VLDB 2026 Research / reviewers in the wild / expert
Yanjiang Yang
dblp:55/2303
· DBLP profile ↗
63ranked-venue papers
37as first author
2since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 45 · 28 first-author · 2 since 2021Computer networks · 4 · 1 first-authorDatabases, data management, data science and information retrieval · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 2 first-authorGraphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2 · 2 first-authorTheory of computation · 2Artificial intelligence and machine learning · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Ramp Hyper-invertible Matrices and Their Applications to MPC Protocols
Hongqing Liu 0005, Chaoping Xing, Yanjiang Yang, Chen Yuan 0003 |
ASIACRYPT (1) | 3 |
| 2021 | Stochastic Workflow Authorizations With Queueing ConstraintsabstractCloud-based workflow architecture has been widely used in e-science, e-business, smart city, and others, to automate business processes and improve their flexibility and maintainability. Online workflow executes in a collaborative and distributed environment and is prone to fraud and information leakage. Workflow authorization models are implemented to ensure that tasks are performed by authorized subjects with compliance of security/privacy polices. However, existing workflow authorization models have some limitations. First, most of the existing research focuses on static workflows, where an order arriving at a workflow traverses tasks in a fixed sequence. In many real applications, however, task routing is not deterministic, having a probability distribution or pattern that may be estimated from historical data. Second, existing research ignores practical resource constraints, like user utilization, order waiting time, etc. To address the limitations, this article studies the workflow authorization model under the more realistic dynamic settings. We formulate a workflow as a queueing system, so business constraints can be analytically represented, under reasonable assumptions. We model the studied problems as pseudo-Boolean satisfiaiblity problems and investigate their theoretical properties. We also develop algorithms and carry out computational studies. The experimental results show the effectiveness and efficiency of our developed solutions. Our research results are useful for production and process design in many real-life settings such as health care, online banking and electronic payment systems. Haibing Lu, Xi Chen 0014, Michele Samorani, Guojie Song, Yanjiang Yang |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2019 | On Data Sovereignty in Cloud-Based Computation Offloading for Smart Cities ApplicationsabstractSmart city applications are increasingly popular due to their potential to improve quality of life in an urbanized society, and such applications typically leverage on cloud computing for data and computation offloading from the sensing infrastructure. Despite the capability of achieving scalability and flexibility, the use of cloud computing imposes inherent security and privacy concerns regarding data analysis and exchange, as well as legal implications. For example, data in a smart city application being outsourced to the cloud and/or exchanged among sensing devices may be accessible to users located in a different jurisdiction or subsequently reside in a data center in a different jurisdiction. There may be conflicting privacy protection and disclosure laws among these jurisdictions/locations; thus, limiting the widespread adoption of smart city applications. Restricting the data flow for such applications is not viable since it may cause inefficiencies, although there are situations requiring to limit the data access to selected geographical locations. Therefore, we propose addressing this issue by using a location-dependent cryptographic approach, and we integrate such an approach within the context of cloud-based smart city applications. Christian Esposito 0001, Aniello Castiglione, Flavio Frattini, Marcello Cinque, Yanjiang Yang, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 5 |
| 2018 | AutoPrivacy: Automatic privacy protection and tagging suggestion for mobile social photo
Zhuo Wei, Yongdong Wu, Yanjiang Yang, Zheng Yan 0002, Qingqi Pei, Yajuan Xie, Jian Weng 0001 |
Comput. Secur. | 3 |
| 2017 | Towards Revocable Fine-Grained Encryption of Cloud Data: Reducing Trust upon Cloud
Yanjiang Yang, Joseph K. Liu, Zhuo Wei, Xinyi Huang 0001 |
ACISP (1) | 1 |
| 2017 | IoVShield: An Efficient Vehicular Intrusion Detection System for Self-driving (Short Paper)
Zhuo Wei, Yanjiang Yang, Rehana Yasmin, Yongdong Wu, Jian Weng 0001, Robert H. Deng |
ISPEC | 2 |
| 2017 | Efficient outsourcing of secure k-nearest neighbour query over encrypted database
Rui Xu 0006, Kirill Morozov, Yanjiang Yang, Jianying Zhou 0001, Tsuyoshi Takagi |
Comput. Secur. | 3 |
| 2017 | Secure server-aided top-k monitoring
HweeHwa Pang, Yanjiang Yang, Xuhua Ding |
Inf. Sci. | 3 |
| 2017 | V2X security: A case study of anonymous authentication
Yanjiang Yang, Zhuo Wei, Youcheng Zhang, Haibing Lu, Kim-Kwang Raymond Choo, Haibin Cai |
Pervasive Mob. Comput. | 1 |
| 2016 | Privacy-Preserving k-Nearest Neighbour Query on Outsourced Database
Rui Xu 0006, Kirill Morozov, Yanjiang Yang, Jianying Zhou 0001, Tsuyoshi Takagi |
ACISP (1) | 3 |
| 2016 | Towards Lightweight Anonymous Entity Authentication for IoT Applications
Yanjiang Yang, Haibin Cai, Zhuo Wei, Haibing Lu, Kim-Kwang Raymond Choo |
ACISP (1) | 1 |
| 2016 | Credential Wrapping: From Anonymous Password Authentication to Anonymous Biometric AuthenticationabstractThe anonymous password authentication scheme proposed in ACSAC'10 under an unorthodox approach of password wrapped credentials advanced anonymous password authentication to be a practically ready primitive, and it is being standardized. In this paper, we improve on that scheme by proposing a new method of "public key suppression" for achieving server-designated credential verifiability, a core technicality in materializing the concept of password wrapped credential. Besides better performance, our new method simplifies the configuration of the authentication server, rendering the resulting scheme even more practical. Further, we extend the idea of password wrapped credential to biometric wrapped credential}, to achieve anonymous biometric authentication. As expected, biometric wrapped credentials help break the linear server-side computation barrier intrinsic in the standard setting of biometric authentication. Experimental results validate the feasibility of realizing efficient anonymous biometric authentication. Yanjiang Yang, Haibing Lu, Joseph K. Liu, Jian Weng 0001, Youcheng Zhang, Jianying Zhou 0001 |
AsiaCCS | 1 |
| 2016 | Authenticated CAN Communications Using Standardized Cryptographic Techniques
Zhuo Wei, Yanjiang Yang, Tieyan Li |
ISPEC | 2 |
| 2016 | Cloud based data sharing with fine-grained proxy re-encryption
Yanjiang Yang, Haiyan Zhu, Haibing Lu, Jian Weng 0001, Youcheng Zhang, Kim-Kwang Raymond Choo |
Pervasive Mob. Comput. | 1 |
| 2015 | Extended Proxy-Assisted Approach: Achieving Revocable Fine-Grained Encryption of Cloud Data
Yanjiang Yang, Joseph K. Liu, Kaitai Liang, Kim-Kwang Raymond Choo, Jianying Zhou 0001 |
ESORICS (2) | 1 |
| 2015 | Towards user-oriented RBAC modelabstractRole mining is to define a role set to implement the role-based access control (RBAC) system and regarded as one of the most important and costliest implementation phases. While various role mining models have been proposed, we find that user experience/perception – one ultimate goal for any information system – is surprisingly ignored by the existing works. One advantage of RBAC is to support multiple role assignments and allow a user to activate the necessary role to perform the tasks at each session. However, frequent role activating and deactivating can be a tendinous thing from the user perspective. A user-friendly RBAC system is expected to assign few roles to every user. So in this paper we propose to incorporate to the role mining process a user-role assignment constraint that mandates the maximum number of roles each user can have. Under this rationale, we formulate user-oriented role mining as the user role mining problem, where all users have the same maximal role assignments, the personalized role mining problem, where users can have different maximal role assignments, and the approximate versions of the two problems, which tolerate a certain amount of deviation from the complete reconstruction. The extra constraint on the maximal role assignments poses a great challenge to role mining, which in general is already a hard problem. We examine some typical existing role mining methods to see their applicability to our problems. In light of their insufficiency, we present a new algorithm, which is based on a novel dynamic candidate role generation strategy, tailored to our problems. Experiments on benchmark data sets demonstrate the effectiveness of our proposed algorithm. Haibing Lu, Yuan Hong 0001, Yanjiang Yang, Nazia Badar |
J. Comput. Secur. | 3 |
| 2015 | A note on the security of KHL scheme
Jian Weng 0001, Yunlei Zhao, Robert H. Deng, Shengli Liu 0001, Yanjiang Yang, Kouichi Sakurai |
Theor. Comput. Sci. | 5 |
| 2014 | Dynamic Workflow Adjustment with Security Constraints
Haibing Lu, Yuan Hong 0001, Yanjiang Yang, Yi Fang 0008 |
DBSec | 3 |
| 2014 | Fine-Grained Conditional Proxy Re-Encryption and Application
Yanjiang Yang, Haibing Lu, Jian Weng 0001, Youcheng Zhang, Kouichi Sakurai |
ProvSec | 1 |
| 2013 | Towards User-Oriented RBAC Model
Haibing Lu, Yuan Hong 0001, Yanjiang Yang, Nazia Badar |
DBSec | 3 |
| 2013 | Self-blindable Credential: Towards Anonymous Entity Authentication Upon Resource Constrained Devices
Yanjiang Yang, Xuhua Ding, Haibing Lu, Jian Weng 0001, Jianying Zhou 0001 |
ISC | 1 |
| 2013 | Achieving Revocable Fine-Grained Cryptographic Access Control over Cloud Data
Yanjiang Yang, Xuhua Ding, Haibing Lu, Zhiguo Wan, Jianying Zhou 0001 |
ISC | 1 |
| 2013 | Adaptable Ciphertext-Policy Attribute-Based Encryption
Junzuo Lai, Robert H. Deng, Yanjiang Yang, Jian Weng 0001 |
Pairing | 3 |
| 2012 | A Generic Approach for Providing Revocation Support in Secret Handshake
Yanjiang Yang, Haibing Lu, Jian Weng 0001, Xuhua Ding, Jianying Zhou 0001 |
ICICS | 1 |
| 2011 | Towards Multi-user Private Keyword Search for Cloud ComputingabstractStorage-as-a-service is an essential component of the cloud computing infrastructure. Database outsourcing is a typical use scenario of the cloud storage services, wherein data encryption is a good approach enabling the data owner to retain its control over the outsourced data. Searchable encryption is a cryptographic primitive allowing for private keyword based search over the encrypted database. The setting of enterprise outsourcing database to the cloud requires multi-user searchable encryption, whereas virtually all existing schemes consider the single-user setting. To bridge this gap, we propose a practical multi-user searchable encryption scheme, which has a number of advantages over the known approaches. Yanjiang Yang |
IEEE CLOUD | 1 |
| 2011 | Multi-User Private Keyword Search for Cloud ComputingabstractEnterprises outsourcing their databases to the cloud and authorizing multiple users for access represents a typical use scenario of cloud storage services. In such a case of database outsourcing, data encryption is a good approach enabling the data owner to retain its control over the outsourced data. Searchable encryption is a cryptographic primitive allowing for private keyword based search over the encrypted database. The above setting of enterprise outsourcing database to the cloud requires multi-user searchable encryption, whereas virtually all of the existing schemes consider the single-user setting. To bridge this gap, we are motivated to propose a practical multi-user searchable encryption scheme, which has a number of advantages over the known approaches. The associated model and security requirements are also formulated. We further discuss to extend our scheme in several ways so as to achieve different search capabilities. Yanjiang Yang, Haibing Lu, Jian Weng 0001 |
CloudCom | 1 |
| 2011 | Cryptanalysis of an identity based broadcast encryption scheme without random oracles
Xu An Wang 0014, Jian Weng 0001, Xiaoyuan Yang 0002, Yanjiang Yang |
Inf. Process. Lett. | 4 |
| 2011 | Better security enforcement in trusted computing enabled heterogeneous wireless sensor networksabstractAbstract A wireless sensor network (WSN) is anad hocwireless network composed of a large number of small sensor nodes. Sensor nodes are usually severely resource limited and power constrained, and as such security enforcement in WSNs is a challenging task. To facilitate security enforcement, we propose a heterogeneous architecture for WSNs, where a WSN is partitioned into clusters, each having a high‐end cluster head. The cluster heads are further equipped with trusted computing technology (TC), such that they act as online trusted parties, thereby expected to help enforce security in a more effective manner. To show this, we discuss various examples on both content security and context security. Copyright © 2010 John Wiley & Sons, Ltd. Yanjiang Yang, Jianying Zhou 0001, Robert H. Deng, Feng Bao 0001 |
Secur. Commun. Networks | 1 |
| 2011 | Database Access Pattern Protection Without Full-ShufflesabstractPrivacy protection is one of the fundamental security requirements for database outsourcing. A major threat is information leakage from database access patterns generated by query executions. The standard private information retrieval (PIR) schemes, which are widely regarded as theoretical solutions, entailO(n) computational overhead per query for a database withnitems. Recent works propose to protect access patterns by introducing a trusted component with constant storage size. The resulting privacy assurance is as strong as PIR, though withO(1) online computation cost, they still haveO(n) amortized cost per query due to periodically full database shuffles. In this paper, we design a novel scheme in the same model with provable security, which only shuffles a portion of the database. The amortized server computational complexity is reduced toO(√{nlogn/k}). With a secure storage storing thousands of items, our scheme can protect the access pattern privacy of databases of billions of entries, at a lower cost than those using ORAM-based poly-logarithm algorithms. Xuhua Ding, Yanjiang Yang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2010 | Towards practical anonymous password authenticationabstractThe conventional approach for anonymous password authentication incurs O(N) server computation, linear to the total number of users. In ACSAC'09, Yang et al. proposed a new approach for anonymous password authentication, breaking this lower bound. However, Yang et al.'s scheme has not considered membership withdrawal and online guessing attacks, two issues must be addressed before anonymous password authentication is acceptable for practical use. Thus our main thrust in this work is to provide solutions to these issues. We do not just work upon Yang et al.'s scheme; rather, we use a set of different primitives, and as a result, our scheme has much better performance. We prove the security of our scheme. Furthermore, we empirically evaluate the efficiency of our scheme, and implement a proof-of-concept prototype. Yanjiang Yang, Jianying Zhou 0001, Jun Wen Wong, Feng Bao 0001 |
ACSAC | 1 |
| 2010 | Privacy Disclosure Analysis and Control for 2D Contingency Tables Containing Inaccurate Data
Kevin Chiew, Yingjiu Li, Yanjiang Yang |
Privacy in Statistical Databases | 4 |
| 2010 | CCA-secure unidirectional proxy re-encryption in the adaptive corruption model without random oracles
Jian Weng 0001, Min-Rong Chen, Yanjiang Yang, Robert H. Deng, Kefei Chen, Feng Bao 0001 |
Sci. China Inf. Sci. | 3 |
| 2010 | Shifting Inference Control to User Side: Architecture and ProtocolabstractInference has been a longstanding issue in database security, and inference control, aiming to curb inference, provides an extra line of defense to the confidentiality of databases by complementing access control. However, in traditional inference control architecture, database server is a crucial bottleneck, as it enforces highly computation-intensive auditing for all users who query the protected database. As a result, most auditing methods, though rigorously studied, are not practical for protecting large-scale real-world database systems. In this paper, we shift this paradigm by proposing a new inference control architecture, entrusting inference control to each user's platform that is equipped with trusted computing technology. The trusted computing technology is designed to attest the state of a user's platform to the database server, so as to assure the server that inference control could be enforced as prescribed. A generic protocol is proposed to formalize the interactions between the user's platform and database server. The authentication property of the protocol is formally proven. Since inference control is enforced in a distributed manner, our solution avoids the bottleneck in the traditional architecture, thus can potentially support a large number of users making queries. Yanjiang Yang, Yingjiu Li, Robert H. Deng, Feng Bao 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2009 | A New Approach for Anonymous Password AuthenticationabstractAnonymous password authentication reinforces password authentication with the protection of user privacy. Considering the increasing concern of individual privacy nowadays, anonymous password authentication represents a promising privacy-preserving authentication primitive. However, anonymous password authentication in the standard setting has several inherent weaknesses, making its practicality questionable. In this paper, we propose a new and efficient approach for anonymous password authentication. Our approach assumes a different setting where users do not register their passwords to the server; rather, they use passwords to protect their authentication credentials. We present a concrete scheme, and get over a number of challenges in securing password-protected credentials against off-line guessing attacks. Our experimental results confirm that conventional anonymous password authentication does not scale well, while our new scheme demonstrates very good performance. Yanjiang Yang, Jianying Zhou 0001, Jian Weng 0001, Feng Bao 0001 |
ACSAC | 1 |
| 2009 | Optionally Identifiable Private Handshakes
Yanjiang Yang, Jian Weng 0001, Jianying Zhou 0001 |
Inscrypt | 1 |
| 2009 | A Lightweight Fast Handover Authentication Scheme in Mobile NetworksabstractWhen a mobile node roams in the mobile networks, its access router and routing path keeps changing. Hence the mobile node needs to authenticate the new access router and establish a new key for secure communication. To this motivation, this paper proposes a lightweight, efficient and scalable protocol to establish and update the authentication key in the mobile IPv6 networks. Feng Bao 0001, Yongdong Wu, Yanjiang Yang |
ICC | 4 |
| 2009 | Computationally Secure Hierarchical Self-healing Key Distribution for Heterogeneous Wireless Sensor Networks
Yanjiang Yang, Jianying Zhou 0001, Robert H. Deng, Feng Bao 0001 |
ICICS | 1 |
| 2009 | Achieving Better Privacy Protection in Wireless Sensor Networks Using Trusted Computing
Yanjiang Yang, Robert H. Deng, Jianying Zhou 0001 |
ISPEC | 1 |
| 2009 | Efficient Conditional Proxy Re-encryption with Chosen-Ciphertext Security
Jian Weng 0001, Yanjiang Yang, Qiang Tang 0001, Robert H. Deng, Feng Bao 0001 |
ISC | 2 |
| 2009 | Private handshakes with optional accountabilityabstractNowadays, users are increasingly concerned about individual privacy in cyberspace and Internet. In this paper, we propose the concept of private handshakes with optional accountability, which allows the two users in handshaking to decide real time whether or not to make their interactions accountable. Such optionally accountable private handshaking protocols are a more flexible privacy-preserving authentication primitive than unlink-able secret handshakes and private handshakes. We formulate a formal definition for optionally accountable private handshakes, and propose a concrete scheme based on bilinear pairings. Yanjiang Yang, Feng Bao 0001, Jian Weng 0001 |
LCN | 1 |
| 2009 | Self-enforcing Private Inference Control
Yanjiang Yang, Yingjiu Li, Jian Weng 0001, Jianying Zhou 0001, Feng Bao 0001 |
ProvSec | 1 |
| 2009 | Hierarchical Self-healing Key Distribution for Heterogeneous Wireless Sensor Networks
Yanjiang Yang, Jianying Zhou 0001, Robert H. Deng, Feng Bao 0001 |
SecureComm | 1 |
| 2009 | Privacy-preserving rental services using one-show anonymous credentialsabstractAbstract Rental services play an important part in our daily life and the trend has been towards digital transactions. Rental records contain lots of sensitive information on individuals, so if abused by rental service providers, users' privacy could be jeopardized. To mitigate this concern, we present privacy‐preserving rental services where interests of both the users and the service provider are protected. Specifically, our system enables normal users to engage in a rental service in an anonymous manner, whereas users with overdue items are subject to anonymity revocation by the rental service provider; moreover, the rental service provider enforces a rental limit which caps the number of rentals per user under a prescribed limit. We propose a novel one‐show anonymous credential scheme to realize the above design objectives. While this scheme is tailored to the scenario of online credential issuing in the proposed rental services, we believe that it is of independent interest and may find its use in other applications. Copyright © 2009 John Wiley & Sons, Ltd. Yanjiang Yang, Robert H. Deng, Feng Bao 0001 |
Secur. Commun. Networks | 1 |
| 2009 | A study of content authentication in proxy-enabled multimedia delivery systems: Model, techniques, and applicationsabstractCompared with the direct server-user approach, the server-proxy-user architecture for multimedia delivery promises significantly improved system scalability. The introduction of the intermediary transcoding proxies between content servers and end users in this architecture, however, brings unprecedented challenges to content security. In this article, we present a systematic study on the end-to-end content authentication problem in the server-proxy-user context, where intermediary proxies transcode multimedia content dynamically. We present a formal model for the authentication problem, propose a concrete construction for authenticating generic data modality and formally prove its security. We then apply the generic construction to authenticating specific multimedia formats, for example, JPEG2000 code-streams and MPEG-4 video streams. The prototype implementation shows that our scheme is suitable for practical applications. Robert H. Deng, Yanjiang Yang |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2008 | Private Query on Encrypted Data in Multi-user Settings
Feng Bao 0001, Robert H. Deng, Xuhua Ding, Yanjiang Yang |
ISPEC | 4 |
| 2008 | An Efficient PIR Construction Using Trusted Hardware
Yanjiang Yang, Xuhua Ding, Robert H. Deng, Feng Bao 0001 |
ISC | 1 |
| 2007 | New Paradigm of Inference Control with Trusted Computing
Yanjiang Yang, Yingjiu Li, Robert H. Deng |
DBSec | 1 |
| 2007 | Achieving End-to-End Authentication in Intermediary-Enabled Multimedia Delivery Systems
Robert H. Deng, Yanjiang Yang |
ISPEC | 2 |
| 2007 | Privacy-Preserving Credentials Upon Trusted Computing Augmented Servers
Yanjiang Yang, Robert H. Deng, Feng Bao 0001 |
ISPEC | 1 |
| 2006 | Fortifying password authentication in integrated healthcare delivery systemsabstractIntegrated Delivery Systems (IDSs) now become a primary means of care provision in healthcare domain. However, existing password systems (under either the single-server model or the multi-server model) do not provide adequate security when applied to IDSs. We are thus motivated to present a practical password authentication system built upon a novel two-server model. We generalize the two-server model to an architecture of a single control server supporting multiple service servers, tailored to the organizational structure of IDSs. The underlying user authentication and key exchange protocols we propose are password-only, neat, efficient, and robust against off-line dictionary attacks mounted by both servers. Yanjiang Yang, Robert H. Deng, Feng Bao 0001 |
AsiaCCS | 1 |
| 2006 | Practical private data matching deterrent to spoofing attacksabstractPrivate data matching between the data sets of two potentially distrusted parties has a wide range of applications. However, existing solutions have substantial weaknesses and do not meet the needs of many practical application scenarios. In particular, practical private data matching applications often require discouraging the matching parties from spoofing their private inputs. In this paper, we address this challenge by forcing the matching parties to "escrow" the data they use for matching to an auditorial agent, and in the "after-the-fact" period, they undertake the liability to attest the genuineness of the escrowed data. Yanjiang Yang, Robert H. Deng, Feng Bao 0001 |
CIKM | 1 |
| 2006 | A Practical Password-Based Two-Server Authentication and Key Exchange SystemabstractMost password-based user authentication systems place total trust on the authentication server where cleartext passwords or easily derived password verification data are stored in a central database. Such systems are, thus, by no means resilient against offline dictionary attacks initiated at the server side. Compromise of the authentication server by either outsiders or insiders subjects all user passwords to exposure and may have serious legal and financial repercussions to an organization. Recently, several multiserver password systems were proposed to circumvent the single point of vulnerability inherent in the single-server architecture. However, these multiserver systems are difficult to deploy and operate in practice since either a user has to communicate simultaneously with multiple servers or the protocols are quite expensive. In this paper, we present a practical password-based user authentication and key exchange system employing a novel two-server architecture. Our system has a number of appealing features. In our system, only a front-end service server engages directly with users while a control server stays behind the scene; therefore, it can be directly applied to strengthen existing single-server password systems. In addition, the system is secure against offline dictionary attacks mounted by either of the two servers. Yanjiang Yang, Robert H. Deng, Feng Bao 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2005 | Security Analysis and Fix of an Anonymous Credential System
Yanjiang Yang, Feng Bao 0001, Robert H. Deng |
ACISP | 1 |
| 2005 | Privacy and Ownership Preserving of Outsourced Medical DataabstractThe demand for the secondary use of medical data is increasing steadily to allow for the provision of better quality health care. Two important issues pertaining to this sharing of data have to be addressed: one is the privacy protection for individuals referred to in the data; the other is copyright protection over the data. In this paper, we present a unified framework that seamlessly combines techniques of binning and digital watermarking to attain the dual goals of privacy and copyright protection. Our binning method is built upon an earlier approach of generalization and suppression by allowing a broader concept of generalization. To ensure data usefulness, we propose constraining binning by usage metrics that define maximal allowable information loss, and the metrics can be enforced off-line. Our watermarking algorithm watermarks the binned data in a hierarchical manner by leveraging on the very nature of the data. The method is resilient to the generalization attack that is specific to the binned data, as well as other attacks intended to destroy the inserted mark. We prove that watermarking could not adversely interfere with binning, and implemented the framework. Experiments were conducted, and the results show the robustness of the proposed framework. Elisa Bertino, Beng Chin Ooi, Yanjiang Yang, Robert H. Deng |
ICDE | 3 |
| 2005 | A Privacy Preserving Rental System
Yanjiang Yang, Beng Chin Ooi |
ISC | 1 |
| 2005 | A New Architecture for User Authentication and Key Exchange Using Password for Federated Enterprises
Yanjiang Yang, Feng Bao 0001, Robert H. Deng |
SEC | 1 |
| 2005 | Tailored reversible watermarking schemes for authentication of electronic clinical atlasabstractIt is accepted that digital watermarking is quite relevant in medical imaging. However, due to the special nature of clinical practice, it is often required that watermarking not introduce irreversible distortions to medical images. The electronic clinical atlas has such a need of "lossless" watermarking. We present two tailored reversible watermarking schemes for the clinical atlas by exploiting its inherent characteristics. We have implemented the schemes and our experimental results look very promising. Feng Bao 0001, Robert H. Deng, Beng Chin Ooi, Yanjiang Yang |
IEEE Trans. Inf. Technol. Biomed. | 4 |
| 2004 | Cryptanalysis of Two Anonymous Buyer-Seller Watermarking Protocols and an Improvement for True Anonymity
Bok-Min Goi, Raphael C.-W. Phan, Yanjiang Yang, Feng Bao 0001, Robert H. Deng, Mohammad Umar Siddiqi |
ACNS | 3 |
| 2004 | New efficient user identification and key distribution scheme providing enhanced security
Yanjiang Yang, Shuhong Wang 0001, Feng Bao 0001, Jie Wang 0038, Robert H. Deng |
Comput. Secur. | 1 |
| 2004 | A smart-card-enabled privacy preserving E-prescription systemabstractWithin the overall context of protection of health care information, privacy of prescription data needs special treatment. First, the involvement of diverse parties, especially nonmedical parties in the process of drug prescription complicates the protection of prescription data. Second, both patients and doctors have privacy stakes in prescription, and their privacy should be equally protected. Third, the following facts determine that prescription should not be processed in a truly anonymous manner: certain involved parties conduct useful research on the basis of aggregation of prescription data that are linkable with respect to either the patients or the doctors; prescription data has to be identifiable in some extreme circumstances, e.g., under the court order for inspection and assign liability. In this paper, we propose an e-prescription system to address issues pertaining to the privacy protection in the process of drug prescription. In our system, patients' smart cards play an important role. For one thing, the smart cards are implemented to be portable repositories carrying up-to-date personal medical records and insurance information, providing doctors instant data access crucial to the process of diagnosis and prescription. For the other, with the secret signing key being stored inside, the smart card enables the patient to sign electronically the prescription pad, declaring his acceptance of the prescription. To make the system more realistic, we identify the needs for a patient to delegate his signing capability to other people so as to protect the privacy of information housed on his card. A strong proxy signature scheme achieving technologically mutual agreements on the delegation is proposed to implement the delegation functionality. Yanjiang Yang, Xiaoxi Han, Feng Bao 0001, Robert H. Deng |
IEEE Trans. Inf. Technol. Biomed. | 1 |
| 2003 | An invertible watermarking scheme for authentication of Electronic Clinical Brain AtlasabstractThe difficulty in watermarking medical imagery for authentication lies in the fact that watermarking itself should not introduce even one bit of alteration to the images. To this point, the recent invertible watermarking technique can help. However, the existing invertible watermarking schemes are not adaptable to the Electronic Clinical Brain Atlas (Nowinski et al. (1998)), a kind of "unnatural" palette images with respect to their uncorrelated contents. We develop an invertible watermarking scheme exclusively for authentication of the Electronic Clinical Brain Atlas. What makes our scheme special consists of the candidate points chosen for embedding and the encoding scheme to encode a bitstream. Furthermore, we present a general framework for invertible authentication watermarking, which encompasses virtually all existing schemes and more importantly, provides higher security over them. As an example, the proposed invertible scheme follows faithfully the framework. Our scheme really solves what others cannot. Yanjiang Yang, Feng Bao 0001 |
ICASSP (3) | 1 |
| 2003 | Flexible authentication of images
Yanjiang Yang, Feng Bao 0001, Robert H. Deng |
VCIP | 1 |
| 2002 | Security Analysis and Improvement of the Global Key Recovery System
Yanjiang Yang, Feng Bao 0001, Robert H. Deng |
ACISP | 1 |