VLDB 2026 Research / reviewers in the wild / expert
Jie Cui 0004
dblp:55/3002-4
· DBLP profile ↗
203ranked-venue papers
38as first author
155since 2021 · last 2026
0000-0001-7258-3418ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 61 · 14 first-author · 48 since 2021Systems, architecture and hardware · 56 · 6 first-author · 40 since 2021Security and privacy · 50 · 5 first-author · 42 since 2021Applied, interdisciplinary, general and emerging computing · 17 · 9 first-author · 14 since 2021Databases, data management, data science and information retrieval · 14 · 3 first-author · 8 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Shadow: Accelerating Regular Expression Matching on VCDIFF Compressed DataabstractData compression techniques significantly improve storage efficiency, bandwidth utilization, and energy efficiency, yet they introduce challenges for the rapid browsing and retrieval of valuable information within compressed data. Existing approaches achieve high-speed, lossless matching by exploiting the context-free property of automata. However, they are constrained by the recursive reference structures in compressed data, which necessitate state copying to ensure matching safety. Xiuwen Sun, Tianxin Wang, Hao Li 0011, Jie Cui 0004, Hong Zhong 0001 |
DCC | 6 |
| 2026 | Similarity-based Field Inference for Unknown Binary Network Protocols
Xiuwen Sun, Linlin Xia, Jie Cui 0004, Hong Zhong 0001 |
Comput. Networks | 5 |
| 2026 | SmartScope: Smart contract vulnerability detection via heterogeneous graph embedding with local semantic enhancement
Zhaoyi Meng, Wansen Wang 0001, Jie Cui 0004, Hong Zhong 0001 |
Expert Syst. Appl. | 4 |
| 2026 | BliChain: A Blockchain-Assisted and Lightweight Cross-Domain Authentication Scheme for 6G-Enabled VANETabstractIn the evolution of 6G-based Vehicular Ad-hoc Networks (VANETs) from closed single-domain environments to open cross-domain environments, several security challenges arise, including heterogeneous domain trust barriers, vehicle identity privacy leakage, and high authentication overhead in dynamic scenarios. Existing schemes based on centralized public key infrastructure (PKI) suffer from single point failure risks and have difficulty balancing low latency with conditional privacy preservation. Meanwhile, blockchain-assisted solutions are often constrained by on-chain storage expansion and high computational overhead. To address these issues, this paper proposes a blockchain-assisted anonymous authentication scheme for 6G-VANETs. The proposed scheme uses blockchain to construct distributed trust anchors and enable secure sharing of public parameters across domains. By generating lightweight authentication parameters based on Lagrange interpolation polynomials, the scheme supports direct mutual authentication and session key agreement between vehicles without requiring massive certificate-related on-chain transactions. In addition, a pseudo-identity mechanism is introduced to achieve conditional privacy preservation, thereby balancing vehicle identity privacy and traceability. Security analysis demonstrates that the proposed scheme satisfies the required security properties under the random oracle model. Performance evaluation shows that compared with existing solutions, the proposed scheme significantly reduces computational overhead by 22.31%, 11.02%, and 29.19%, respectively, and communication overhead by 51.2%, 20.08%, and 24.61%, respectively. Jiaxin Li 0001, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Jie Cui 0004 |
IEEE Internet Things J. | 6 |
| 2026 | Blockchain-Assisted Proxy Re-Encryption Scheme With Revocation for Federal DiagnosticsabstractFederated diagnosis, a concept emerging in Internet of Things (IoT)-based e-health systems, addresses the interconnectivity challenges of medical resources across different regions. Furthermore, flexible access control is required, which allows users to modify the access policy for encrypted data in the cloud without revealing sensitive information. Current solutions rely on third parties for policy modification, incur high computational overheads during user revocation, and expose user attributes to plaintext access policies. To address these issues, this study introduces a blockchain-assisted revocable federated diagnostic ciphertext policy attribute-based encryption (RFD-CPABE) scheme that enables policy conversion and revocation, which allows users to convert attribute-based encryption ciphertext to inner product encryption ciphertext swiftly and facilitates fast revocation using binary trees. This scheme enhances privacy protection by separating attribute names from values, thus concealing sensitive information within the access policies. Moreover, to reduce the computational burden on trusted institutions, the workload is decentralized utilizing a blockchain to minimize the pressure on the central servers. The formal security proof demonstrates the resilience of the scheme against selective chosen-plaintext attacks, and the experimental analysis confirms its superior efficiency compared to existing solutions. Qingyang Zhang 0001, Jie Cui 0004, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Internet Things J. | 3 |
| 2026 | Length field recognition for unknown network protocol in static trace
Xiuwen Sun, Jie Cui 0004, Hong Zhong 0001 |
J. Netw. Comput. Appl. | 4 |
| 2026 | CAAS-DMSK: A Certificateless Anonymous Authentication Scheme with Dynamic Master Secret Keys in VANETs
Yan Xu 0007, Huilan Zhang, Jie Cui 0004, Hong Zhong 0001 |
J. Syst. Archit. | 3 |
| 2026 | Privacy-Accountable Distributed Collaborative Authentication for Malicious Node Resistance in Vehicular Ad Hoc NetworksabstractIn vehicular ad hoc networks (VANETs), distributed identity authentication provides the foundation for securing sessions among entities over wireless channels while eliminating single points of failure. However, existing distributed authentica tion schemes for VANETs typically make unrealistic assumptions about node reliability and trustworthiness, failing to account for scenarios where authentication nodes may be compromised or collude with vehicles. Moreover, these schemes expose the com munication process to linkability attacks while allowing vehicles to self-register their public keys. To address these limitations, we propose a privacy-preserving and accountable distributed collab orative authentication scheme for VANETs that is resilient to ma licious nodes. Using threshold signature techniques, distributed authentication nodes collaboratively perform decentralized ve hicle identity authentication using a predefined threshold. Zero knowledge proof protects the privacy of the signing process while maintaining accountability and effectively preventing malicious behavior by nodes under external or internal adversarial attacks. Furthermore, vehicles self-register their public keys via smart contracts and blockchain technology, ensuring anonymity and unlinkability during registration while enabling the traceability of malicious vehicles. Security and performance analyses show that the proposed scheme enhances the security and robustness of distributed collaborative authentication in VANETs, achieving a better balance between computational and communication costs than existing schemes Ru Li 0005, Jie Cui 0004, Lu Wei 0003, Irina Pavlovna Bolodurina, Jing Zhang 0024, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Cloud Data Sharing System With Enhanced Effectiveness for Flexible User RevocationabstractAttribute revocation is a secure data-sharing system that allows user revocation of shared data. The most effective attribute revocation scheme is still less effective in the revocation process. When revoking a user's access rights to a specified ciphertext, both that ciphertext and the keys of all other users must be updated. Similarly, when revoking a user from accessing all ciphertexts, all ciphertexts related to the revoked user and the keys of all non-revoked users must be updated, with computational cost linear to the number of attributes associated with the revoked user. In this work, to enhance the effectiveness of revocation, we design a cloud data-sharing system that supports flexible revocation. By introducing edge-server-assisted key puncturing techniques, our approach eliminates the need to update ciphertext and other users' keys when revoking a user's access rights to a specific ciphertext. Additionally, we leverage key splitting technology to divide data users' permissions between the data owner and the authority, ensuring that the update overhead for non-revoked users remains constant when revoking a user's access to all ciphertexts. On resource-constrained devices, when involving 50 attributes, non-revoked users only need approximately 0.02 milliseconds to update their keys, resulting in a 25x improvement in update speed. Hong Zhong 0001, Jie Cui 0004, Chengjie Gu, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | MalFlows: Context-Aware Fusion of Heterogeneous Flow Semantics for Android Malware Detection
Zhaoyi Meng, Fenglei Xu, Wenxiang Zhao, Wansen Wang 0001, Wenchao Huang 0001, Jie Cui 0004, Hong Zhong 0001, Yan Xiong 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | JANUS: A Difference-Oriented Analyzer for Financial Centralized Risks in Smart ContractsabstractSome smart contracts violate decentralization principles by defining privileged accounts that manage other users' assets without permission, introducing centralized risks that have caused financial losses. Existing methods, however, face challenges in accurately detecting diverse centralized risks due to their dependence on predefined behavior patterns. In this paper, we propose JANUS, an automated analyzer for Solidity smart contracts that detects financial centralized risks independently of their specific behaviors. JANUS identifies differences between states reached by privileged and ordinary accounts, and analyzes whether these differences are finance-related. Focusing on the impact of risks rather than behaviors, JANUS achieves improved accuracy compared to existing tools and can uncover centralized risks with unknown patterns. To evaluate JANUS's performance, we compare it with other tools using a dataset of 540 contracts. Our evaluation demonstrates that JANUS outperforms representative tools in terms of detection accuracy for financial centralized risks. Additionally, we evaluate JANUS on a real-world dataset of 33,151 contracts, successfully identifying two types of risks that other tools fail to detect. We also prove that the state traversal method and variable summaries, which are used in JANUS to reduce the number of states to be compared, do not introduce false alarms or omissions in detection. Wansen Wang 0001, Renjie Ji, Wenchao Huang 0001, Zhaoyi Meng, Jie Cui 0004, Hong Zhong 0001, Yan Xiong 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | Blockchain-Based Asynchronous Authentication and Key Agreement Scheme for Securing VANETsabstractIn vehicular ad hoc networks (VANETs), authentication and key agreement (AKA) protocols are crucial for establishing secure authentication and session keys for network communications, ensuring security for short-term vehicle interactions. However, traditional VANETs AKA schemes heavily rely on centralized trust architectures. This dependence raises significant concerns about overall system security and resilience, especially when these schemes operate over insecure wireless channels. Although recent studies have introduced decentralized architectures to mitigate this issue, a key limitation remains. These approaches typically assume synchronous network environments, which in practice limits their true decentralization capabilities in dynamic VANETs. To address these challenges, we propose a decentralized and asynchronous AKA scheme based on a consortium blockchain that enables the execution of the key agreement process in asynchronous VANETs environments. Furthermore, we employ lightweight cryptographic techniques combined with a Cuckoo filter to optimize computational efficiency, reduce communication overhead, and minimize on-chain storage costs. Security analyses and simulation experiments demonstrate that the proposed scheme delivers robust security and high performance under realistic network conditions. Lu Wei 0003, Yujia Zhong, Jie Cui 0004, Irina Pavlovna Bolodurina, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Runtime Threshold Signature-Based Unmanned Aerial Vehicle Swarm Authentication With Autonomous Splitting SupportabstractRecently, unmanned aerial vehicles (UAVs) have undergone rapid development, demonstrating significant potential in various fields, including logistics, military operations, and entertainment. By collaborating to form swarms, UAVs can undertake more complex tasks such as mapping and disaster relief. To address the limited flexibility of UAV swarm identity authentication and the requirement for swarm splitting during task execution, we propose a runtime threshold signature (RTS) scheme. Unlike traditional threshold signatures, RTS defers the selection of the threshold from the initialization phase to the signing phase, allowing verifiers to dynamically adjust the threshold as required, thus achieving an effective balance between efficiency and security. Moreover, the RTS has the same signature size as the Schnorr signature, which is a non-interactive threshold signature. Building on the RTS primitive, we designed a novel identity authentication scheme that supports the autonomous splitting of UAV swarms. This scheme enables secure swarm-level identity authentication while adapting naturally to dynamic swarm restructuring. Furthermore, we demonstrate that the proposed scheme satisfies unforgeability under the t-VCDH assumption. To evaluate its performance, we implemented our scheme in C++ on AmovLab Prometheus 600 (P600) UAVs and assessed it under varying network latency and bandwidth conditions. Comparative results with existing schemes demonstrate that our approach achieves lower computational overhead and high practical applicability. Notably, even with the threshold set to 128, the authentication process takes only 2.6 ms per UAV. Mingwei Zeng, Hong Zhong 0001, Qingyang Zhang 0001, Fengqun Wang, Jiaxin Li 0001, Jie Cui 0004 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | MPDA-HPR: Multi-Dimensional Privacy-Preserving Data Aggregation Based on Homomorphic Proxy Re-Encryption for Industrial Internet of ThingsabstractAs modern communication technologies advance, the Industrial Internet of Things (IIoT) is progressively evolving towards greater intelligence. The extensive implementation of smart grids has significantly affected IIoT factories. Data aggregation is commonly used to protect the factory's privacy. However, existing multi-dimensional data aggregation schemes lack flexibility and are vulnerable to internal attacks, where private data from certain smart devices may be decrypted by insiders. Moreover, replacing related devices necessitates updating the keys of the entire system, which incurs heavy overhead. To address these issues, a multi-dimensional privacy-preserving data aggregation scheme based on homomorphic proxy re-encryption (MPDA-HPR) is proposed. Using a modified Paillier encryption algorithm supported by proxy re-encryption and super-increasing sequences, the proposed scheme enhances flexibility and scalability. Security analyses demonstrate that the proposed scheme can withstand various security threats and effectively preserve the privacy of devices. Finally, the prototype is implemented and evaluated, demonstrating that the proposed scheme is robust, efficient, and feature-rich. Qingyang Zhang 0001, Jie Cui 0004, Hulin Jin, Fengqun Wang, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Anonymous Integrity Auditing Scheme Based on Trusted Execution Environment for Distributed Edge ComputingabstractMulti-replica data storage is widely adopted in edge computing to improve both data availability and access efficiency for latency-sensitive applications. Integrity auditing is a critical mechanism for ensuring data reliability in this distributed setting. However, existing schemes face a trade-off between security and efficiency: ensuring replica authenticity typically requires users to generate unique tags for all copies, creating a bottleneck for resource-constrained devices. Delegation schemes reduce this burden but struggle to prevent collusion or on-the-fly generation attacks. Therefore, this study proposes ATRIA to resolve this dilemma. Uniquely, ATRIA leverages the Trusted Execution Environments (TEEs) not only for isolation but to securely offload the intensive replica tag generation from the user, ensuring authentic physical storage with minimal user overhead. By leveraging the hardware isolation of the TEEs, this mechanism ensures authentic physical storage and protects against on-the-fly and collusion attacks. In addition, the scheme incorporates a privacy-preserving identity management solution that balances anonymity and traceability. It employs a traceable anonymous identity mechanism whereby users interact via pseudonyms, hiding their real identities while allowing a trusted Key Generation Center (KGC) to perform identity tracing only when authorized. Our security analysis demonstrates that the proposed scheme achieves its security objectives and resists various attacks. Furthermore, a comprehensive performance evaluation demonstrates that ATRIA outperforms related schemes in terms of computational overhead. Qingyang Zhang 0001, Jie Cui 0004, Fengqun Wang, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Distributed Multi-Attribute Anonymous Certificate Management Scheme With Fine-Grained Revocation for Uncrewed Aerial VehiclesabstractIn unmanned aerial vehicle (UAV) scenarios, the execution of specific flight missions requires anonymous certificates containing multiple attributes as proof of authorization. However, existing certificate- management schemes are ineffective in achieving an optimal trade-off between verification overhead and attribute-level revocation. First, most existing schemes bind multiple attributes to a single certificate but typically lack the capability of fine-grained revocation at the individual attribute level. Second, most existing schemes rely on centralized certificate authorities, necessitating UAVs to apply for certificates from multiple regions separately when performing cross-regional access. This scenario increases the certificate management burden. To address these challenges, this paper proposes a distributed multiattribute anonymous certificate management scheme for UAVs. First, the proposed scheme integrates redactable signatures and dynamic accumulators, enabling the selective disclosure and fine-grained revocation of attributes within a single certificate. Second, the proposed scheme utilizes a distributed key-generation mechanism, enabling decentralized certificate issuance and secure management. Qingyang Zhang 0001, Hong Zhong 0001, Fengqun Wang, Mingwei Zeng, Jie Cui 0004 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | FairRoP: Robust Client Selection Scheme for Fairness-Aware Federated LearningabstractFederated learning is a privacy-preserving distributed learning paradigm in which a server coordinates multiple clients to train a global model. However, current federated optimization introduces bias by favoring the interests of specific clients, overlooking the concerns of vulnerable participants to maximize global benefits. Many efforts have been made in the pursuit of fairness for this shortcoming, yet we notice that such endeavors exhibit extremely poor robustness. A minimal amount of malicious tampering is sufficient to disrupt convergence. In fact, we recognize a subtle trade-off between robustness and fairness, which remains an open question. To address these concerns, we propose FairRoP, a systematic strategy that enhances fairness and guarantees robustness with adaptive client selection. We model complex multi-objective optimization problems using a simple and efficient ϵ-greedy Thompson Sampling Multi-Armed Bandit (TS-MAB). At the core of this approach are three submodules:fairness awareness, attack detection, andq-Balance, each designed to tackle specific sub-problems within the broader optimization challenge. Our experimental results, conducted on real datasets, showcase that FairRoP significantly improves overall fairness and robustness compared to state-of-the-art solutions. Furthermore, our approach seamlessly integrates with other aggregation algorithms. Rolando Trujillo-Rasua, Hong Zhong 0001, Jie Cui 0004 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | Blockchain-Assisted Secure Announcement Sharing Scheme With Controllable Verifiable Distributed Security for VANETsabstractIn recent years, vehicle announcement sharing has become increasingly important in intelligent transportation networks. However, the demand for secure communication and real-time responses necessitates the development of an efficient and confidential announcement sharing scheme. Existing solutions are constrained by inadequate privacy in inter-group sharing and lack of storage security consideration. To address these issues, we propose a blockchain-assisted secure announcement sharing scheme with controllable verifiable distributed security. This scheme constructs a re-encrypted group signature framework to achieve controlled confidentiality of announcements while ensuring efficient and secure sharing. Additionally, by designing a lightweight verification algorithm powered by the Inter Planetary File System (IPFS) and blockchain, the scheme ensures rapid verifiable secure both the initial and long-term storage of announcements. Security proof and analysis show that the proposed scheme offers enhanced security and robust privacy protection. Performance analysis demonstrates that, while providing better computational efficiency than other schemes, the proposed scheme maintains low communication overhead and smaller storage verification costs, outperforming existing announcement sharing schemes. Jie Cui 0004, Jing Zhang 0024, Ru Li 0005, Yimin Wang 0004, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2026 | Post-Quantum Secure Authenticated Key Agreement Scheme for Vehicular Digital Twin
Jie Cui 0004, Jiyu Liu, Lu Wei 0003, Irina Pavlovna Bolodurina, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2026 | Blockchain-Assisted Message Reporting Scheme With Weighted Threshold Signature for Vehicular Ad-Hoc NetworksabstractIn vehicular ad-hoc networks (VANETs), message reporting is an effective method for improving traffic safety and efficiency. Most existing VANET message reporting schemes rely on the trust value of a single vehicle to determine message authenticity, which leads to unreliable message sources. Even multi vehicle-assisted reporting schemes are limited by the assumption that all vehicles have the same credibility, which does not reflect the actual dynamic VANET environment in which vehicles have different credibilities. To address this issue, we propose a blockchain-assisted VANET message reporting scheme with weighted threshold signatures. Through the design of weights, the credibility of different vehicles is quantified, and the impact of vehicles on the signing process is differentiated. Threshold signature generation relies on the weight sum of all signatories reaching a predetermined threshold, to enable flexible and reliable message reporting. Security analysis shows that our proposed scheme combined with blockchain can satisfy the security and privacy requirements of VANET message reporting. Performance analysis indicates that our proposed scheme outperforms the most advanced VANET message reporting schemes in terms of transmission and computation performance. Ru Li 0005, Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Hong Zhong 0001, Debiao He |
IEEE Trans. Mob. Comput. | 2 |
| 2026 | Distributed and Autonomous Group Management Supporting Group Fusion for UAVsabstractWith increasingly complex tasks, cooperation among multiple unmanned aerial vehicle (UAV) groups has become more significant. However, in complex operational environments, UAVs may operate outside the communication coverage of the trusted authority (TA), making continuous online TA services unavailable. Under such circumstances, most existing group management methods have difficulty achieving group fusion and cannot flexibly update post-fusion member certificates. Therefore, we propose an autonomous UAV group management scheme based on mobile proactive secret sharing. First, the scheme achieves autonomous group fusion by updating the subsecrets of UAVs. Second, without the participation of a TA, the scheme supports the dynamic self-updating of certificates, ensuring secure communication in the new group and continuous availability of certificates. Security proofs and analyses show that the proposed scheme is secure under the random oracle model and can resist several common attacks. The experimental results demonstrate that the proposed scheme outperforms related schemes in computational performance and is suitable for secure and efficient UAV group management scenarios. Fengqun Wang, Manting Gan, Hong Zhong 0001, Qingyang Zhang 0001, Jie Cui 0004, Debiao He |
IEEE Trans. Mob. Comput. | 5 |
| 2026 | Game Theory and Trust Management Driven Dynamic Proof-of-Work Blockchain Consensus Algorithm for Securing Internet of Vehicles
Lu Wei 0003, Yuanzhi Cao, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 3 |
| 2026 | Toward Stable and Low-Latency Task Offloading: A Multi-Agent Framework for Vehicular Edge Computing
Lu Wei 0003, Jie Cui 0004, Xianfeng Xie, Jing Zhang 0024, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2026 | Forward Secure Data Sharing Based on Proxy Re-Encryption in Industrial Internet of ThingsabstractIn the Industrial Internet of Things (IIoT), data is shared among different production segments for collaborative production. However, industrial production processes often involve corpus sensitive information, and during data sharing, every flow of data between different subjects increases its exposure to vulnerabilities. Proxy re-encryption offers a practical approach to enabling secure data exchange, thereby partially mitigating the tension between information sharing and privacy protection. Many scholars have proposed data-sharing schemes utilizing proxy re-encryption technologies. However, existing schemes still face issues, such as excessive communication and computational overhead, and cannot guarantee forward security. Therefore, this study proposes a lightweight and forward-secure data-sharing scheme. First, the proxy generates the re-encryption key, substantially alleviating the overhead on the data owner. Second, whenever the time node changes or a data user is revoked, the data user loses access to historical data, which effectively ensures forward security. The security proof confirms the scheme’s IND-CPA security under the DBDH assumption. Performance analyses reveals that the proposed scheme achieves higher security in data sharing with a lower computational overhead. Qingyang Zhang 0001, Siqi Fu, Jie Cui 0004, Fengqun Wang, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2026 | ECC-IDS: A Robust ECC-Based Identity Signcryption Scheme for UAV to Ground Station in Intelligent Search and Rescue
Yimin Wang 0004, Quan Fan, Hong Zhong 0001, Jie Cui 0004 |
IEEE Trans. Reliab. | 5 |
| 2025 | CAUA: A Realistic and Effective Attack on Machine Unlearning Under Limited InformationabstractMachine unlearning aims to remove specific data from models to meet privacy regulations. While prior work has explored potential vulnerabilities in unlearning mechanisms, most assume adversaries with privileged access—an unrealistic premise in real-world Machine Learning-as-a-Service (MLaaS) settings. This raises a fundamental question: Can unlearning be exploited under restricted access constraints? We answer this affirmatively by proposing Class-Aligned Unlearning Attack (CAUA), a novel attack framework tailored to realistic deployment settings. CAUA uses target-class examples and public out-of-distribution data to generate semantically aligned inputs that integrate seamlessly into training. These inputs maintain model performance during training but, when unlearned, induce localized representation collapse and significant shifts in decision boundaries. We comprehensively evaluate CAUA across multiple datasets and unlearning paradigms. Notably, unlearning just 0.2% of training data causes up to a 73.4% drop in target-class F1 and a 60.4% drop in overall accuracy, revealing a previously overlooked vulnerability. Our work sheds new light on the risks of machine unlearning and lays a foundation for building more robust defenses. Jing Zhang 0024, Jie Cui 0004, Xianfeng Xie, Chunyang Fan |
ACSAC | 3 |
| 2025 | Edge Computing-Based Anonymous Cross-Domain Authentication Scheme for VANETsabstractIn the vehicular ad-hoc networks (VANETs), crossdomain communication among vehicles significantly improves traffic efficiency and road safety. However, due to the vulnerabilities of vehicle communication, it faces numerous security challenges when performing cross-domain communication. Existing schemes rely on trusted third parties for cross-domain authentication, resulting in issues such as low computational efficiency and weak privacy protection for vehicles, which cannot meet the demands of large-scale vehicle cross-domain communication. To address these problems, we propose an efficient and anonymous cross-domain authentication scheme based on edge computing. By using edge gateways to manage vehicle groups and handle cross-domain event requests, we solve the performance bottleneck issues caused by centralized authentication. Additionally, the use of a batch authentication mechanism further improves computational efficiency during large-scale authentications and reduces authentication latency. Security and performance analyses show that the proposed scheme can meet the security and performance requirements for cross-domain vehicle communication. Hong Zhong 0001, Chengdong Gu, Jing Zhang 0024, Qingyang Zhang 0001, Jiaxin Li 0001, Jie Cui 0004 |
HPCC | 7 |
| 2025 | TDID: A Three-Factor Decentralized Identity Authentication Scheme in MetaverseabstractThe Metaverse, an immersive parallel digital world, faces critical security challenges such as data leakage and impersonation attack. Existing authentication schemes often suffer from single-point failures due to centralization, incomplete decentralization, and low efficiency. To address these challenges, this paper proposes TDID, a three-factor decentralized identity authentication scheme. Our core contribution lies in the novel synergy of a confidential smart contract, executed within a Trusted Execution Environment (TEE), with the offline attackresistant OPAQUE password-authenticated key exchange protocol. The scheme achieves full decentralization by using the TEE-based contract as a decentralized root of trust. It allows users to establish a globally unique, collision-resistant identity, and ensures that a user's password and biometric key are never revealed to the server during authentication, thus providing robust resistance against offline dictionary attacks even from a compromised server. Rigorous security analysis, including formal verification using ProVerif and a provable security proof, along with performance evaluations, demonstrates that the proposed scheme significantly enhances security while maintaining efficient computational and communication performance. Jie Cui 0004, Mengfei Cheng, Jing Zhang 0024, Li Wang 0139, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
ICPADS | 1 |
| 2025 | A Secure Anonymous Authentication and Key Agreement Scheme for UAV Swarms in Emergency Rescue EnvironmentsabstractTo achieve secure communication in unmanned aerial vehicle (UAV) swarms during emergency rescue operations, A wide range of authentication key agreement (AKA) schemes has emerged in recent research. However, these schemes generally face three critical limitations. First, UAVs may struggle to maintain persistent communication with the trusted authority in complex environments, and efficient authentication cannot be guaranteed when the TA is offline. Second, most existing schemes lack traceability, preventing the TA from revealing the true identity of malicious UAVs. Finally, UAVs are constrained by limited computational and communication resources. So we propose an AKA scheme that enables secure communication between the UAV and BS. Specifically, proposed scheme eliminates reliance on a trusted authority during the AKA phase, while still ensuring the establishment of a secure communication channel. In addition, by combining the Chinese remainder theorem with the chameleon hash function, the scheme not only enables mutual authentication between UAVs and base stations but also enhances overall computational efficiency in complex environments. Formal security analysis and rigorous proof indicate this design upholds various protective attributes and effectively withstands diverse known attacks. Finally, experimental evaluations validate efficiency and practicality about proposed scheme in some environments. Fengqun Wang, Hang Hai, Jie Cui 0004, Wuquan Wen, Qingyang Zhang 0001, Hong Zhong 0001 |
ICPADS | 3 |
| 2025 | Toward Secure Trajectory Similarity Range Query Under Multiuser SettingabstractThe widespread availability of similarity queries over trajectory data has led to numerous real-world applications, such as traffic management and path planning. With the proliferation of trajectory data, data owners often outsource storage and computation tasks to the cloud due to limited computing and storage resources. However, this scenario raises sharp security concerns, where it is critical to ensure both the integrity of query results and privacy during query processing. Furthermore, most existing works assume a single-user setting where all query users share the same key, which may lead to query privacy leakage. Therefore, in this article, we take the first step in studying the issue of multiuser and secure trajectory similarity range query (MSRQ). Specifically, inspired by the M-tree, we propose a secure index based on a distributed two-trapdoor public-key cryptosystem (DT-PKC), called M*-tree, and devise secure protocols to support multiuser query processing. We also carefully design a filtering strategy and verification scheme to ensure fast search and integrity guarantees. Finally, we theoretically analyze the security and complexity and empirically evaluate the performance and feasibility of our proposed approach. Ningning Cui, Lili Pei, Mengxiang Wang, Dong Wang 0057, Jianxin Li 0001, Hulin Jin, Jie Cui 0004, Hong Zhong 0001 |
IEEE Internet Things J. | 8 |
| 2025 | Dynamic and Verifiable Fuzzy Keyword Search With Forward Security in Cloud EnvironmentsabstractDynamic searchable symmetric encryption (DSSE) ensures that outsourced data can be searched and updated without compromising data availability. Recent efforts on DSSE have mainly focused on exact keyword retrieval, but considering that misspellings are common and practical, it is necessary to support the functionality of fuzzy keyword search. However, most existing fuzzy keyword search schemes do not consider malicious cloud servers and forward-privacy guarantees. The former may lead to the implementation of a fraction of search operations or forge the results and the latter may reveal the association between the newly updated data and previous search tokens. Therefore, in this article, we investigate the issue of dynamic and verifiable fuzzy keyword search with forward security (DVFKF). Specifically, DVFKF first uses locality sensitive hash to map approximate keywords into the same hash bucket, then links the hash buckets to obtain the bucket strings. Next, to accelerate the performance and support forward privacy, we propose a chain index for each bucket string through counters. Further, to guarantee the integrity of the results, we integrate the Merkle hash tree and chain index to verify the correctness and completeness of the results. Finally, we conduct formal security analysis and empirical evaluations to demonstrate the feasibility and practicality of our scheme on real datasets. Ningning Cui, Lili Pei, Mengxiang Wang, Dong Wang 0057, Jie Cui 0004, Hong Zhong 0001 |
IEEE Internet Things J. | 6 |
| 2025 | Graph-Based Multitask Transfer Learning for Fault Detection and Diagnosis of Few-Shot Analog CircuitsabstractBuilding an interpretable fault detection and diagnostic model based on few-shot circuit samples and prior information about circuit structures is of significant importance. To fill these gaps, we propose a graph-based multitask transfer learning (TL) method for fault detection and diagnosis of circuits under few-shot conditions. First, in order to model the interconnections of nodes in a circuit, the sample data is organized into a graph structure, and a semi-supervised graph-based structural feature fusion method is proposed. The proposed method can accept graph-structured data and process the data using feature fusion methods. Second, to improve the model performance under few-shot conditions, two TL mechanisms are proposed for the topological structure characteristics of analog circuits as well as circuit signal characteristics. Finally, through a parameter-shared strategy, we propose a task transfer-based fault diagnosis approach. Experimental results on three different circuits show that the proposed method has the best diagnostic accuracy compared to typical detection and diagnosis schemes. Zhongyu Gao, Aibin Yan, Zhengfeng Huang, Jie Cui 0004, Byeong-Hee Roh, Guangzhu Liu, Patrick Girard 0001, Xiaoqing Wen |
IEEE Internet Things J. | 4 |
| 2025 | FEELPGen: Data-Free Knowledge Distillation for Personalized Federated Learning Across Heterogeneous Edge SilosabstractDeploying machine learning models on large-scale IoT devices in edge networks is challenging. Federated edge learning (FEEL) has emerged as a potential solution based on a hierarchical architecture. However, existing research relies primarily on an idealized cross-device assumption, overlooking more realistic cross-silo scenarios where devices typically belong to different organizational silos. To facilitate multi-group collaboration, we first propose a semi-decentralized FEEL structure called FEELPGen, in which different silos collaborate in training to maximize local model benefits without relying on trusted third-party coordination. Based on that, a two-layer aggregation algorithm is proposed to enhance the generalization ability under highly heterogeneous data distribution. For inner-silo learning, we devise a heterogeneity-aware, synchronous inner-silo aggregation algorithm utilizing data-free knowledge distillation based on generative learning (Gen). Feature vectors are generated to approximate silo knowledge. For inter-silo learning, a personalized (P), asynchronous inter-silo aggregation algorithm is proposed with adaptive selection and dynamic weight queues. To further improve efficiency, we introduce an optional optimized scheme, FEELPGen+, which integrates a privacy-preserving dimension-reduction algorithm. Finally, we provide a detailed analysis for convergence and complexity to verify the feasibility of FEELPGen. Extensive experiments demonstrate that FEELPGen achieves significant improvement in accuracy compared to the state-of-the-art schemes. Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Jie Cui 0004 |
IEEE Internet Things J. | 6 |
| 2025 | Achieving Fair and Efficient Revocable Access Control for IIoT Data Sharing: A Blockchain-Enabled ApproachabstractWith the advancement of computing and communication technologies, Industrial Internet of Things (IIoT) has emerged accordingly. In IIoT environments, efficient data sharing is achieved through collaboration among end devices, edge servers, and cloud servers. However, ensuring the security, efficiency, and fairness of service data access for end devices remains a significant challenge. To address this, we propose a fair and efficient revocable access control scheme based on blockchain. The proposed scheme leverages smart contracts to establish a fair payment mechanism, ensuring fairness for IIoT data sharing. In addition, a proxy-assisted decryption approach is employed to minimize the decryption overhead on end devices. Moreover, the scheme supports efficient user revocation without requiring updates to the private keys of end users. This enhances the overall security and usability of the system. Finally, a thorough security and performance analysis indicate that the proposed scheme fits well within IIoT scenarios. Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Jiaxin Li 0001, Jie Cui 0004 |
IEEE Internet Things J. | 6 |
| 2025 | Conditional Privacy-Preserving Transaction for the Unspent Transaction Output-Based Multi-Chain Blockchain SystemabstractThe anonymity of blockchain may be exploited by criminals for illegal fund transfers, thus a conditional privacy-preserving scheme is important for blockchain regulation. Currently, sharding technology under a multi-chain architecture is used to improve blockchain scalability. However, current conditional privacy-preserving schemes cannot work on this architecture. To protect the privacy of the transaction, we present a conditional privacy-preserving transaction scheme (MC-CPPT) for multi-chain blockchain system. In this system, we proposed a zero-knowledge proof based anonymous transaction, in terms of the identities of transaction participants and amounts, which also enables the unlinkability of transactions and indistinguishability between cross-chain and intra-chain transactions in multi-chain blockchain system. In addition, a multi-node regulatory agency is introduced to control the transaction amount and frequency in the system without a single point of failure. Moreover, an ECC-based encryption scheme is proposed to achieve the traceability of suspicious transactions. A security model is defined and the security of MC-CPPT is demonstrated to meet the expected security goals. Evaluating the prototype revealed acceptable performance and additional security features. Jie Cui 0004, Wenting Zhuang, Hong Zhong 0001, Qingyang Zhang 0001, Fengqun Wang, Debiao He |
IEEE Trans. Computers | 1 |
| 2025 | Blockchain-Based Privacy-Preserving Deduplication and Integrity Auditing in Cloud StorageabstractEnsuring cloud data security and reducing cloud storage costs have become particularly important. Many schemes expose user file ownership privacy when deduplicating authentication tags and during integrity auditing. Moreover, key management becomes more difficult as the number of files increases. Also, many audit schemes rely on third-party auditors (TPAs), but finding a fully trustworthy TPA is challenging. Therefore, we propose a blockchain-based integrity audit scheme supporting data deduplication. It protects file tag privacy during deduplication of ciphertexts and authentication tags, safeguards audit proof privacy, and effectively protects user file ownership privacy. To reduce key management costs, we introduce identity-based broadcast encryption (IBBE) that does not require interaction with key servers, eliminating additional communication costs. Additionally, we use smart contracts for integrity auditing, eliminating the need for a fully trusted TPA. We evaluate the proposed scheme through security and theoretical analyses and a series of experiments, demonstrating its efficiency and practicality. Qingyang Zhang 0001, Shuai Qian, Jie Cui 0004, Hong Zhong 0001, Fengqun Wang, Debiao He |
IEEE Trans. Computers | 3 |
| 2025 | Cost Efficient Flip-Flop Designs With Multiple-Node Upset-Tolerance and Algorithm-Based VerificationsabstractThis article presents radiation-hardened flip-flop (FF) designs capable of tolerating soft errors, e.g., single-node upsets (SNUs), double-node upsets (DNUs) and multiple-node upsets (MNUs). First, a 2-input FF and a 3-input FF are proposed as the baseline FFs that not only, respectively, tolerate SNUs and DNUs but also exhibit cost efficiency in terms of delay, power, and area. Through adding two stages of c-elements, a 4-input FF and a 5-input FF are proposed as the baseline FFs as well. Utilizing the structural characteristics of these FFs, an$N-1$input FF and an N input FF are proposed as the extended FFs capable of tolerating more node upsets. Moreover, a highly efficient algorithm for verifying MNU-tolerance of these FFs is proposed. Algorithm and HSPICE-tool-based verification results both demonstrate the MNU-tolerance for the proposed FFs with more inputs. Aibin Yan, Zhengfeng Huang, Jie Cui 0004, Tianming Ni, Patrick Girard 0001, Xiaoqing Wen |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 5 |
| 2025 | FP-MLP: A Frequency Domain Patch-Based MLP Model for GPU-Dominated Cloud Workload PredictionabstractCloud Data Centers are typically equipped with various types and performance levels of GPUs, making it crucial to effectively leverage these heterogeneous resources when deploying deep learning tasks. However, differences in GPU performance pose complex resource management challenges. Accurate workload forecasting can help address these challenges. Many existing prediction models employ Multi-Layer Perceptrons (MLPs) due to their simplicity, computational efficiency, and general applicability. Nevertheless, most MLP-based methods tend to prioritize low-frequency features, neglecting high-frequency features that are essential for capturing fine-grained patterns in resource utilization data. Our analysis reveals that this bias primarily stems from the dominance of low-frequency features in the dataset, causing the model's attention to disproportionately focus on them. To tackle this issue, we propose a frequency domain patch-based MLP model called FP-MLP, which partitions the frequency series into small patches, thereby balancing the representation of high and low-frequency features across different bands. This approach enables the model to fully capture hidden features in high-frequency data, thus improving predictive accuracy. Extensive experiments demonstrate that the FP-MLP model consistently outperforms various state-of-the-art baseline models with stable performance. For instance, on the Alibaba dataset, compared to the best baseline model, the FP-MLP model reduces the Mean Squared Error (MSE) by 8% and the Mean Absolute Error (MAE) by 17%; meanwhile, it also achieves competitive results on the Google. Yao Lu 0021, Yongjing Shang, Jie Cui 0004, Hong Zhong 0001, Lu Liu 0001, Geyong Min |
IEEE Trans. Cloud Comput. | 3 |
| 2025 | STiFF-Net: Spatial-Temporal Insights via Image-Driven Feature Fusion for Workload Prediction in Intelligent Cloud Data CentersabstractThe rapid growth of Cloud Computing, Artificial Intelligence, and Big Data cloud workloads, intensifying resource contention, operational costs, and carbon emissions due to underutilized data centers. Accurate workload prediction is thus for proactive resource management and improved utilization of Cloud data centers. However, traditional statistical and machine learning methods struggle with the dynamic, high-dimensional, and heterogeneous nature of cloud workloads. This paper proposes STiFF, a novel prediction framework that, for the first time in workload forecasting, transforms time series data into graph-based image representations to capture spatiotemporal dependencies. STiFF integrates three key modules: (1) a Two-Dimensional Moving Average Decomposition (2D-MAD) for trend smoothing, (2) a Global-Local Feature Extraction (GLE) module combining CNNs and Transformers for hierarchical pattern learning, and (3) a Multi-modal Feature Fusion (MFF) module leveraging attention mechanisms and partial prior knowledge. Extensive experiments on four real-world datasets demonstrate that STiFF achieves an average error reduction of 62.14%, with a maximum of 90.84%, and outperforms state-of-the-art methods in 84.375% of the evaluated cases. Yao Lu 0021, Xiaoqin Yu, Jie Cui 0004, Hong Zhong 0001, Lu Liu 0001, Geyong Min |
IEEE Trans. Cloud Comput. | 5 |
| 2025 | Blockchain-Assisted Revocable Cross-Domain Authentication for Vehicular Ad-Hoc NetworksabstractWith the rapid development of vehicular ad-hoc networks (VANETs) and the increasing diversification of user demands, interactions between different management domains have become more frequent. Identity authentication is an effective way to establish cross-domain trust and secure communication. However, the existing cross-domain authentication schemes of VANETs are limited to the same management or authentication technology for each domain and rely on centralized cross-domain identity management. Even distributed management solutions encounter latency sensitivity, security and privacy challenges. To address these challenges, we propose a blockchain-assisted revocable cross-domain authentication scheme for VANETs. The proposed scheme can establish trust between domain entities by deploying different authentication methods and using distributed management to avoid single-point failures. In addition, the scheme can revoke the identity of malicious vehicles by updating the group public key, thereby ensuring the security and privacy of cross-domain Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communication. This design avoids the additional impacts of blockchain technology constraints on the high mobility and real-time requirements of VANETs. Security analysis and performance evaluation show that our scheme can resist more attacks and has better security than other related schemes while also achieving a better balance between communication and computational cost. Ru Li 0005, Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Hong Zhong 0001, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | DBCSec: DBC File-Guided Secure Communication Mechanism for CAN-FD BusabstractThe network architecture of modern vehicles is composed of multiple communication protocols and electronic control units (ECU). Compared to the widely used protocol of Controller Area Network (CAN), CAN with Flexible Data-Rate (CAN-FD) protocol is suitable for applications requiring higher data throughput. However, the CAN-FD bus is vulnerable to intrusion by external attackers. Nowadays, several secure mechanisms have been proposed to protect the security of in-vehicle data. However, there are still two issues: 1) Most schemes use a centralized controller for key distribution, which can easily lead to a single point of failure; 2) The existing key management modes are not suitable for real-world CAN-FD networks in vehicle manufacturing. To address these issues, we propose a lightweight semi-decentralized scheme based on Database CAN (DBC) files to secure in-vehicle communication. ECUs are grouped on the send-receive relationships set in the DBC file, considering both the communication mode and sending efficiency. Furthermore, the proposed scheme overcomes reliance on long-term keys. Moreover, the security is analyzed by the random oracle model. The performance analysis is evaluated on microcontroller units (MCU) STM32H743IIT and Raspberry Pi 3B. The proposed scheme optimizes the computational costs of authentication, key agreement, and secure communication stages by up to 97.89%, 99.95%, and 82.35%, and optimizes the communication costs by up to 75.52%, 98.42%, and 29.41% compared to existing methods. Simulation experiments demonstrate that the bus load of the scheme increases by up to 9.84% compared to the baseline network. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Lu Wei 0003, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | LSHSC: Lightweight and Secure Handover Scheme With Conditional Privacy-Preserving for Group-Based SDVNabstractIntroducing the SDN paradigm can further improve the handover efficiency of mobile nodes, and researchers have proposed corresponding solutions to the security problems in the handover process. Some existing cryptography-based schemes delegate authentication to the fog nodes to accelerate the handover process, however, the computation and communication overheads are not low enough to satisfy the requirements of delay-sensitive vehicular applications. To realize secure handover of vehicles in software defined vehicular networks (SDVN), in this paper, based on symmetric cryptography, we propose a lightweight and secure handover scheme with conditional privacy-preserving for group-based SDVN. The handover authentication only involves lightweight operation, without based on elliptic curve cryptography or involving complex bilinear pairing operations. After successfully authenticating with the SDN controller, the vehicle can directly authenticate with the fog nodes in the same group. The polynomial and one-way hash chain are used to realize group key update. We use BAN logic and ProVerif to formally analyze and test the security of our scheme. The detailed security analyses show that the scheme can resist common types of attacks and meet the essential security and privacy requirements. Compared with other related and represented works, our scheme exhibits better performance in computation and communication overheads. Hong Zhong 0001, Jie Cui 0004, Irina Pavlovna Bolodurina, Chengjie Gu, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Backdoor Attack on Encryption-Protected Vertical Federated LearningabstractVertical Federated Learning (VFL), as one of the key paradigms in federated learning, is commonly employed in scenarios where multiple parties share the same sample set but possess different features for these samples. Previous studies have demonstrated that VFL is vulnerable to backdoor attacks due to its inherent characteristics. However, the issue of backdoor attacks in encryption-protected VFL has been underexplored. In such scenarios, adversaries cannot directly access plaintext sample-level gradients, which seemingly offers enhanced security for VFL. Adversaries are restricted to leveraging their own bottom model and a small subset of auxiliary samples to conduct backdoor attacks, rendering many existing attack strategies ineffective. In this paper, we propose a powerful backdoor attack: BAEVFL (Backdoor Attack on Encryption-protected Vertical federated Learning), which is executed through three key stages: pseudo-label inference, trigger optimization, and backdoor poisoning. Our attack can be successfully launched without access to plaintext gradient information or auxiliary samples including all classes. Instead, it requires only the adversary’s bottom model and a minimal set of target class samples. We conducted extensive experiments demonstrating that BAEVFL outperforms various state-of-the-art baseline methods, achieving over 98% ASR on four benchmark datasets, while the impact on model utility remained below 0.3%. Additionally, we evaluated the effectiveness of current representative defense methods against our BAEVFL. The results indicate that existing defenses fail to strike a balance between defense and utility, and we provide key suggestions for potential improvements to these methods. The BAEVFL, with its stealth and effectiveness, exposes significant security vulnerabilities in encryption-protected VFL, underscoring the urgent need for future research on robust defense mechanisms for this paradigm. Jie Cui 0004, Hong Zhong 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | RRMAC: A Multi-Data Owner Access Control Scheme With Robust Revocation for Co-Owned Data SharingabstractDue to the rising requirement for data sharing, multi-data owner access control schemes have emerged, where a single data file is jointly owned by multiple data owners. Since the shared files contain information from multiple data owners, it is crucial to revoke malicious users to minimize harm when data leakage occurs. However, current multi-data owner solutions typically rely on a single data owner to encrypt and share data and fail to provide robust user revocation. When revocation is managed by a single entity, it may fail to protect the rights of all data owners and can introduce a single point of failure in multi-data owner settings. On the other hand, if revocation requires the participation of all data owners, user access may fail if some owners are offline or compromised. To address these issues, we propose a robust multi-data owner access control scheme with efficient user revocation. We construct a secret resharing protocol based on secret sharing technology and proposed a multi-data owner access control scheme. Only users who obtain a sufficient number of private keys can decrypt the ciphertext. To achieve multi-owner controlled revocation, we use key splitting to divide the user’s private key into an authorization key and an update key and embed a period into the update keys. During user revocation, the cloud updates the ciphertext and the data user can decrypt the ciphertext without obtaining the update keys of all data owners. The thorough performance analysis shows that the overhead of the proposed scheme is acceptable. Specifically, the proposed scheme takes approximately 0.5 seconds to encrypt, and with preprocessing, this time is reduced to 0.06 seconds, while decryption requires around 0.15 seconds on the Raspberry Pi. Hong Zhong 0001, Jie Cui 0004, Chengjie Gu, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | BAST: Blockchain-Assisted Secure and Traceable Data Sharing Scheme for Vehicular NetworksabstractIn vehicular networks, caching service content on edge servers (ESs) is a widely accepted strategy for promptly responding to vehicle requests, reducing communication overhead, and improving service experience. However, implementing such an architecture requires addressing the challenges associated with ES response data reliability and communication security. In this study, to tackle the ES response data reliability issue, a blockchain-assisted threshold signature scheme for cache-based vehicular networks is proposed. The scheme utilizes a threshold mechanism to sign the data broadcast by the ES, incorporates blockchain to trace malicious signers, and avoids the shortcomings and limitations associated with idealized assumptions for the ES in existing data-sharing schemes. Moreover, considering the communication security and high-speed mobility of vehicles, using the non-interactive signatures of knowledge based on the Σ-protocol, a secure and efficient message authentication scheme for vehicles and ESs is provided. Through rigorous security proofs and comprehensive analyses, our scheme satisfies the communication security requirements of vehicular networks. By leveraging the JPBC library for performance analysis, the proposed scheme demonstrates advantages as concerns both computation and communication overheads compared to related schemes. Moreover, we implemented the proposed scheme on an Ethereum test network (i.e., Goerli) to validate its feasibility. Xinzhong Liu 0002, Jie Cui 0004, Jing Zhang 0024, Rongwang Yin, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Detecting Android Malware by Visualizing App Behaviors From Multiple Complementary ViewsabstractDeep learning has emerged as a promising technology for achieving Android malware detection. To further unleash its detection potentials, software visualization can be integrated for analyzing the details of app behaviors clearly. However, facing increasingly sophisticated malware, existing visualization-based methods, analyzing from one or randomly-selected few views, can only detect limited attack types. We propose and implement LensDroid, a novel technique that detects Android malware by visualizing app behaviors from multiple complementary views. Our goal is to harness the power of combining deep learning and software visualization to automatically capture and aggregate high-level features that are not inherently linked, thereby revealing hidden maliciousness of Android app behaviors. To thoroughly comprehend the details of apps, we visualize app behaviors from three related but distinct views of behavioral sensitivities, operational contexts and supported environments. We then extract high-order semantics based on the views accordingly. To exploit semantic complementarity of the views, we design a deep neural network based model for fusing the visualized features from local to global based on their contributions to downstream tasks. A comprehensive comparison with six baseline techniques is performed on datasets of more than 51K apps in three real-world typical scenarios, including overall threats, app evolution and zero-day malware. The experimental results show that the overall effectiveness of LensDroid is better than the baseline techniques. We also validate the complementarity of the views and demonstrate that the multi-view fusion in LensDroid enhances Android malware detection. Zhaoyi Meng, Jiale Zhang 0002, Wansen Wang 0001, Wenchao Huang 0001, Jie Cui 0004, Hong Zhong 0001, Yan Xiong 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | A Blockchain-Driven Hierarchical Authentication and Key Agreement Scheme for VANETs With Cloud-Edge CollaborationabstractVehicular ad-hoc networks (VANETs) are the cornerstone of intelligent transportation systems, designed to enhance road safety and traffic efficiency. However, their dynamic and distributed nature poses significant challenges for secure communication and key management. Traditional authentication and key agreement (AKA) schemes for VANETs often rely on centralized trust architectures, resulting in system security and reliability issues. Despite the introduction of distributed trust architecture schemes that have appeared recently, they fail to solve one issue, i.e., how the key agreement requests can be authenticated in the distributed communication scenario where the authentication authorities are all non-full-credible and have differentiated credibility. To solve this issue, we propose a hierarchical AKA scheme for VANETs with cloud-edge collaboration powered by consortium blockchain. Specifically, we first proposed a vehicle reputation evaluation algorithm for evaluating the trustworthiness of the vehicle, so that the AKA requests sent by vehicles with low reputation will be rejected. On the basis of the reputation evaluation algorithm, we proposed a hierarchical threshold-based AKA scheme for VANETs where cloud servers (CSs) and edge servers (ESs) can collaboratively authenticate the AKA requests, so that the authentication service can be trusted upon getting authenticated by a series of valid combinations of CSs and ESs. Both formal and informal security proofs validate the security of our proposed scheme, and simulation experiments demonstrate its efficiency. Lu Wei 0003, Yongjuan Zhang, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Efficient Revocable Cross-Domain Anonymous Authentication Scheme for IIoTabstractThe rapid evolution of the Industrial Internet of Things (IIoT) has necessitated increased device interactions across various management domains. This entails devices from different domains collaborating on the same production task. This poses significant challenges for the dynamics of cross-domain authentication schemes. Traditional cross-domain authentication schemes struggle to support seamless switching between domains and face difficulties when accommodating devices that join and leave the same domain. Moreover, these schemes suffer from intricate interactions and suboptimal efficiency. To address these issues, we propose a dynamic group signature scheme based on a dynamic accumulator and a non-interactive zero-knowledge proof. We integrated this scheme with blockchain technology to construct an efficient revocation cross-domain authentication scheme. The proposed scheme enables cross-domain anonymous authentication with simple interactions and provides an efficient revocation function for illegal devices. This approach ensures conditional privacy-preserving and enables efficient member joining and exiting through a dynamic accumulator. It effectively addresses the dynamic requirements of devices involved in IIoT production and manufacturing processes. We prove the security of the proposed scheme using a random Oracle model and conduct thorough analyses to verify its resistance against various attacks. Furthermore, the experimental results demonstrate that the proposed scheme achieves better performance in terms of computational and communication costs. Mingwei Zeng, Jie Cui 0004, Qingyang Zhang 0001, Hong Zhong 0001, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | A Decentralized Threshold Credential Management With Fine-Grained Authentication for VANETsabstractIn Vehicular Ad-hoc Networks (VANETs), vehicles must authenticate their identities before accessing services. However, existing authentication schemes based on anonymous credentials still face single-point failure in multi-authority scenarios. In addition, in traditional anonymous credential schemes, the public key of credential authority is used directly to verify the credential, which may increase the risk of vehicle privacy being misused. To address these issues, we propose a decentralized threshold credential management system with fine-grained authentication for VANETs. The decentralized credential management architecture is proposed for VANETs with multiple credential authorities, each credential authority consists of multiple credential managers who issue credentials using the threshold mechanism, effectively solving the single-point failure. Based on this architecture, we design a fine-grained, privacy-preserving authentication scheme that allows vehicles to autonomously perform selective attribute disclosure, credential aggregation, and randomization before requesting verification from the Cloud Service Provider, thereby achieving a balance between privacy preservation and authentication efficiency. The security proofs and analysis show that our scheme satisfies the target security properties. Performance evaluations indicate that our scheme enables efficient, flexible credential management and authentication in VANETs while ensuring privacy preservation. Jing Zhang 0024, Xin Wang 0225, Jie Cui 0004, Ru Li 0005, Hong Zhong 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | False Message Detection System for VANETs: A Reputation Evaluation Method Based on Voting MechanismabstractVehicular ad hoc networks (VANETs) enable vehicles to engage in vehicle-to-vehicle and vehicle-to-infrastructure communications to enhance driving safety. However, the open nature of the network and the uncertainty of information sources make VANETs vulnerable to false message attacks, potentially causing severe traffic accidents. Existing false-message detection systems suffer from high false alarm rates and high resource consumption. To address these challenges, we propose a false message attack detection system based on a software-defined network architecture that can efficiently and accurately detect false message attacks with minimal consumption of system resources. The system aims to detect emergency and normal beacon messages broadcast by vehicles, construct an automotive reputation evaluation system using the voting mechanism of the Byzantine consensus, and introduce an XGBoost-based traffic event classifier to improve classification accuracy. Experimental results show that the system can reliably assess vehicle reputation levels, effectively defend against conspiracy attacks, and perform well in intrusion detection. Jie Cui 0004, Danting Yu, Jing Zhang 0024, Lu Wei 0003, Xianfeng Xie, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2025 | Sustainable Learning-Based Intrusion Detection System for VANETsabstractVehicular intrusion detection systems (VIDSs) play a crucial role in protecting the security of vehicular ad hoc networks (VANETs). Recently, numerous researchers have proposed effective vehicular intrusion detection systems to protect the security of VANETs. However, some existing vehicle intrusion systems are susceptible to catastrophic forgetfulness in the process of implementing incremental updates to target novel attacks. Other solutions lack consideration for the continuous updating capabilities of vehicle intrusion detection systems. It is worth mentioning that in the real world, the network attacks suffered by vehicles are not constant, and fixed intrusion detection systems may struggle to detect new network attacks effectively. To address these challenges, we propose an incremental learning-based vehicular intrusion detection scheme that supports continuous updating of the intrusion detection system. Specifically, we design a sample gradient optimization algorithm to enhance the data quality of training samples. Additionally, we utilize locally stored historical data to balance the number of old attack classes for model distillation, thus mitigating the problem of forgetting the old classes as the model learns new classes. The comprehensive experimental results on the CICIDS2017, TON_IOT, and Veremi datasets demonstrate that the proposed vehicular intrusion detection system maintains superior detection accuracy during continuous updating and surpasses the state-of-the-art solution. Lu Wei 0003, Hulin Jin, Jie Cui 0004, Jiaxin Li 0001, Debiao He |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2025 | Reputation System-Based Vehicle Violation Reporting Service With Invalid Signature Identification in VANETsabstractOwing to frequent traffic accidents, the violation reporting service is a promising method to enhance road safety in vehicular ad hoc networks (VANETs). However, to implement such a service, it is critical to ensure security, privacy, and efficiency when vehicles send messages to roadside units (RSU). In this study, to address these issues, a vehicle violation reporting service is proposed using reputation systems and a physically unclonable function. The proposed scheme ensures secure authentication between vehicles and RSUs, facilitates an efficient search for invalid signatures, and overcomes the limitations present in ID-based conditional privacy-preserving authentication schemes. Moreover, considering the dynamic VANET environment, the distribution of invalid signatures may vary across multiple scenarios. Therefore, a fault-tolerant mechanism is proposed to ensure the robustness of this approach. Security proof with the random oracle model and detailed security analysis proved that the scheme could satisfy the security requirements of VANETs. Our scheme outperforms related approaches in terms of authentication overhead and the identification of invalid signatures, achieving superior performance in both aspects. Jing Zhang 0024, Chengzhi Xia, Jie Cui 0004, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2025 | Robust Intrusion Detection System for Vehicular Networks: A Federated Learning Approach Based on Representative Client SelectionabstractThe rapid development of network technology has allowed numerous vehicular applications to be deployed in vehicles, thereby enriching the driving experience of users. However, the openness of vehicular networks enables attackers to launch network attacks on vehicles through network ports, leading to the destruction of vehicular networks. To develop an intrusion detection system suitable for distributed vehicular networks, researchers have utilized federated learning to train detection models. Nevertheless, most federated learning-based vehicular intrusion detection systems seldom consider rapidly updating the detection model and fail to detect unknown attacks effectively. In this study, we propose a federated learning-based vehicular intrusion detection system that fully considers the traffic characteristics of multiple network regions and selects representative clients to participate in model aggregation, thereby accelerating the convergence of the global model. Furthermore, to enhance the robustness of the detection system, we utilize extreme value theory and multilayer activation vectors to construct an unknown attack discriminator that can determine whether a network flow is an unknown attack. Comprehensive experiments on three open datasets demonstrate that the proposed intrusion detection system can quickly update and effectively identify known/unknown attacks in open vehicular networks Chunyang Fan, Jie Cui 0004, Hulin Jin, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | Security-Enhanced Data Sharing via Efficient Sanitization for VANETsabstractWith the widespread deployment of vehicular ad-hoc networks (VANETs), data sharing has garnered considerable attention as a core feature of VANETs. Attribute-based proxy re-encryption (ABPRE) enables fine-grained access control and provides flexible ciphertext updates. The initially authorized vehicle generates the re-encryption key to enable ciphertext-to-ciphertext conversion in the cloud, allowing ciphertext to be shared with new recipients. However, initially authorized vehicles may not always be trustworthy and could share data with malicious receivers. In addition, the computation and communication overhead of ABPRE hinders its widespread application in VANETs. To address these issues, we propose a lightweight sanitizable scheme for edge-assisted VANETs based on ABPRE. In this scheme, the re-encryption key is verified by a sanitizer, to prevent the data from being shared with malicious data receivers. In addition, key-splitting techniques and edge computing are employed to reduce the communication and computation overhead of re-encryption. A comprehensive security analysis and performance evaluation demonstrate that the proposed scheme is efficient and practical. Hong Zhong 0001, Jie Cui 0004, Li Wang 0139, Jing Zhang 0024, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | SynBoost: Robust Text Generation Model via Beam Search and Synonym-Driven Boosting
Mengdie Xia, Jie Cui 0004 |
ACISP (3) | 3 |
| 2024 | Improved PBFT Consensus Based on Reputation System in Vehicle NetworkabstractBlockchain technology is a decentralized distributed database technology, which greatly improves the security and credibility of the data exchange process through decentralization. A great deal of research has already been conducted on combining blockchain and vehicular ad-hoc networks(VANETs) applications to solve the problems of opaque user transactions, data tampering, and insufficient motivation of participating parties. However, in the large-scale VANETs, the commonly used blockchain consensus mechanism PBFT suffers from poor scalability, high communication volume, and insufficient control of node behaviour. Therefore, in this paper, an improved consensus mechanism N-PBFT is designed for the field of VANETs based on the construction of vehicle trust management system. The improved consensus mechanism N-PBFT solves the problems of node identity peering, poor scalability, and high communication volume. After experimental testing, the proposed reputation system is able to effectively manage the information of the VANETs. And the improved PBFT consensus algorithm has a significant performance improvement over the traditional PBFT, SG-PBFT and RIPPB in terms of both throughput and latency. Jing Zhang 0024, Peiyv Yang, Jie Cui 0004, Lu Wei 0003, Hong Zhong 0001 |
BDCAT | 3 |
| 2024 | IDLD: Interlocked Dual-Circle Latch Design with Low Cost and Triple-Node-Upset-Recovery for Aerospace ApplicationsabstractModern powerful CMOS chips are usually highly integrated and implemented with aggressively shrunk technology nodes. In radiation environment, under charge-sharing mechanism, one particle striking can simultaneously impact multiple nodes causing double-node-upsets (DNUs) and triple-node-upsets (TNUs). In this paper, we propose an Interlocked Dual-circle Latch Design, namely IDLD, with low cost and TNU recovery for aerospace applications. IDLD consists of four transmission gates and twelve 2-input C-elements (CEs) implemented in 22nm CMOS process. Simulation results demonstrate the complete TNU recovery as well as cost-effectiveness for the proposed IDLD latch. Aibin Yan, Jie Cui 0004, Tianming Ni, Patrick Girard 0001, Xiaoqing Wen |
ACM Great Lakes Symposium on VLSI | 5 |
| 2024 | Enabling Efficient, Verifiable, and Secure Conjunctive Keyword Search in Hybrid-Storage BlockchainsabstractBlockchain has emerged as a prevailing paradigm for decentralized applications due to its reliability and transparency. To scale up retrieval services, a common strategy is to use a hybrid storage model, where on-chain storage is responsible for small metadata and off-chain storage is for outsourced raw data. However, data security and result authenticity are ongoing challenges in this scenario, and little work has been done due to the difficulty of combining result verification and privacy preservation, especially for dynamic updates while supporting forward privacy. In this paper, we formally define the problem of efficient, verifiable, and secure conjunctive keyword search in hybrid-storage blockchains (vsChain) and propose a novel hybrid index that achieves efficient query and verification while supporting dynamic updates with forward privacy guarantee. Finally, we provide empirical evaluations using real and synthetic datasets to demonstrate the feasibility of our proposed scheme. Ningning Cui, Dong Wang 0057, Jianxin Li 0001, Huaijie Zhu, Xiaochun Yang 0001, Jianliang Xu, Jie Cui 0004, Hong Zhong 0001 |
ICDE | 7 |
| 2024 | Textual Backdoor Attack via Keyword Positioning
Fangfang Mao, Hulin Jin, Jie Cui 0004 |
ICIC (10) | 4 |
| 2024 | Nonvolatile and SEU-Recoverable Latch Based on FeFET and CMOS for Energy-Harvesting DevicesabstractNonvolatile memories are widely used in emerging energy-harvesting Internet-of-Things (IoT) applications, and nonvolatile memories constructed from FeFET devices hold great promise. This paper presents a nonvolatile and single-event-upset (SEU)-recoverable latch based on FeFET and CMOS for energyharvesting devices. The latch uses n-type FeFET devices to provide nonvolatility without any additional control signals. Moreover, since the soft error problem has become increasingly severe, radiation hardening by design gains a great attention as a promising approach to mitigate the reliability issue. The latch uses feedback interlocked loops with n-type FeFETs and C-elements, enabling it to provide nonvolatility and SEU-recovery simultaneously. Simulation results with Candence Virtuoso verifies that the proposed latch design has correct functioning with excellent performance compared to the state-of-the-art designs. Aibin Yan, Zhuoyuan Lin, Guangzhu Liu, Qingyang Zhang 0001, Zhengfeng Huang, Jie Cui 0004, Xiaoqing Wen, Patrick Girard 0001 |
ISCAS | 6 |
| 2024 | Variable-length Field Extraction for Unknown Binary Network ProtocolsabstractProtocol reverse engineering can infer the specification or behaviour of unknown network protocols, which is essential in analyzing and evaluating network functionality and performance. There are variable-length fields in many network protocols, and the field boundaries significantly impact subsequent analysis as well as the inferred results. The existing works focus on extracting protocol keyword fields without considering whether the fields' length is variable. In this paper, we propose BERRY for extracting variable-length field of unknown binary network protocols from static traces. At first, BERRY clusters the same type of messages from the input trace and extracts their headers with the help of the information entropy. Then, it combines the feature of message length and location-aware association analysis with to locate candidate variable fields. Finally, it infers the variable-length field by the sequence alignment. We evaluate BERRY with BinaryInferno using six groups of real network protocol traces. BERRY exhibits high accuracy and reliability on the metrics of precision, recall, and F1-score while extracting variable-length fields. It also performs similar results to the Binaryinferno on extracting all the fields. Xiuwen Sun, Jie Cui 0004, Hong Zhong 0001 |
LCN | 4 |
| 2024 | Verifiable Data Sharing Based on Autonomous Path Proxy Re-Encryption for Industrial Internet of ThingsabstractIn the Industrial Internet of Things (IIoT), massive amounts of data are generated and shared among different industrial entities, and it is crucial to realize the security and flexibility of data sharing. Autonomous path proxy re-encryption technology enables the autonomous creation of an ordered data-sharing path as specified by the data owner, supporting multi-hop re-encryption. However, the security of this technology requires further enhancement. Therefore, we propose a verifiable data-sharing scheme. To prevent data leakage due to collusion between the proxy and users, we introduce blockchain technology to supervise the decryption behavior of users in the autonomous path. Second, we verify the proxy re-encryption computation, ensuring its validity. Finally, a security analysis demonstrates that the proposed scheme meets the security requirements. Furthermore, we evaluated the performance of the proposed scheme, and the results show that our scheme has only increased less overhead, but has enhanced security. Jie Cui 0004, Xiaoxi Sun, Qingyang Zhang 0001, Fengqun Wang, Hong Zhong 0001 |
MSN | 1 |
| 2024 | Multi-Authority Ciphertext-Policy Attribute-based Encryption with Hidden Policy for Securing Internet-of-VehiclesabstractWith the rapid development of the Internet-of-Vehicles (IoV) technologies, security and privacy issues associated with IoV data sharing have become increasingly prominent. Although attribute-based encryption (ABE) schemes offer effective solutions to these problems, the prevalent single-point failure vulnerabilities and risks of user privacy leakage in existing ABE schemes must be addressed. To this end, an original hidden policy scheme based on multi-authority ciphertext policy ABE is proposed. This scheme validates users by introducing multiple attribute authorities and generating intermediate attribute keys, effectively dispersing single-point performance pressure. Simultaneously, partial policy-hiding techniques are developed to ensure efficient system operation while protecting user privacy. Furthermore, this scheme introduces a central authority to track potentially malicious attribute authorities, preventing them from continuously generating incorrect attribute intermediate keys, thereby maintaining the overall security of the system. Additionally, by updating and revoking attribute versions, a flexible attribute revocation mechanism is achieved to further enhance system flexibility. Through in-depth security and performance analyses, the scheme is proven to be both secure and efficient for securing IoV. Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Hong Zhong 0001, Geyong Min |
TrustCom | 1 |
| 2024 | Cross-Domain Authentication Scheme for Vehicles Based on Given Virtual IdentitiesabstractThe advancement of intelligent transportation systems has enhanced both vehicle ad hoc networks (VANETs) and road safety. However, traditional cross-domain scenarios in VANETs face challenges such as the computational burden of identity and message authentication, as well as privacy breaches. In this study, to mitigate the issues surrounding communication security and the significant computational overhead within traditional cross-domain scenarios in VANETs, we propose a certificate-based cross-domain authentication scheme specifically tailored for VANETs. Moreover, considering the inter-domain vehicle authentication challenges, the scheme introduces an efficient batch verification mechanism suitable for dynamic multi-vehicle cross-domain scenarios. To mitigate the potential single point of failure, a two-way synchronization database mechanism is presented, ensuring uninterrupted operations in case of primary database failure. Moreover, privacy protection for vehicles is enhanced through the use of virtual identities. Through rigorous security proofs and detailed security analyses, we demonstrate that the scheme meets the security requirements of vehicular networks and can resist more security attacks. Moreover, performance analysis highlights its superiority over related advanced schemes in cross-domain VANET scenarios. Through performance evaluation using the JPBC library and comparison with relevant schemes, the proposed solution demonstrated superior results in terms of communication and computational overhead. Jing Zhang 0024, Xiyang Wei, Yibo Wang 0017, Jie Cui 0004 |
IEEE Internet Things J. | 5 |
| 2024 | Efficient Blockchain-Based Mutual Authentication and Session Key Agreement for Cross-Domain IIoTabstractSeveral studies have introduced edge computing and blockchain into the Industrial Internet of Things (IIoT) to satisfy the requirements of delay-sensitive applications and support cross-domain authentication. Although there have been many protocols to ensure the security and privacy of devices in the IIoT, existing protocols still suffer from problems. Updating keys and pseudonyms of devices by a trusted third party (e.g., certificate authority) will cause high communication and computation overhead, especially when the number of devices becomes much larger. Furthermore, an increasing number of transactions also cause high storage overhead on the blockchain. Therefore, we propose a blockchain-based cross-domain authentication protocol. Specifically, we propose a privacy-preserving method based on pseudonyms that offloads the task of generating pseudonyms from a trusted third party to edge servers to ensure the conditional anonymity of the devices. The device is allowed to request pseudonyms in bulk to reduce the number of transactions, thus reducing the storage overhead on the blockchain. Security analysis and experimental results demonstrate that our scheme achieves an efficient tradeoff between security and efficiency. Jie Cui 0004, Yihu Zhu, Hong Zhong 0001, Qingyang Zhang 0001, Chengjie Gu, Debiao He |
IEEE Internet Things J. | 1 |
| 2024 | MM-SDVN: Efficient Mobility Management Scheme for Optimal Network Handover in Software-Defined Vehicular NetworkabstractProviding high-quality network services for vehicles is a challenge because of the fast-moving character of the vehicles. To address the shortcomings of traditional centralized and distributed mobility management schemes, such as triangular routing and poor scalability, many researchers use software-defined networking (SDN) to build mobility management schemes. However, most schemes rarely consider how to select the optimal base station for high-speed mobile vehicles in a dense network environment. Only using the received signal strength to select the base station tends to cause a ping-pong effect. Moreover, due to the high mobility of vehicles, the routing updates between vehicles and communication nodes will frequently occur, resulting in the significant consumption of network resources. In this article, we propose a mobility management scheme MM-SDVN based on SDN for vehicles. MM-SDVN uses deep Q-network to construct the optimal base station selection model, designs a multipath prefix matching algorithm to reduce the cost of route update, and realizes the seamless handover of vehicles in SDN intradomain and interdomain scenarios. The comprehensive experimental results show that MM-SDVN greatly improves the network service quality and handover performance of the vehicle. Compared to the other schemes, MM-SDVN improved vehicle throughput by 6.14%, 8.85%, and 10.34%, respectively. Chunyang Fan, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He |
IEEE Internet Things J. | 2 |
| 2024 | Lightweight and Secure Data Sharing Based on Proxy Re-Encryption for Blockchain-Enabled Industrial Internet of ThingsabstractIn the Industrial Internet of Things (IIoT), data sharing is crucial for promoting the intelligent development of industrial production. To achieve effective data supervision, introducing blockchain into traditional cloud-based data-sharing frameworks has attracted widespread attention. However, existing blockchain-based data-sharing schemes still have issues with security and efficiency. Therefore, we propose a blockchain-enabled data-sharing scheme based on proxy re-encryption. First, the scheme considers both storage and access authentication, guaranteeing data sources’ trustworthiness and preventing data misuse. Second, the scheme uses an on-chain and off-chain cooperative storage mechanism, saving the storage resources of the blockchain. Third, the scheme supports data packing, which effectively improves data storage efficiency. The security analysis shows that our scheme satisfies the security requirements. Finally, we build a blockchain platform using the hyperledger fabric. The performance evaluation shows that our scheme is more advantageous regarding computational overhead than other related schemes. Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Chengjie Gu, Hong Zhong 0001 |
IEEE Internet Things J. | 2 |
| 2024 | Revocable and Efficient Blockchain-Based Fine-Grained Access Control Against EDoS Attacks in Cloud StorageabstractUsers have become accustomed to storing data on the cloud using ciphertext policy attribute-based encryption (CP-ABE) for fine-grained access control. However, this encryption method does not consider the ability of malicious users to launch thousands of file download requests when launching an economic denial of sustainability attack (EDoS), which may be more expensive for data owners. Existing solutions typically use a cloud server to verify the download permissions of the data users. However, cloud servers are not completely trusted and cloud server providers and colluding data users can still launch an EDoS attack. With our scheme, using CP-ABE, a blockchain is introduced for verifying the download permission of data users. In addition, we propose a new mechanism to solve the problem of malicious user revocations under EDoS attacks by updating the ciphertext and symmetric encryption technology. A formal security proof has demonstrated that the proposed scheme is suitable for plaintext attack security. Theoretical and experimental analyses show that our scheme performs more efficiently than previous methods. Qingyang Zhang 0001, Chang Xu 0015, Hong Zhong 0001, Chengjie Gu, Jie Cui 0004 |
IEEE Trans. Computers | 5 |
| 2024 | MURLAV: A Multiple-Node-Upset Recovery Latch and Algorithm-Based Verification MethodabstractIn advanced CMOS technologies, integrated circuits are sensitive to multiple-node-upsets (MNUs) induced in harsh radiation environments. The existing verification of the reliability of latches highly relies on electronic design automation (EDA) tools considering complex error-injection scenarios. In this paper, we propose a novel latch, namely MURLAV, protected against quadruple node-upsets (QNUs) induced in harsh radiation environments, as well as an algorithmic error-recovery verification method. The latch provides complete recovery from all QNUs with a formed redundant structure. The algorithm can simplify the verification process and demonstrate the QNU recovery for the proposed MURLAV latch. Simulation results demonstrate that the proposed latch can recover from any QNU and that it has lower area and delay overhead. Compared with existing latches of the same type, the proposed MURLAV latch achieves an overhead reduction of 34% in silicon area and 15% in delay on average at the cost of moderate power consumption. Aibin Yan, Zhongyu Gao, Zhengfeng Huang, Tianming Ni, Jie Cui 0004, Patrick Girard 0001, Xiaoqing Wen |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 7 |
| 2024 | DSChain: A Blockchain System for Complete Lifecycle Security of Data in Internet of ThingsabstractThere is a growing concern about the complete lifecycle security of data in Internet of Things (IoT). This may cause privacy and trust problems for users regarding data sources, data storage, and access control for data sharing. Blockchain is a valuable solution to the above problems through distributed ledger technology, and it has been widely applied in various fields such as public services, finance, and IoT. However, the data in IoT are characterized by a large quantity, large capacity, and timely response, and existing blockchain systems only partially resolve them for data security and performance. We propose DSChain for IoT data security to address the challenges mentioned above. Our system uses a certificateless signature to ensure a trusted data source and public auditing to ensure the integrity of stored data while using ciphertext-policy attribute-based encryption to control access to shared data. Moreover, we propose a packaging mechanism based on the Merkle Hash Tree that effectively improves system performance. We implement the DSChain and provide a detailed analysis of performance and security. The experimental results indicate that DSChain can achieve approximately 1,035 transactions per second on a single peer and is scalable. Jie Cui 0004, Yatao Li, Qingyang Zhang 0001, Hong Zhong 0001, Chengjie Gu, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Blockchain-Based Lightweight Message Authentication for Edge-Assisted Cross-Domain Industrial Internet of ThingsabstractIn edge-assisted cross-domain Industrial Internet of Things (IIoT), blockchain-based authentication is an effective way to build cross-domain trust and secure cross-domain data. However, existing authentication schemes still have serious challenges in terms of efficiency and security. In this paper, we propose a blockchain-based lightweight message authentication scheme. First, to address efficiency challenges, we build a blockchain-enabled edge-assisted lightweight authentication framework. This framework uses edge servers to assist smart devices in achieving cross-domain authentication and effectively reduce redundant interactions between entities. Second, to resolve the security challenges, we design a lightweight message authentication algorithm for cross-domain IIoT. The algorithm guarantees message security with low computational overhead and is suitable for multi-receiver cross-domain IIoT. The security proof and analysis demonstrate that the proposed scheme is secure under the random oracle model and can resist various attacks. The performance evaluation shows that our proposed scheme is superior in terms of computation and communication overhead when compared with other related schemes. Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Chengjie Gu, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Efficient Fine-Grained Data Sharing Based on Proxy Re-Encryption in IIoTabstractWith the development of the industrial Internet of Things (IIoT), the amount of data generated by industrial manufacturing equipment will increase. To reduce the cost of data management while achieving secure data sharing, data owners generally upload the resulting ciphertexts to a cloud server after encrypting their data. Attribute-based encryption (ABE) is a valuable technology that implements fine-grained access control over shared information; however, its computational complexity is not suitable for resource-constrained IIoT devices, making it difficult to apply directly to an IIoT environment. To address this problem, we design a fine-grained data sharing scheme based on proxy re-encryption in IIoT. In the proposed scheme, data files are encrypted through an identity-based encryption and a data owner can authorize a semi-trusted proxy server to transform the ciphertext into an ABE ciphertext. This realizes fine-grained access control and decreases a data owner's computational cost in data sharing. In addition, the computational burden is outsourced to a cloud server, and users only need to perform simple computing operations. A formal security proof indicates the proposed scheme's selective chosen-plaintext attack security. Theoretical and experimental analyses illustrate that our construction is more efficient than previous schemes. Qingyang Zhang 0001, Yujie Fu, Jie Cui 0004, Debiao He, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Blockchain-Based Secure Cross-Domain Data Sharing for Edge-Assisted Industrial Internet of ThingsabstractIn the Industrial Internet of Things (IIoT), blockchain-based data-sharing frameworks can effectively build cross-domain trust and facilitate data sharing. However, secure data-sharing schemes are lacking for the IIoT scenario, in which smart devices cannot communicate across domains and can only access data through edge servers. In this study, we propose a lightweight and secure data-sharing scheme for the blockchain-enabled cross-domain IIoT, in which authorized smart devices can access cross-domain data anonymously. First, smart devices can dynamically generate pseudonyms by themselves and without the online participation of domain authorization centers, effectively reducing the storage overhead of smart devices and the workload of domain authorization centers. Second, the scheme combines broadcast encryption and proxy re-encryption techniques, which realize flexible data sharing across domains while protecting the privacy of smart devices. Detailed security proofs and analyses demonstrate that the proposed scheme is secure and resistant to various attacks. The performance analysis shows that our proposed scheme is efficient and performs better than related schemes. Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Hong Zhong 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Secure and Efficient User-Centric V2C Communication for Intelligent Cyber-Physical Transportation SystemabstractRecently, the concept of intelligent cyber-physical transportation systems (ICTS) has entered the vehicle network, providing more efficient, safe, and sustainable services by applying intelligent technology to the transportation system. Because the communication channel between the vehicle and the cloud service provider (CSP) is open and insecure. Therefore, we must construct a secure Vehicle-to-CSP (V2C) communication scheme to ensure the security of vehicle privacy data. Current communication schemes mainly have two limitations. One is that the user’s role in communication is not considered, and the other is that the computational and communication overhead are not sufficiently low to satisfy the low latency requirements. To address the deficiencies, we propose a user-centric V2C communication scheme. The primary key in the signature is concealed, which ensures the confidentiality of the user’s legal real identity. Its main steps, based on the extended Chebyshev chaotic map and hash function, reduce the computational and communication overhead in the process. The security proof and analysis show that our proposed scheme satisfies the security and privacy requirements. The performance analysis shows that our proposed scheme outperforms other related schemes. Jing Zhang 0024, Ruonan Ying, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Device-Side Lightweight Mutual Authentication and Key Agreement Scheme Based on Chameleon Hashing for Industrial Internet of ThingsabstractSeveral authentication and key agreement (AKA) schemes have been proposed to ensure secure communication in the Industrial Internet of Things (IIoT). However, most of these schemes face two primary problems. First, they cannot resist various attacks, such as impersonation and device capture attacks. Second, these schemes overlook the resource-constrained IIoT devices, failing to guarantee lightweight overhead for device operations. Therefore, we propose a novel and efficient AKA scheme. Utilizing the chameleon hash function and physical unclonable function, the proposed scheme implements a lightweight overhead for both authentication parties while maintaining the overhead of the gateway within a reasonable range. Furthermore, we implement device anonymity based on lightweight operations such as hash and XOR. In addition, we perform a rigorous security analysis using the widely accepted Real-Or-Random model, BAN logic, and Proverif tool. Finally, through heuristic analysis and experiments, we substantiate that our scheme surpasses the compared schemes in terms of both security attributes and system overhead. Qingyang Zhang 0001, Hong Zhong 0001, Jie Cui 0004, Jiaxin Li 0001, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | A Multilevel Electronic Control Unit Re-Encryption Scheme for Autonomous VehiclesabstractElectronic control units (ECUs) connected by a controller area network (CAN) are used to perform various functions in modern vehicles. In the latest autonomous vehicles, redundant ECUs and a backup bus (different from CAN) are always equipped to prevent a single point of failure or network attack. However, due to the lack of protection measures of CAN bus, attackers can remotely intrude into the vehicle. Many schemes have proposed to use encryption to solve the security problem of CAN bus. Considering the current ECU storage space is limited, it is impossible to store all ECUs’ keys. When a single point of failure or network attack against an ECU occurs, it is necessary for the backup ECU to process the messages related to the failed ECU. How to ensure that the backup ECU can decrypt the encrypted messages and at the same time securely isolates the backbone network from the backup network is an urgent issue to be solved. In order to solve the problem of forwarding and processing such messages under encryption conditions, we propose an efficient re-encryption scheme based on proxy re-encryption. The scheme is also suitable for cross-bus communication without backup networks. Burrows-Abadi-Needham (BAN) logic, random oracle model and Automated Validation of Internet Security Protocols and Applications (AVISPA) tool are utilized to prove that the scheme is secure. The scheme is simulated based on the MIRACL cryptography library on the computer and Raspberry Pi. The simulation results demonstrate that the proposed scheme is secure compared with the existing scheme. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Lu Liu 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2024 | A Two-Layer Dynamic ECU Group Management Scheme for In-Vehicle CAN BusabstractTo enable the vehicle control system to provide better service, an increasing number of network nodes are being introduced into the vehicle; this also dramatically expands the attack surface of modern vehicles. In recent years, the security of vehicle communication buses and electronic control units (ECUs) has been extensively studied. However, in actual deployment, there is little concern for the fine management of secure communication schemes with respect to the security level of the ECU on the controller area network (CAN). On this basis, this paper proposes a two-layer ECU group dynamic management scheme based on the Chinese remainder theorem. Dynamic grouping management based on the credibility of ECUs while the vehicle is running can effectively balance efficiency and security. During communication, different groups use different modes to achieve higher efficiency. Security analysis shows that the proposed scheme can satisfy the requirements of security and privacy. Simulation results further demonstrate that the proposed scheme performs well in terms of computing and communication costs. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | CVAR: Distributed and Extensible Cross-Region Vehicle Authentication With Reputation for VANETsabstractThis study proposes a distributed and extensible cross-region vehicle authentication scheme with the reputation for improving the security and efficiency of cross-region vehicle authentication. The existing authentication schemes demonstrate the following drawbacks: 1) Each vehicle is preloaded with the same system private key, which may be leaked so that the entire system would be destroyed; 2) Other schemes rely on trusted authority to aid in selecting some cluster head nodes; 3) The existing cross-region authentication schemes are not flexible and scalable since they depend on the infrastructure fixed on the roadside. With the proposed scheme, each vehicle stores a long-term private key that is different from those of other vehicles, thereby avoiding a system crash when destroying a vehicle. When the cross-region vehicle enters a new region, it can verify the reputation value of the surrounding vehicles to select the edge computing vehicle. The formal security proof shows that the proposed scheme has adequate security under the real-or-random model. The performance evaluation of our scheme with several related schemes reveals that it generates relatively low computation and communication overhead, is more robust, and achieves minimum packet loss ratio and delay. Jing Zhang 0024, Hong Zhong 0001, Jie Cui 0004, Lu Wei 0003, Lu Liu 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2024 | Enabling Efficient, Verifiable, and Secure Conjunctive Keyword Search in Hybrid-Storage BlockchainsabstractBlockchain has emerged as a prevailing paradigm for decentralized applications due to its reliability and transparency. To scale up retrieval services, a common strategy is to use a hybrid storage model, where on-chain storage is responsible for small metadata and off-chain storage is for outsourced raw data. However, data security and result authenticity are ongoing challenges in this scenario, and little work has been done due to the difficulty of combining result verification and privacy preservation, especially for dynamic updates while supporting forward privacy. In this paper, we formally define the problem of efficient, verifiable, and secure conjunctive keyword search in hybrid-storage blockchains (vsChain) and propose a novel hybrid index that achieves efficient query and verification while supporting dynamic updates with forward privacy guarantee. We also design two optimized schemes to improve query and verification performance by using a partition-based method and an obfuscated counting Bloom filter mechanism. Finally, we provide a theoretical security analysis and empirical evaluations using real and synthetic datasets to demonstrate the feasibility of our proposed schemes. Ningning Cui, Dong Wang 0057, Jianxin Li 0001, Huaijie Zhu, Xiaochun Yang 0001, Jianliang Xu, Jie Cui 0004, Hong Zhong 0001 |
IEEE Trans. Knowl. Data Eng. | 7 |
| 2024 | LH-IDS: Lightweight Hybrid Intrusion Detection System Based on Differential Privacy in VANETsabstractVehicular Ad hoc Networks (VANETs) are vulnerable to various types of attacks. Intrusion Detection System (IDS) based on machine learning can effectively detect malicious network attacks in VANETs. However, machine learning training necessitates ample data which contain significant ample private information, increasing the risk of privacy disclosure. The privacy protection of training data for machine learning used in the IDS of VANETs is rarely investigated. Meanwhile, Differential Privacy (DP) is one of the most secure privacy protection methods based on perturbations. Therefore, we propose a lightweight hybrid IDS (LH-IDS) based on machine learning and DP. It uses algorithms based on unsupervised learning to detect anomalous network behaviour with high performance, especially unknown attacks in VANETs, while protecting data privacy. The DP is used to secure the privacy of the training data. Noise from different privacy budgets is added to datasets to obtain DP datasets. Subsequently, LH-IDS is used to verify the utility of the DP datasets. Extensive experiments confirm LH-IDS can not only detect anomalous and normal traffic with excellent performance but can also protect the private information of the training data. Additionally, the proposed model incurs only minimal CPU and memory overhead, making it a lightweight solution. Jie Cui 0004, Jietian Xiao, Hong Zhong 0001, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Privacy-Preserving and Secure Distributed Data Sharing Scheme for VANETsabstractData sharing is one of the essential services of vehicular ad hoc networks (VANETs), which primarily requires data security and access control, and ciphertext-policy attribute-based encryption (CP-ABE) is a promising tool. However, data sharing schemes of distributed CP-ABE have concerns about the single-point performance bottleneck and privacy leakage. The factor for the former is that the authority manages a disjoint attribute set. The latter is because the user's identity and attributes are required to submit to authorities, which targets to bind this information to decryption keys for collusion-resistant. We propose a privacy-preserving distributed data sharing scheme for VANETs. This scheme introduces asymmetric group key agreement to distributed CP-ABE, which realizes that multiple authorities manage an attribute, and the user can obtain the attribute key bound with his identity from any authority in the group. To match up to the requirement of privacy-preserving, a key extract protocol provided user anonymity is proposed, which implements that attribute keys can be obtained without revealing the user's identity and attributes. Moreover, partial policy hiding is satisfied. Finally, we analyze and evaluate the proposed scheme, and the results indicate that our scheme is secure and efficient. Li Wang 0139, Hong Zhong 0001, Jie Cui 0004, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | A Decentralized Authenticated Key Agreement Scheme Based on Smart Contract for Securing Vehicular Ad-Hoc NetworksabstractSince the communication channels in vehicular ad-hoc networks (VANETs) are wireless and open, malicious adversaries can monitor or fabricate messages transmitted across them. To secure vehicular communications, an authenticated key agreement (AKA) scheme needs to be designed for VNAETs. Traditional VANETs AKA schemes require the trusted authority (TA) to authenticate the legality of message and corresponding sender. However, the TA in these schemes is vulnerable to suffer from single-point-of-failure issues. Some blockchain-based VANETs AKA schemes have been proposed recently to address the deficiency. However, these schemes rely on the consortium or private blockchain in which TAs are still required for key generation, resulting that the practicality is limited. To solve the issue, we design a smart contract-based VANETs AKA scheme, where the AKA algorithm of our proposed scheme is implemented on smart contract deployed on a public blockchain system and the TA that is responsible for key generation will not be required. The security proof and analysis show that our proposed scheme satisfies the session-key semantic security and essential security and privacy requirements, respectively. The performance analysis demonstrates that our proposed scheme outperforms existing blockchain-based VANETs AKA schemes. Lu Wei 0003, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Chengjie Gu, Debiao He |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | A Threshold-Based Full-Decentralized Authentication and Key Agreement Scheme for VANETs Powered by Consortium BlockchainabstractThe authentication and key agreement (AKA) scheme for VANETs can produce a series of short-term session keys, which can be used to secure the vehicular communications across open and insecure wireless channels. Traditional VANETs AKA schemes tend to employ the centralized trust architecture as the core authentication backend, which raises concerns about system security and reliability. Recently, several VANETs AKA schemes that are constructed on decentralized trust architecture have been proposed. However, these schemes do not achieve full decentralization and tend to suffer from key exposure issues, insufficient performance, and lack of optimization for on-chain storage costs. To address these shortcomings, we propose a threshold-based full-decentralized VANETs AKA scheme that is powered by consortium blockchain. In our proposed scheme, the threshold-based voting concept is employed to mitigate the key exposure issue inherent to the network infrastructure. Furthermore, we leverage lightweight cryptography in conjunction with the Cuckoo filter to reduce computational, communication, and on-chain operation costs brought by cryptographic operations and smart contracts. The security proof together with the cryptographic protocol validation tool prove the security of our proposed scheme, whereas the simulation experiment demonstrates the efficiency of our proposed scheme. Lu Wei 0003, Yongjuan Zhang, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | DBCPA: Dual Blockchain-Assisted Conditional Privacy-Preserving Authentication Framework and Protocol for Vehicular Ad Hoc NetworksabstractVehicular ad hoc networks (VANETs) connect all vehicles through wireless channels. They provide extensive real-time traffic information services that improve driving safety and traffic management efficiency. However, VANETs are vulnerable to security attacks because of the open wireless nature of their communication channels. Most security mechanisms for traditional VANETs are centralized and have certain limitations in satisfying security requirements, such as anti-single-point failure, distributed security authentication of messages, and privacy preservation in VANETs. To address these issues, herein, we propose a dual blockchain-assisted conditional privacy-preserving authentication framework and protocol for VANETs. The identity authentication and privacy preservation of vehicles in VANETs can be realized without relying on a centralized trusted third party. The proposed scheme also allows for the conditional tracking of illegal vehicles. The decentralized dynamic revocation of illegal vehicles can be realized through smart contracts, rendering the scheme efficient and scalable. We implement this scheme in an Ethereum test network to demonstrate its feasibility and conduct an in-depth security analysis and comprehensive performance evaluation of the proposed scheme. The results demonstrate that the proposed scheme is an effective solution for the development of a decentralized authentication system for VANETs. Jing Zhang 0024, Jie Cui 0004, Debiao He, Irina Pavlovna Bolodurina, Hong Zhong 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | CBDDS: Secure and Revocable Cache-Based Distributed Data Sharing for Vehicular NetworksabstractIn vehicular networks, caching content on an edge server (ES) is a popular method for quickly responding to massive vehicle service requests, reducing communication delays, and enhancing driver and passenger service experiences. However, after integrating ESs with vehicular networks to provide vehicles access to the cached content in these ESs, significant challenges regarding protecting the privacy of vehicle data and communication security arise. In this study, to address security and privacy-preserving issues, we propose a secure and revocable cache-based distributed data sharing scheme for vehicular networks wherein a token authentication mechanism and multi-authority ciphertext-policy attribute-based encryption are integrated. In this scheme, both authentication and authorization capabilities are delegated to an ES while restricting access to service content to only legal vehicles, achieving proper access control between vehicles and ESs, and effectively preserving the privacy of vehicle data. Moreover, we attributed the revocations of ESs to the associated attribute authorities, eliminating the need for a system-wide update of keying materials. Through rigorous security proofs and detailed security analyses, we demonstrate that the scheme meets the security requirements of vehicular networks and can resist more security attacks. The proposed scheme achieves better balance between computational and communication costs than related schemes. Jing Zhang 0024, Xinzhong Liu 0002, Jie Cui 0004, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Nonvolatile Latch Designs With Node-Upset Tolerance and Recovery Using Magnetic Tunnel Junctions and CMOSabstractAs semiconductor technologies scale down, radiative-particle-induced soft errors and static power consumption are becoming major concerns for digital circuits. Magnetic-tunnel-junctions (MTJs) are widely used to address these concerns. MTJs are nonvolatile (NV) and compatible with traditional CMOS processes. In this article, we first propose a double-node-upset (DNU) tolerant and NV latch, i.e., M-TPDICE-V2, providing high reliability. In addition, we further propose an advanced latch, namely, M-8C, that is able to completely recover from single-node upsets (SNUs) and DNUs. M-8C uses a DNU recovery module and a backup and restore module based on a pair of MTJs. Furthermore, we propose a universal backup and restore module suitable for any latch providing nonvolatility. We simulate the proposed latches using the Synopsys HSPICE tool with a 45-nm CMOS process model. Simulation results confirm the superior capabilities of our proposed M-TPDICE-V2 and M-8C latches. M-TPDICE-V2 exhibits strong SNU and DNU tolerance and nonvolatility, while the M-8C latch provides complete DNU recovery capabilities. Aibin Yan, Litao Wang, Jie Cui 0004, Zhengfeng Huang, Tianming Ni, Patrick Girard 0001, Xiaoqing Wen |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2023 | A High-Performance and P-Type FeFET-Based Non-Volatile LatchabstractNon-volatile memory has a significant future in the Internet of Things and computation-in-memory applications. Among them, non-volatile memories using emerging FeFET devices have garnered significant attention. This paper proposes a novel P-type FeFET -based non-volatile latch. This design takes advantage of the unique characteristics of a P-type FeFET device to achieve non-volatility with no additional control signals. The Cadence simulation tool Virtuoso verifies that our proposed design has correct functioning with excellent power, area, and delay performance compared to state-of-the-art designs. Aibin Yan, Zhengfeng Huang, Jie Cui 0004, Xiaoqing Wen |
ATS | 4 |
| 2023 | Poster: Membership Inference Attacks via Contrastive LearningabstractSince machine learning model is often trained on a limited data set, the model is trained multiple times on the same data sample, which causes the model to memorize most of the training set data. Membership Inference Attacks (MIAs) exploit this feature to determine whether a data sample is used for training a machine learning model. However, in realistic scenarios, it is difficult for the adversary to obtain enough qualified samples that mark accurate identity information, especially since most samples are non-members in real world applications. To address this limitation, in this paper, we propose a new attack method called CLMIA, which uses unsupervised contrastive learning to train an attack model. Meanwhile, in CLMIA, we require only a small amount of data with known membership status to fine-tune the attack model. We evaluated the performance of the attack using ROC curves showing a higher TPR at low FPR compared to other schemes. Jie Cui 0004, Hong Zhong 0001 |
CCS | 3 |
| 2023 | An Efficient Authentication and Key Agreement Scheme for CAV Internal Applications
Yang Li 0215, Qingyang Zhang 0001, Wenwen Cao, Jie Cui 0004, Hong Zhong 0001 |
CollaborateCom (2) | 4 |
| 2023 | Authenticated Ranked Keyword Search over Encrypted Data with Strong Privacy Guarantee
Ningning Cui, Zheli Deng, Yuliang Ma 0001, Jie Cui 0004, Hong Zhong 0001 |
DASFAA (1) | 5 |
| 2023 | High Performance and DNU-Recovery Spintronic Retention Latch for Hybrid MTJ/CMOS TechnologyabstractWith the advancement of CMOS technologies, circuits have become more vulnerable to soft errors, such as single-node-upsets (SNUs) and double-node-upsets (DNUs). To effectively provide nonvolatility as well as tolerance against DNUs caused by radiation, this paper proposes a nonvolatile and DNU resilient latch that mainly comprises two magnetic tunnel junction (MTJ), two inverters and eight C-elements. Since two MTJs are used and all internal nodes are interlocked, the latch can provide nonvolatility and recovery from all possible DNUs. Simulation results demonstrate the nonvolatility, DNU recovery and high performance of the proposed latch. Aibin Yan, Jie Cui 0004, Zhengfeng Huang, Xiaoqing Wen, Patrick Girard 0001 |
DATE | 4 |
| 2023 | Two Highly Reliable and High-Speed SRAM Cells for Safety-Critical Applications
Aibin Yan, Yang Chang, Jing Xiang, Jie Cui 0004, Zhengfeng Huang, Tianming Ni, Xiaoqing Wen |
ACM Great Lakes Symposium on VLSI | 5 |
| 2023 | A Low Area and Low Delay Latch Design with Complete Double-Node-Upset-Recovery for Aerospace Applications
Aibin Yan, Shaojie Wei, Jinjun Zhang, Jie Cui 0004, Tianming Ni, Patrick Girard 0001, Xiaoqing Wen |
ACM Great Lakes Symposium on VLSI | 4 |
| 2023 | SLCSA: Scalable Layered Cooperative Service Attestation Scheme in Cloud-Edge-End Cooperation EnvironmentsabstractIn a cloud-edge-end cooperation environment, edge and core cloud services are complementary and synergistic, jointly processing a large amount of private data uploaded by users. To prevent the leakage of private data, users must ensure that services are secure and trusted through remote attestation. Traditional one-to-one remote attestation schemes are typically used to test the cloud services. However, as the cloud platform scales and the number of edge and core cloud services grows rapidly, the traditional attestation method has problems, such as poor scalability and low attestation efficiency. Thus far, there has been a lack of feasible methods for users to verify multiple related services in a cloud-edge-end cooperation environment quickly. This paper presents a scalable layered cooperative service attestation (SLCSA) scheme, the first secure and scalable protocol for the efficient attestation of multiple cooperative services. The SLCSA scheme is based on a Boneh–Lynn–Shacham (BLS) multi-signature to improve the scalability of the scheme while enabling users to conduct the batch verification of services. We also analyze the security of the proposed scheme. To evaluate the proposed scheme, we implement it using Intel SGX, which can provide basic hardware-assisted attestation and a trusted execution environment for services. The experimental results show that the SLCSA scheme is practical and efficient in a cloud-edge-end cooperative environment. Jie Cui 0004, Qipeng Chen, Yang Li 0215, Qingyang Zhang 0001, Lu Liu 0001, Hong Zhong 0001 |
ICPADS | 1 |
| 2023 | Design of Low-Cost Approximate CMOS Full AddersabstractMany applications have an inherent tolerance for insignificant inaccuracies. Full adders are key arithmetic functions for many error-tolerant applications. Approximate full adders are considered an efficient technique to trade off energy relative to performance and accuracy. In this paper, we propose four approximate full adders with low overhead. The proposed and the existing approximate full adders are classified into two groups according to their error distances. Simulation results show that, compared with the existing approximate full adders, in the first group, the proposed ones can reduce power-area-delay product (PADP) by 61.83%, power by 54.15%, area by 44.67%, and delay by 22.78%on average; in the second group, the proposed ones can reduce PADP by 97.01%, power by 93.43%, area by 24.98%, and delay by 36.14% on average. Aibin Yan, Shaojie Wei, Jie Cui 0004, Zhengfeng Huang, Patrick Girard 0001, Xiaoqing Wen |
ISCAS | 4 |
| 2023 | Design of A Highly Reliable and Low-Power SRAM With Double-Node Upset Recovery for Safety-critical ApplicationsabstractFor high-speed operations, low power consumption and small silicon area, transistors are being scaled aggressively. Meanwhile, circuit reliability is facing greater challenges in advanced technologies. In this paper, a highly reliable and low-power SRAM with double-node-upset (DNU) recovery, namely HRLP16T, is proposed for safety-critical fields. HRLP16T can recover from single-node-upset (SNU) at all the sensitive nodes, and it has eight node pairs recoverable from DNUs. Simulation results demonstrate its advantages in terms of delay and power consumption over typical existing SRAM cell designs. Aibin Yan, Jing Xiang, Zhengfeng Huang, Tianming Ni, Jie Cui 0004, Patrick Girard 0001, Xiaoqing Wen |
ITC-Asia | 5 |
| 2023 | A Low Overhead and Double-Node-Upset Self-Recoverable LatchabstractWith the rapid advancement of semiconductor technologies, integrated circuits, especially storage elements (e.g., latches) have become increasingly vulnerable to soft errors. In order to effectively tolerate double-node-upsets (DNUs) caused by radiation and reduce the power and area of latches, this paper proposes a DNU self-recoverable latch with low overhead in terms of power and area. The proposed latch mainly comprises seven 2-input C-elements and two inverters to achieve DNU self-recovery. Simulation results show that the proposed latch can recover from all possible DNUs and that it can reduce delay by 45.7%, power by 29.1%, area by 65.9%, and area-power-delay-product by 87.4%, on average, compared to typical existing DNU self-recoverable latches. Aibin Yan, Tianming Ni, Jie Cui 0004, Zhengfeng Huang, Patrick Girard 0001, Xiaoqing Wen |
ITC-Asia | 4 |
| 2023 | Design of a Novel Latch with Quadruple-Node-Upset Recovery for Harsh Radiation HardnessabstractAs CMOS processes continue to shrink, nano-scale CMOS latches have become increasingly sensitive to multiple-node upset (MNU) errors caused by radiation. To tolerate MNU, a novel quadruple-node-upset (QNU) self-recoverable latch is proposed in this paper. The proposed latch is mainly constructed from six blocks of three-level C-elements (TLCEs) and six inverters. With the mutual feedback of the various TLCEs, the proposed latch can recover from any QNU. Furthermore, due to the clock gating methodology and a high-speed transmission path, the proposed latch has lower overhead in terms of power dissipation and transmission delay. Simulation results show that the proposed latch achieves high reliability with moderate overhead compared to typical existing latches. Aibin Yan, Shaojie Wei, Jie Cui 0004, Zhengfeng Huang, Patrick Girard 0001, Xiaoqing Wen |
ITC-Asia | 4 |
| 2023 | Reversible Data Hiding in Encrypted Images Based on Block Classification Coding of Sparse Representation
Fuhu Wu, Shun Zhang 0002, Jie Cui 0004, Hong Zhong 0001 |
ProvSec | 4 |
| 2023 | Extracting Length Field of Unknown Binary Network Protocol from Static TraceabstractNetwork protocol specification is essential in analyzing and evaluating network functionality, performance, and security. However, increasing private protocols become a hindrance to these features. The existing works study how to extract protocol keyword fields rather than infer the semantics of the fields, such as the length field, which can indicate the length associated with a message and is fundamental for deep analysis of network protocols. In this paper, we propose a nonparametric and unsupervised method, ROSE, to extract the length field of unknown binary network protocols from static traces. It segments the fields from the raw network trace and gets the inferred length of a subset of messages by clustering similar fields with k-means. Then, it generates candidate fields using n-gram and builds a multidimensional equation based on the length of the clustered messages and the candidate length fields. Finally, ROSE extracts the inferred length fields through linear regression. As far as we know, it is the first study on extracting length field from the static trace. The evaluation experiments using raw network traces exhibit high precision and recall in extracting the length field or identifying protocols without the length field. Xiuwen Sun, Pengfei Fu, Jie Cui 0004, Hong Zhong 0001 |
TrustCom | 5 |
| 2023 | Parallel Pattern Matching over Brotli Compressed Network TrafficabstractPattern matching is a crucial technique for network traffic detection applications. As a fundamental computation model used by pattern matching, the finite state automata execute sequential matching due to the state dependence among transitions. Meanwhile, most services tend to compress their data to improve transmission or storage efficiency. The increased compressed data challenges the straightforward method of matching the whole decompressed data and incurs data dependence among the compression encodings. The related approaches either leverage techniques to break the state dependence of matching uncompressed data or accelerate matching compressed data in a single-threaded manner without considering the state and data dependence. None of them can perform parallel matching over compressed data. This paper provides PETALS, a parallel pattern matching method over Brotli compressed network traffic. PETALS partitions the original compressed traffic into fixed- length blocks for parallel matching and patches the broken compression encodings crossing blocks to break the data dependence. Then, it merges the compressed traffic matching method into path fusion, an enumerative parallelization of finite state automata, to present parallel matching over compressed traffic. Evaluation using real-world network traffic and regular expressions shows that PETALS can raise the speedup from 1.53x to 3.53x of the state-of-the-art parallelization schemes on a 56-cores machine. Xiuwen Sun, Guangzheng Zhang, Qingying Yu, Jie Cui 0004, Hong Zhong 0001 |
TrustCom | 5 |
| 2023 | Multi-factor based session secret key agreement for the Industrial Internet of Things
Jie Cui 0004, Fangzheng Cheng, Hong Zhong 0001, Qingyang Zhang 0001, Chengjie Gu, Lu Liu 0001 |
Ad Hoc Networks | 1 |
| 2023 | Conditional privacy-preserving message authentication scheme for cross-domain Industrial Internet of Things
Hong Zhong 0001, Chengdong Gu, Qingyang Zhang 0001, Jie Cui 0004, Chengjie Gu, Debiao He |
Ad Hoc Networks | 4 |
| 2023 | Efficient regular expression matching over hybrid dictionary-based compressed data
Xiuwen Sun, Da Mo, Chunhui Ye, Qingying Yu, Jie Cui 0004, Hong Zhong 0001 |
J. Netw. Comput. Appl. | 6 |
| 2023 | LPPA-RCM: A lightweight privacy-preserving authentication scheme for road condition monitoring in fog-based VANETs
Yan Xu 0007, ChongYue Yao, Jie Cui 0004, Hong Zhong 0001 |
J. Syst. Archit. | 3 |
| 2023 | Efficient Integrity Auditing Mechanism With Secure Deduplication for Blockchain StorageabstractMassive nodes in a blockchain form an off-chain distributed storage network to provide storage resources for users to meet large data upload requirements. However, this storage approach introduces security and performance issues. Firstly, it is difficult to guarantee the integrity of the data uploaded, and these data may be easily corrupted or lost. Moreover, uploading excessive duplicate data leads to a waste of storage resources. In this study, to address these issues, with a double-copy storage model for blockchain off-chain storage, a novel public auditing scheme with client-side deduplication is proposed to reduce the storage overhead of nodes and check the integrity of the off-chain data. Based on smart contracts, our scheme could realize efficient user ownership and off-chain data integrity verification automatically. In addition, both data encryption and deduplication are achieved based on message-locked encryption and an improved authenticator generation algorithm. Security analysis and experimental comparisons show that the proposed scheme is effective and practical. Qingyang Zhang 0001, Dongfang Sui, Jie Cui 0004, Chengjie Gu, Hong Zhong 0001 |
IEEE Trans. Computers | 3 |
| 2023 | LDAVPM: A Latch Design and Algorithm-Based Verification Protected Against Multiple-Node-Upsets in Harsh Radiation EnvironmentsabstractIn deep nano-scale and high-integration CMOS technologies, storage circuits have become increasingly sensitive to charge-sharing-induced multiple-node-upsets (MNUs) that include double, triple, and quadruple node-upsets. Currently, verifications for error recovery of existing latches highly rely on EDA tools with complex error-injection combinations. In this article, a latch design protected against MNUs in the harsh radiation as well as an algorithm-based verification process is proposed. Due to the constructed redundant feedback loops, the latch can completely recover from any MNU. Algorithm-based verification and simulations both demonstrate the MNU recovery of the proposed latch. Simulation results demonstrate the low area overhead of the proposed latch compared with the only one existing of the same type. Aibin Yan, Jie Cui 0004, Zhengfeng Huang, Tianming Ni, Patrick Girard 0001, Xiaoqing Wen |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2023 | An Efficient Integrity Checking Scheme With Full Identity Anonymity for Cloud Data SharingabstractCloud storage services can support data sharing for a group of users. However, the cloud server may lose some of the shared data when attacked. The integrity of stored data is a key issue for cloud storage. However, identity anonymity, an important problem in data integrity, has not been fully investigated yet. Furthermore, the existing schemes of data integrity checking are usually based on public key infrastructure and thus have to perform complex certificate management. In this paper, we propose an efficient integrity checking scheme to achieve full identity anonymity. Additionally, the proposed scheme can reduce the workloads of certificate management and simplify key management. Inspired by the idea of attribute-based signature, we devise a common predicate to manage the identities of legitimate users and disable illegal users from joining the data sharing. By adopting the technique of the monotone span program, the legitimate user can compute the valid authenticators of shared data for all attributes in the common predicate without the need of binding his attribute set to the shared data. Whereupon, the user's identity remains anonymous to all parties in the data sharing because he can share the data and authenticators without revealing his attribute set to other parties. The extensive experimental results demonstrate that the proposed scheme has less computational and communication overhead compared with the existing schemes while achieving full identity anonymity. Yan Xu 0007, Hong Zhong 0001, Jie Cui 0004, Geyong Min |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | Achieving Revocable Attribute Group-Based Encryption for Mobile Cloud Data: A Multi-Proxy Assisted ApproachabstractAlthough proxy-assisted revocable attribute-based encryption provides fine-grained privacy protection and reduces the decryption cost of data users, it inherits several disadvantages in outsourcing decryption. The decryption capability in outsourcing decryption is divided into two parts: the outsourcing transformation key and the user decryption key. The proxy server utilizes transformation keys to transform the ciphertext which can only be decrypted by the users who generated the transformation key. When multiple users with the same attributes request outsourcing transformation, the proxy server must do numerous transformation operations, increasing the computing overhead of the proxy server and the user request response time. To address the aforementioned issues, we propose a multi-proxy assisted revocable attribute group-based encryption (MP-RAGBE) scheme. We form a user group out of users who have the same attributes and send the transformation keys directly to the proxy server. Users in the same group can decrypt the transformed ciphertext, and only a small number of transformation keys need to be updated when revocation occurs. The security and experimental analyses show that the proposed scheme meets the defined security requirements while significantly reducing user request response time, the overhead of transformation key generation, transmission, and ciphertext transformation. Jie Cui 0004, Hong Zhong 0001, Yan Xu 0007, Lu Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | A Lightweight and Conditional Privacy-Preserving Authenticated Key Agreement Scheme With Multi-TA Model for Fog-Based VANETsabstractRecently, the fog computing concept has been introduced into vehicular ad-hoc networks (VANETs) to formulate fog-based VANETs. Since the communication channels between vehicles and fog nodes are open and insecure, it is necessary to construct an authenticated key agreement (AKA) scheme for securing the channels. The existing AKA schemes have two main deficiencies. One is that the computational and communication overhead are not low enough to satisfy the requirements of delay-sensitive applications. The other is that the multi-trusted-authority (multi-TA) model has not been considered. To solve the deficiencies, we propose a lightweight and conditional privacy-preserving AKA scheme, where the main steps are designed with symmetric cryptography methods. The design can reduce the computational and communication overhead of the AKA process. Additionally, we consider the multi-TA model in the AKA process to solve the single-point-of-failure issue. By integrating Cuckoo filter into the multi-TA model, the secrecy of real identities of legal vehicles is guaranteed and the identity revocation function for illegal vehicles is supported in the AKA process. The security proof and analysis show that our proposed scheme satisfies the essential security and privacy requirements of VANETs. The performance analysis shows that our proposed scheme outperforms other related and represented schemes. Lu Wei 0003, Jie Cui 0004, Hong Zhong 0001, Irina Pavlovna Bolodurina, Lu Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Identity-Based Broadcast Proxy Re-Encryption for Flexible Data Sharing in VANETsabstractData sharing is an integral part of vehicular ad hoc networks (VANETs), which provide drivers with safe and comfortable driving environments. However, when data are shared among multiple vehicles, they must be encrypted multiple times. Some solutions have used identity-based broadcast encryption to solve this problem. However, these schemes have two major limitations. First, the decryption cost is linearly related to the number of data receivers, where the identity of other receivers must be known. Second, only the data sender can forward the data. To address these important deficiencies, we propose an identity-based broadcast proxy re-encryption scheme to realize flexible and efficient data-sharing in VANETs. The data sender generates a fixed ciphertext that can be obtained by newly added vehicles through authorized vehicles. Data receivers can decrypt ciphertext directly without knowing the identities of other receivers, where the decryption overhead is constant. In addition, our scheme can achieve complete anonymous data sharing to protect vehicle privacy. A security proof shows that our scheme has sufficient security, and a performance analysis shows that our scheme performs well. Our proposed scheme is thus suitable for securing VANETs. Jing Zhang 0024, Shuangshuang Su, Hong Zhong 0001, Jie Cui 0004, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Efficient Anonymous Authentication Based on Physically Unclonable Function in Industrial Internet of ThingsabstractOwing to the open Industrial Internet of Things (IIoT) environment, information interacting between devices and servers is transmitted over the public channel, which may lead to privacy breach of the device identity. Furthermore, communication entities are not fully trusted, and they may maliciously disclose the device identity information. Therefore, the anonymity of devices must be guaranteed. In addition, IIoT is resource-constrained, and complex algorithms are unsuitable for the IIoT system. Several researchers have attempted to design anonymous authentication schemes. The one-authentication-multiple-access approach allows devices to access server resources multiple times after a single authentication, and its authentication overhead is independent of the number of accesses. This can reduce the computational burden for devices that need to access the server frequently. However, existing anonymous authentication schemes do not support multiple accesses after one authentication, and still suffer from privacy issues and low efficiency for devices that need frequent access to the server. To address these issues, we propose a new anonymous authentication scheme that uses group signature technology to ensure device anonymity and uses Merkle hash tree technology to achieve multiple accesses after one authentication, thereby greatly reducing the authentication overhead of IIoT devices. Then, we validate the security of the scheme using the random oracle model and the BAN logic. Finally, compared with other related schemes, the experimental results show that our proposed scheme is more efficient and practical for resource-constrained IIoTs than other schemes. Qingyang Zhang 0001, Hong Zhong 0001, Debiao He, Jie Cui 0004 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Secure Edge Computing-Assisted Video Reporting Service in 5G-Enabled Vehicular NetworksabstractSince traffic accidents occur frequently, a real-time video traffic reporting service is necessary in vehicular networks for a prompt response to accidents. Although the fifth-generation (5G) network provides a solution for real-time services in vehicular networks, the security and privacy of the services needs to be addressed first. The existing secure video reporting service schemes in 5G-enabled vehicular networks have significant computing, communication, and storage overheads, because of public key certificates, expensive bilinear pairing operations, and repeated video reporting to the cloud. To address these issues, we propose a secure edge computing-assisted video reporting service in 5G-enabled vehicular networks. In the proposed method, edge nodes complete the message verification and classification. Moreover, these nodes send the first received report message of the same accident to the designated official vehicles to realizes a local upload and download of video reports and to minimize the storage of repeated accident reports in the cloud. Security analysis indicates the proposed scheme is secure under the random oracle model and meets a series of vehicular networks requirements. In addition, performance evaluations show that the scheme achieves lower authentication overhead than existing signature schemes, and has lower total delay than other relevant video reporting service schemes. Hong Zhong 0001, Li Wang 0139, Jie Cui 0004, Jing Zhang 0024, Irina Pavlovna Bolodurina |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Chaotic Map-Based Authentication Scheme Using Physical Unclonable Function for Internet of Autonomous VehicleabstractAutonomous Vehicles (AVs) are a highly discussed topic owing to their great performance and convenience. However, some requirements limit their wider deployment. Specifically, AV should be controlled by remote users during emergencies. It may lead to AV’s system facing the risk of being intruded on by a malicious party, resulting in unreasonable decisions. We, therefore, design the Internet of autonomous vehicle (IoAV) model to mitigate the problems arising from these limitations. To promote a secure remote control of the AV, a reliable authentication scheme, which can be used in IoAV, must be performed. Our proposed chaotic map-based authenticated key agreement (CMAKA) method provides secure remote control features for AVs. In this method, users, data centers, and AV establish a secure communication channel through the negotiation of three independent session keys. Furthermore, a physical unclonable function (PUF) is employed to produce a trusted private key during the authentication. The security of our scheme is evaluated using game hopping through the widespread Real-or-Random (ROR) model. Compared with other existing three-factor authentication schemes, the performance of our protocol is higher in both security requirements and total cost. Jie Cui 0004, Hong Zhong 0001, Lu Wei 0003, Lu Liu 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2023 | Towards Multi-User, Secure, and Verifiable $k$NN Query in Cloud DatabaseabstractWith the boom in cloud computing, data outsourcing in location-based services is proliferating and has attracted increasing interest from research communities and commercial applications. Nevertheless, since the cloud server is probably both untrusted and malicious, concerns about data security and result integrity have become on the rise sharply. In addition, in the single-user situation assumed by most existing works, query users can capture query content from each other even though the queries are encrypted, which may incur the leakage of query privacy. Unfortunately, there exists little work that can commendably assure data security and result integrity in the multi-user setting. To this end, in this article, we study the problem of multi-user, secure, and verifiable$k$nearest neighbor query (MSV$k$kNN). To support MSV$k$NN, we first propose a novel unified structure, called verifiable and secure index (VSI). Based on this, we devise a series of secure protocols to facilitate query processing and develop a compact verification strategy. Given an MSV$k$NN query, our proposed solution can not merely answer the query efficiently while can guarantee: 1) preservingdata privacy,query privacy,result privacy, andaccess patterns privacy; 2) authenticating thecorrectnessandcompletenessof the results; 3) supportingmulti-userwith different keys. Finally, the formal security analysis and complexity analysis are theoretically proven and the performance and feasibility of our proposed approach are empirically evaluated and demonstrated. Ningning Cui, Kang Qian, Taotao Cai, Jianxin Li 0001, Xiaochun Yang 0001, Jie Cui 0004, Hong Zhong 0001 |
IEEE Trans. Knowl. Data Eng. | 6 |
| 2023 | AC-SDVN: An Access Control Protocol for Video Multicast in Software Defined Vehicular NetworksabstractThe way to use limited bandwidth resources to achieve high-quality video services in vehicular networks is an important research topic. A large number of studies have shown that the fast-growing field of software defined networking (SDN) can provide solutions to the problems encountered by traditional IP networks when implementing video multicasting. However, there is no research addressing the security issues for this scenario. In this paper, we explore the application scenarios of video multicast in software defined vehicular networks (SDVN), and propose a secure and effective access control protocol to solve multicast security issues. This protocol realizes the authentication of multicast video requesting vehicles and RSUs. According to the authentication results, the SDN controller constructs multicast paths that only reach legitimate RSUs and vehicles, and only the vehicle passing the authentication can obtain video decryption keys. The protocol resists common attacks and satisfies the security requirements in vehicular networks. In addition, the scheme supports batch verification, which reduces the time cost of authentication, and adopts broadcast encryption technology to effectively reduce the communication load. Compared with related schemes, our protocol performs better in terms of computation and communication cost, packet loss rate, and time delay. Hong Zhong 0001, Jie Cui 0004, Chengjie Gu, Irina Pavlovna Bolodurina, Lu Liu 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2023 | Efficient Batch Authentication Scheme Based on Edge Computing in IIoTabstractIn the industrial Internet of Things (IIoT) environment (e.g., a smart factory), smart devices with limited computing power can bring large amounts of privacy-sensitive data into insecure networks when they interact. If a network attacker intercepts and tampers with this data, it may cause chaos in production and even paralyze the entire IIoT system. Therefore, to ensure the regular operation of intelligent production, data receivers must authenticate the data before using them. However, existing message authentication schemes in the IIoT environment authenticate each message individually, which creates many redundant operations. Hence, to ensure data security among smart devices and reduce the computational overhead of data processing, we propose a batch authentication scheme based on edge computing in IIoT. Specifically, we design a lightweight batch authentication algorithm and use edge servers to assist smart devices in authenticating data, thus reducing the computational burden on smart devices and improving the efficiency of message authentication. The security analysis shows that the proposed scheme is secure in the random oracle model and meets the series of security requirements of the IIoT. In addition, we illustrate the efficiency of the scheme through experiments. Jie Cui 0004, Fengqun Wang, Qingyang Zhang 0001, Chengjie Gu, Hong Zhong 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | Blockchain-Assisted Privacy-Preserving Traffic Route Management Scheme for Fog-Based Vehicular Ad-Hoc NetworksabstractTraffic route management is essential for reducing traffic jams and enhancing driving safety because of the growing number of vehicles and frequent occurrence of traffic accidents. However, in vehicular ad-hoc networks (VANETs), real-time messages are transmitted via wireless channels, which can result in security and privacy concerns. Existing proposals for traffic route management exist security vulnerabilities, as well as high calculation and communication costs. Encouraged by this fact, we design a lightweight traffic route management scheme for fog-based VANETs. In this scheme, vehicles utilize homomorphic encryption to encrypt their driving routes and then send the encrypted information to a fog node. The traffic management center (TMC) decrypts the received ciphertexts that are aggregated by the fog node and performs traffic management according to the decrypted data, without knowing individual route of each vehicle. Furthermore, blockchain is used in the scheme to conduct public keys management of vehicles. Our detailed security proof and analysis indicate that our proposal can meet the security objectives of VANETs. Further, to demonstrate the feasibility of the scheme, we also implement it in the Ethereum test network (i.e., Rinkeby). Significantly, the performance analysis demonstrates that our proposal achieves a better performance than other relevant representative schemes. Jing Zhang 0024, Huixia Fang, Hong Zhong 0001, Jie Cui 0004, Debiao He |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | Collaborative Intrusion Detection System for SDVN: A Fairness Federated Deep Learning ApproachabstractWith the continuous innovations and development in communication technology and intelligent transportation systems, a new generation of vehicular ad hoc networks (VANETs) has become increasingly popular, making VANET communication security increasingly important. An intrusion detection system (IDS) is an important tool for detecting network attacks and is an effective means of improving network security. However, existing IDSs encounter several problems involving inaccurate detections, low detection efficiencies, and incomplete detections owing to extensive changes in vehicle locations in VANETs. This study explores federated learning in software-defined VANETs and designs an efficient and accurate collaborative intrusion detection system (CIDS) model. The model utilizes the collaboration among local software-defined networks (SDNs) to jointly train the CIDS model without directly exchanging local network data flows to improve the expansibility and globality of IDSs. To reduce the model difference between different SDN clients and improve the detection accuracy, this study regards the prediction loss for each SDN client as an objective from the perspective of constrained multi-objective optimization. By optimizing a surrogate maximum function containing all the objectives, the method adopts two-stage gradient optimization to achieve Pareto optimality for SDN clients with the worst fairness constraint maximization performance. In addition, this study evaluates the training model using two open-source datasets and compares it with the latest methods. Experimental results reveal that the proposed model ensures local data privacy and demonstrates high accuracy and efficiency in detecting attacks and is thus superior to the current schemes. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Lu Wei 0003, Irina Pavlovna Bolodurina, Debiao He |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2023 | Efficient Blockchain-Based Data Integrity Auditing for Multi-Copy in Decentralized StorageabstractAs the disruptor of cloud storage, decentralized storage could lead to a major shift in how organizations store data in the future. To ensure data availability, users generally encrypt the data and distribute it to multiple storage service providers. It is necessary to study data integrity verification in decentralized storage. Although some recent studies have proposed the using blockchain technology to assist auditing work in decentralized storage networks, the on-chain overhead still increases linearly with an increase in audit requests. Blockchain networks will inevitably be overloaded. In this study, we propose an efficient data integrity auditing scheme for multiple copies in decentralized storage. Particularly, using different polynomial commitment schemes, we first propose a basic scheme for verifying multiple copies of a single file, and then we propose an efficient batch auditing scheme for multiple copies of multiple files. Our scheme can significantly reduce the computation overhead of storage service providers while keeping the on-chain storage overhead constant. Security analysis and performance analysis show that our scheme is efficient and practical. Qingyang Zhang 0001, Jie Cui 0004, Hong Zhong 0001, Yang Li 0215, Chengjie Gu, Debiao He |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2023 | Towards Fully Anonymous Integrity Checking and Reliability Authentication for Cloud Data SharingabstractCloud storage services improve the efficiency and popularity of data sharing. These services allow groups of participants to jointly maintain the shared data. As important security properties of cloud data sharing, the integrity and the reliability of the shared data have been studied recently. However, the existing research cannot sufficiently solve the issue of participant identity anonymity in the scenario of data modification. In this paper, we propose a novel approach to achieve fully anonymous integrity checking and reliability authentication for cloud data sharing. We design a predicate for the shared data, and construct the Lagrange interpolation polynomials for all participants to compute the secret keys based on the designed predicate. When modifying the shared data, the participants compute the authenticators of the modified data using the secret key associated with the designed predicate instead of their identities. In this way, the integrity checking and reliability authentication of the shared data modified by different participants can be performed while the identities of the corresponding participants remain fully anonymous. In addition, the traceability and revocation of participant identity are considered. The performance analysis demonstrates the efficiency of the proposed approach, and the security analysis shows that the proposed approach satisfies the desired properties. Yan Xu 0007, Hong Zhong 0001, Jie Cui 0004, Kewei Sha |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | A Radiation-Hardened Non-Volatile Magnetic Latch with High Reliability and Persistent StorageabstractWith technology scaling down, the vulnerability of circuits to radiation and the increase of static power have become severe concerns. Spintronic devices such as magnetic tunnel junction (MTJ) have been developed to cope with many concerns, among which reliability concerns [1]. Spintronic devices have attractive properties, such as non-volatility and compatibility with conventional CMOS fabrication process. Based on an advanced triple-path dual-interlocked-storage-cell (TPDICE) and MTJs, this paper proposes a radiation-hardened non-volatile magnetic latch, namely M-TPDICE, that can completely tolerate single-node upsets (SNUs) and double-node upsets (DNUs). Simulations of the proposed latch with the HSPICE tool with a 45 nm CMOS technology model have demonstrated the effectiveness of the proposed latch. Aibin Yan, Zhengfeng Huang, Jie Cui 0004, Patrick Girard 0001, Xiaoqing Wen |
ATS | 5 |
| 2022 | SCLCRL: Shuttling C-elements based Low-Cost and Robust Latch Design Protected against Triple Node Upsets in Harsh Radiation EnvironmentsabstractAs the CMOS technology is continuously scaling down, nano-scale integrated circuits are becoming susceptible to harsh-radiation induced soft errors, such as double-node upsets (DNUs) and triple-node upsets (TNUs). This paper presents a shuttle C-elements based low-cost and robust latch (namely SCLCRL) that can recover from any TNU in harsh radiation environments. The latch comprises seven primary storage nodes and seven secondary storage nodes. Each pair of primary nodes feeds a secondary node through one C-element (CE) and each pair of secondary nodes feeds a primary node through another CE, forming redundant feedback loops to robustly retain values. Simulation results validate all key TNUs' recoverability features of the proposed latch. Simulation results also demonstrate that the proposed SCLCRL latch can approximately save 29% silicon area and 47% D-Q delay on average at the cost of moderate power, compared with the state-of-the-art TNU-recoverable reference latches of the same-type. Aibin Yan, Shiwei Huang, Zijie Zhai, Xiangyu Cheng, Jie Cui 0004, Tianming Ni, Xiaoqing Wen, Patrick Girard 0001 |
DATE | 6 |
| 2022 | Sextuple Cross-Coupled-DICE Based Double-Node-Upset Recoverable and Low-Delay Flip-Flop for Aerospace ApplicationsabstractThis paper proposes a novel sextuple cross-coupled dual-interlocked-storage-cell (DICE) based double-node-upset (DNU) recoverable and low-delay flip-flop (FF), namely SCDRL-FF, for aerospace applications. The SCDRL-FF mainly consists of sextuple cross-coupled DICEs controlled by clock-gating. The use of clock-gating based DICEs significantly reduces the CLK-Q transmission delay of the SCDRL-FF. Through the redundant and interlocked clock-gating based DICEs, the SCDRL-FF can provide complete DNU recoverability. Simulation results demonstrate the DNU recoverability of the SCDRL-FF and a 65% delay reduction on average compared with the state-of-the-art hardened FFs. The low delay overhead makes the proposed SCDRL-FF effectively applicable to high-performance applications and the DNU recoverability makes the proposed SCDRL-FF also suitable for aerospace applications. Aibin Yan, Shukai Song, Zijie Zhai, Jie Cui 0004, Zhengfeng Huang, Patrick Girard 0001, Xiaoqing Wen |
ACM Great Lakes Symposium on VLSI | 5 |
| 2022 | Two 0.8 V, Highly Reliable RHBD 10T and 12T SRAM Cells for Aerospace ApplicationsabstractAggressive scaling of CMOS technologies requires to pay attention to the reliability issues of circuits. This paper presents two highly reliable RHBD 10T and 12T SRAM cells, which can protect against single-node upsets (SNUs) and double-node upsets (DNUs). The 10T cell mainly consists of two cross-coupled input-split inverters and the cell can robustly keep stored values through a feedback mechanism among its internal nodes. It also has a low cost in terms of area and power consumption, since it uses only a few transistors. Based on the 10T cell, a 12T cell is proposed that uses four parallel access transistors. The 12T cell has a reduced read/write access time with the same soft error tolerance when compared to the 10T cell. Simulation results demonstrate that the proposed cells can recover from SNUs and a part of DNUs. Moreover, compared with the state-of-the-art hardened SRAM cells, the proposed 10T cell can save 28.59% write access time, 55.83% read access time, and 4.46% power dissipation at the cost of 4.04% silicon area on average. Aibin Yan, Zhihui He, Jing Xiang, Jie Cui 0004, Zhengfeng Huang, Patrick Girard 0001, Xiaoqing Wen |
ACM Great Lakes Symposium on VLSI | 4 |
| 2022 | A Highly Robust, Low Delay and DNU-Recovery Latch Design for Nanoscale CMOS TechnologyabstractWith the advancement of semiconductor technologies, nano-scale CMOS circuits have become more vulnerable to soft errors, such as single-node-upsets (SNUs) and double-node-upsets (DNUs). In order to effectively tolerate DNUs caused by radiation and reduce the delay and area consumption of latches, this paper proposes a DNU resilient latch in the nanoscale CMOS technology. The latch mainly comprises four input-split inverters and four 2-input C-elements. Since all internal nodes are interlocked, the latch can recover from all possible DNUs. Simulation results show that, compared with the state-of-the-art DNU self-recovery latch designs, the proposed latch can save 64.51% transmission delay and 56.88% delay-area-power-product (DAPP) on average, respectively. Aibin Yan, Shaojie Wei, Jie Cui 0004, Tianming Ni, Patrick Girard 0001, Xiaoqing Wen |
ACM Great Lakes Symposium on VLSI | 4 |
| 2022 | Cost-Optimized and Robust Latch Hardened against Quadruple Node Upsets for Nanoscale CMOSabstractWith the aggressive reduction of CMOS transistor feature sizes, the soft error rate of nano-scale integrated circuits increases exponentially. In this paper, we propose a novel cost-optimized and robust latch, namely CRLHQ, hardened against quadruple-node-upsets (QNUs) for nanoscale CMOS technologies. The latch mainly comprises a 5×5 matrix based on interlocked source-drain cross-coupled inverters to robustly store logic values. Owing to the redundant constructed feedback loops, the latch can recover from all possible QNUs. Simulation results demonstrate all key QNUs' recovery of the proposed CRLHQ latch. Simulation results also show that the proposed latch can approximately reduce the D-Q delay by 44.3%, the silicon area by 7.3% and the delay-area-power product (DAPP) by 14.2%, compared with the state-of-the-art same-type reference latches that can recover from any QNU. Aibin Yan, Shukai Song, Jixiang Zhang 0007, Jie Cui 0004, Zhengfeng Huang, Tianming Ni, Xiaoqing Wen, Patrick Girard 0001 |
ITC-Asia | 4 |
| 2022 | A Highly Reliable and Low Power RHBD Flip-Flop Cell for Aerospace ApplicationsabstractIn space, the impact of radiative particles, such as neutrons and heavy ions, can change the node states of a flip-flop, thus resulting in loss of data. In this paper, a Highly reliable and Low power Radiation-hardened-by-design (RHBD) Flip-Flop cell, namely HLRFF, completely hardened against double-node-upsets (DNUs), is proposed for aerospace applications. The HLRFF is a master-slave structure. The master latch is mainly constructed from two 2-input C-elements (CEs) and one 2-input clock-gating based CE, while the slave latch has an additional keeper at the output stage. The verification results demonstrate that the proposed HLRFF is completely DNU-tolerant. Furthermore, compared to the state-of-the-art radiation-hardened FF cells, the proposed HLRFF can reduce power consumption by approximately 69%. However, only the proposed HLRFF is not only completely DNU-tolerant but also insensitive to high-impedance-state. Aibin Yan, Kuikui Qian, Jie Cui 0004, Ningning Cui, Zhengfeng Huang, Xiaoqing Wen, Patrick Girard 0001 |
VTS | 3 |
| 2022 | Dataset for Evaluation of DDoS Attacks Detection in Vehicular Ad-Hoc Networks
Hong Zhong 0001, Lu Wei 0003, Jing Zhang 0024, Chengjie Gu, Jie Cui 0004 |
WASA (3) | 6 |
| 2022 | Forward and backward secure searchable encryption with multi-keyword search and result verification
Jie Cui 0004, Yan Xu 0007, Miaomiao Tian 0001, Hong Zhong 0001 |
Sci. China Inf. Sci. | 1 |
| 2022 | Prediction-based dual-weight switch migration scheme for SDN load balancing
Hong Zhong 0001, Jinshan Xu, Jie Cui 0004, Xiuwen Sun, Chengjie Gu, Lu Liu 0001 |
Comput. Networks | 3 |
| 2022 | Secure and Lightweight Conditional Privacy-Preserving Authentication for Fog-Based Vehicular Ad Hoc NetworksabstractVehicular ad hoc networks (VANETs) play an ever-increasing important role in improving traffic management and enhancing driving safety. However, vehicular communication using a wireless channel faces security and privacy challenges. The conditional privacy-preserving authentication (CPPA) scheme is suitable for solving the above challenges, but the existing identity-based CPPA schemes suffer from inborn key escrow issues. Motivated by this, we propose a lightweight CPPA scheme based on elliptic curve cryptography to solve the above issues, in which the pseudonym and public/private key pair of the vehicle is generated by itself, so that the proposed scheme avoids the key escrow issue. Furthermore, to achieve efficient vehicular communication, a CPPA scheme is proposed using a fog computing model that supports mobility, low latency, and location awareness. The pseudonym of the vehicle is generated by two hash chains in the proposed scheme, so that the storage overhead can be reduced efficiently under the condition that backward security is guaranteed. Security analysis shows that the scheme is secure under the random oracle and satisfies the security requirements of VANETs. Performance evaluation demonstrates that the proposed scheme outperforms related schemes in terms of computational and communication overhead. Hong Zhong 0001, Jie Cui 0004, Jing Zhang 0024, Irina Pavlovna Bolodurina, Lu Liu 0001 |
IEEE Internet Things J. | 3 |
| 2022 | Authentication and Key Agreement Based on Anonymous Identity for Peer-to-Peer CloudabstractCross-cloud data migration is one of the prevailing challenges faced by mobile users, which is an essential process when users change their mobile phones to a different provider. However, due to the insufficient local storage and computational capabilities of the smart phones, it is often very difficult for users to backup all data from the original cloud servers to their mobile phones in order to further upload the downloaded data to the new cloud provider. To solve this problem, we propose an efficient data migration model between cloud providers and construct a mutual authentication and key agreement scheme based on elliptic curve certificate-free cryptography for peer-to-peer cloud. The proposed scheme helps to develop trust between different cloud providers and lays a foundation for the realization of cross-cloud data migration. Mathematical verification and security correctness of our scheme is evaluated against notable existing schemes of data migration, which demonstrate that our proposed scheme exhibits a better performance than other state-of-the-art scheme in terms of the achieved reduction in both the computational and communication cost. Hong Zhong 0001, Chuanwang Zhang, Jie Cui 0004, Yan Xu 0007, Lu Liu 0001 |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | CBACS: A Privacy-Preserving and Efficient Cache-Based Access Control Scheme for Software Defined Vehicular NetworksabstractIn vehicular networks, caching content in fog nodes is a widely accepted and favorable way to quickly respond to massive vehicle requests, reduce content retrieval delay and improve service quality. However, to implement such caching mode, it is critical to ensure efficient security and privacy protection when vehicles access the cached content in fog nodes. In this paper, aiming at the security issue, a novel lightweight cryptography-based access control scheme for software defined vehicular networks (SDVN) is proposed, by using TESLA broadcast authentication protocol and Pederson commitment. The scheme realizes direct and efficient authentication between vehicles and fog nodes while limiting only legitimate vehicles can get request responses, and avoids limitations or deficiencies in existing access control schemes. Moreover, considering the limited cache space of the fog node, by utilizing the flexibility of the SDN paradigm, a cooperative cache update mechanism is provided. The security verification with ProVerif and detailed security analyses prove that the scheme can meet the security requirements in SDVN. And compared with the related works, our scheme achieves better performance in terms of computation and communication costs. Hong Zhong 0001, Chunyang Fan, Irina Pavlovna Bolodurina, Jie Cui 0004 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Parallel Key-Insulated Multiuser Searchable Encryption for Industrial Internet of ThingsabstractWith the rapid development of the industrial Internet of Things (IIoT) and cloud computing, an increasing number of companies outsource their data to cloud servers to save costs. To protect data privacy, sensitive industrial data must be encrypted before being outsourced to cloud servers. A multiuser searchable encryption (MUSE) scheme was introduced to ensure high efficiency of encrypted data retrieval. In an IIoT system with numerous users, the existing MUSE schemes suffer from certain key exposure problems owing to the limited key protection of smart devices and frequent queries by users. In this article, we propose a parallel key-insulated MUSE scheme for IIoT. This scheme utilizes broadcast encryption technology to implement MUSE. In addition, our scheme introduces a key-insulated primitive to improve the tolerance to key exposure. The security of our scheme is proved in the random oracle model. The experimental results show that our scheme achieves high computational efficiency. Jie Cui 0004, Hong Zhong 0001, Qingyang Zhang 0001, Chengjie Gu, Lu Liu 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | Secure and Efficient Data Sharing Among Vehicles Based on Consortium BlockchainabstractThe large amount of driving data can help intelligent vehicles make decisions to drive safely, improve vehicular services and enhance driving experience. In traditional vehicular networks, data sharing needs to be done with roadside units (RSUs). However, RSUs cannot be entirely trusted and the data stored in the RSUs may be tampered with. In addition, the deployment of RSUs along roads consumes a large amount of social resources. Further, data sharing between vehicles lacks a trusted environment, and vehicles may be unwilling to share data with others because of data security and privacy concerns. Moreover, in the event of unauthorized data sharing, the source of the leaked data is difficult to trace. In this study, we exploit consortium blockchain technology to achieve traceable and anonymous vehicle-to-vehicle (V2V) data sharing, effectively preventing second-hand sharing of data. The combination of 5G and blockchain makes it possible to share data without using RSUs. We design an enhanced delegated proof-of-stake consensus algorithm to make it more suitable for applications in the distributed Internet of Vehicles (IoV). A comprehensive analysis shows that the proposed scheme is secure and efficient. Jie Cui 0004, Fenqiang Ouyang, Zuobin Ying, Lu Wei 0003, Hong Zhong 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2022 | Reliable and Efficient Content Sharing for 5G-Enabled Vehicular NetworksabstractConditional privacy preservation and message authentication serve as the primary research issues in terms of security in vehicular networks. With the arrival of 5G era, the downloading speed of network services and the message transmission speed have significantly improved. Consequently, the content exchanged by users in vehicular networks is not limited to traffic information, and vehicles moving at high speeds can share a wide variety of contents. However, sharing content reliably and efficiently remains challenging owing to the fast-moving character of vehicles. To solve this problem, we propose a reliable and efficient content sharing scheme in 5G-enabled vehicular networks. The vehicles with content downloading requests quickly filter the adjacent vehicles to choose capable and suitable proxy vehicles and request them for content services. Thus, the purpose of obtaining a good hit ratio, saving network traffic, reducing time delay, and easing congestion during peak hours can be achieved. The security analysis indicates that the proposed scheme meets the security requirements of vehicular networks. Our cryptographic operations are based on the elliptic curve, and finally, the proposed scheme also displays favorable performance compared to other related schemes. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Lu Liu 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2022 | Proven Secure Tree-Based Authenticated Key Agreement for Securing V2V and V2I Communications in VANETsabstractVehicular ad hoc networks (VANETs) are vulnerable to many kinds of security attacks, so it is necessary to design an authenticated key agreement (AKA) scheme for securing communication channels in VANETs. Existing AKA schemes in VANETs have not provided an efficient and secure method to secure V2V and V2I communications simultaneously while meeting the necessary security and privacy requirements. Further, few key updating mechanisms, which are secure, conditional privacy-preserving, practical, and lightweight, exist in current VANETs AKA schemes. In this paper, we propose a proven secure AKA scheme for securing V2V and V2I communications in VANETs, which can be divided into two parts. The first part is a three-party authentication process in which vehicles, road side unit (RSU), and trust authority (TA) authenticate each other. The second part is the key agreement process, which is used in the key generation and updating processes. For this phase, we design a tree-based key agreement algorithm that considers two scenarios, i.e., the joining of an authenticated vehicle and the leaving of the vehicle. The formal security proof and the security analysis show that our proposed scheme satisfies session key security and the necessary security requirements in VANETs, respectively. The performance analysis demonstrates that our proposed scheme has an advantage over several representative AKA schemes in VANETs. Lu Wei 0003, Jie Cui 0004, Hong Zhong 0001, Yan Xu 0007, Lu Liu 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2022 | MOE/RF: A Novel Phishing Detection Model Based on Revised Multiobjective Evolution Optimization Algorithm and Random ForestabstractTo effectively boost computer usage, machine learning models are used in several phishing detection systems to classify enormous phishing datasets. Based on phishing patterns, researchers prefer to extract a considerable number of features to improve phishing detection performance. However, redundant and useless features in the feature set degrade the performance of the underlying classification models. In addition, several existing phishing detection models mainly focus on detection accuracy and overlook recall rates. However, in phishing detection, it is more harmful to falsely detect a phishing website as a legitimate website than it is to detect a legitimate website as a phishing website. This study proposes a novel phishing detection model, multi-objective evolution/random forest (MOE/RF), which is based on the revised multi-objective evolution optimization algorithm (MOE) and random forest (RF). The MOE/RF model uses accuracy as the detection target and minimizes the probability of false detection of phishing sites. In addition, two new strategies, the symmetric uncertainty-based population initialization and the population state-based adaptive environmental selection, are proposed to improve the performance of the MOE. Experimental results on testing five different phishing datasets demonstrated that the MOE/RF performs superior to several existing methods. Erzhou Zhu, Zhile Chen, Jie Cui 0004, Hong Zhong 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | Toward Data Transmission Security Based on Proxy Broadcast Re-encryption in Edge CollaborationabstractWith the development of IoT, more and more data is offloaded from the cloud to the edge for computing, eventually forming a collaborative computing model at the edge. However, in this model, the problem of secure data transmission has not been solved. In this model, data is transmitted and forwarded in multiple messaging systems, and existing security schemes cannot achieve end-to-end security in a multi-hop, broadcast transmission model. Therefore, in this paper, we propose a new security scheme based on proxy re-encryption and broadcast encryption techniques. Moreover, the performance and security of the scheme are further enhanced by using online-offline techniques and a trusted execution environment when integrating the scheme with edge collaboration. Finally, this paper proves the security of the scheme in theory, compares the functionality of the scheme, analyzes the theoretical performance of the scheme, and finally measures the actual performance of the scheme in the edge collaboration system. Qingyang Zhang 0001, Jie Cui 0004, Hong Zhong 0001, Lu Liu 0001 |
ACM Trans. Sens. Networks | 2 |
| 2022 | A Practical and Efficient Bidirectional Access Control Scheme for Cloud-Edge Data SharingabstractThe cloud computing paradigm provides numerous tempting advantages, enabling users to store and share their data conveniently. However, users are naturally resistant to directly outsourcing their data to the cloud since the data often contain sensitive information. Although several fine-grained access control schemes for cloud-data sharing have been proposed, most of them focus on the access control of the encrypted data (e.g., restricting the decryption capabilities of the receivers). Distinct from the existing work, this article aims to address this challenging problem by developing a more practical bidirectional fine-grained access control scheme that can restrict the capabilities of both senders and receivers. To this end, we systematically investigate the access control for cloud data sharing. Inspired by the access control encryption (ACE), we propose a novel data sharing framework that combines the cloud side and the edge side. The edge server is located in the middle of all the communications, checking and preventing illegal communications according to the predefined access policy. Next, we develop an efficient access control algorithm by exploiting the attribute-based encryption and proxy re-encryption for the proposed framework. The experimental results show that our scheme exhibits superior performance in the encryption and decryption compared to the prior work. Jie Cui 0004, Hong Zhong 0001, Geyong Min, Yan Xu 0007, Lu Liu 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2021 | Secure and Efficient Certificateless Provable Data Possession for Cloud-Based Data Management Systems
Jing Zhang 0024, Jie Cui 0004, Hong Zhong 0001, Chengjie Gu, Lu Liu 0001 |
DASFAA (1) | 2 |
| 2021 | Accelerating Knuth-Morris-Pratt String Matching over LZ77 Compressed TextabstractFor comprehensive analyzing or efficient searching from massive data, string matching is widely used as a core technique of the network traffic detection applications and text editors. However, the increasing compressed text challenges string matching to achieve high-speed processing. In this paper, we propose KCM, a fast Knuth-Morris-Pratt based string matching method over LZ77 compressed text. It leverages the gathered heuristic information during scanning to skip the characters that should have been scanned. In our evaluation with real traffic, KCM skips more than 90% compression text, which nearly approaches the theoretical upper bound. It can achieve 1.61 Gbps throughput and boost 1.87 times than the classic string matching. Xiuwen Sun, Da Mo, Jie Cui 0004, Hong Zhong 0001 |
DCC | 4 |
| 2021 | Scalable QoS-Aware Multicast for SVC Streams in Software-Defined NetworksabstractBecause network nodes are transparent in media streaming applications, traditional networks cannot utilize the scalability feature of Scalable video coding (SVC). Compared with the traditional network, SDN supports various flows in a more fine-grained and scalable manner via the OpenFlow protocol, making QoS requirements easier and more feasible. In previous studies, a Ternary Content-Addressable Memory (TCAM) space in the switch has not been considered. This paper proposes a scalable QoS-aware multicast scheme for SVC streams, and formulates the scalable QoS-aware multicast routing problem as a nonlinear programming model. Then, we design heuristic algorithms that reduce the TCAM space consumption and construct the multicast tree for SVC layers according to video streaming requests. To alleviate video quality degradation, a dynamic layered multicast routing algorithm is proposed. Our experimental results demonstrate the performance of this method in terms of the packet loss ratio, scalability, the average satisfaction, and system utility. Jie Cui 0004, Lingbiao Kong, Hong Zhong 0001, Xiuwen Sun, Chengjie Gu, Jianfeng Ma 0001 |
ISCC | 1 |
| 2021 | Assessing Profit of Prediction for SDN controllers load balancing
Hong Zhong 0001, Jinpeng Fan, Jie Cui 0004, Yan Xu 0007, Lu Liu 0001 |
Comput. Networks | 3 |
| 2021 | Design of Radiation Hardened Latch and Flip-Flop with Cost-Effectiveness for Low-Orbit Aerospace Applications
Aibin Yan, Aoran Cao, Zhelong Xu, Jie Cui 0004, Tianming Ni, Patrick Girard 0001, Xiaoqing Wen |
J. Electron. Test. | 4 |
| 2021 | An efficient and outsourcing-supported attribute-based access control scheme for edge-enabled smart healthcare
Hong Zhong 0001, Yiyuan Zhou, Qingyang Zhang 0001, Yan Xu 0007, Jie Cui 0004 |
Future Gener. Comput. Syst. | 5 |
| 2021 | Toward Achieving Fine-Grained Access Control of Data in Connected and Autonomous VehiclesabstractA connected and autonomous vehicle (CAV) is often fitted with a large number of onboard sensors and applications to support autonomous driving functions. Based on the current research, little work on applications' access to in-vehicle data has been done. Furthermore, most existing autonomous driving operating systems lack authentication and encryption units. As such, applications can excessively obtain confidential information, such as vehicle location and owner preferences and even upload it to the cloud, threatening the security of the vehicle and the privacy of the owner. In this study, we propose a fine-grained access control scheme to restrict applications' access to data in CAVs (FGAC-inCAVs). First, we present a system model composed of the following elements: a trusted third party (TTP), which is a fully trusted authority; perception components like sensors, which can capture the road information (pictures, videos, etc.); and multiple applications. Then, a fast attribute-based encryption (ABE) is presented, and security analysis also shows it is secure against selective and chosen-plaintext attacks. Furthermore, we propose a key update scheme based on the Chinese remainder theorem (CRT). Finally, the theoretical analysis and simulation experiments demonstrate its feasibility and efficiency. Jie Cui 0004, Xuelian Chen, Jing Zhang 0024, Qingyang Zhang 0001, Hong Zhong 0001 |
IEEE Internet Things J. | 1 |
| 2021 | Attribute-Based Secure Announcement Sharing Among Vehicles Using BlockchainabstractVehicles gather data collected by sensor nodes, combined with messages obtained from the other nodes in vehicular ad hoc networks (VANETs), to achieve safe driving. An announcement type of message is sent in the VANET; it is collected by mobile vehicles, uploaded to a cloud server for storage, and provided to other vehicles for reference. However, in an open cloud environment, plaintext data are vulnerable to unauthorized access and even malicious tampering. To solve this issue, we propose an attribute-based encryption algorithm using blockchain, which is maintained by a roadside unit (RSU). The uploader's symmetric key is recorded on the blockchain, and all uploaded and accessed transactions are recorded for auditing. Our scheme can achieve the function of securely accessing different types of announcement messages according to different vehicle attributes. Security analysis and experimental results indicate that our scheme has achieved a balance between security and efficiency. Jianfeng Ma 0001, Jie Cui 0004, Zuobin Ying, Jiujun Cheng |
IEEE Internet Things J. | 3 |
| 2021 | AC4AV: A Flexible and Dynamic Access Control Framework for Connected and Autonomous VehiclesabstractSensing data plays a pivotal role in connected and autonomous vehicles (CAVs), enabling CAV to perceive surroundings. For example, malicious applications might tamper this life-critical data, resulting in erroneous driving decisions and threatening the safety of passengers. Access control, one of the promising solutions to protect data from unauthorized access, is urgently needed for vehicle sensing data. However, due to the intrinsic complexity of vehicle sensing data, including historical and real time, and access patterns of different data sources, there is currently no suitable access control framework that can systematically solve this problem; current frameworks only focus on one aspect. In this article, we propose a novel and flexible access control framework,AC4AV, which aims to support various access control models, and provide APIs for dynamically adjusting access control models and developing customized access control models, thus supporting access control research on CAV for the community. In addition, we propose a data abstraction method to clearly identify data, applications, and access operations in CAV, and therefore is easily able to configure the permits of each data and application in access control policies. We have implemented a prototype to demonstrate our architecture on NATS for real-time data and NGINX for historical data, and three access control models as built-in models. We measured the performance of ourAC4AVwhile applying these access control models to real-time and historical data. The experimental results show that the framework has little impact on real-time data access within a tolerable range. Qingyang Zhang 0001, Hong Zhong 0001, Jie Cui 0004, Lingmei Ren, Weisong Shi |
IEEE Internet Things J. | 3 |
| 2021 | Toward Trusted and Secure Communication Among Multiple Internal Modules in CAVabstractBy equipping various sensors and analyzing sensed data, vehicles can perform automatic driving; these vehicles are known as connected and autonomous vehicles (CAVs). In CAVs, tampered data will result in incorrect driving decisions. Hence, secure data transmission should be ensured to enable correct life-critical decisions. Untrusted resource-constrained modules allow attackers to obtain private data from CAVs, such as the key. Benefitting from trusted computing, the proposed scheme can verify the trusted status of internal modules and achieve secure data transmission by adopting the remote attestation and hash message authentication code. The scheme is proven to be secure in the random oracle model under the computational Diffie–Hellman problem. Furthermore, we perform experiments and evaluate the performance using Intel Software Guard eXtensions, which provide part of the trusted computing function. The experimental results show that the scheme could be efficient and suitable for CAVs. Hong Zhong 0001, Wenwen Cao, Qingyang Zhang 0001, Jing Zhang 0024, Jie Cui 0004 |
IEEE Internet Things J. | 5 |
| 2021 | PA-CRT: Chinese Remainder Theorem Based Conditional Privacy-Preserving Authentication Scheme in Vehicular Ad-Hoc NetworksabstractExisting security and identity-based vehicular communication protocols used in Vehicular Ad-hoc Networks (VANETs) to achieve conditional privacy-preserving mostly rely on an ideal hardware device called tamper-proof device (TPD) equipped in vehicles. Achieving fast authentication during the message verification process is usually challenging in such strategies and further they suffer performance constraints from resulting overheads. To address such challenges, this paper proposes a novel Chinese remainder theorem (CRT)-based conditional privacy-preserving authentication scheme for securing vehicular authentication. The proposed protocol only requires realistic TPDs, and eliminates the need for pre-loading the master key onto the vehicle's TPDs. Chinese remainder theorem can dynamically assist the trusted authorities (TAs) whilst generating and broadcasting new group keys to the vehicles in the network. The proposed scheme solves the leakage problem during side channel attacks, and ensures higher level of security for the entire system. In addition, the proposed scheme avoids using the bilinear pairing operation and map-to-point hash operation during the authentication process, which helps achieving faster verification even under increasing number of signature. Moreover, the security analysis shows that our proposed scheme is secure under the random oracle model and the performance analysis shows that our proposed scheme is efficient in reducing computation and communication overheads. Jing Zhang 0024, Jie Cui 0004, Hong Zhong 0001, Lu Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Secure and Lightweight Conditional Privacy-Preserving Authentication for Securing Traffic Emergency Messages in VANETsabstractOwing to the development of wireless communication technology and the increasing number of automobiles, vehicular ad hoc networks (VANETs) have become essential tools to secure traffic safety and enhance driving convenience. It is necessary to design a conditional privacy-preserving authentication (CPPA) scheme for VANETs because of their vulnerability and security requirements. Traditional CPPA schemes have two deficiencies. One is that the communication or storage overhead is not sufficiently low, but the traffic emergency message requires an ultra-low transmission delay. The other is that traditional CPPA schemes do not consider updating the system secret key (SSK), which is stored in an unhackable Tamper Proof Device (TPD), whereas side-channel attack methods and the wide usage of the SSK increase the probability of breaking the SSK. To solve the first issue, we propose a CPPA signature scheme based on elliptic curve cryptography, which can achieve message recovery and be reduced to elliptic curve discrete logarithm assumption, so that traffic emergency messages are secured with ultra-low communication overhead. To solve the second issue, we design an SSK updating algorithm, which is constructed on Shamir's secret sharing algorithm and secure pseudo random function, so that the TPDs of unrevoked vehicles can update SSK securely. Formal security proof and analysis show that our proposed scheme satisfies the security and privacy requirements of VANETs. Performance analysis demonstrates that our proposed scheme requires less storage size and has a lower transmission delay compared with related schemes. Lu Wei 0003, Jie Cui 0004, Yan Xu 0007, Jiujun Cheng, Hong Zhong 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | SMAKA: Secure Many-to-Many Authentication and Key Agreement Scheme for Vehicular NetworksabstractWith the rising popularity of the Internet and communication technology, vehicles can analyze and judge the real-time data collected by various cloud service providers (CSPs) in a vehicular network. However, in a vehicular network environment, real-time data are transmitted via wireless channels, which can lead to security and privacy issues. To avoid illegal access by adversaries, vehicle authentication and key agreement mechanism has been considered as one of the promising security measures in vehicular network environments. Besides, most of the solutions focus on authentication between one vehicle and one CSP. In such strategies, the implementation of efficient authentication for multiple vehicles and CSPs simultaneously is usually challenging. Further, they are also subjected to performance limitations due to the overhead incurred. To solve these issues, we propose a many-to-many authentication and key agreement scheme for secure authentication between multiple vehicles and CSPs. The proposed scheme can prevent unauthorized access and provide SK-security even if temporary information is leaked. To improve the service, the CSP only needs to broadcast an anonymous message periodically instead of having to generate a unique anonymous message for each of vehicles. Similarly, when a vehicle wants to request the services of m CSPs, it only needs to send one request message instead of m. Therefore, the proposed scheme not only implements many-to-many communication but also significantly reduces the computation and communication overhead. Moreover, a thorough security analysis shows that the proposed scheme provides better security compared to other related schemes. Jing Zhang 0024, Hong Zhong 0001, Jie Cui 0004, Yan Xu 0007, Lu Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | QoS-Aware Multicast for Scalable Video Streaming in Software-Defined NetworksabstractScalable Video Coding (SVC) is a promising coding technique that enables flexible video transmission to support heterogeneous devices. However, the current best-effort delivery model characterized by the Internet cannot fully exploit the scalability feature of SVC because the network nodes are transparent for multimedia streaming applications. Software-defined networking (SDN) has emerged as an innovative network paradigm that decouples the control and forwarding planes while routing. This architecture with the OpenFlow protocol enables network operators to obtain per-flow QoS control in a more scalable, flexible, and finely granular manner compared to the conventional network architecture. Inspired by these facts, this paper designs a comprehensive QoS-aware multicast scheme for scalable video streaming over SDN networks. First, we present the designed multimedia streaming multicast system architecture and formulate the QoS-aware multicast routing problem as a non-linear programming model. We then propose a fundamental tree construction algorithm that decomposes the video streaming requests into subrequests and serves them in a bottom-up manner. Furthermore, we design a layer switching strategy based on the video distortion model to mitigate network-induced video quality distortion. Finally, the experimental results are presented to validate the performance of our methods in terms of scalability, network utility, video playout quality, and playback interruption ratio. Hong Zhong 0001, Yan Xu 0007, Jie Cui 0004 |
IEEE Trans. Multim. | 4 |
| 2020 | A Sextuple Cross-Coupled SRAM Cell Protected against Double-Node UpsetsabstractIn this paper, we propose a sextuple cross-coupled SRAM cell, namely SCCS18T, protected against double-node upsets. Since the proposed SCCS18T cell forms a large feedback loop for value retention and error interception, the cell can provide self-recoverability from any single-node upsets (SNUs) and partial double-node upsets (DNUs). Moreover, the proposed cell has optimized operation speed due to the use of six access transistors. Simulation results show that the SCCS18T cell can save approximately 65% read access time at the cost of 49% power dissipation and 50% silicon area on average, compared with typical hardened SRAM cells. Aibin Yan, Jun Zhou 0016, Jie Cui 0004, Tianming Ni, Xiaoqing Wen, Patrick Girard 0001 |
ATS | 4 |
| 2020 | HITTSFL: Design of a Cost-Effective HIS-Insensitive TNU-Tolerant and SET-Filterable Latch for Safety-Critical ApplicationsabstractThis paper proposes a cost-effective, high-impedance-state (HIS)-insensitive, triple-node-upset (TNU)-tolerant and single-event-transient (SET)-filterable latch, namely HITTSFL, to ensure high reliability with low-cost. The latch mainly comprises an output-level SET-filterable Schmitt-trigger and three inverters that make the values stored in three parallel single-node-upset (SNU)-recoverable dual-interlocked-storage-cells (DICEs) converge at a common node to tolerate any possible TNU. The latch does not use C-elements to be insensitive to the HIS. Simulation results demonstrate the TNU-tolerability and SET-filterability of the proposed HITTSFL latch. Moreover, due to the use of clock-gating technologies and fewer transistors, the proposed latch can reduce delay, power, and area by 76.65%, 6.16%, and 28.55%, respectively, compared with the state-of-the-art TNU hardened latch (TNUHL) that cannot filter SETs. Aibin Yan, Xiangfeng Feng, Jie Cui 0004, Zuobin Ying, Patrick Girard 0001, Xiaoqing Wen |
DAC | 5 |
| 2020 | Dual-Interlocked-Storage-Cell-Based Double-Node-Upset Self-Recoverable Flip-Flop Design for Safety-Critical ApplicationsabstractThis paper presents a novel dual-interlocked storage-cell (DICE)-based double-node-upset (DNU) self-recoverable, namely DURI-FF, in the nano-scale CMOS technology. The master latch of the DURI-FF cell consists of three transmission gates (TGs) and three interlocked DICEs with three common nodes. The common nodes are connected to TGs for value initialization. The slave latch of the DURI-FF cell comprises six TGs, six inverters and three interlocked DICEs. The outputs of the inverters respectively feed the internal nodes of the slave latch. The interlocked DICEs make the master latch and the slave latch DNU self-recoverable. Simulation results validate the DNU self-recoverability of the proposed DURI-FF cell. Moreover, compared with the state-of-the-art hardened flip-flop cells, the proposed DURI-FF cell achieves roughly 43% delay reduction at the cost of moderate silicon area and power dissipation. Aibin Yan, Zhelong Xu, Jie Cui 0004, Zuobin Ying, Zhengfeng Huang, Huaguo Liang, Patrick Girard 0001, Xiaoqing Wen |
ISCAS | 3 |
| 2020 | Design of a Highly Reliable SRAM Cell with Advanced Self-Recoverability from Soft ErrorsabstractIn this paper, a highly reliable SRAM cell, namely SESRS cell, is proposed. Since the cell has a special feedback mechanism among its internal nodes and has more access transistors compared to a standard SRAM cell, the SESRS cell provides the following advantages: (1) it can self-recover from single node upsets (SNUs) and double-node upsets (DNUs); (2) it can reduce power consumption by 49.78% and silicon area by 7.92%, compared with the only existing SRAM cell which can self-recover from all possible DNUs. Simulation results validate the robustness of the proposed SESRS cell. Moreover, compared with the state-of-the-art hardened SRAM cells, the proposed SESRS cell can reduce read access time by 61.93% on average. Zhengda Dou, Aibin Yan, Jun Zhou 0016, Yuanjie Hu, Tianming Ni, Jie Cui 0004, Patrick Girard 0001, Xiaoqing Wen |
ITC-Asia | 7 |
| 2020 | LPE-RCM: Lightweight Privacy-Preserving Edge-Based Road Condition Monitoring for VANETs
Yan Xu 0007, Jie Cui 0004, Jing Zhang 0024, Hong Zhong 0001 |
WASA (2) | 3 |
| 2020 | Two-stage index-based central keyword-ranked searches over encrypted cloud data
Hong Zhong 0001, Zhanfei Li, Yan Xu 0007, Jie Cui 0004 |
Sci. China Inf. Sci. | 5 |
| 2020 | LBBESA: An efficient software-defined networking load-balancing scheme based on elevator scheduling algorithmabstractSummary Elevator scheduling algorithms generally denote methods used to calculate how to use the elevator. These algorithms can distribute elevators to various floors of a building, thereby achieving efficient transportation. From the perspective of the elevator scheduling problem, we address the load‐balancing problem for software‐defined networking (SDN) architecture and propose a load‐balancing method based on the elevator scheduling algorithm, LBBESA. We take advantage of the flexibility of the SDN architecture, obtain the real‐time load of the server through real‐time statistical analyses of the SDN switch port traffic by the controller, and combine this with the idea of regional elevator allocation to coordinate the connection of the client's requests and realize the load balancing of each server in the cluster. Simulation experiments show that, compared with the round‐robin algorithm, LBBESA is more effective in the load balancing of the server pool and can improve the throughput of the server pool to a certain extent. In addition, our scheme is easy to implement and has high scalability. Qiliang Li, Jie Cui 0004, Hong Zhong 0001, Yichao Du, Yonglong Luo, Lu Liu 0001 |
Concurr. Comput. Pract. Exp. | 2 |
| 2020 | An Extensible and Effective Anonymous Batch Authentication Scheme for Smart Vehicular NetworksabstractIn recent years, research on the security of Industry 4.0 and the Internet of Things (IoT) has attracted a close attention from industry, government, and the scientific community. Smart vehicular networks, as a type of industrial IoT, inevitably exchange large amounts of security and privacy-sensitive data, which make them attractive targets for attackers. For protecting network security and privacy, we have proposed an extensible and effective anonymous batch authentication scheme. In contrast to traditional pseudonym authentication schemes, the same system private key need not to be preloaded in our scheme, effectively avoiding a system failure when destroying a vehicle. Besides, the certificate revocation list (CRL) size is merely related to the number of vehicles that have been revoked, regardless of the number of pseudonym certificates for revoked vehicles. Moreover, this scheme maintains the effectiveness of the traditional scheme, effectively reduces the scale of the CRL, and employs an identity revocation scheme that supports rapid distribution. The scheme supports conditional privacy protection, namely, only the trusted authority (TA) can uniquely trace and revoke vehicles. For illegal vehicles, the TA releases the two hashed seeds to facilitate traceability by all entities in its domain. Furthermore, security analysis indicates that our solution is secure under the random oracle model and fulfills a series of security requirements of vehicular networks. Compared to existing authentication schemes, performance evaluations show that the scheme offers relatively good performance in terms of time consumption. Jing Zhang 0024, Hong Zhong 0001, Jie Cui 0004, Yan Xu 0007, Lu Liu 0001 |
IEEE Internet Things J. | 3 |
| 2020 | Intrusion-resilient public cloud auditing scheme with authenticator update
Yan Xu 0007, Jie Cui 0004, Hong Zhong 0001 |
Inf. Sci. | 3 |
| 2020 | Efficient dynamic multi-keyword fuzzy search over encrypted cloud data
Hong Zhong 0001, Zhanfei Li, Jie Cui 0004, Lu Liu 0001 |
J. Netw. Comput. Appl. | 3 |
| 2020 | Edge Computing in VANETs-An Efficient and Privacy-Preserving Cooperative Downloading SchemeabstractWith the advancements in social media and rising demand for real traffic information, the data shared in vehicular ad hoc networks (VANETs) indicate that the size and amount of requested data will continue increasing. Vehicles in the same area often have similar data downloading requests. If we ignore the common requests, the resource allocation efficiency of the VANET system will be quite low. Motivated by this fact, we propose an efficient and privacy-preserving data downloading scheme for VANETs, based on the edge computing concept. In the proposed scheme, a roadside unit (RSU) can find the popular data by analyzing the encrypted requests sent from nearby vehicles without having to sacrifice the privacy of their download requests. Further, the RSU caches the popular data in nearby qualified vehicles called edge computing vehicles (ECVs). If a vehicle wishes to download the popular data, it can download it directly from the nearby ECVs. This method increases the downloading efficiency of the system. The security analysis results show that the proposed scheme can resist multiple security attacks. The performance analysis results demonstrate that our scheme has reasonable computation and communication overhead. Finally, the OMNeT++ simulation results indicate that our scheme has good network performance. Jie Cui 0004, Lu Wei 0003, Hong Zhong 0001, Jing Zhang 0024, Yan Xu 0007, Lu Liu 0001 |
IEEE J. Sel. Areas Commun. | 1 |
| 2020 | Information Assurance Through Redundant Design: A Novel TNU Error-Resilient Latch for Harsh Radiation EnvironmentabstractIn nano-scale CMOS technologies, storage cells such as latches are becoming increasingly sensitive to triple-node-upset (TNU) errors caused by harsh radiation effects. In the context of information assurance through redundant design, this article proposes a novel low-cost and TNU on-line self-recoverable latch design which is robust against harsh radiation effects. The latch mainly consists of a series of mutually interlocked 3-input Muller C-elements (CEs) that forms a circular structure. The output of any CE in the latch respectively feeds back to one input of some specified downstream CEs, making the latch completely self-recoverable from any possible TNU, i.e., the latch is completely TNU-resilient. Simulation results demonstrate the complete TNU-resiliency of the proposed latch. In addition, due to the use of fewer transistors and a high-speed path, the proposed latch reduces the delay-power-area product by approximately 91 percent compared with the state-of-the-art TNU hardened latch (TNUHL), which cannot provide a complete TNU-resiliency. Aibin Yan, Yuanjie Hu, Jie Cui 0004, Zhengfeng Huang, Tianming Ni, Patrick Girard 0001, Xiaoqing Wen |
IEEE Trans. Computers | 3 |
| 2020 | Extensible Conditional Privacy Protection Authentication Scheme for Secure Vehicular Networks in a Multi-Cloud EnvironmentabstractWith an increasing number of cloud service providers (CSPs), research works on multi-cloud environments to provide solutions to avoid vendor lock-in and deal with the single-point failure problem have expanded considerably. However, a few schemes focus on the conditional privacy protection authentication of vehicular networks under a multi-cloud environment. In this regard, we propose a robust and extensible authentication scheme for vehicular networks to fulfil the ever-growing diversified service demands from users. According to our solution, the vehicles need to register with the trusted authority (TA) only once to achieve a fast and efficient authentication with CSPs. Additionally, as long as the new CSP is successfully registered in TA, it can participate in vehicular service. A cloud broker, which is managed by the TA, is responsible for connecting all the cloud services; consequently, the complexity involved in the selection of CSPs is hidden from the users' view. A detailed security analysis establishes that our scheme can fulfil conditional privacy protection and achieve the security objectives of vehicular networks. Our scheme is based on elliptic curve cryptography and does not employ the complex bilinear pairing operation. An evaluation of performance of the proposed scheme indicates that it is suitable for applications involving vehicular networks. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Lu Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | RTEF-PP: A Robust Trust Evaluation Framework with Privacy Protection for Cloud Services Providers
Hong Zhong 0001, JianZhong Zou, Jie Cui 0004, Yan Xu 0007 |
ICA3PP (1) | 3 |
| 2019 | A Novel Triple-Node-Upset-Tolerant CMOS Latch Design using Single-Node-Upset-Resilient CellsabstractNano-scale CMOS circuits are vulnerable to single-event triple-node-upsets (SETUs). This paper proposes the design of a novel CMOS latch to tolerate any SETU using single-node-upset-resilient cells converged at a highly reliable node. The latch makes use of three single-node-upset-resilient cells, each of which mainly consists of triple mutually feeding back 2-input C-elements. These cells have a common converged output node feeding back to the output of the latch, making the latch capable of tolerating any SETU. Simulation results not only confirm the SETU tolerance capability but also show a significant area-power-delay-product reduction of 96.81% for the proposed latch compared with the only existing SETU hardened latch. Zhiyuan Song, Aibin Yan, Jie Cui 0004, Xiaoqing Wen, Chaoping Lai, Zhengfeng Huang, Huaguo Liang |
ITC-Asia | 3 |
| 2019 | DDoS detection and defense mechanism based on cognitive-inspired computing in SDN
Jie Cui 0004, Yonglong Luo, Hong Zhong 0001 |
Future Gener. Comput. Syst. | 1 |
| 2019 | RSMA: Reputation System-Based Lightweight Message Authentication Framework and Protocol for 5G-Enabled Vehicular NetworksabstractTraditional public key infrastructure-based authentication schemes provide vehicular networks with identity authentication and conditional privacy protection, which are not sufficient for assessing the credibility of messages. Additionally, although the new generation of cellular networks (5G) can dramatically improve the transmission efficiency of the messages, many existing authentication schemes are based on complex bilinear pairing operations, and the calculation time is too long to be suitable for delay-sensitive 5G-enabled vehicular networks. To address these issues, we propose a reputation system-based lightweight message authentication framework and protocol for 5G-enabled vehicular networks. The trusted authority (TA) is in charge of reputation management. A vehicle with a reputation score below the given threshold cannot obtain a credit reference from the TA for participating in the communication; therefore, the number of untrusted messages in vehicular networks is reduced from the source. Security analysis shows that our scheme is secure against an adaptively chosen-message attack, and also satisfies a series of requirements of vehicular networks. The scheme is based on the elliptic curve cryptosystem and supports batch authentication; therefore, it shows better performance in terms of time consumption when compared with related schemes. Jie Cui 0004, Hong Zhong 0001, Zuobin Ying, Lu Liu 0001 |
IEEE Internet Things J. | 1 |
| 2019 | OOABKS: Online/offline attribute-based encryption for keyword search in mobile cloud
Jie Cui 0004, Yan Xu 0007, Hong Zhong 0001 |
Inf. Sci. | 1 |
| 2019 | Privacy-preserving authentication scheme with full aggregation in VANET
Hong Zhong 0001, Shunshun Han, Jie Cui 0004, Jing Zhang 0024, Yan Xu 0007 |
Inf. Sci. | 3 |
| 2019 | SCPLBS: a smart cooperative platform for load balancing and security on SDN distributed controllers
Hong Zhong 0001, Jianqiao Sheng, Yan Xu 0007, Jie Cui 0004 |
Peer-to-Peer Netw. Appl. | 4 |
| 2019 | Differentially Private Double Spectrum Auction With Approximate Social Welfare MaximizationabstractSpectrum auction is an effective approach to improve the spectrum utilization, by leasing an idle spectrum from primary users to secondary users. Recently, a few differentially private spectrum auction mechanisms have been proposed, but, as far as we know, none of them addressed the differential privacy in the setting of double spectrum auctions. In this paper, we combine the concept of differential privacy with double spectrum auction design and present a differentially private double spectrum auction mechanism with approximate social welfare maximization (DDSM). Specifically, we design the mechanism by employing the exponential mechanism to select clearing prices for the double spectrum auction with probabilities exponentially proportional to the related social welfare values and then improve the mechanism in several aspects, such as the designs of the auction algorithm, the utility function, and the buyer grouping algorithm. Through theoretical analysis, we prove that DDSM achieves differential privacy, approximate truthfulness, and approximate social welfare maximization. Extensive experimental evaluations show that DDSM achieves a good performance in terms of social welfare. Tianjiao Ni, Hong Zhong 0001, Shun Zhang 0002, Jie Cui 0004 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2019 | An Efficient Message-Authentication Scheme Based on Edge Computing for Vehicular Ad Hoc NetworksabstractWith the progress in wireless communication technology and the increasing number of vehicles, vehicular ad hoc networks (VANETs) have become essential for improving road conditions and enhancing driving experience. The core of the VANETs is the communication between different vehicles, and the security of the communication is based on message authentication. Several schemes have been designed to enhance the efficiency of message authentication. However, these schemes have the disadvantage of redundant authentication, i.e., repeated authentication of the same message, and fail to seek invalid messages from the batch of messages. To solve these problems, this paper introduces a novel edge-computing concept into the message-authentication process of VANETs. In our scheme, the roadside unit can efficiently authenticate messages from nearby vehicles and broadcast the authentication results to the vehicles within its communication range, thereby reducing redundant authentication and enhancing the efficiency of the entire system. The security analysis results show that the proposed scheme satisfies the security requirements of the VANETs. The performance analysis results show that the proposed scheme can not only work well in an ideal environment where the attacker is absent but also capable of quickly identifying valid and invalid messages even if the VANET is attacked. Jie Cui 0004, Lu Wei 0003, Jing Zhang 0024, Yan Xu 0007, Hong Zhong 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2019 | PATH: privacy-preserving auction for heterogeneous spectrum allocations
Ruihong Che, Hong Zhong 0001, Miaomiao Tian 0001, Jie Cui 0004 |
Wirel. Networks | 5 |
| 2018 | TDDAD: Time-Based Detection and Defense Scheme Against DDoS Attack on SDN Controller
Jie Cui 0004, Jiantao He, Yan Xu 0007, Hong Zhong 0001 |
ACISP | 1 |
| 2018 | Intrusion-Resilient Public Auditing Protocol for Data Storage in Cloud Computing
Yan Xu 0007, Jie Cui 0004, Hong Zhong 0001 |
ACISP | 3 |
| 2018 | Identity-Based Proofs of Storage with Enhanced Privacy
Miaomiao Tian 0001, Shibei Ye, Hong Zhong 0001, Lingyan Wang, Fei Chen 0003, Jie Cui 0004 |
ICA3PP (4) | 6 |
| 2018 | Efficient Conditional Privacy-Preserving Authentication Scheme Using Revocation Messages for VANETabstractVehicular ad-hoc network (VANET) plays an extremely important role in future intelligent transportation systems. Many researchers proposed different schemes to improve communication efficiency under the premise that conditional privacy is preserved. In this paper, we propose an efficient conditional privacy-preserving authentication scheme using revocation messages to optimize VANET communication. Our scheme consists of two phases. First, in the anonymous identity generation and message signing phase, lightweight hash operations are used, and message length is reduced both the computation and communication overheads in VANET. Second, in the vehicle revocation phase, Road Side Units broadcast revocation messages to prevent malicious vehicles from generating anonymous identity and signing messages quickly. Security and performance analysis demonstrate that our proposed scheme is more secure and efficient than many existing schemes, and is more suitable for the deployment of VANET. Hong Zhong 0001, Jie Cui 0004, Kewei Sha |
ICCCN | 3 |
| 2018 | Transaction-Based Flow Rule Conflict Detection and Resolution in SDNabstractSoftware-defined Networking (SDN) brings new vitality to traditional network technology as its nice property of network programmability makes our network more open and flexible. By using interfaces of SDN controllers, different applications with diverse network functions can deploy their needed flow rules into SDN switches. However, some of these flow rules would probably produce conflicts that result in invalidation of network functions and cause security issues. To address this issue, we design a novel approach, Transaction-based flow rule Conflict Detection and Resolution (TCDR), which can isolate the flow rules of different network functions to avoid interference between different network functions. Meanwhile, our proposed method introduces a transaction-based authentication to guarantee the legality of flow rules. Finally, we implement a prototype of our solution, and evaluate its effectiveness and efficiency. The performance evaluation shows that TCDR can reject illegal flow rules and avoid many flow rule conflicts with a small overhead. Jie Cui 0004, Hong Zhong 0001, Yan Xu 0007, Kewei Sha |
ICCCN | 1 |
| 2018 | Novel low cost and DNU online self-recoverable RHBD latch design for nanoscale CMOSabstractThis paper presents a novel low cost and double node upset (DNU) online self-recoverable latch design using radiation hardening by design (RHBD) technology. The latch mainly consists of 8 interlocked input-split inverters. Since all internal nodes are interlocked, if any of the possible node pairs occurs a DNU, the latch can restore back. Simulation results have demonstrated the DNU online self-recoverability and also demonstrated that the proposed latch design saves 71.68% transmission delay, 72.92% power dissipation and 93.69% comprehensive delay-power-area product (DPAP) on average, compared with the up-to-date DNU online self-recoverable latch designs. Aibin Yan, Chaoping Lai, Yinlei Zhang, Chunming Liu, Zhile Chen, Jie Cui 0004, Huaguo Liang |
ISCAS | 8 |
| 2018 | Reprint of "LBBSRT: An efficient SDN load balancing scheme based on server response time"
Hong Zhong 0001, Yaming Fang, Jie Cui 0004 |
Future Gener. Comput. Syst. | 3 |
| 2018 | Efficient Privacy-Preserving Scheme for Real-Time Location Data in Vehicular Ad-Hoc NetworkabstractThe development of vehicular ad-hoc network (VANET) allows vehicle users to enjoy location-based services through the network at any time and place. However, it also raises location privacy issues. Privacy-preservation of large amounts real-time location data is a critical issue. Existing research work, such as the mix-zone scheme, has protected users' location privacy and driving routes to a certain extent. However, existing schemes have some deficiencies in security and efficiency. This paper presents a novel location privacy protection scheme. Vehicles can generate virtual locations dynamically based on the situation of surrounding vehicles to provide misleading information regarding the driving route and thus achieve location privacy. We use entropy of anonymity set and tracking success ratio as metrics to measure the level of privacy-preserving. Simulation experiments have been carried out to compare with other existing schemes. The results show that entropy of anonymity set in our scheme is 100% larger than the compared scheme and the tracking success ratio has decreased from 10% to 1%. So, the results illustrate that the proposed scheme offers better security and location-based services. Jie Cui 0004, Jingyu Wen, Shunshun Han, Hong Zhong 0001 |
IEEE Internet Things J. | 1 |
| 2018 | An efficient certificateless aggregate signature without pairings for vehicular ad hoc networks
Jie Cui 0004, Jing Zhang 0024, Hong Zhong 0001, Yan Xu 0007 |
Inf. Sci. | 1 |
| 2018 | AKSER: Attribute-based keyword search with efficient revocation in cloud computing
Jie Cui 0004, Hong Zhong 0001, Yan Xu 0007 |
Inf. Sci. | 1 |
| 2018 | An efficient and secure recoverable data aggregation scheme for heterogeneous wireless sensor networks
Hong Zhong 0001, Lili Shao, Jie Cui 0004, Yan Xu 0007 |
J. Parallel Distributed Comput. | 3 |
| 2018 | Data aggregation with end-to-end confidentiality and integrity for large-scale wireless sensor networksabstractIn wireless sensor networks, data aggregation allows in-network processing, which leads to reduced packet transmissions and reduced redundancy, and thus is helpful to prolong the overall lifetime of wireless sensor networks. In current studies, Elliptic Curve ElGamal homomorphic encryption algorithm has been widely used to protect end-to-end data confidentiality. However, these works suffer from the expensive mapping function during decryption. If the aggregated results are huge, the base station has no way to gain the original data due to the hardness of the elliptic curve discrete logarithm problem. Therefore, these schemes are unsuitable for the large-scale WSNs. In this paper, we propose a secure energy-saving data aggregation scheme designed for the large-scale WSNs. We employ Okamoto-Uchiyama homomorphic encryption algorithm to protect end-to-end data confidentiality, use MAC to achieve in-network false data filtering, and utilize the homomorphic MAC algorithm to achieve end-to-end data integrity. Two popular IEEE 802.15.4-compliant wireless sensor network platforms, Tmote Sky and iMote 2 have been used to evaluate the efficiency and feasibility of our scheme. The results demonstrate that our scheme achieved better performance in reducing energy consumption. Moreover, system delay, especially decryption delay at the base station, has been reduced when compared to other state-of-art methods. Jie Cui 0004, Lili Shao, Hong Zhong 0001, Yan Xu 0007, Lu Liu 0001 |
Peer-to-Peer Netw. Appl. | 1 |
| 2018 | Multi-authority attribute-based encryption access control scheme with policy hidden for cloud storage
Hong Zhong 0001, Yan Xu 0007, Jie Cui 0004 |
Soft Comput. | 4 |
| 2018 | A Load-Balancing Mechanism for Distributed SDN Control Plane Using Response TimeabstractSoftware-defined networking (SDN) has become a popular paradigm for managing large-scale networks including cloud servers and data centers because of its advantages of centralized management and programmability. The issues of scalability and reliability that a single centralized controller suffers makes distributed controller architectures emerge. One key limitation of distributed controllers is the statically configured switch-controller mapping, easily causing uneven load distribution among controllers. Previous works have proposed load-balancing methods with switch migration to address this issue. However, the higher-load controller is always directly considered as the overloaded controller that need to shift its load to other controllers, even if it has no response time delay. The pursuit of absolute load-balancing effect can also result in frequent network delays and service interruptions. Additionally, if there are several overloaded controllers, just one controller with the maximum load can be addressed within a single load-balancing operation, reducing load-balancing efficiency. To address these problems, we propose SMCLBRT, a load-balancing strategy of multiple SDN controllers based on response time, considering the changing features of real-time response times versus controller loads. By selecting the appropriate response time threshold and dealing with multiple overloading controllers simultaneously, it can well solve load-balancing problem in SDN control plane with multiple overloaded controllers. Simulation experiments exhibit the effectiveness of our scheme. Jie Cui 0004, Qinghe Lu, Hong Zhong 0001, Miaomiao Tian 0001, Lu Liu 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2017 | An Efficient Identity-Based Privacy-Preserving Authentication Scheme for VANETs
Jie Cui 0004, Wenyu Xu, Kewei Sha, Hong Zhong 0001 |
CollaborateCom | 1 |
| 2017 | Secure, efficient and practical double spectrum auctionabstractTruthful spectrum auction is believed to be an effective method for spectrum redistribution. However, privacy concerns have largely hampered the practical applications of truthful spectrum auctions. In this paper, to make the applications of double spectrum auctions practical, we present a secure, efficient and practical double spectrum auction design, SDSA. Specifically, by combining three security techniques: homomorphic encryption, secret sharing and garbled circuits, we design a secure two-party protocol computing a socially efficient double spectrum auction, TDSA, without leaking any information about sellers' requests or buyers' bids beyond the auction outcome. We give the formal security definition in our context, and theoretically prove the security that our design achieves. Experimental results show that our design is efficient and practical even for large-scale double spectrum auctions. Xuemei Wei, Hong Zhong 0001, Jie Cui 0004, Yan Xu 0007, Shun Zhang 0002 |
IWQoS | 4 |
| 2017 | HLDTL: High-performance, low-cost, and double node upset tolerant latch designabstractThis paper presents a high-performance, low-cost, and double node upset (DNU) tolerant latch design. The latch mainly constructs from a 3-input Muller C-element at the output stage and a single node upset resilient cell for keeping data, and the cell mainly consists of triple mutual feedback 2-input Muller C-elements, thus the latch is DNU tolerant. Using fewer CMOS transistors, clock gating technique, and high-speed transmission path, the latch also performs with lower cost penalties. Simulation results have demonstrated the DNU tolerability and a ~97.78% area-power-delay product saving for the latch design on average compared with the DNU tolerant latch designs. Aibin Yan, Zhengfeng Huang, Maoxiang Yi, Jie Cui 0004, Huaguo Liang |
VTS | 4 |
| 2017 | Area-based mobile multicast group key management scheme for secure mobile cooperative sensing
Jie Cui 0004, Hong Zhong 0001, Weiya Luo, Jing Zhang 0024 |
Sci. China Inf. Sci. | 1 |
| 2017 | Multiple multicast group key management for the Internet of PeopleabstractSummary Group key management (GKM) is an important research topic in mobile multicast communication nowadays. With the development of multiple services based on groups, it may be a very common phenomenon that multiple multicast groups coexist under a single network, and mobile subscribers can subscribe a variety of these services. Nevertheless, the current GKM schemes are focused on the communication in only a single group, which do not fit for multiple multicast group scenarios because of inefficient use of keys. In this paper, we propose a novel GKM scheme for multiple multicast groups in the Internet of People, called the area based multiple GKM (AMGKM) scheme. AMGKM can be implemented in wireless mobile network environments such as VANETs, and supports users to move across the wireless networks in the Internet of People while users subscribing to multiple multicast services with minimized communication overheads. AMGKM can also effectively mitigate the investment pressure of signaling load, and satisfy both the forward and the backward security and support membership changes. Our proposed method exploits the master key encryption (MKE) algorithm for efficiently reducing the rekeying overheads while providing intense security. Copyright © 2016 John Wiley & Sons, Ltd. Hong Zhong 0001, Weiya Luo, Jie Cui 0004 |
Concurr. Comput. Pract. Exp. | 3 |
| 2017 | LBBSRT: An efficient SDN load balancing scheme based on server response time
Hong Zhong 0001, Yaming Fang, Jie Cui 0004 |
Future Gener. Comput. Syst. | 3 |
| 2017 | LEPA: A Lightweight and Efficient Public Auditing Scheme for Cloud-Assisted Wireless Body Sensor NetworksabstractFrom smart watch to remote healthcare system, wireless body sensor networks (WBSNs) play an important role in modern healthcare system. However, the weak capacity of devices has limited WBSNs development. Considering the huge processing and storage capacity of the cloud, it can be merged with WBSNs to make up for the deficiencies of weak capacity. Based on this consideration, the concept of cloud-assisted WBSNs has been proposed recently. In contrast to generic data, the data in cloud-assisted WBSNs will be used for providing medical diagnosis, so the integrity of data is very important because any modification will result in severe consequences such as misdiagnosis. The public auditing scheme could provide an efficient solution to check the data integrity remotely without downloading them. However, the traditional public auditing scheme for cloud cannot be used directly due to the high data density and weak processing capacity in WBSNs. So, in this paper, we proposed a lightweight and efficient public auditing scheme, LEPA, for cloud-assisted WBSNs. Compared with similar schemes, the WBSNs’ client only needs to do one symmetrical encryption with low computational cost in LEPA. Security proof shows that LEPA can resist two types of adversaries in random oracle model. The efficiency evaluation also shows that LEPA outperforms previous proposals. Jie Cui 0004, Hong Zhong 0001, Yiwen Zhang 0001, Qiang He 0001 |
Secur. Commun. Networks | 2 |
| 2016 | Quantum private set intersection cardinality and its application to anonymous authentication
Yi Mu 0001, Hong Zhong 0001, Shun Zhang 0002, Jie Cui 0004 |
Inf. Sci. | 5 |
| 2016 | Efficient extensible conditional privacy-preserving authentication scheme supporting batch verification for VANETsabstractAbstract By using pseudo‐identity‐based signature, a conditional privacy‐preserving authentication scheme was proposed in this paper, called EECB, to solve the anonymous authentication issue in vehicular ad hoc networks. In this scheme, pseudo‐identities and the corresponding private keys are generated by the private key generator alone, which is credible and independent. So only Adding private key generators can satisfy the increasing pseudo‐identities demand. In other words, it has achieved the extensible of the scheme. However, the malicious vehicle can only be traced by trust authority. Furthermore, the protocol supports batch verification and the operation of a signature verification only needs two bilinear pairings and some point multiplication. The security of the signature scheme in EECB can be proved to be equivalent to the standard computational Diffie–Hellman problem in the random oracle. The experiment and the analysis indicated that, compared with the existing well‐known schemes, EECB has higher authentication efficiency and less communication cost. Copyright © 2017 John Wiley & Sons, Ltd. Yimin Wang 0004, Hong Zhong 0001, Yan Xu 0007, Jie Cui 0004, Fuchun Guo |
Secur. Commun. Networks | 4 |
| 2016 | Many-to-one homomorphic encryption schemeabstractThe existing homomorphic encryption schemes are mostly in the form of “one-to-one” deployment models, where one party usually encrypts the plaintext and another party decrypts the ciphertext in public key cryptosystem. This form of cryptography loses efficiency under the demands of “one-to-many”, “many-to-one”, and “many-to-many” scenarios. In practice, there are many “many-to-one” scenarios, where the number of the receivers is usually very small compared with the number of the senders, and a receiver may serve millions of senders. The traditional “one-to-one” homomorphic encryption schemes are inefficient in such “many-to-one” scenarios. In this paper, we combine the homomorphic encryption concept with the cryptography form of “multi-party encryption, one-party decryption” to propose the “many-to-one” homomorphic encryption scheme. Firstly, the model of “many-to-one” homomorphic encryption scheme is built. Secondly, a “many-to-one” homomorphic encryption scheme is constructed based on the “somewhat” scheme, following by which, proving the correctness, homomorphism and security of our proposed scheme. Furthermore, an application example of our scheme is illustrated, and the complexity analysis of our scheme is presented. The complexity analysis along with a comparative study of our scheme with the existing schemes indicates that our proposed scheme is more efficient than the existing schemes. Finally, based on the construction of our proposed many-to-one scheme, a multi-level “many-to-one” homomorphic encryption scheme is also proposed. Copyright © 2015 John Wiley & Sons, Ltd. Hong Zhong 0001, Jie Cui 0004 |
Secur. Commun. Networks | 2 |
| 2015 | A novel one-to-many and many-to-one asymmetric encryption model and its algorithmsabstractAbstract Traditional asymmetric encryption algorithms involve only two parties: one party is a sender (encrypter) and the other a receiver (decrypter), in which each party has two different keys: a private key and a public key. However, if applied in some multiparty‐oriented environments, there may be a serious problem that each party needs to store and manage many keys, which is not only an overload but also a potential safety hazard. In this paper, we built a new secure communication model for private client–server networks, in which each party only needs to store a private key, but it can still implement two‐way secure communications with two properties of “one‐to‐many encryption” (i.e., if the server encrypts a plaintext, all clients can decrypt the ciphertext by using their respective private keys) and “many‐to‐one encryption” (i.e., if each client encrypts a plaintext by using his or her private key, only the server can decrypt the ciphertext). Furthermore, by introducing the basic theories for solving linear equations and ElGamal cryptographic algorithms, we designed the corresponding encryption and decryption algorithms in detail. The analysis results show that our algorithms are secure and efficient, and there are many good potential applications in military and electronic commerce fields. Copyright © 2015 John Wiley & Sons, Ltd. Hong Zhong 0001, Jie Cui 0004, Shun Zhang 0002 |
Secur. Commun. Networks | 3 |