Fangguo Zhang

dblp:52/2421 · DBLP profile ↗
← Back
132ranked-venue papers
19as first author
34since 2021 · last 2026
0000-0002-0486-6413ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 68 · 11 first-author · 18 since 2021Applied, interdisciplinary, general and emerging computing · 19 · 2 first-author · 5 since 2021Databases, data management, data science and information retrieval · 16 · 4 first-author · 2 since 2021Theory of computation · 13 · 2 first-author · 5 since 2021Systems, architecture and hardware · 9 · 3 since 2021Computer networks · 5 · 2 since 2021Software engineering, systems software and programming languages · 5 · 1 first-authorArtificial intelligence and machine learning · 2 · 1 since 2021
YearPublicationVenuePosition
2026 Batch-Puncturing Circuit CP-ABE (and More) from Lattices
Yongkang Lang, Fangguo Zhang, Jianghong Wei, Xinyi Huang 0001, Xiaofeng Chen 0001
ACISP (2)2
2026 Accelerating Stage 2 in ECM Using Elliptic Divisibility Sequences
Ziwen Liao, Fangguo Zhang
Theory Comput. Syst.2
2025 Deny Whatever You Want: Dual-Deniable Public-Key Encryption
Zhiyuan An, Fangguo Zhang
PKC (4)2
2025 Quantum algorithm for solving binary hyperelliptic curve discrete logarithm problem
abstract
Abstract It is well-established that Shor’s algorithm can solve the discrete logarithm problem (DLP) in polynomial time. The hyperelliptic curve DLP (HCDLP) of genus 2 has found widespread industrial applications and remains an active research domain. In this work, we develop a quantum algorithm for solving HCDLP over binary fields $$\mathbb {F}_{2^n}$$ F 2 n by adapting Shor’s algorithmic framework. The core innovation lies in our divisor addition implementation, which combines the geometric interpretation of divisor operations with symmetric polynomial techniques. Using representative parameters ( $$n = 163, 283, 571$$ n = 163 , 283 , 571 ), we quantify the required quantum resources from the perspective of minimal qubit count, minimal T-gate usage, and minimal quantum depth. Furthermore, we compare the quantum resources required for solving HCDLP over binary fields with those for solving HCDLP over general prime fields and demonstrate the vulnerability of HCDLP-based cryptosystems to quantum attacks. Our analysis reveals that: (1) solving HCDLP over binary fields requires fewer quantum gates and less quantum depth compared to solving it over general prime fields; (2) the maximum achievable quantum depth for HCDLP attacks falls below NIST’s minimum security threshold of $$2^{40}$$ 2 40 for comparable protection levels, and (3) the quantum computational cost is orders of magnitude lower than the $$2^{157}$$ 2 157 resources needed for AES-128 attacks.
Du Zeng, Chao Chen 0036, Zijian Zhou 0004, Fangguo Zhang
Cybersecur.5
2025 How to reduce the number of steps for (multi-valued validated) Byzantine agreement?
Baohan Huang, Chao Liu 0039, Shengli Liu 0001, Yong Yu 0002, Fangguo Zhang, Liehuang Zhu
J. Parallel Distributed Comput.6
2025 Low-Complexity Chase Decoding of Elliptic Codes
abstract
This paper proposes two low-complexity Chase (LCC) decoding algorithms for elliptic codes, which are realized by K¨otter’s interpolation and the basis reduction (BR) interpolation, respectively. They are both developed from the perspective of computing the Gr¨obner bases of the interpolation modules. By identifying η unreliable symbols, 2η decoding testvectors are formulated and the corresponding interpolation modules can be defined. The re-encoding transform (ReT) is further introduced to facilitate the interpolation. The LCC-K ¨otter decoding performs interpolation for the common elements, producing an intermediate outcome shared by all test-vectors. The desired Gr¨obner basis w.r.t. each test-vector can be obtained in a binary tree growing fashion. The new interpolation process can start from intermediate nodes of the previously interpolated paths, resulting in a low complexity. But the decoding latency cannot be contained. In contrast, the LCC-BR decoding performs the common computation in basis construction, which partly substantiates the bases for all interpolation modules. The subsequent basis construction and reduction can be performed in parallel. Besides a low complexity, it offers a latency advantage over the LCC-K¨otter decoding. The decoding complexity and latency are analyzed and verified numerically. The LCC decoding performance are also presented, demonstrating their advantage over both the Guruswami-Sudan decoding and the algebraic soft decoding. Moreover, the performance advantage of elliptic codes over the Reed-Solomon (RS) codes is demonstrated.
Yunqi Wan, Jiwei Liang, Li Chen 0013, Fangguo Zhang
IEEE Trans. Commun.4
2025 Everything Distributed and Asynchronous: A Practical System for Key Management Service
abstract
A key management service (KMS) is vital to modern mission-critical systems. At the core of KMS are the key generation process and the key refresh process. In this paper, we design and implement a purely asynchronous system for completely distributed KMS supporting traditional applications such as threshold cryptosystems and multiparty computation (MPC) as well as emerging blockchains and Web3 applications. In this system, we have built a number of new asynchronous distributed key generation (ADKG) protocols and their corresponding asynchronous distributed key refresh (ADKR) protocols. We have demonstrated that our ADKG and ADKR protocols in the standard model outperform existing ones of the same kind, while our protocols in the random oracle model (ROM) are more efficient than other protocols with small and medium-sized networks.
Zhaoyang Xie, Sisi Duan, Chao Liu 0039, Shengli Liu 0001, Xuanji Meng, Yong Yu 0002, Fangguo Zhang, Boxin Zhao, Liehuang Zhu, Tianqing Zhu
IEEE Trans. Parallel Distributed Syst.8
2024 Parallel Algorithms on Hyperelliptic Pairings Using Hyperelliptic Nets
Chao Chen 0036, Fangguo Zhang
ACISP (1)2
2024 New Construction of Code-Based Signature Schemes
Yang Yang 0134, Fangguo Zhang
ICICS (2)2
2023 TVES: Threshold Verifiably Encrypted Signature and Its Applications
Haibo Tian, Fangguo Zhang
Inscrypt (1)3
2023 Practical Asynchronous Distributed Key Generation: Improved Efficiency, Weaker Assumption, and Standard Model
abstract
Distributed key generation (DKG) allows bootstrapping threshold cryptosystems without relying on a trusted party, nowadays enabling fully decentralized applications in blockchains and multiparty computation (MPC). While we have recently seen new advancements for asynchronous DKG (ADKG) protocols, their performance remains the bottleneck for many applications, with only one protocol being implemented (DYX+ ADKG, IEEE S&P 2022). DYX+ ADKG relies on the Decisional Composite Residuosity assumption (being expensive to instantiate) and the Decisional Diffie-Hellman assumption, incurring a high latency (more than 100s with a failure threshold of 16). Moreover, the security of DYX+ ADKG is based on the random oracle model (ROM) which takes hash function as an ideal function; assuming the existence of random oracle is a strong assumption, and up to now, we cannot find any theoretically-sound implementation. Furthermore, the ADKG protocol needs public key infrastructure (PKI) to support the trustworthiness of public keys. The strong models (ROM and PKI) further limit the applicability of DYX+ ADKG, as they would add extra and strong assumptions to underlying threshold cryptosystems. For instance, if the original threshold cryptosystem works in the standard model, then the system using DYX+ ADKG would need to use ROM and PKI. In this paper, we design and implement a modular ADKG protocol that offers improved efficiency and stronger security guarantees. We explore a novel and much more direct reduction from ADKG to the underlying blocks, reducing the computational overhead and communication rounds of ADKG in the normal case. Our protocol works for both the low-threshold and high-threshold scenarios, being secure under the standard assumption (the well-established discrete logarithm assumption only) in the standard model (no trusted setup, ROM, or PKI).
Sisi Duan, Chao Liu 0039, Boxin Zhao, Xuanji Meng, Shengli Liu 0001, Yong Yu 0002, Fangguo Zhang, Liehuang Zhu
DSN8
2023 Deniable Cryptosystems: Simpler Constructions and Achieving Leakage Resilience
Zhiyuan An, Haibo Tian, Chao Chen 0036, Fangguo Zhang
ESORICS (1)4
2023 New Obfuscation Scheme for Conjunctions
abstract
Abstract Recently, there has been renewed interest in conjunction obfuscations. A conjunction, which is called pattern matching with wildcards sometimes, is associated with a pattern $\mathsf{pat}\in \{0,1,*\}^n$ where * is a wildcard. It accepts if and only if the input bits are the same as the pattern at all non-wildcard positions. The conjunction obfuscation starts to get noticed because it provides the ability to protect these sensitive patterns while preserving its functionality. It is meaningful when the conjunction obfuscation is applied in the pattern matching, biological recognition, resisting SQL injection attacks and so on. In this work, we propose a new candidate of conjunction obfuscation. It not only retains the simplicity of the intuitive scheme in BKM18, but also adds wildcards to the pattern. Besides, we also propose a conjunction obfuscation with multi-bit output. The second obfuscation has the same size of the obfuscated program as the first obfuscation. Both obfuscations provide the distributional virtual black-box security.
Fangguo Zhang
Comput. J.2
2023 Verifiable delay functions and delay encryptions from hyperelliptic curves
abstract
Abstract Verifiable delay functions (VDFs) and delay encryptions (DEs) are two important primitives in decentralized systems, while existing constructions are mainly based on time-lock puzzles. A disparate framework has been established by applying isogenies and pairings on elliptic curves. Following this line, we first employ Richelot isogenies and non-degenerate pairings from hyperelliptic curves for a new verifiable delay function, such that no auxiliary proof and interaction are needed for the verification. Then, we demonstrate that our scheme satisfies all security requirements, in particular, our VDF can resist several attacks, including the latest attacks for SIDH. Besides, resorting to the same techniques, a secure delay encryption from hyperelliptic curves is constructed by modifying Boneh and Frankiln’s IBE scheme, which shares the identical setup with our VDF scheme. As far as we know, these schemes are the first cryptographic applications from high-genus isogenies apart from basic protocols, i.e., hash functions and key exchange protocols.
Chao Chen 0036, Fangguo Zhang
Cybersecur.2
2023 Isogeny computation on Kummer lines and applications
Chao Chen 0036, Fangguo Zhang, Changan Zhao
J. Inf. Secur. Appl.2
2023 Secret handshakes: Full dynamicity, deniability and lattice-based design
Zhiyuan An, Yamin Wen, Fangguo Zhang
Theor. Comput. Sci.4
2022 Algebraic Chase Decoding of Elliptic Codes Through Computing the Gröbner Basis
abstract
This paper proposes two interpolation-based algebraic Chase decoding for elliptic codes. It is introduced from the perspective of computing the Gröbner basis of the interpolation module, for which two Chase interpolation approaches are utilized. They are Kötter’s interpolation and the basis reduction (BR) interpolation. By identifying η unreliable symbols, 2ηdecoding test-vectors are formulated, and the corresponding interpolation modules can be defined. The re-encoding further helps transform the test-vectors, facilitating the two interpolation techniques. In particular, Kötter’s interpolation is performed for the common elements of the test-vectors, producing an intermediate outcome that is shared by the decoding of all test-vectors. The desired Gröbner bases w.r.t. all test-vectors can be obtained in a binary tree growing fashion, leading to a low complexity but its decoding latency cannot be contained. In contrast, the BR interpolation first performs the common computation in basis construction which is shared by all interpolation modules, and then conducts the module basis construction and reduction for all test-vectors in parallel. It results in a significantly lower decoding latency. Finally, simulation results are also presented to demonstrate the effectiveness of the proposed Chase decoding.
Yunqi Wan, Li Chen 0013, Fangguo Zhang
ISIT3
2022 Searching for Encrypted Data on Blockchain: An Efficient, Secure and Fair Realization
Jianzhang Chen, Haibo Tian, Fangguo Zhang
ISC3
2022 Forward-Secure Revocable Secret Handshakes from Lattices
Zhiyuan An, Yamin Wen, Fangguo Zhang
PQCrypto4
2022 Pseudorandom number generator based on supersingular elliptic curve isogenies
Fangguo Zhang, Haibo Tian
Sci. China Inf. Sci.2
2022 Lattice-based group encryptions with only one trapdoor
Fangguo Zhang, Xiaofeng Chen 0001, Willy Susilo
Sci. China Inf. Sci.3
2022 Consensus algorithm based on verifiable quantum random numbers
abstract
Blockchain systems based on the proof-of-work (PoW) consensus introduce entropy to the system in a natural way due to the randomness of mining. However, for non-PoW consensus (e.g., proof-of-stake and delegated proof-of-stake consensus) blockchain systems, a different approach to introducing entropy, such as the distributed random number generation (dRNG) algorithm, must be established. The dRNG algorithm is one of the key challenges in developing the consensus mechanism, as well as one of the relevant parameters for determining the merit of the consensus mechanism. In this paper, we first derive a publicly verifiable quantum random numbers generation protocol based on the certifiable randomness scheme from any untrusted quantum device, which offers features, such as fairness, no trusted third party, and publicly verifiable. Then, based on verifiable quantum random numbers, we propose a new consensus algorithm. The algorithm selects block proposer and block verification committees for each round using verifiable quantum random numbers, resulting in better randomness, fairness, and efficiency of the entire consensus process. In addition, the new consensus algorithm is not only resistant to adaptive adversary models as well as to collusion attacks, but also requires negligible computation for each user to avoid unnecessary consumption of power resources. Finally, we analyze the verifiable randomness, fairness, liveness, and communication complexity of the consensus algorithm.
Ping Wang 0005, Weiqian Chen, Songlian Lin, Fangguo Zhang
Int. J. Intell. Syst.6
2022 Optimizing the evaluation of ℓ-isogenous curve for isogeny-based cryptography
Fangguo Zhang
Inf. Process. Lett.4
2022 Algebraic Soft Decoding of Elliptic Codes
abstract
This paper proposes the algebraic soft decoding (ASD) for one-point elliptic codes, where the interpolation problem is solved from the perspective of module basis reduction. In ASD, the interpolation polynomial$\mathcal {Q}(x, y, z)$is the minimum candidate of a Gröbner basis. Based on a multiplicity matrix, an interpolation ideal can be defined. With the decoding output list size, an equivalent interpolation module can be led to. By further defining the set of interpolation points, a sequence of modules from the elliptic curve coordinate ring can be obtained. Based on the Lagrange interpolation functions over elliptic function field, a basis of the interpolation module can be constructed. The desired Gröbner basis that contains$\mathcal {Q}$can be determined by reducing the module basis. Re-encoding transform (ReT) is further introduced to reduce the basis reduction complexity. It is also shown that the interpolation can be facilitated by assessing the degree of the Lagrange interpolation polynomials. The decoding complexity is analyzed, which is verified by numerical results. That shows the advantage of this interpolation technique over the conventional Kötter’s interpolation. The ASD performance of elliptic codes is also presented.
Yunqi Wan, Li Chen 0013, Fangguo Zhang
IEEE Trans. Commun.3
2021 Forward-Secure Group Encryptions from Lattices
Xiaofeng Chen 0001, Fangguo Zhang, Willy Susilo
ACISP3
2021 Lattice-Based Group Encryption with Full Dynamicity and Message Filtering Policy
Xiaofeng Chen 0001, Fangguo Zhang, Willy Susilo
ASIACRYPT (4)3
2021 Identity Based Linkable Ring Signature with Logarithmic Size
Mohamed Nassurdine, Fangguo Zhang
Inscrypt3
2021 Lattice-Based Secret Handshakes with Reusable Credentials
Zhiyuan An, Yamin Wen, Fangguo Zhang
ICICS (2)4
2021 Algebraic Soft Decoding of Elliptic Codes
abstract
This paper proposes algebraic soft decoding (ASD) for one-point elliptic codes, where the interpolation is realized through the perspective of obtaining a Gröbner basis. The desired interpolation polynomial$\mathcal{Q}(x, y, z)$is the minimum candidate in the basis. This work shows how to obtain such a Gröbner basis. Based on an interpolation multiplicity matrix M, an interpolation ideal$\mathcal{I}_{\mathrm{M}}$can be defined. With a predefined decoding output list size (OLS)$l\ (l\geq\deg_{z}\mathcal{Q})$, an equivalent interpolation module$\mathcal{I}_{\mathrm{M}, l}$can be led to. By further defining the Lagrange interpolation functions, a basis of the interpolation module can be constructed. The desired Gröbner basis can be obtained by reducing this module basis. Finally, the decoding complexity is also analyzed.
Yunqi Wan, Li Chen 0013, Fangguo Zhang
ISIT3
2021 Efficient List Decoding Applied to $\mathrm{ECC}^2$
Peidong Guan, Yunqi Wan, Fangguo Zhang
PDCAT4
2021 Inner-Product Functional Encryption from Random Linear Codes: Trial and Challenges
Fangguo Zhang
ProvSec3
2021 Functional encryption for cubic polynomials and implementation
Fangguo Zhang
Theor. Comput. Sci.2
2021 ASBKS: Towards Attribute Set Based Keyword Search Over Encrypted Personal Health Records
abstract
With the growth of public demand for online access to health services, many efforts have been devoted to personal health records (PHR) in cloud computing. It enables patients to manage their personal health information (PHI) in cloud servers, which greatly facilitates the collection, access and sharing of PHI. Since cloud servers are not fully trusted, it is desirable that the PHI can be encrypted for privacy protection before uploaded to the cloud. Besides the privacy of PHI, fine-grained and flexible search control is also strongly desired for a secure PHR system. In this article, we first present attribute set based keyword search (ASBKS) which can realize fine-grained keyword search of encrypted PHR. Compared with the existing searchable encryption with access control, the proposed ASBKS can achieve more flexibility in user attributes organization and more efficiency in specifying policies. Furthermore, we present a hierarchical ASBKS scheme to improve scalability by extending ASBKS with a hierarchical structure of users. We implement our ASBKS scheme and the experimental results demonstrate that it is both efficient and flexible for encrypted PHR in cloud computing.
Xiaofeng Chen 0001, Fangguo Zhang, Wanhua Li 0002, Haotian Wu 0009, Shaohua Tang, Yang Xiang 0001
IEEE Trans. Dependable Secur. Comput.3
2021 Guruswami-Sudan Decoding of Elliptic Codes Through Module Basis Reduction
abstract
This paper proposes the Guruswami-Sudan (GS) list decoding algorithm for one-point elliptic codes, in which the interpolation is realized by the module basis reduction (BR). Elliptic codes are a kind of algebraic-geometric (AG) codes with a genus of one. Over the same finite field, they have a greater codeword length than Reed-Solomon (RS) codes, capable of correcting more errors. The GS decoding consists of interpolation and root-finding, while the former that determines the interpolation polynomial$\mathcal {Q}(\text {x}, \text {y}, \text {z})$dominates the decoding complexity. By defining the Lagrange interpolation function over an elliptic function field, a basis of the interpolation module can be constructed. The desired Gröbner basis that contains$\mathcal {Q}(\text {x}, \text {y}, \text {z})$can be determined by reducing the constructed basis. This is namely the BR interpolation and it requires less finite field arithmetic operations than the conventional Kötter’s interpolation, facilitating the GS decoding. Re-encoding transform (ReT) is further introduced to facilitate the BR interpolation. This work also shows that both the BR interpolation and its ReT variant will have a lower complexity as the code rate${k}/{n}$increases, where n and${k}$are the length and dimension of the code, respectively. Our numerical results demonstrate the complexity advantage of the BR interpolation over Kötter’s interpolation, and the performance advantage of elliptic codes over RS codes.
Yunqi Wan, Li Chen 0013, Fangguo Zhang
IEEE Trans. Inf. Theory3
2020 Optimized Arithmetic Operations for Isogeny-Based Cryptography on Huff Curves
Fangguo Zhang
ACISP2
2020 An Efficient Blind Signature Scheme Based on SM2 Signature Algorithm
Yudi Zhang 0001, Debiao He, Fangguo Zhang, Xinyi Huang 0001
Inscrypt3
2020 CSH: A Post-quantum Secret Handshake Scheme from Coding Theory
Fangguo Zhang, Haibo Tian
ESORICS (2)2
2020 New Practical Public-Key Deniable Encryption
Yanmei Cao, Fangguo Zhang, Chong-zhi Gao, Xiaofeng Chen 0001
ICICS2
2020 Algebraic List Decoding of Elliptic Codes Through Module Basis Reduction
Yunqi Wan, Li Chen 0013, Fangguo Zhang
ISITA3
2020 Intersection-policy private mutual authentication from authorized private set intersection
Yamin Wen, Fangguo Zhang, Huaxiong Wang, Yinbin Miao
Sci. China Inf. Sci.2
2020 Multi-user Boolean searchable encryption supporting fast ranking in mobile clouds
Zehong Chen, Fangguo Zhang, Peng Zhang 0029, Hanbang Zhao
Comput. Commun.2
2020 Implementing confidential transactions with lattice techniques
abstract
The notion of confidential transactions plays a central role in ensuring the confidentiality of transaction amounts in a block‐chain‐based cryptocurrency. Past researches have confirmed that the access policy of transaction amounts influences the anonymity of a cryptocurrency. Most of the current techniques of confidential transactions are based on the discrete logarithm problem. Because of the threats from quantum algorithms, clients are eager to enjoy security guarantees in a post‐quantum scenario. Lattices are an ideal source of hardness, due to its exclusive worst‐case to the average‐case phenomenon. Nevertheless, the distinctions between the discrete logarithm problem and lattice problems build an obstacle in the way of borrowing the ideas from the former to the latter directly. In this study, inspired by the notion of commitments to polynomials and zero‐knowledge arguments of knowledge for the inhomogeneous short integer solution problem, the authors give an approach to implement confidential transactions using lattice techniques.
Fangguo Zhang, Baodian Wei, Yusong Du
IET Inf. Secur.2
2020 A new secret handshake scheme with multi-symptom intersection for mobile healthcare social networks
Yamin Wen, Fangguo Zhang, Huaxiong Wang, Yinbin Miao, Yuqiao Deng
Inf. Sci.2
2020 ECC2: Error correcting code and elliptic curve based cryptosystem
Fangguo Zhang, Peidong Guan
Inf. Sci.1
2020 Side-Channel Analysis and Countermeasure Design on ARM-Based Quantum-Resistant SIKE
abstract
The implementations of post-quantum cryptographic algorithms have been newly explored, whereas, the protection against side-channel attacks shall be considered upfront, since it can have a non-negligible impact on security and performance. In this article, the security of supersingular isogeny key encapsulation (SIKE), a second-round candidate of NIST's on-going post-quantum standardization process, is thoroughly evaluated under side-channel analysis. First, the vulnerabilities of reference and optimized implementations of SIKE are thoroughly analyzed in terms of both horizontal and vertical side-channel leakage. After the optimized SIKE, which is based on Three-point Montgomery Differential Ladder algorithm, is proved to be constant-time and there is no horizontal leakage, a vertical vulnerability is analyzed based on the source code at the algorithmic level, and a theoretical differential power analysis (DPA) attack is proposed. In order to exploit this vulnerability, the differential electromagnetic attack (DEMA) is put into practice to extract the private key of SIKE based on a 32-bit ARM platform. To the best of our knowledge, this is the first practical side-channel attack at SIKE implemented on real ARM-based devices. Our experiments show that the DEMA needs only hundreds of electromagnetic traces to carry out the attack. More importantly, an efficient window-based countermeasure is proposed to eliminate the vertical leakage and prevent side-channel attacks with only a little overhead. The security of our countermeasure is carefully evaluated against most of well-known power analysis attacks. Through careful evaluation and comparison with other countermeasures, this method can lead to higher security at a very small cost in terms of time and memory.
Fan Zhang 0010, Bolin Yang, Xiaofei Dong, Sylvain Guilley, Zhe Liu 0001, Wei He 0015, Fangguo Zhang, Kui Ren 0001
IEEE Trans. Computers7
2020 Authorized Keyword Searches on Public Key Encrypted Data With Time Controlled Keyword Privacy
abstract
Recently, more and more data have been stored in the cloud with keyword indices so that the data users can make search over the databases. In some of these database applications, the query frequency analysis of keywords is quite important to the optimization of the databases and it is easy to be implemented when the data are not encrypted. However, with the growing demands of data privacy, it is desired that the data should be encrypted before uploaded to the cloud. Searchable encryption has been proposed which enables users to make keyword search over the encrypted data with keyword privacy. In a secure searchable encryption scheme, it is required that the keyword in each query should not be revealed. So it becomes challenging to analyze the query frequency of keywords in an encrypted database which has the pressing need of optimization. In this paper, we first consider this problem and present an efficient solution to it which enables the query frequency analysis of keywords without destroying the privacy of the encrypted data and the identity privacy of data users. We also simulate our solution and show that it is practical to the real applications.
Wanhua Li 0002, Fangguo Zhang, Rong Cheng, Shaohua Tang
IEEE Trans. Inf. Forensics Secur.3
2020 SDSRS: A Novel White-Box Cryptography Scheme for Securing Embedded Devices in IIoT
abstract
In this article, with the rapid development of industrial Internet of Things, a large number of embedded devices, such as sensors and tag readers, have been widely deployed for gathering and sending data. These devices are commonly unreliable and vulnerable to many threats, because they are located in unattended areas which are vulnerable to device capture attacks. Such environments can be regarded as white-box attack contexts, in which the adversary has total visibility and full control of the implementations. White-box cryptography (WBC) aims to protect implementations of symmetric encryption algorithms in white-box attack contexts. Unfortunately, existing WBC schemes are vulnerable to various attacks, and most of them are insufficiently secure in strict white-box attack contexts. Based on the investigation of existing designs and the corresponding cryptanalysis, we propose a novel design approach for securing WBC schemes, which is named state-dependent selectable random substitutions (SDSRS). It uses SDSRSs to defeat various related white-box cryptanalytic approaches. With special considerations for IIoT systems, such as high performance for supporting real-time applications and small block size for fitting industrial protocols, a concrete WBC scheme designed with the proposed approach has been provided. Our theoretical analysis shows that the proposed scheme is secure. Additionally, experimental results indicate that the scheme performs well in practice, and it is significantly efficient in time and energy consumptions compared with existing secure white-box cryptographic schemes.
Yang Shi 0002, Wujing Wei, Fangguo Zhang, Xiapu Luo, Zongjian He, Hongfei Fan
IEEE Trans. Ind. Informatics3
2019 Improving ECDLP Computation in Characteristic 2
Fangguo Zhang, Ping Wang 0005, Haibo Tian
Inscrypt1
2019 Design of Guruswami-Sudan List Decoding for Elliptic Codes
abstract
Advancing from Reed-Solomon (RS) codes, the length of algebraic-geometric (AG) codes can exceed the size of finite field, resulting in a greater error-correction capability. However, this is realized with a genus penalty. Usually, they are not maximum distance separable (MDS) codes. One-point elliptic codes are either MDS or almost MDS, yielding a good tradeoff between codeword length and distance property. This paper proposes the Guruswami-Sudan (GS) list decoding algorithm for elliptic codes. To define the interpolated polynomial Q(x, y, z), an explicit construction for the zero basis of each affine point is introduced. Given an interpolation multiplicity m, the error-correction capability τmand the maximum decoding output cardinality lmof the GS algorithm are characterized. An efficient interpolation algorithm is further presented for elliptic codes. Performance of elliptic codes is shown for the first time, demonstrating their advantage over RS codes.
Yunqi Wan, Li Chen 0013, Fangguo Zhang
ITW3
2019 Solving ECDLP via List Decoding
Fangguo Zhang, Shengli Liu 0001
ProvSec1
2019 Efficient obfuscation for CNF circuits and applications in cloud computing
Fangguo Zhang, Rong Cheng, Haibo Tian
Soft Comput.2
2018 AFCoin: A Framework for Digital Fiat Currency of Central Banks Based on Account Model
Haibo Tian, Xiaofeng Chen 0001, Yong Ding 0005, Xiaoyan Zhu 0005, Fangguo Zhang
Inscrypt5
2018 Verifiable keyword search for secure big data-based mobile healthcare networks with fine-grained authorization control
Zehong Chen, Fangguo Zhang, Peng Zhang 0029, Joseph K. Liu, Jiwu Huang, Hanbang Zhao, Jian Shen 0001
Future Gener. Comput. Syst.2
2018 Privacy preserving multi-party computation delegation for deep learning in cloud computing
Fangguo Zhang, Xiaofeng Chen 0001, Jian Shen 0001
Inf. Sci.2
2017 Implementing Indistinguishability Obfuscation Using GGH15
Fangguo Zhang
Inscrypt2
2017 Bit Security of the Hyperelliptic Curves Diffie-Hellman Problem
Fangguo Zhang
ProvSec1
2017 Deniable Searchable Symmetric Encryption
Huige Li, Fangguo Zhang, Chun-I Fan
Inf. Sci.2
2016 Homomorphic Linear Authentication Schemes from (ε)-Authentication Codes
abstract
Proofs of Data Possession/Retrievability (PoDP/PoR) schemes are essential to cloud storage services, since they can increase clients' confidence on the integrity and availability of their data. The majority of PoDP/PoR schemes are constructed from homomorphic linear authentication (HLA) schemes, which decrease the price of communication between the client and the server. In this paper, a new subclass of authentication codes, named ε-authentication codes, is proposed, and a modular construction of HLA schemes from ε-authentication codes is presented. We prove that the security notions of HLA schemes are closely related to the size of the authenticator/tag space and the successful probability of impersonation attacks (with non-zero source states) of the underlying ε-authentication codes. We show that most of HLA schemes used for the PoDP/PoR schemes are instantiations of our modular construction from some ε-authentication codes. Following this line, an algebraic-curves-based ε-authentication code yields a new HLA scheme.
Shuai Han 0001, Shengli Liu 0001, Fangguo Zhang, Kefei Chen
AsiaCCS3
2016 Memory leakage-resilient searchable symmetric encryption
Shuguang Dai, Huige Li, Fangguo Zhang
Future Gener. Comput. Syst.3
2016 Solutions to the anti-piracy problem in oblivious transfer
Fangguo Zhang, Willy Susilo, Yamin Wen
J. Comput. Syst. Sci.2
2016 A lattice-based partially blind signature
abstract
Abstract Blind signature is a crucial technique to provide anonymity in many information systems such as e‐cash, e‐voting, and smart grid systems. Partially blind signature is a more applicable extension where the part of the message includes some common information known by the signer and the signature requestor. In the family of lattice‐based schemes, blind signatures are given in ASIACRYPT 2010 by R ckert in the random oracle model, and until now, no partially blind signatures are given. We here design the first scheme based on Lyubashevsky's signature scheme in EUROCRYPT 2012 and Abe and Okamoto's construction of partially blind signature in CRYPTO 2000 in the random oracle model. The scheme shows an alternative approach to achieve the blindness property without the supports of a commitment scheme and of a final round communication to confirm the validity of a signature. Copyright © 2016 John Wiley & Sons, Ltd.
Haibo Tian, Fangguo Zhang, Baodian Wei
Secur. Commun. Networks2
2015 Verifiable Searchable Symmetric Encryption from Indistinguishability Obfuscation
abstract
Searchable symmetric encryption (SSE) allows a client to encrypt his data in such a manner that the data can be efficiently searched. SSE has practical application in cloud storage, where a client outsources his encrypted data to a cloud server while maintaining the searchable ability over his data. Most of the current SSE schemes assume that the cloud server is honest-but-curious. However, the cloud may actively cheat on the search process to keep its cost low. In this paper, we focus on the malicious cloud model and propose a new verifiable searchable symmetric encryption scheme. Our scheme is built on the secure indistinguishability obfuscation (iO) and can be considered as the first step to apply iO in the SSE field. Moreover, our scheme can be easily extended to multiple functionalities, such as conjunctive and boolean queries. Furthermore, it can be extended to realize a publicly verifiable SSE. Thorough analysis shows that our scheme is secure and achieves a better performance.
Rong Cheng, Jingbo Yan, Chaowen Guan, Fangguo Zhang, Kui Ren 0001
AsiaCCS4
2015 Secure Bilinear Pairing Outsourcing Made More Efficient and Flexible
abstract
The increasing availability of cloud computing allows more and more mobile devices to outsource expensive computations. Among these computations, bilinear pairing is very fundamental and frequently-used by many modern cryptographic protocols. Currently, the most efficient outsourcing algorithm of bilinear pairings requires about 5 point additions in G1 and G2 and 4 multiplications in GT under the one-malicious version of a two-untrusted-program assumption. And the result of the algorithm is checkable with a probability about 1/2. In this paper, we improve the state-of-the-art by proposing two new outsourcing algorithms for bilinear pairings. One is a more efficient outsourcing algorithm under the same assumption with the same checkability. The other is more flexible under a two-untrusted-program assumption with improved checkability. Both algorithms are better suited to various applications where on-line computations are strictly limited due to the lack of available computing resources.
Haibo Tian, Fangguo Zhang, Kui Ren 0001
AsiaCCS2
2015 Symmetric-Key Based Proofs of Retrievability Supporting Public Verification
abstract
Proofs-of-Retrievability enables a client to store his data on a cloud server so that he executes an efficient auditing protocol to check that the server possesses all of his data in the future. During an audit, the server must maintain full knowledge of the client’s data to pass, even though only a few blocks of the data need to be accessed. Since the first work by Juels and Kaliski, many PoR schemes have been proposed and some of them can support dynamic updates. However, all the existing works that achieve public verifiability are built upon traditional public-key cryptosystems which imposes a relatively high computational burden on low-power clients (e.g., mobile devices). In this work we explore indistinguishability obfuscation for building a Proof-of-Retrievability scheme that provides public verification while the encryption is based on symmetric key primitives. The resulting scheme offers light-weight storing and proving at the expense of longer verification. This could be useful in apations where outsourcing files is usually done by low-power client and verifications can be done by well equipped machines (e.g., a third party server). We also show that the proposed scheme can support dynamic updates. At last, for better assessing our proposed scheme, we give a performance analysis of our scheme and a comparison with several other existing schemes which demonstrates that our scheme achieves better performance on the data owner side and the server side.
Chaowen Guan, Kui Ren 0001, Fangguo Zhang, Florian Kerschbaum, Jia Yu 0003
ESORICS (1)3
2015 Memory leakage-resilient secret sharing schemes
Shuguang Dai, Jinfeng Wei, Fangguo Zhang
Sci. China Inf. Sci.3
2015 Obfuscation for multi-use re-encryption and its application in cloud computing
abstract
Summary With the rapid development of cloud computing, more and more data are being centralized into cloud server for sharing. It is a challenge problem on how to keep them both private and accessible. Re‐encryption function is a useful tool to fulfill secure cloud computing. Cloud data owners store their encrypted data on the cloud server. When other cloud users want to share the cloud data, cloud server can re‐encrypt the encrypted data for them. So data on the cloud server can be both accessible and private. Secure obfuscation for re‐encryption function can hide all the private information in the re‐encryption function, so the obfuscated program can be directly outsourced to cloud server without leaking anything about the computation task. In this paper, we study on secure obfuscation for three kinds of new re‐encryption functions: multi‐use re‐encryption, conditional re‐encryption with keyword search, and broadcast re‐encryption. We utilize the obfuscated results as tools to fulfill secure cloud computing. Cloud‐computing schemes based on obfuscation have better security compared with other tools. Copyright © 2014 John Wiley & Sons, Ltd.
Rong Cheng, Fangguo Zhang
Concurr. Comput. Pract. Exp.2
2015 Lattice-based obfuscation for re-encryption functions
abstract
Abstract Program obfuscation is a compiler that transfers a program into an unintelligible form while preserving the original functionality. Secure obfuscation for several particular function families has been raised out despite the general impossibility result presented by Barak et al. Re‐encryption function is a useful primitive, which transforms ciphertexts for one party into ciphertexts under another party's public key. Hohenberger et al. constructed a special re‐encryption function and securely obfuscated it in TCC'07, and the security is based on classical hardness assumption. In this paper, we construct a new re‐encryption function and securely obfuscate it based on the standard learning with error (LWE) assumption. LWE is proved to be reducible to standard lattice problems, which are conjectured immune to quantum cryptanalysis or ‘post‐quantum’. Besides, we discuss about the relations between these two cryptographic primitives in detail: proxy re‐encryption and obfuscation for re‐encryption functions. Copyright © 2014 John Wiley & Sons, Ltd.
Rong Cheng, Fangguo Zhang
Secur. Commun. Networks2
2014 Identity Based Threshold Ring Signature from Lattices
Baodian Wei, Yusong Du, Fangguo Zhang, Haibo Tian, Chong-zhi Gao
NSS4
2014 Secure linear system computation in the presence of malicious adversaries
Bo Zhang 0072, Fangguo Zhang
Sci. China Inf. Sci.2
2014 Public-key encryption scheme with selective opening chosen-ciphertext security based on the Decisional Diffie-Hellman assumption
abstract
SUMMARY Chosen‐ciphertext security has been well‐accepted as a standard security notion for public‐key encryption. But in a multi‐user surrounding, it may not be sufficient, because the adversary may corrupt some users to obtain the random coins as well as the plaintexts used to generate ciphertexts. The attack is named ‘selective opening attack’. We study how to achieve full‐fledged chosen‐ciphertext security in selective opening setting directly from the Decisional Diffie–Hellman assumption. Our construction is actually a tag‐based public‐key encryption scheme free of chameleon hashing and has a tight security reduction to the Decisional Diffie–Hellman assumption and the collision‐resistant assumption of hash functions. The tag for each ciphertext is generated in a flexible way to serve the chosen‐ciphertext security proof in selective opening settings. Copyright © 2013 John Wiley & Sons, Ltd.
Shengli Liu 0001, Fangguo Zhang, Kefei Chen
Concurr. Comput. Pract. Exp.2
2014 Secure similarity coefficients computation for binary data and its extensions
abstract
SUMMARY Similarity measures play an important role in classification problems, cluster analysis, and identification issues. This paper studies the secure similarity coefficients computation in the two‐party setting. Recently, a privacy‐preserving similarity coefficients protocol for binary data was proposed by Wong and Kim (Computers and Mathematics with Application 2012). We point out that their protocol is not secure, even in the semi‐honest model. In their protocol, the client can retrieve the inputs of the server without deviating from the protocol. Next, we propose a secure similarity coefficients computation protocol in the presence of malicious adversaries, which solves the same similarity coefficients functionality as that proposed by Wong and Kim. Meanwhile, we prove the protocol secure against the malicious adversaries by using the standard simulation‐based security definitions for secure two‐party computation. Also several extensions of our protocol for settling other specific problems are discussed. At last, we present a protocol computing the similarity coefficients with better privacy by using the secure integer division on ciphertexts. Copyright © 2013 John Wiley & Sons, Ltd.
Bo Zhang 0072, Fangguo Zhang
Concurr. Comput. Pract. Exp.2
2014 Identity-based chameleon hashing and signatures without key exposure
Xiaofeng Chen 0001, Fangguo Zhang, Willy Susilo, Haibo Tian, Jin Li 0002, Kwangjo Kim
Inf. Sci.2
2014 Efficient computation outsourcing for inverting a class of homomorphic functions
Fangguo Zhang, Shengli Liu 0001
Inf. Sci.1
2014 Timed-release oblivious transfer
abstract
We study a variant of oblivious transfer, we called timed-release oblivious transfer that permits a sender to restrict when each receiver may open his chosen messages, without learning anything about the receiver's message choices. To achieve this functionality, we import a time server into the protocol that broadcasts a time token periodically and needs neither to interact with the sender nor the receiver. In our generic construction for the protocol, a primitive called verifiably ID-based encrypted blind signature is introduced as a basic building block. We also present a concrete scheme for the protocol's generic construction. Copyright © 2013 John Wiley & Sons, Ltd.
Fangguo Zhang, Shaohua Tang
Secur. Commun. Networks2
2013 Security Model and Analysis of FHMQV, Revisited
Shengli Liu 0001, Kouichi Sakurai, Jian Weng 0001, Fangguo Zhang, Yunlei Zhao
Inscrypt4
2013 Selectively unforgeable but existentially forgeable signature schemes and applications
Haibo Tian, Fangguo Zhang, Xiaofeng Chen 0001, Baodian Wei
Sci. China Inf. Sci.2
2013 Speeding up elliptic curve discrete logarithm computations with point halving
Fangguo Zhang, Ping Wang 0005
Des. Codes Cryptogr.1
2012 Zero-Value Point Attacks on Kummer-Based Cryptosystem
Fangguo Zhang, Qiping Lin, Shengli Liu 0001
ACNS1
2012 Selective Opening Chosen Ciphertext Security Directly from the DDH Assumption
Shengli Liu 0001, Fangguo Zhang, Kefei Chen
NSS2
2012 Tracing and revoking scheme for dynamic privileges against pirate rebroadcast
Xingwen Zhao, Fangguo Zhang
Comput. Secur.2
2012 Efficient precomputation schemes of kP+IQ
Qiping Lin, Fangguo Zhang
Inf. Process. Lett.2
2012 Generic security-amplifying methods of ordinary digital signatures
Jin Li 0002, Fangguo Zhang, Xiaofeng Chen 0001, Kwangjo Kim, Duncan S. Wong
Inf. Sci.2
2012 Computing elliptic curve discrete logarithms with the negation map
Ping Wang 0005, Fangguo Zhang
Inf. Sci.2
2012 Fully CCA2 secure identity-based broadcast encryption with black-box accountable authority
Xingwen Zhao, Fangguo Zhang
J. Syst. Softw.2
2012 Faster Computation of Self-Pairings
abstract
Self-pairings have found interesting applications in cryptographic schemes. In this paper, we present a novel method for constructing a self-pairing on supersingular elliptic curves with even embedding degrees, which we call the Ateil pairing. This new pairing improves the efficiency of the self-pairing computation on supersingular curves over finite fields with large characteristic. Based on the ηTpairing, we propose a generalization of the Ateil pairing, which we call the Ateilipairing. The optimal Ateilipairing which has the shortest Miller loop is faster than previously known self-pairings on supersingular elliptic curves over finite fields with small characteristic. We also present a new self-pairing based on the Weil pairing which is faster than the self-pairing based on the Tate pairing on ordinary elliptic curves with embedding degreeone.
Changan Zhao, Fangguo Zhang, Dongqing Xie
IEEE Trans. Inf. Theory2
2011 Finding More Boolean Functions with Maximum Algebraic Immunity Based on Univariate Polynomial Representation
Yusong Du, Fangguo Zhang
ACISP2
2011 Two Applications of an Incomplete Additive Character Sum to Estimating Nonlinearity of Boolean Functions
Yusong Du, Fangguo Zhang
ICICS2
2011 Traitor Tracing against Public Collaboration
Xingwen Zhao, Fangguo Zhang
ISPEC2
2011 Secure Obfuscation of Encrypted Verifiable Encrypted Signatures
Rong Cheng, Bo Zhang 0072, Fangguo Zhang
ProvSec3
2011 Dynamic asymmetric group key agreement for ad hoc networks
Xingwen Zhao, Fangguo Zhang, Haibo Tian
Ad Hoc Networks2
2011 Computing bilinear pairings on elliptic curves with automorphisms
Changan Zhao, Dongqing Xie, Fangguo Zhang, Binglong Chen
Des. Codes Cryptogr.3
2011 New receipt-free voting scheme using double-trapdoor commitment
Xiaofeng Chen 0001, Qianhong Wu, Fangguo Zhang, Haibo Tian, Baodian Wei, Byoungcheon Lee, Hyunrok Lee, Kwangjo Kim
Inf. Sci.3
2011 An efficient public key encryption with conjunctive-subset keywords search
Bo Zhang 0072, Fangguo Zhang
J. Netw. Comput. Appl.2
2011 Oblivious transfer with timed-release receiver's privacy
Fangguo Zhang
J. Syst. Softw.3
2011 Delegatable secret handshake scheme
Yamin Wen, Fangguo Zhang
J. Syst. Softw.2
2011 Identity-based trapdoor mercurial commitments and applications
Xiaofeng Chen 0001, Willy Susilo, Fangguo Zhang, Haibo Tian, Jin Li 0002
Theor. Comput. Sci.3
2010 Identity-Based Chameleon Hash Scheme without Key Exposure
Xiaofeng Chen 0001, Fangguo Zhang, Willy Susilo, Haibo Tian, Jin Li 0002, Kwangjo Kim
ACISP2
2010 Comments and Improvements on Key-Exposure Free Chameleon Hashing Based on Factoring
Xiaofeng Chen 0001, Haibo Tian, Fangguo Zhang, Yong Ding 0005
Inscrypt3
2010 Twisted Ate pairing on hyperelliptic curves and applications
Fangguo Zhang
Sci. China Inf. Sci.1
2009 Cryptanalysis and improvement of an ID-based ad-hoc anonymous identification scheme at CT-RSA 05
Fangguo Zhang, Xiaofeng Chen 0001
Inf. Process. Lett.1
2008 Generic Security-Amplifying Methods of Ordinary Digital Signatures
Jin Li 0002, Kwangjo Kim, Fangguo Zhang, Duncan S. Wong
ACNS3
2008 Efficient designated confirmer signature from bilinear pairings
abstract
Designated confirmer signature is an important cryptographic primitive, it is widely used in E-commerce. In this paper, we propose a new designated confirmer signature scheme which is transformed from a new signature scheme. The proposed scheme has very simple construction and is much more efficient than the previous ones and does not need any commitment scheme or strong witness hiding proofs.
Fangguo Zhang, Xiaofeng Chen 0001, Baodian Wei
AsiaCCS1
2008 Efficient Tate pairing computation using double-base chains
Changan Zhao, Fangguo Zhang, Jiwu Huang
Sci. China Ser. F Inf. Sci.2
2008 Efficient generic on-line/off-line (threshold) signatures without key exposure
Xiaofeng Chen 0001, Fangguo Zhang, Haibo Tian, Baodian Wei, Willy Susilo, Yi Mu 0001, Hyunrok Lee, Kwangjo Kim
Inf. Sci.2
2008 Forgeability of Wang-Tang-Li's ID-Based Restrictive Partially Blind Signature Scheme
Shengli Liu 0001, Xiaofeng Chen 0001, Fangguo Zhang
J. Comput. Sci. Technol.3
2007 Efficient Generic On-Line/Off-Line Signatures Without Key Exposure
Xiaofeng Chen 0001, Fangguo Zhang, Willy Susilo, Yi Mu 0001
ACNS2
2007 Efficient Partially Blind Signatures with Provable Security
Qianhong Wu, Willy Susilo, Yi Mu 0001, Fangguo Zhang
ICCSA (3)4
2007 ID-based Ring Proxy Signatures
abstract
In this paper, by combining the functionalities of proxy signatures and ring signatures, we propose a new concept, named ring proxy signature, which is a proxy signature generated by an anonymous member from a set of potential signers. We construct two ID-based ring proxy signature schemes. The security analysis is provided as well.
Baodian Wei, Fangguo Zhang, Xiaofeng Chen 0001
ISIT2
2007 Aggregate Proxy Signature and Verifiably Encrypted Proxy Signature
Jin Li 0002, Kwangjo Kim, Fangguo Zhang, Xiaofeng Chen 0001
ProvSec3
2007 ID-based restrictive partially blind signatures and applications
Xiaofeng Chen 0001, Fangguo Zhang, Shengli Liu 0001
J. Syst. Softw.2
2006 Efficient Signcryption Without Random Oracles
Qianhong Wu, Yi Mu 0001, Willy Susilo, Fangguo Zhang
ATC4
2006 Efficient Partially Blind Signatures with Provable Security
Qianhong Wu, Willy Susilo, Yi Mu 0001, Fangguo Zhang
ICCSA (3)4
2006 Privately Retrieve Data from Large Databases
Qianhong Wu, Yi Mu 0001, Willy Susilo, Fangguo Zhang
ISPEC4
2005 Group Signature Where Group Manager, Members and Open Authority Are Identity-Based
Victor K.-W. Wei, Tsz Hon Yuen, Fangguo Zhang
ACISP3
2005 Privacy-Enhanced Internet Storage
abstract
One of the main important uses of Internet is its ability to connect people through the use of email or Internet storage. However, it is often desirable to limit the use of email or Internet storage clue to organization's restriction, avoiding spams, etc. In this paper, we propose cryptographic schemes that can be used to stop unwanted messages to be stored in the Internet server. We refer this technique as privacy enhancement for Internet storage, since the Internet server will not learn any information directed to its users, other than performing its task to deliver or stop the messages. Firstly, we describe a notion of non-interactive publicly verifiable 1-out-of-n encryption by proposing a model together with its security requirements. Then, we extend this notion to a publicly verifiable ring-to-1-out-of-n encryption, that provides sender anonymity. We note that the previously known interactive versions of the publicly verifiable 1-out-of-n encryption cannot be used to construct publicly verifiable ring-to-1-out-of-n encryption.
Willy Susilo, Fangguo Zhang, Yi Mu 0001
AINA2
2005 Reducing Security Overhead for Mobile Networks
abstract
Security of mobile communications comes with the cost of computational overhead. Reducing the overhead in security computations is critical to ensure the overall performance of a mobile network. In this paper, we present the notion of online/offline signcryption, where most of computations are carried out offline and the online part of our scheme does not require any exponent computations and therefore is very efficient. Our scheme allows any third party to verify the encryption without compromising confidentiality. We also show that our scheme is secure against existential forgery under chosen message attacks and adaptively chosen ciphertext attacks under the notion of indistinguishability of ciphertext.
Fangguo Zhang, Yi Mu 0001, Willy Susilo
AINA1
2005 Cryptanalysis of Huang-Chang partially blind signature scheme
Fangguo Zhang, Xiaofeng Chen 0001
J. Syst. Softw.1
2004 Identity-Based Strong Designated Verifier Signature Schemes
Willy Susilo, Fangguo Zhang, Yi Mu 0001
ACISP2
2004 Limited Verifier Signature from Bilinear Pairings
Xiaofeng Chen 0001, Fangguo Zhang, Kwangjo Kim
ACNS2
2004 Perfect Concurrent Signature Schemes
Willy Susilo, Yi Mu 0001, Fangguo Zhang
ICICS3
2004 Chameleon Hashing Without Key Exposure
Xiaofeng Chen 0001, Fangguo Zhang, Kwangjo Kim
ISC2
2004 Attack on an ID-based authenticated group key agreement scheme from PKC 2004
Fangguo Zhang, Xiaofeng Chen 0001
Inf. Process. Lett.1
2004 Authenticating Tripartite Key Agreement Protocol with Pairings
Shengli Liu 0001, Fangguo Zhang, Kefei Chen
J. Comput. Sci. Technol.2
2003 Efficient ID-Based Blind Signature and Proxy Signature from Bilinear Pairings
Fangguo Zhang, Kwangjo Kim
ACISP1
2003 New traitor tracing schemes using bilinear map
abstract
Mitsunari et al [15] presented a new traitor tracing scheme which uses Weil pairing in elliptic curves. To the best of our knowledge this is the first scheme that uses bilinear map. The claimed advantage of the scheme is that the ciphertext size is independent of the number of traitors. It is shown that the problem of constructing a pirate key by k colluders is as hard as the so-called k-weak Diffie-Hellman problem.In this paper, we show an attack on this scheme in which traitors find a linear combination of their keys to construct a pirate key that can be used to decrypt the ciphertext. We identify a class of schemes, that includes MSK, with the property that correct tracing requires the ciphertext size to depend on the collusion threshold. We derive a lower bound on the size of the ciphertext that depends on the number of colluders.We propose a modification to MSK scheme, Scheme 1, which not only ensures constructing a pirate decoder is hard, but also has a number of significant advantages over the initial proposal. In particular, it is a public key traitor tracing scheme while the original scheme is a secret key traitor tracing scheme; it has a black box tracing algorithm while MSK scheme only has an open box tracing algorithm, and finally its security is provable (semantic secure against passive adversary) while there was no security proof for MSK.We also propose two other schemes based on bilinear pairing. Scheme~2, is a generic scheme and can be used with any linear error correcting code. Scheme~3 uses Shamir's secret sharing scheme and has the added property that the encrypted message can be targeted to a subset of users. This is by including user revocation property and allowing selected users to be revoked from the original set of users. We also give proof of security, similar to Scheme 1, and also a tracing algorithm for the two schemes. Finally we give an efficiency comparison for the three schemes against the most efficient schemes with similar security and traceability properties and show that all three schemes are the most efficient ones of their kind.
Vu Dong Tô, Reihaneh Safavi-Naini, Fangguo Zhang
Digital Rights Management Workshop3
2003 ID-Based Distributed "Magic Ink" Signature from Pairings
Fangguo Zhang, Xiaofeng Chen 0001, Kwangjo Kim
ICICS2
2003 Secure Web Transaction with Anonymous Mobile Agent over Internet
Changjie Wang, Fangguo Zhang, Yumin Wang
J. Comput. Sci. Technol.2
2002 Compact Representation of Domain Parameters of Hyperelliptic Curve Cryptosystems
Fangguo Zhang, Shengli Liu 0001, Kwangjo Kim
ACISP1
2002 ID-Based Blind Signature and Ring Signature from Pairings
Fangguo Zhang, Kwangjo Kim
ASIACRYPT1
2002 Selection of Secure Hyperelliptic Curves of g_2 Based on a Subfield
Fangguo Zhang, Futai Zhang, Yumin Wang
J. Comput. Sci. Technol.1
2001 Fast Scalar Multiplication on the Jacobian of a Family of Hyperelliptic Curves
Fangguo Zhang, Futai Zhang, Yumin Wang
ICICS1
2000 Fair Electronic Cash Systems with Multiple Banks
Fangguo Zhang, Futai Zhang, Yumin Wang
SEC1