of our knowledge, this is the first aggregate signature scheme from general elliptic curves without bilinear maps (in particular, the secp256k1 curve used by Bitcoin). The security of aggregate -signature is proved based on a new assumption proposed and justified in this work, referred to as non-malleable discrete-logarithm (NMDL), which might be of independent interest. When applying the resultant aggregate -signature to Bitcoin, the storage volume of signatures reduces about 49.8%, and the signature verification time can even reduce about 72%. Finally, we specify in detail the application of the proposed AS scheme to Bitcoin, with the goal of maximizing performance and compatibility. We adopt a Merkle-Patricia tree based implementation, and the resulting system is also more friendly to segregated witness and provides better protection against transaction malleability attacks.
Yunlei Zhao
AsiaCCS1
2019 Certificateless Identity-Concealed Authenticated Encryption Under Multi-KGC
Chuang Li 0008, Chunxiang Xu, Yunlei Zhao, Kefei Chen
Inscrypt3
2019 Functional broadcast encryption with applications to data sharing for cloud storage
Huige Wang, Yuan Zhang 0006, Kefei Chen, Guangye Sui, Yunlei Zhao, Xinyi Huang 0001
Inf. Sci.5
2019 AP-PRE: Autonomous Path Proxy Re-Encryption and Its Applications
abstract
In this paper, we introduce a new cryptographic primitive, called autonomous path proxy re-encryption (AP-PRE), which is motivated by several application scenarios where the delegator would like to control the whole delegation path in a multi-hop delegation process. Compared with the traditional proxy re-encryption, AP-PRE provides much better fine-grained access control to delegation path. Briefly speaking, in an AP-PRE scheme, the delegator designates a path of his preferred delegatees. The path consists of several delegatees with the privilege from high to low. If the delegatee in the path cannot complete the decryption, the decryption right is automatically delegated to the next one in the path. In this way, the delegator can ensure that the delegation has always been done among those delegatees the delegator trusts. Moreover, an AP-PRE scheme has to obey the following path rules. The delegation, for ciphertexts of a delegator i, can only be carried out on the autonomous path Paidesignated by the delegator i, in the sense that (1) re-encrypted ciphertexts along the autonomous path Pa cannot branch off Pa with meaningful decryption, and (2) original ciphertexts generated under pkjfor j ≠ i (i.e., for a path Pajdifferent from Pai) cannot be inserted into (i.e., cannot be transformed along) the autonomous path Paiwith meaningful decryption. We give the formal definition, as well as the formal security model, for this cryptographic primitive. Under this concept, we construct an IND-CPA secure AP-PRE scheme under the decisional bilinear DiffieHellman (DBDH) assumption in the random oracle model. Our scheme is with the useful properties of proxy re-encryption, i.e., unidirectionality and multi-hop.
Zhenfu Cao, Yunlei Zhao
IEEE Trans. Dependable Secur. Comput.3
2018 Order-Revealing Encryption: File-Injection Attack and Forward Security
Yunlei Zhao
ESORICS (2)2
2018 Practical Constant-Size Ring Signature
Meng-Jun Qin, Yunlei Zhao, Zhoujun Ma
J. Comput. Sci. Technol.2
2017 Compact Lossy and All-but-One Trapdoor Functions from Lattice
Leixiao Cheng, Quanshui Wu, Yunlei Zhao
ISPEC3
2017 Cryptanalysis of RLWE-Based One-Pass Authenticated Key Exchange
Boru Gong, Yunlei Zhao
PQCrypto2
2017 Socialized policy administration
Zeqing Guo, Weili Han, Liangxing Liu, Wenyuan Xu 0001, Minyue Ni, Yunlei Zhao, Xiaoyang Sean Wang
Comput. Secur.6
2016 Secure Dynamic SSE via Access Indistinguishable Storage
abstract
Cloud storage services such as Dropbox [1] and Google Drive [2] are becoming more and more popular. On the one hand, they provide users with mobility, scalability, and convenience. However, privacy issues arise when the storage becomes not fully controlled by users. Although modern encryption schemes are effective at protecting content of data, there are two drawbacks of the encryption-before-outsourcing approach: First, one kind of sensitive information, Access Pattern of the data is left unprotected. Moreover, encryption usually makes the data difficult to use. In this paper, we propose AIS (Access Indistinguishable Storage), the first client-side system that can partially conceal access pattern of the cloud storage in constant time. Besides data content, AIS can conceal information about the number of initial files, and length of each initial file. When it comes to the access phase after initiation, AIS can effectively conceal the behavior (read or write) and target file of the current access. Moreover, the existence and length of each file will remain confidential as long as there is no access after initiation.
Tianhao Wang 0001, Yunlei Zhao
AsiaCCS2
2016 Identity-Concealed Authenticated Encryption and Key Exchange
abstract
Identity concealment and zero-round trip time (0-RTT) connection are two of current research focuses in the design and analysis of secure transport protocols, like TLS1.3 and Google's QUIC, in the client-server setting. In this work, we introduce a new primitive for identity-concealed authenticated encryption in the public-key setting, referred to as higncryption, which can be viewed as a novel monolithic integration of public-key encryption, digital signature, and identity concealment. We then present the security definitional framework for higncryption, and a conceptually simple (yet carefully designed) protocol construction. As a new primitive, higncryption can have many applications. In this work, we focus on its applications to 0-RTT authentication, showing higncryption is well suitable to and compatible with QUIC and OPTLS, and on its applications to identity-concealed authenticated key exchange (CAKE) and unilateral CAKE (UCAKE). Of independent interest is a new concise security definitional framework for CAKE and UCAKE proposed in this work, which unifies the traditional BR and (post-ID) frameworks, enjoys composability, and ensures very strong security guarantee. Along the way, we make a systematically comparative study with related protocols and mechanisms including Zheng's signcryption, one-pass HMQV, QUIC, TLS1.3 and OPTLS, most of which are widely standardized or in use.
Yunlei Zhao
CCS1
2016 Practical Signature Scheme from \varGamma Γ -Protocol
Zhoujun Ma, Yunlei Zhao
ISPEC3
2016 Efficient Tag Path Authentication Protocol with Less Tag Memory
Yingjiu Li, Zongyang Zhang, Yunlei Zhao
ISPEC4
2016 Concurrent Knowledge Extraction in Public-Key Models
Andrew Chi-Chih Yao, Moti Yung, Yunlei Zhao
J. Cryptol.3
2015 Black-Box Separations of Hash-and-Sign Signatures in the Non-Programmable Random Oracle Model
Zongyang Zhang, Yu Chen 0003, Sherman S. M. Chow, Goichiro Hanaoka, Zhenfu Cao, Yunlei Zhao
ProvSec6
2015 A note on the security of KHL scheme
Jian Weng 0001, Yunlei Zhao, Robert H. Deng, Shengli Liu 0001, Yanjiang Yang, Kouichi Sakurai
Theor. Comput. Sci.2
2014 All-but-One Dual Projective Hashing and Its Applications
Zongyang Zhang, Yu Chen 0003, Sherman S. M. Chow, Goichiro Hanaoka, Zhenfu Cao, Yunlei Zhao
ACNS6
2014 Identity-Based Encryption Secure against Selective Opening Chosen-Ciphertext Attack
Junzuo Lai, Robert H. Deng, Shengli Liu 0001, Jian Weng 0001, Yunlei Zhao
EUROCRYPT5
2014 Privacy-Preserving Authenticated Key-Exchange Over Internet
abstract
Key-exchange, in particular Diffie-Hellman key-exchange (DHKE), is among the core cryptographic mechanisms for ensuring network security. For key-exchange over the Internet, both security and privacy are desired. In this paper, we develop a family of privacy-preserving authenticated DHKE protocols named deniable Internet key-exchange (DIKE), both in the traditional PKI setting and in the identity-based setting. The newly developed DIKE protocols are of conceptual clarity and practical (online) efficiency. They provide useful privacy protection to both protocol participants, and add novelty and new value to the IKE standard. To the best of our knowledge, our protocols are the first provably secure DHKE protocols that additionally enjoy all the following privacy protection advantages: 1) forward deniability, actually concurrent non-malleable statistical zero-knowledge, for both protocol participants simultaneously; 2) the session transcript and session-key can be generated merely from DH-exponents (together with some public values), which thus cannot be traced to the pair of protocol participants; and 3) exchanged messages do not bear peer's identity, and do not explicitly bear player role information.
Andrew Chi-Chih Yao, Yunlei Zhao
IEEE Trans. Inf. Forensics Secur.2
2013 Privacy-preserving smart metering with regional statistics and personal enquiry services
abstract
In smart grid, households may send the readings of their energy usage to the utility and a third-party service provider which provides analyzed statistics data to users. User privacy becomes an important issue in this application. In this paper, we propose a new cryptographic-based solution for the privacy issue in smart grid systems. The advantages of our system are twofold: Households can send authenticated energy consumption readings to a third-party service provider anonymously. The service provider learns only the region where the readings come from but not their respective identities. On the other hand, users with personal secret information can enquiry their usage history records or regional statistics.
Cheng-Kang Chu, Joseph K. Liu, Jun Wen Wong, Yunlei Zhao, Jianying Zhou 0001
AsiaCCS4
2013 OAKE: a new family of implicitly authenticated diffie-hellman protocols
abstract
Cryptographic algorithm standards play an important role both to the practice of information security and to cryptography theory research. Among them, the KEA and OPACITY (KEA/OPACITY, in short) protocols, and the MQV and HMQV ((H)MQV, in short) protocols, are a family of implicitly authenticated Diffie-Hellman key-exchange (IA-DHKE) protocols that are among the most efficient authenticated key-exchange protocols known and are widely standardized. In this work, from some new design insights, we develop a new family of practical IA-DHKE protocols, referred to as OAKE (standing for "optimal authenticated key-exchange" in brief). We show that the OAKE protocol family combines, in essence, the advantages of both (H)MQV and KEA/OPACITY, while saving from or alleviating the disadvantages of them both.
Andrew Chi-Chih Yao, Yunlei Zhao
CCS2
2013 Security Model and Analysis of FHMQV, Revisited
Shengli Liu 0001, Kouichi Sakurai, Jian Weng 0001, Fangguo Zhang, Yunlei Zhao
Inscrypt5
2013 Accountable Authority Identity-Based Encryption with Public Traceability
Junzuo Lai, Robert H. Deng, Yunlei Zhao, Jian Weng 0001
CT-RSA3
2013 Efficient Public Key Cryptosystem Resilient to Key Leakage Chosen Ciphertext Attacks
Shengli Liu 0001, Jian Weng 0001, Yunlei Zhao
CT-RSA3
2013 Online/Offline Signatures for Low-Power Devices
abstract
When digital signature is applied on low-power devices, like smart cards, wireless sensors and RFID tags, some specific properties, e.g., better offline storage, more modular and flexible deployment, are desired. To meet these needs, a new variant of the Fiat-Shamir transformation for digital signatures, referred to as Γ -transformation, is introduced and formalized in this work. Following this new transformation approach, some new signature schemes (referred to as Γ-signatures) are presented and discussed. In particular, it is shown that the Γ-signatures for discrete logarithm problem (DLP) developed in this work combine, in essence, the advantages of both Schnorr's signature and the digital signature standard (DSS), while saving from the disadvantages of them both.
Andrew Chi-Chih Yao, Yunlei Zhao
IEEE Trans. Inf. Forensics Secur.2
2012 A New Framework for Privacy of RFID Path Authentication
Shaoying Cai, Robert H. Deng, Yingjiu Li, Yunlei Zhao
ACNS4
2012 Generic Construction of Chosen Ciphertext Secure Proxy Re-Encryption
Goichiro Hanaoka, Yutaka Kawai, Noboru Kunihiro, Takahiro Matsuda 0002, Jian Weng 0001, Rui Zhang 0002, Yunlei Zhao
CT-RSA7
2012 Distributed Path Authentication for Dynamic RFID-Enabled Supply Chains
Shaoying Cai, Yingjiu Li, Yunlei Zhao
SEC3
2012 Computationally-Fair Group and Identity-Based Key-Exchange
Andrew Chi-Chih Yao, Yunlei Zhao
TAMC2
2011 Hierarchical Identity-Based Chameleon Hash and Its Applications
Feng Bao 0001, Robert H. Deng, Xuhua Ding, Junzuo Lai, Yunlei Zhao
ACNS5
2011 Designated Confirmer Signatures with Unified Verification
Guilin Wang, Fubiao Xia, Yunlei Zhao
IMACC3
2011 Taxonomical Security Consideration of Authenticated Key Exchange Resilient to Intermediate Computation Leakage
Kazuki Yoneyama, Yunlei Zhao
ProvSec2
2011 A zero-knowledge based framework for RFID privacy
abstract
Formal RFID security and privacy frameworks are fundamental to the design and analysis of robust RFID systems. In this paper, we develop a new definitional framework for RFID privacy in a rigorous and precise manner. Our framework is based on a zero-knowledge (ZK) formulation [The Foundations of Cr yptography, Cambridge Univ. Press, Cambridge, 2001; ACM Symposium on Theory of Computing, 1985, pp. 291–304] and incorporates the notions of adaptive completeness and mutual authentication. We provide meticulous justification of the new framework and contrast it with existing ones in the literature. In particular, we prove that our framework is strictly stronger than the ind-privacy model in International Conference on Pervasive Computing and Communications, 2007, which answers an open question posed in International Conference on Pervasive Computing and Communications, 2007, for developing stronger RFID privacy models. We also clarify certain confusions and rectify several defects in the existing frameworks. Finally, based on the protocol in Conference on Computer and Communications Security, 2009, we propose an efficient RFID mutual authentication protocol and analyze its security and privacy. The methodology used in our analysis can also be applied to analyze other RFID protocols within the new framework.
Robert H. Deng, Yingjiu Li, Moti Yung, Yunlei Zhao
J. Comput. Secur.4
2010 Deniable Internet Key Exchange
Andrew Chi-Chih Yao, Yunlei Zhao
ACNS2
2010 A New Framework for RFID Privacy
Robert H. Deng, Yingjiu Li, Moti Yung, Yunlei Zhao
ESORICS4
2010 Concurrent Knowledge Extraction in the Public-Key Model
Andrew Chi-Chih Yao, Moti Yung, Yunlei Zhao
ICALP (1)3
2009 A note on the feasibility of generalised universal composability
abstract
In this paper we study (interpret) the precise composability guarantee of the generalised universal composability (GUC) feasibility with global setups that was proposed in the recent paper Canetti et al. (2007) from the point of view of full universal composability (FUC), that is, composability with arbitrary protocols, which was the original security goal and motivation for UC. By observing a counter-intuitive phenomenon, we note that the GUC feasibility implicitly assumes that the adversary has limited access to arbitrary external protocols. We then clarify a general principle for achieving FUC security, and propose some approaches for fixing the GUC feasibility under the general principle. Finally, we discuss the relationship between GUC and FUC from both technical and philosophical points of view. This should be helpful in gaining a precise understanding of the GUC feasibility, and for preventing potential misinterpretations and/or misuses in practice.
Andrew Chi-Chih Yao, F. Frances Yao, Yunlei Zhao
Math. Struct. Comput. Sci.3
2009 A note on universal composable zero-knowledge in the common reference string model
Andrew Chi-Chih Yao, F. Frances Yao, Yunlei Zhao
Theor. Comput. Sci.3
2007 Generic and Practical Resettable Zero-Knowledge in the Bare Public-Key Model
Moti Yung, Yunlei Zhao
EUROCRYPT2
2007 A Note on Universal Composable Zero Knowledge in Common Reference String Model
Andrew Chi-Chih Yao, F. Frances Yao, Yunlei Zhao
TAMC3
2007 A Note on the Feasibility of Generalized Universal Composability
Andrew Chi-Chih Yao, F. Frances Yao, Yunlei Zhao
TAMC3
2006 Interactive Zero-Knowledge with Restricted Random Oracles
Moti Yung, Yunlei Zhao
TCC2
2006 A note on the Dwork-Naor timed deniable authentication
Yunlei Zhao
Inf. Process. Lett.1
2004 Some Observations on Zap and Its Applications
Yunlei Zhao, Chan H. Lee, Hong Zhu 0004
ACNS1
2004 (2+f(n))-SAT and its properties
Yunlei Zhao, Xiaotie Deng, Chan H. Lee, Hong Zhu 0004
Discret. Appl. Math.1
2003 Resettable Zero-Knowledge in the Weak Public-Key Model
Yunlei Zhao, Xiaotie Deng, Chan H. Lee, Hong Zhu 0004
EUROCRYPT1
2002 (2+ f(n))-SAT and Its Properties
Xiaotie Deng, Chan H. Lee, Yunlei Zhao, Hong Zhu 0004
COCOON3