VLDB 2026 Research / reviewers in the wild / expert
Zheng Yang 0001
dblp:59/5806-1
· DBLP profile ↗
47ranked-venue papers
22as first author
19since 2021 · last 2026
0000-0001-8610-9936ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 32 · 16 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 3 first-author · 3 since 2021Computer networks · 3 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Proof of Persistent AlivenessabstractProof of Aliveness (PoA) has emerged as a useful cryptographic concept for periodically ascertaining the operational status (aliveness) of devices, especially for those in cyber-physical systems. However, existing PoA schemes exhibit shortcomings stemming from intermittent aliveness proofs and a lack of resilience against the threats caused by malicious verifiers. Motivated by this, we introduce a new security notion called Proof of Persistent Aliveness (PoPA), which encompasses two new properties: persistent aliveness (PAlive) and audit (Audit). Our PAlive strengthens prior work by addressing the security concerns associated with generating persistent aliveness proofs in a continuous time manner, while Audit covers the threats posed by malicious verifiers. To efficiently realize PoPA, we developed two new building blocks: a deterministic hash-based Proof of Work (HPoW) scheme and private tweakable hash (PTH) functions. Using these primitives, we propose a scalable and lightweight PoPA construction, named SPAC, which is provably secure in our PoPA model without relying on random oracles. SPAC leverages HPoW and a customized authenticated credential structure that employs a variant of the Winternitz one-time signature scheme derived from PTH, enabling unlimited aliveness proofs with very small proof size. Over 93% of aliveness proofs are 84 bytes in size, with the worst-case proof size being only 372 bytes. Xuelian Cao, Zheng Yang 0001, Jianting Ning, Chenglu Jin, Zhiming Liu 0001, Jianying Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | EndPCA: Ensemble Defense With Provably Convergent Aggregation Against Poisoning Attacks in Federated LearningabstractDespite its success in many applications, federated learning is increasingly vulnerable to sophisticated poisoning attacks. Existing defenses, particularly Byzantine Robust Aggregation Rules (BRARs), offer some protection but rely on strong assumptions or challenging technical prerequisites. To address these shortcomings, we propose anensemble defense with provably convergent aggregation(EndPCA). By using the entropy weight method to consolidate scores from multiple BRARs into an ensemble trust score, it effectively integrates heterogeneous weak BRARs to resist a wide range of poisoning attacks under practical assumptions. We formally prove that EndPCA can provide theoretical guarantees of convergence with bounded error. Our empirical evaluations show that EndPCA consistently outperforms existing BRARs, demonstrating its effectiveness across various scenarios. Mingyue Zhang 0002, Chenyu Hu, Xuelian Cao, Atul Sajjanhar, Zheng Yang 0001, Muneeb Ul Hassan 0001, Zhi Jin 0001, Jialong Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Infiltrated Selfish Mining: Think Win-Win to Escape Dilemmas
Xuelian Cao, Zheng Yang 0001, Tao Xiang 0001, Jianting Ning, Yuhan Liu 0003, Zhiming Liu 0001, Jianying Zhou 0001 |
AsiaCCS | 2 |
| 2024 | Lightweight Leakage-Resilient Authenticated Key Exchange for Industrial Internet of ThingsabstractAuthenticated key exchange (AKE) protocols are widely deployed in many real-world applications to secure communication channels. Recently, side-channel attacks have been conducted to defeat traditional cryptographic protocols because a side-channel adversary can retrieve partial content of secret keys. Several leakage-resilient AKE (LRAKE) protocols have been presented to resist such attacks. However, existing LRAKE protocols are not suitable for the Industrial Internet of Things (IIoT) environment due to their expensive public-key cryptographic operations. Even worse, IIoT devices have few security protection measures, making them very vulnerable to side-channel or information leakage attacks. In response to this challenge, this paper presents a novel lightweight LRAKE protocol called LLRAKE. By leveraging lightweight cryptographic primitives such as hash function, symmetric encryption, and secret sharing scheme, our protocol achieves dual objectives of perfect forward secrecy and leakage resilience. The sole reliance on lightweight cryptographic operations ensures that LLRAKE is well-suited for resource-constrained IIoT devices. Moreover, we give the formal security result of the proposed protocol in the random oracle model. Wenxin Jia, Zheng Yang 0001 |
TrustCom | 2 |
| 2024 | Optimizing Proof of Aliveness in Cyber-Physical SystemsabstractAt ACSAC 2019, we introduced a new cryptographic primitive called proof of aliveness (PoA), allowing us to remotely and automatically track the running status (aliveness) of devices in the fields in cyber-physical systems. We proposed to use a one-way function (OWF) chain structure to build an efficient proof of aliveness, such that the prover sends every node on the OWF chain in a reverse order periodically, and it can be verified by a remote verifier with the possession of the tail node (last node) of the OWF chain. However, the practicality of this initial construction is limited by the finite number of nodes on an OWF chain. We enhance our first PoA construction by linking multiple OWF chains together using a pseudo-random generator chain in our second PoA scheme. This enhancement allows us to integrate one-time signature (OTS) schemes into the structure of the second construction to realize the auto-replenishment of the aliveness proofs. This implies that securely an initialized PoA instance can be used forever without interruption for reinitialization. In this work, our primary motivation is to further improve our secondary PoA and auto-replenishment schemes. Instead of storing the tail nodes of multiple OWF chains on the verifier side, we use a Bloom Filter to compress them. This saves$ 4.7$times the storage cost compared to our previous version at ACSAC 2019. Moreover, the OTS-based auto-replenishment solution cannot be applied to our first scheme solely based on OWFs, and it is not so efficient despite its standard model security. To overcome these limitations, we design a new auto-replenishment scheme from a hash-based commitment under the random oracle model in this work, which is much faster and can be used by both PoA schemes. Additionally, we implement and evaluate our PoA constructions on Raspberry Pis to demonstrate their performance. Considering the implementation on a storage/memory-constrained device, we particularly study the strategies for efficiently generating proofs. Zheng Yang 0001, Chenglu Jin, Xuelian Cao, Marten van Dijk, Jianying Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Dynamic Group Time-Based One-Time PasswordsabstractGroup time-based one-time passwords (GTOTP) is a novel lightweight cryptographic primitive for achieving anonymous client authentication, which enables the efficient generation of time-based one-time passwords on behalf of a group without revealing any information about the actual client’s identity beyond their group membership. The security properties of GTOTP regarding anonymity and traceability have been formulated in a static group management setting (where all group members should be determined during the group initialization phase), yet, a formal treatment for real-world dynamic groups (i.e., group members may join and leave at any time) is still an open question. It is non-trivial to construct an efficient GTOTP scheme that can provide a lightweight password generation procedure run by group members and support dynamic group management, allowing group members to join and leave without affecting other members’ states (non-disruptively). To address the above challenge, we first define the notion and the security model of dynamic group time-based one-time passwords (DGTOTP) in this work. We then present an efficient DGTOTP construction that can generically transform an asymmetric time-based one-time passwords scheme into a DGTOTP scheme utilizing a chameleon hash function family and a Merkle tree scheme. Within our construction, we particularly tailor an outsourcing solution realizing an issue-first-and-join-later (IFJL) strategy, enabling smooth joining and revocation without disrupting other group members. Moreover, our scheme minimizes symmetric cryptographic operations and maintains constant storage for group members, compared to the linear storage cost that grows rapidly with respect to the lifetime of the GTOTP instance in the previous static GTOTP scheme. Our DGTOTP scheme satisfies stronger security guarantees in a dynamic group management setting without random oracles. Our experimental results confirm the efficiency of our DGTOTP scheme. Xuelian Cao, Zheng Yang 0001, Jianting Ning, Chenglu Jin, Rongxing Lu, Zhiming Liu 0001, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Polling Sanitization to Balance I/O Latency and Data Security of High-density SSDsabstractSanitization is an effective approach for ensuring data security through scrubbing invalid but sensitive data pages, with the cost of impacts on storage performance due to moving out valid pages from the sanitization-required wordline, which is a logical read/write unit and consists of multiple pages in high-density SSDs. To minimize the impacts on I/O latency and data security, this article proposes a polling-based scheduling approach for data sanitization in high-density SSDs. Our method polls a specific SSD channel for completing data sanitization at the block granularity, meanwhile other channels can still service I/O requests. Furthermore, our method assigns a low priority to the blocks that are more likely to have future adjacent page invalidations inside sanitization-required wordlines, while selecting the sanitization block, to minimize the negative impacts of moving valid pages. Through a series of emulation experiments on several disk traces of real-world applications, we show that our proposal can decrease the negative effects of data sanitization in terms of the risk-performance index, which is a united time metric of I/O responsiveness and the unsafe time interval, by 16.34% , on average, compared to related sanitization methods. Zhigang Cai, Fan Yang 0110, Jun Li 0062, François Trahay, Zheng Yang 0001, Chao Wang 0069, Jianwei Liao 0001 |
ACM Trans. Storage | 6 |
| 2023 | Catch Me If You Can: A New Low-Rate DDoS Attack Strategy Disguised by FeintabstractWhile collaborative systems provide convenience to our lives, they also face many security threats. One of them is the Low-rate Distributed Denial-of-Service (LDDoS) attack, which is a worthy concern. Unlike volumetric DDoS attacks that continuously send large volumes of traffic, LDDoS attacks are more stealthy and difficult to be detected owing to their low-volume feature. Due to its stealthiness and harmfulness, LDDoS has become one of the most destructive attacks in cloud computing. Although a few LDDoS attack detection and defense methods have been proposed, we observe that sophisticated LDDoS attacks (being more stealthy) can bypass some of the existing LDDoS defense methods. To verify our security observation, we proposed a new Feint-based LDDoS (F-LDDoS) attack strategy. In this strategy, we divide a Pulse Interval into a Feinting Interval and an Attack Interval. Unlike the previous LDDoS attacks, the bots also send traffic randomly in the Feinting Interval, thus disguise themselves as benign users during the F-LDDoS attack. In this way, although the victim detects that it is under an LDDoS attack, it is difficult to locate the attack sources and apply mitigation solutions. Experimental results show that F-LDDoS attack can degrade TCP bandwidth 6.7%-14% more than the baseline LDDoS attack. Besides, F-LDDoS also reduces the similarities between bot traffic and aggregated attack traffic, and increases the uncertainty of packet arrival. These results mean that the proposed F-LDDoS is more effective and more stealthy than normal LDDoS attacks. Finally, we discuss the countermeasures of F-LDDoS to draw the attention of defenders and improve the defense methods. Tianyang Cai, Tao Jia 0001, Leo Yu Zhang, Zheng Yang 0001 |
CSCWD | 5 |
| 2023 | Optimizing Lightweight Intermittent Message Authentication for Programmable Logic Controller
Jun Xian Chia, Xijie Ba, Jianying Zhou 0001, Zheng Yang 0001 |
SecureComm (1) | 5 |
| 2023 | TAP: Transparent and Privacy-Preserving Data Services
Daniël Reijsbergen, Aung Maw, Zheng Yang 0001, Tien Tuan Anh Dinh, Jianying Zhou 0001 |
USENIX Security Symposium | 3 |
| 2023 | HMACCE: Establishing Authenticated and Confidential Channel From Historical Data for Industrial Internet of ThingsabstractIndustrial Internet of Things (IIoT) is a new paradigm for building intelligent industrial control systems, and how to establish a secure channel in IIoT for machine-to-machine (M2M) communication is a critical problem because the devices in IIoT suffer from various attacks and may leak confidential information. Traditional authenticated and confidential channel establishment (ACCE) protocols neither apply for resource-constrained IIoT devices nor satisfy leakage resilience. In this paper, we introduce a new security notion: historical data based multi-factor ACCE (HMACCE) to address this issue and propose two HMACCE protocols. Our HMACCE protocols use three authentication factors, i.e., a symmetric secret key, historical data, and a set of secret tags associated with the historical data, to establish a secure communication channel between the client and the server. The key idea is to use the secret key managed by an IIoT edge device to quickly verify the relationship between the historical data and its associated tags stored on the server. Our HMACCE has the following remarkable features. First, it is lightweight and tailored for resource-constrained IIoT devices. Second, it is bounded historical tag leakage resilience, which means that if a small portion of the secret tags is leaked to an adversary, it will not affect its security with an overwhelming probability. Moreover, as a security enhancement service, our HMACCE can be easily integrated with legacy IIoT devices by running simple authenticated key exchange protocols. Chenglu Jin, Zheng Yang 0001, Tao Xiang 0001, Sridhar Adepu, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | ADAM: An Adaptive DDoS Attack Mitigation Scheme in Software-Defined Cyber-Physical SystemabstractWith the widespread innovation of the Internet of Things, software-defined networking (SDN), and cloud computing, cyber-physical systems (CPSs) have been developed and widely adopted to facilitate our daily life and economy. In particular, modern society heavily relies on all kinds of CPSs, such as smart grids, and transportation systems. So the shutdown of critical services can lead to serious consequences. Meanwhile, distributed denial-of-service (DDoS) attacks are becoming a major threat to the CPSs due to their ease of execution and the devastation they cause. In addition, owing to the constant updating of attack methods, there is an urgent need for a method to defend against both the known and unknown DDoS attacks. In this article, we present an adaptive DDoS attack mitigation (ADAM) scheme to detect and mitigate DDoS attacks in software-defined CPSs. By combining information entropy and unsupervised anomaly detection methods, ADAM can not only automatically determine the current state, but also adaptively identify suspicious features and thereafter precisely mitigate DDoS attacks. We also propose a pipeline filtering mechanism to accurately drop attack traffic, and this method can be implemented in the existing SDN networks without additional devices required. Unlike most of the classification-based DDoS mitigation scenarios, we aim to mitigate a wide spectrum of DDoS attacks without defining attack characteristics in advance. Real data-driven experimental results show that ADAM has an average mitigation accuracy of 99.13% under high-intensity DDoS attacks. Compared to similar work, our method reduces the false-positive rate by 35%-59%. Tianyang Cai, Tao Jia 0001, Sridhar Adepu, Zheng Yang 0001 |
IEEE Trans. Ind. Informatics | 5 |
| 2022 | If You Can't Beat Them, Pay Them: Bitcoin Protection Racket is ProfitableabstractPooled mining has become the most popular mining approach in the Bitcoin system, which can effectively reduce the variance of the block generation reward of participants. The security of pooled mining depends on whether it is incentive compatible, that is, an honest participant will get a reward proportional to his work. Recent attacks on mining pools, for example, Block Withholding, Fork After Withholding, and Power Adjusting Withholding (PAW) attacks, show that malicious participants may undermine the revenue of the honest pools and receive an unfair share of the mining reward. This paper shows that the security of Bitcoin is even worse than what the recent attacks demonstrated. We describe an attack called Fork Withholding Attack under a Protection Racket (FWAP), in which the mining pool pays the attacker for withholding a fork. Our insight is that the mining pools under forking attacks have incentives to pay in exchange for not being forked. The attacker and the paying pool negotiate how much to be paid, and we show that it is possible for both the attacker and the paying pool to earn higher rewards at the expense of the other pools. In particular, our formal analysis and simulation demonstrate that the payer and the FWAP attacker can get up to 1.8 × and 3.8 × of extra reward as in PAW, respectively. Furthermore, FWAP can escape from the “miners’ dilemma’’ when two FWAP attackers attack each other under some circumstances. We also propose simple approaches that serve as the first step towards preventing the FWAP attack. Zheng Yang 0001, Junming Ke, Tien Tuan Anh Dinh, Jianying Zhou 0001 |
ACSAC | 1 |
| 2022 | LARP: A Lightweight Auto-Refreshing Pseudonym Protocol for V2XabstractVehicle-to-everything (V2X) communication is the key enabler for emerging intelligent transportation systems. Applications built on top of V2X require both authentication and privacy protection for the vehicles. The common approach to meet both requirements is to use pseudonyms which are short-term identities. However, both industrial standards and state-of-the-art research are not designed for resource-constrained environments. In addition, they make a strong assumption about the security of the vehicle's on-board computation units. In this paper, we propose a lightweight auto-refreshing pseudonym protocol (LARP) for V2X. LARP supports efficient operations for resource-constrained devices, and provides security even when parts of the vehicle are compromised. We provide formal security proof showing that the protocol is secure. We conduct experiments on a Raspberry Pi 4. The results demonstrate that LARP is feasible and practical. Zheng Yang 0001, Tien Tuan Anh Dinh, Yingying Yao, Dianshi Yang, Xiaolin Chang, Jianying Zhou 0001 |
SACMAT | 1 |
| 2022 | New stability results of generalized impulsive functional differential equations
Chao Liu 0026, Xiaoyang Liu 0001, Zheng Yang 0001, Junjian Huang |
Sci. China Inf. Sci. | 3 |
| 2022 | Policy-Based Editing-Enabled Signatures: Authenticating Fine-Grained and Restricted Data ModificationabstractAbstract Data owners often encrypt their bulk data and upload it to cloud in order to save storage while protecting privacy of their data at the same time. A data owner can allow a third-party entity to decrypt and access her data. However, if that entity wants to modify the data and publish the same in an authenticated way, she has to ask the owner for a signature on the modified data. This incurs substantial communication overhead if the data is modified often. In this work, we introduce the notion of policy-based editing-enabled signatures, where the data owner specifies a policy for her data such that only an entity satisfying this policy can decrypt the data. Moreover, the entity is permitted to produce a valid signature for the modified data (on behalf of the owner) without interacting with the owner every time the data is modified. On the other hand, a policy-based editing-enabled signature (PB-EES) scheme allows the data owner to choose any set of modification operations applicable to her data and still restricts a (possibly untrusted) entity to authenticate the data modified using operations from that set only. We provide two PB-EES constructions, a generic construction and a concrete instantiation. We formalize the security model for PB-EESs and analyze the security of our constructions. Finally, we evaluate the performance of the concrete PB-EES instantiation. Binanda Sengupta, Yingjiu Li, Yangguang Tian, Robert H. Deng, Zheng Yang 0001 |
Comput. J. | 5 |
| 2021 | Group Time-based One-time Passwords and its Application to Efficient Privacy-Preserving Proof of LocationabstractTime-based One-Time Password (TOTP) provides a strong second factor for user authentication. In TOTP, a prover authenticates to a verifier by using the current time and a secret key to generate an authentication token (or password) which is valid for a short time period. Our goal is to extend TOTP to the group setting, and to provide both authentication and privacy. To this end, we introduce a new authentication scheme, called Group TOTP (GTOTP), that allows the prover to prove that it is a member of an authenticated group without revealing its identity. We propose a novel construction that transforms any asymmetric TOTP scheme into a GTOTP scheme. Our approach combines Merkle tree and Bloom filter to reduce the verifier’s states to constant sizes. Zheng Yang 0001, Chenglu Jin, Jianting Ning, Zengpeng Li 0001, Tien Tuan Anh Dinh, Jianying Zhou 0001 |
ACSAC | 1 |
| 2021 | Transparent Electricity Pricing with Privacy
Daniël Reijsbergen, Zheng Yang 0001, Aung Maw, Tien Tuan Anh Dinh, Jianying Zhou 0001 |
ESORICS (2) | 2 |
| 2021 | Building Low-Interactivity Multifactor Authenticated Key Exchange for Industrial Internet of ThingsabstractIndustrial Internet of Things (IIoT) brings together computers, devices, advanced analytics, and people in industries, such as transportation, oil plant, and power grid that leads to major efficiency and productivity gains for almost any industrial procedures. Due to the interconnection of devices in IIoT, communication security has become a critical issue to address in many emerging industry standards that require the authentication and key exchange procedure to be done to guarantee the authorized machine access (e.g., from users) and secure the data transmission between machines. To overcome the shortcoming (i.e., low entropy) of the memorable password in user authentication, it is rightfully recommended by industry standards (such as IEC-62443 family) to use multifactor authentication (MFA) for higher security levels. Notably, latency is one of the main sources of inefficiency when a device is communicating with other machines on IIoT. To mitigate latency, a smooth projective hash function (SPHF) built from well-studied standard assumptions is used to achieve a lowinteractivity multifactor authenticated key exchange protocol (MFAKE) because SPHF allows each party to prove to the others that he knows the right authentication factor(s). In this article, we are, therefore, motivated to build a new MFAKE named “secure remote multifactor (SRMF)” to achieve the humaninvolved “machine-to-machine” secure communication in IIoT. That is, SRMF leverages multiple user-centric authentication factors (such as password, biometric fingerprints, and PIN), and it can synergistically support multifactor registration (MFR), MFA, and multifactor key exchange (MFKE). Furthermore, to prevent authentication factors stored at the server exposing to attackers, the password-harden service (i.e., Pythia-PRF and USENIX'15) inspires us to develop a multifactor hardening service (MFHS) utilizing an oblivious pseudorandom function (OPRF). The balanced security of the proposed protocol is proved under the model of Bellare-Pointcheval-Rogaway (EUROCRYPTO'00) along with theoretical and experimental evaluations. Zengpeng Li 0001, Zheng Yang 0001, Pawel Szalachowski, Jianying Zhou 0001 |
IEEE Internet Things J. | 2 |
| 2020 | LiS: Lightweight Signature Schemes for Continuous Message Authentication in Cyber-Physical SystemsabstractCyber-Physical Systems (CPS) provide the foundation of our critical infrastructures, which form the basis of emerging and future smart services and improve our quality of life in many areas. In such CPS, sensor data is transmitted over the network to the controller, which will make real-time control decisions according to the received sensor data. Due to the existence of spoofing attacks (more specifically to CPS, false data injection attacks), one has to protect the authenticity and integrity of the transmitted data. For example, a digital signature can be used to solve this issue. However, the resource-constrained field devices like sensors cannot afford conventional signature computation. Thus, we have to seek for an efficient signature mechanism that can support the fast and continuous message authentication in CPS, while being easy to compute on the devices. Zheng Yang 0001, Chenglu Jin, Yangguang Tian, Junyu Lai, Jianying Zhou 0001 |
AsiaCCS | 1 |
| 2020 | A New Construction for Linkable Secret HandshakeabstractAbstract In this paper, we introduce a new construction for linkable secret handshake that allows authenticated users to perform handshake anonymously within allowable times. We define formal security models for the new construction, and prove that it can achieve session key security, anonymity, untraceability and linkable affiliation-hiding. In particular, the proposed construction ensures that (i) anyone can trace the real identities of dishonest users who perform handshakes for more than k times; and (ii) an optimal communication cost between authorized users is achieved by exploiting the proof of knowledges. Yangguang Tian, Yingjiu Li, Robert H. Deng, Nan Li 0007, Guomin Yang, Zheng Yang 0001 |
Comput. J. | 6 |
| 2020 | Faster privacy-preserving location proximity schemes for circles and polygonsabstractIn the last decade, location information became easily obtainable using off‐the‐shelf mobile devices. This gave momentum to developing location‐based services (LBSs) such as location proximity detection, which can be used to find friends or taxis nearby. LBSs can, however, be easily misused to track users, which draws attention to the need for protecting the privacy of these users. In this work, the authors address this issue by designing, implementing, and evaluating multiple algorithms for privacy‐preserving location proximity (PPLP) that are based on different secure computation protocols. Their PPLP protocols support both circle and polygon range queries and have runtimes from a few to some hundreds of milliseconds and bandwidth requirements from a few hundreds of bytes to one megabyte. Consequently, they are well suited for different scenarios and offer faster runtimes and savings in bandwidth and computational power as well as security improvements compared to previous PPLP schemes. In addition, the computationally most expensive parts of the PPLP computation can be precomputed in their protocols, such that the input‐dependent online phase runs in just a few milliseconds. Kimmo Järvinen 0001, Ágnes Kiss, Thomas Schneider 0003, Zheng Yang 0001 |
IET Inf. Secur. | 5 |
| 2020 | Faster Authenticated Key Agreement With Perfect Forward Secrecy for Industrial Internet-of-ThingsabstractIndustrial Internet-of-Things (IIoT) is the basis of Industry 4.0, which extends Internet connectivity beyond traditional computing devices like computers and smartphones to the physical world for improving efficiency and accuracy while reducing the production cost. However, there are tremendous security threats to IIoT, such as IIoT device hijacking and data leaks. Therefore, a lightweight authenticated key agreement (AKA) protocol is commonly applied to establish a session key for securing the communication between IIoT devices. To protect the previous session keys from being compromised, perfect forward secrecy (PFS) has been one of the most important security properties of AKA. In this article, we present an efficient PFS-enabled AKA protocol for IIoT systems, which is developed based on a new dynamic authentication credential (DAC) framework, without using any public-key cryptographic primitives. It is worth noting that our protocol is also faster than the state-of-the-art DAC-based AKA protocols with PFS. Moreover, we give the formal security result of the proposed protocol in the random oracle model. Zheng Yang 0001, Yangguang Tian, Jianying Zhou 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2019 | Proof of alivenessabstractIn 2017, malware Triton was discovered in a petrol plant in Saudi Arabia, and it shut down the safety instrumented systems in the affected industrial control system without being noticed by the operators. If the malware was not discovered by a security company on time, it could leave the system running without any safety measures, and eventually lead to an explosion. To detect such attacks, one can track the running status of the devices in the field to know that they are still "alive". However, in practice, there yet does not exist an efficient and cryptographically secure mechanism/ protocol that can prove the aliveness of a device to control centers over an open network. Chenglu Jin, Zheng Yang 0001, Marten van Dijk, Jianying Zhou 0001 |
ACSAC | 2 |
| 2019 | PILOT: Practical Privacy-Preserving Indoor Localization Using OuTsourcingabstractIn the last decade, we observed a constantly growing number of Location-Based Services (LBSs) used in indoor environments, such as for targeted advertising in shopping malls or finding nearby friends. Although privacy-preserving LBSs were addressed in the literature, there was a lack of attention to the problem of enhancing privacy of indoor localization, i.e., the process of obtaining the users' locations indoors and, thus, a prerequisite for any indoor LBS. In this work we present PILOT, the first practically efficient solution for Privacy-Preserving Indoor Localization (PPIL) that was obtained by a synergy of the research areas indoor localization and applied cryptography. We design, implement, and evaluate protocols for Wi-Fi fingerprint-based PPIL that rely on 4 different distance metrics. To save energy and network bandwidth for the mobile end devices in PPIL, we securely outsource the computations to two non-colluding semi-honest parties. Our solution mixes different secure two-party computation protocols and we design size-and depth-optimized circuits for PPIL. We construct efficient circuit building blocks that are of independent interest: Single Instruction Multiple Data (SIMD) capable oblivious access to an array with low circuit depth and selection of the k-Nearest Neighbors with small circuit size. Additionally, we reduce Received Signal Strength (RSS) values from 8 bits to 4 bits without any significant accuracy reduction. Our most efficient PPIL protocol is 553x faster than that of Li et al. (INFOCOM'14) and 500× faster than that of Ziegeldorf et al. (WiSec'14). Our implementation on commodity hardware has practical run-times of less than 1 second even for the most accurate distance metrics that we consider, and it can process more than half a million PPIL queries per day. Kimmo Järvinen 0001, Helena Leppäkoski, Elena Simona Lohan, Philipp Richter, Thomas Schneider 0003, Zheng Yang 0001 |
EuroS&P | 7 |
| 2019 | IBWH: An Intermittent Block Withholding Attack with Optimal Mining Reward Rate
Junming Ke, Pawel Szalachowski, Jianying Zhou 0001, Qiuliang Xu, Zheng Yang 0001 |
ISC | 5 |
| 2019 | A Novel Authenticated Key Agreement Protocol With Dynamic Credential for WSNsabstractPublic key cryptographic primitive (e.g., the famous Diffie-Hellman key agreement, or public key encryption) has recently been used as a standard building block in authenticated key agreement (AKA) constructions for wireless sensor networks (WSNs) to provide perfect forward secrecy (PFS), where the expensive cryptographic operation (i.e., exponentiation calculation) is involved. However, realizing such complex computation on resource-constrained wireless sensors is inefficient and even impossible on some devices. In this work, we introduce a new AKA scheme with PFS for WSNs without using any public key cryptographic primitive. To achieve PFS, we rely on a new dynamic one-time authentication credential that is regularly updated in each session. In particular, each value of the authentication credential is wisely associated with at most one session key that enables us to fulfill the security goal of PFS. Furthermore, the proposed scheme enables the principals to identify whether they have been impersonated previously. We highlight that our scheme can be very efficiently implemented on sensors since only hash function and XOR operation are required. Zheng Yang 0001, Junyu Lai, Yingbing Sun, Jianying Zhou 0001 |
ACM Trans. Sens. Networks | 1 |
| 2018 | Faster Privacy-Preserving Location Proximity Schemes
Kimmo Järvinen 0001, Ágnes Kiss, Thomas Schneider 0003, Zheng Yang 0001 |
CANS | 5 |
| 2018 | Two-Message Key Exchange with Strong Security from Ideal Lattices
Zheng Yang 0001, Yu Chen 0003 |
CT-RSA | 1 |
| 2018 | The Death and Rebirth of Privacy-Preserving WiFi Fingerprint Localization with Paillier EncryptionabstractLocalization based on premeasured WiFi fingerprints is a popular method for indoor localization where satellite based positioning systems are unavailable. In these systems, privacy of the user's location is lost because the location is computed by the service provider. In INFOCOM'14, Li et al. presented PriWFL, a WiFi fingerprint localization system based on additively homomorphic Paillier encryption, that was claimed to protect both the users' location privacy and the service provider's database privacy. In this paper, we demonstrate a severe weakness in PriWFL that allows an attacker to compromise the service provider's database under a realistic attack model and also identify certain other problems in PriWFL that decrease its localization accuracy. Hence, we show that PriWFL does not solve the privacy problems of WiFi fingerprint localization. We also explore different solutions to implement secure privacy-preserving WiFi fingerprint localization and propose two schemes based on Paillier encryption which do not suffer from the weakness of PriWFL and offer the same localization accuracy as the privacy-violating schemes. Zheng Yang 0001, Kimmo Järvinen 0001 |
INFOCOM | 1 |
| 2018 | Modeling Privacy in WiFi Fingerprinting Indoor Localization
Zheng Yang 0001, Kimmo Järvinen 0001 |
ProvSec | 1 |
| 2018 | New constructions for (multiparty) one-round key exchange with strong security
Zheng Yang 0001, Junyu Lai |
Sci. China Inf. Sci. | 1 |
| 2018 | Cryptanalysis of a generic one-round key exchange protocol with strong securityabstractIn Public‐Key Cryptography (PKC) 2015, Bergsma et al . introduced an interesting one‐round key exchange protocol (which will be referred to as BJS scheme) with strong security in particular for perfect forward secrecy (PFS). In this study, the authors unveil a PFS attack against the BJS scheme. This would simply invalidate its security proof. An improvement is proposed to fix the problem of the BJS scheme with minimum changes. Zheng Yang 0001, Junyu Lai, Guoyuan Li |
IET Inf. Secur. | 1 |
| 2018 | Stability of switched neural networks with time-varying delays
Chao Liu 0026, Zheng Yang 0001, Dihua Sun, Xiaoyang Liu 0001, Wanping Liu |
Neural Comput. Appl. | 2 |
| 2017 | New Proof for BKP IBE Scheme and Improvement in the MIMC Setting
Lu Yan, Jian Weng 0001, Zheng Yang 0001 |
ISPEC | 4 |
| 2017 | Simpler Generic Constructions for Strongly Secure One-round Key Exchange from Weaker AssumptionsabstractIn PKC 2015, Bergsma et al. introduced a generic one-round key exchange (ORKE) protocol (which is referred to as BJS) from digital signature (SIG) and simplified non-interactive key exchange (NIKE) without involving any identity. The BJS scheme is shown to satisfy extended Canetti and Krawczyk-PFS security if the NIKE is adaptive-CKS-light secure and the SIG is strongly secure against existential unforgeability under chosen message attacks. However, the BJS scheme cannot be instantiated with NIKE scheme with identity (e.g. the one proposed by Boneh and Zhandry in Crypto 2014). In this paper, we propose a much simpler generic construction for ORKE from NIKE and SIG. In particular, our scheme only makes weaker security assumptions on the underlying building blocks. Namely, we first show that the static-CKS-light security of NIKE, where the target identities are chosen by the adversary before seeing the system parameters, is sufficient for our construction. On the second, we observe that the SIG only needs to provide strong existential unforgeability under weak chosen message attacks for our construction. These results enable our proposal to have more concrete instantiations which might be easier to build and realize. At the same time, our new protocol is much more computationally efficient than the BJS protocol. Zheng Yang 0001, Junyu Lai, Chao Liu 0026, Wanping Liu |
Comput. J. | 1 |
| 2017 | A note on the strong authenticated key exchange with auxiliary inputs
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo, Zheng Yang 0001 |
Des. Codes Cryptogr. | 6 |
| 2017 | SignORKE: improving pairing-based one-round key exchange without random oraclesabstractThe study presents a new efficient way to construct the one‐round key exchange (ORKE) without random oracles based on standard hard complexity assumptions. The authors propose a (PKI‐based) ORKE protocol which is more computational efficient than existing pairing‐based ORKE protocols without random oracles in the post‐specified peer setting. The core idea of this construction is to integrate the consistency check of the ephemeral public key and the verification of the signature into the session key generation. This enables us to roughly save two pairing operations. The authors just call this kind of scheme that is deeply composed by signature and one‐round key exchange as SignORKE. The authors’ protocol is shown to be secure in a variant of the Canetti–Krawczyk security model which covers the majority of state‐of‐the‐art active attacks. Zheng Yang 0001, Junyu Lai, Wanping Liu, Chao Liu 0026 |
IET Inf. Secur. | 1 |
| 2017 | Randomized authentication primitive problem in key exchange with strong security
Zheng Yang 0001, Chao Liu 0026, Wanping Liu |
J. Inf. Secur. Appl. | 1 |
| 2016 | Stability of neural networks with delay and variable-time impulses
Chao Liu 0026, Wanping Liu, Zheng Yang 0001, Xiaoyang Liu 0001, Chuandong Li 0001, Guangjian Zhang |
Neurocomputing | 3 |
| 2016 | On security analysis of an after-the-fact leakage resilient key exchange protocol
Zheng Yang 0001 |
Inf. Process. Lett. | 1 |
| 2015 | A new efficient signcryption scheme in the standard modelabstractAbstract We introduce an efficient signcryption scheme for hybrid authenticated encryption that is provably secure in the standard model under a strong multiuser insider setting. Our new signcryption scheme is built on the basis of a variant of Boneh–Boyen short signature, which works under bilinear groups. The new construction idea is to reuse the signature value to derive the encryption key. This could dramatically save not only the computational cost but also the communication bandwidth. The session key security of the proposed scheme is reduced to a hard problem that is a variant of bilinear decisional Diffie–Hellman problem. Copyright © 2014 John Wiley & Sons, Ltd. Zheng Yang 0001 |
Secur. Commun. Networks | 1 |
| 2015 | An efficient strongly secure authenticated key exchange protocol without random oraclesabstractAbstract Since the introduction of extended Canetti–Krawczyk (eCK) security model for two‐party key exchange, many protocols have been proposed to provide eCK security. However, most of those protocols are provably secure in the random oracle model or rely on special design technique, which is well known as the NAXOS trick. In contrast to previous schemes, we present an eCK secure protocol in the standard model, without NAXOS trick and without knowledge of secret key assumption for public key registration. The security proof of our scheme is based on standard pairing assumption, collision‐resistant hash functions, Bilinear Decision Diffie–Hellman and Decision Linear Diffie–Hellman assumptions, and pseudo‐random functions with pairwise independent random source. Although our proposed protocol is based on bilinear groups, it does not require any pairing operation during key exchange procedure. Copyright © 2014 John Wiley & Sons, Ltd. Zheng Yang 0001 |
Secur. Commun. Networks | 1 |
| 2015 | On constructing practical multi-recipient key-encapsulation with short ciphertext and public keyabstractAbstract In this paper, we introduce a novel multiple‐recipient key‐encapsulation mechanism (mKEM) scheme which takes as input multiple public keys and outputs a single key shared by corresponding recipients. We focus on seeking practical construction for mKEM with short ciphertext and public key. Our scheme is IND‐CCA2 secure without random oracles. The security is reduced to a new variant of square bilinear Diffie–Hellman assumption. Copyright © 2015 John Wiley & Sons, Ltd. Zheng Yang 0001 |
Secur. Commun. Networks | 1 |
| 2015 | A practical strongly secure one-round authenticated key exchange protocol without random oraclesabstractAbstract Most recently, a variant of extended Canetti–Krawczyk model called aseCKwis introduced to provide stronger security than previous eCK models. NamelyeCKwmodels formulate a stronger notion regarding weak perfect forward secrecy than other eCK models. In particular, anyeCKwsecure protocols can be generally transformed to achieve full provide perfect forward secrecy without requiring additional round. So far, there is no protocol which has been proven secure in theeCKwmodel without random oracles. In this paper, we study the open problem on constructingeCKwsecure AKE protocol in the standard model. A new one‐round AKE protocol is introduced relying on standard cryptographic primitives and a variant of bilinear decisional Diffie–Hellman assumption. The main advantage of our proposal is its high efficiency in key exchange in contrast to the previous eCK secure protocols without random oracles and under post‐specified peer setting. Copyright © 2014 John Wiley & Sons, Ltd. Zheng Yang 0001 |
Secur. Commun. Networks | 1 |
| 2015 | Towards modelling perfect forward secrecy in two-message authenticated key exchange under ephemeral-key revelationabstractAbstract We examine the recently introduced CF and CF‐perfect forward secrecy (PFS) models for two‐message authenticated key exchange (TMAKE) by Cremers et al., where the difference between CF and CF‐PFS model is that the CF formulates the weak PFS (wPFS), whereas the CF‐PFS formulates the PFS. The CF model is claimed by Cremers et al. to be strictly stronger the previous extended Canetti‐Krawczyk (eCK) model. However, we notice that the implication relations among CF, CF‐PFS, eCK and eCK‐PFS model have not been completely studied. Based on TMAKE, we particularly show that CF model and eCK model imply each other under random oracle model. Moreover, we provide a new result on the generic security strengthening transformation (compiler) for building CF‐PFS‐secure TMAKE protocols. In contrast to a previous work, we show that it is possible to apply the transformation to all CF‐secure AKE protocols including all eCK‐secure TMAKE protocols in the random oracle model, without restricting to a small specific class of Diffie–Hellman key based protocols. Copyright © 2015 John Wiley & Sons, Ltd. Zheng Yang 0001, Lingyun Zhu, Daigu Zhang |
Secur. Commun. Networks | 1 |
| 2014 | Authenticated key exchange with synchronized stateabstractABSTRACT We study the problem on how to either prevent identity impersonation (IDI) attacks or limit its consequences by on‐line detecting previously unidentified IDI attacks, where IDI attacks are normally caused by the leakage of identity related long‐term key. Such problem has, up until now, lacked a provably good solution. We deal with this problem through the scenario on authenticated key exchange with synchronized state (AKESS). This work provides a security model for AKESS, in which we particularly formalize the security of synchronized state based on indistinguishability. We propose a two party execution state synchronization framework for symmetric case, based on which we propose a generic compiler for AKESS protocols. Our goal is to transform any existing passively secure KE protocols to AKESS protocols using synchronized state, without any modification on those KE protocols. The new generic compiler is probably secure in the standard model under standard assumptions. Copyright © 2014 John Wiley & Sons, Ltd. Zheng Yang 0001 |
Secur. Commun. Networks | 1 |