VLDB 2026 Research / reviewers in the wild / expert
Fei Tang 0001
dblp:60/406-1
· DBLP profile ↗
20ranked-venue papers
8as first author
18since 2021 · last 2026
0000-0002-0048-9876ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 4 first-author · 8 since 2021Computer networks · 7 · 3 first-author · 7 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SecOutPIR: privacy preservation for data owner and access control for data user in outsourced private information retrievalabstractAbstract Private Information Retrieval (PIR) is a cryptographic technique that allows Data User (DU) to retrieve data from a SERVER without revealing which specific data item is being accessed. Traditional PIR protocols typically assume that the data is locally stored and directly controlled by Data Owner (DO), but in real-world scenarios, data is often hosted on untrusted third-party SERVERs, making it difficult for DO to effectively restrict the SERVER’s access to their data or control which DU is authorized to retrieve the data. Consequently, malicious SERVERs or unauthorized DU may infringe upon the privacy rights of DO. This paper presents SecOutPIR, a novel outsourced PIR system that addresses two key challenges: privacy preservation for DO and access control for DU. SecOutPIR integrates attribute-based encryption for fine-grained retrieval access control to ensure that only DU with valid retrieval can access the data, while also utilizing a decentralized identity management system based on decentralized identifiers and verifiable credentials to authenticate DU requests. The proposed system ensures that the DO’s data privacy is protected during data storage and retrieval, while also ensuring that only DU with authorized retrieval can make retrieval requests, thus preventing unauthorized access. We provide a detailed description of the system model, security requirements, and an in-depth security analysis. Furthermore, experimental results demonstrate that SecOutPIR significantly enhances the practicality and efficiency of PIR in outsourced settings by enabling fine-grained retrieval access control without degrading query performance. Our implementation demonstrates that the SERVER reply time increases with the dataset size, from 82.5 ms (1000 entries) to 113.8 ms (2000 entries) and 199.6 ms (5000 entries), while the query generation time remains approximately constant at around 2.0 ms. Fei Tang 0001, Ruixue Li, Huihui Zhu 0001, Mingjie Han |
Cybersecur. | 1 |
| 2026 | Efficient Multiuser Searchable and Revocable Data Sharing Scheme for IoVabstractThe Internet of Vehicles (IoV), as a critical component of future intelligent transportation systems, enables vehicles to generate and exchange massive volumes of sensing data in real time. To facilitate efficient data sharing and alleviate the burden of local storage, vehicle data is typically encrypted and outsourced to the cloud, with data availability ensured through searchable encryption. However, existing IoV data sharing frameworks offer limited support for secure multi-keyword search and dynamic user revocation. Moreover, most current solutions rely on public-key searchable encryption, which compromises the efficiency required for data processing in IoV environments. To address these challenges, we propose an efficient multi-user searchable and revocable data sharing scheme (EMUSR-SSE) tailored for IoV. EMUSR-SSE extends symmetric searchable encryption to support efficient multi-user access control and trustworthy multi-keyword search by designing a proxy matrix transformation mechanism integrated with Intel SGX. To enable flexible and scalable user revocation, EMUSR-SSE introduces a revocable dynamic sparse Merkle tree structure to manage multi-user permissions effectively. Furthermore, by leveraging the trusted execution environment within SGX and encrypting each data item individually, EMUSR-SSE significantly mitigates the risk of key leakage. Security analysis and experimental evaluations demonstrate that EMUSR-SSE achieves high efficiency and strong practical performance in dynamic IoV environments. Ping Wang 0086, Fei Tang 0001, Haining Luo, Fengjie Peng, Huihui Zhu 0001, Ankui Jing, Yawen Huang |
IEEE Internet Things J. | 2 |
| 2026 | Blockchain-Based Efficient and Trusted Cloud-Stored Image Integrity Verification SchemeabstractThe existing cloud-storage image integrity verification (CSIIV) schemes typically assume that the cloud server is untrusted while the user is trusted. This one-way trust model renders these schemes incapable of defending against malicious users who may forge authentication information or manipulate the verification process. To address these issues, this paper proposes a blockchain-based efficient and trusted cloud-stored image integrity verification scheme. The scheme explicitly requires resistance against tampering by the cloud server and false accusations by the user, thereby establishing a bidirectional trusted verification model. Specifically, a robust metadata generation and storage method based on blockchain is designed. By employing a differential hashing algorithm, metadata robust to common image noise yet sensitive to malicious tampering are generated, and blockchain is utilized for distributed storage. This approach prevents user forgery at the source and overcomes the fragility of metadata. Additionally, a verification dispute arbitration mechanism based on smart contracts is developed. When a verification dispute occurs, this mechanism determines the responsible party based on the on-chain metadata, achieving fair arbitration and ensuring the trustworthiness of the entire verification process. Theoretical analysis and experimental results demonstrate that the proposed scheme meets security requirements while significantly improving verification efficiency. On images from the real-world Set12 dataset, the verification efficiency is improved by 77%, 18% and 38%, respectively, compared with existing CSIIV schemes. Hongjie He 0005, Fan Chen 0003, Fei Tang 0001 |
IEEE Trans. Cloud Comput. | 4 |
| 2026 | ISSCC: Integrated Service for Full-Process Delivery in Secure Cloud ComputingabstractSecure cloud computing offers a range of services including storage, search, and computation, all of which have experienced ongoing performance advancements. However, seamlessly integrating these services into a unified “storage–search–computation” workflow remains challenging due to heterogeneous security mechanisms. For instance, searchable encryption, while effective for secure search, does not natively support computation over ciphertext. To address this gap, we propose ISSCC, an integrated service framework that seamlessly bridges storage, search, and computation in secure cloud environments. ISSCC employs searchable encryption to ensure secure data storage and search. To support post-search computation on retrieved results, ISSCC utilizes trusted execution environments instead of purely cryptographic approaches. We implement ISSCC on a real TEE-enabled cloud platform and conduct a comprehensive performance evaluation and security analysis. Experimental results demonstrate that ISSCC is both feasible and practical, delivering effective end-to-end services across the full “storage–search–computation” pipeline in secure cloud computing. Ping Wang 0086, Fei Tang 0001, Huihui Zhu 0001, Shiyue Kang |
IEEE Trans. Cloud Comput. | 2 |
| 2026 | DMS-P$^{2}$2CQ: Privacy-Preserving Collaborative Query Protocol for Distributed Multi-Server SystemsabstractA privacy-preserving collaborative query protocol for distributed multi-server systems (DMS-P$^{2}$CQ) enables a querying party to interact with multiple independent servers using an identifier$x_{u}$and receive a categorical decision (e.g.,Good/Moderate/Poor) determined by the total number of servers whose datasets contain$x_{u}$. This setting is motivated by financial applications such as credit assessment, where the querying party must not reveal$x_{u}$to data-owning institutions, and each institution must protect its proprietary user list. To meet both the functionality and privacy requirements of the querying party and the servers, we present two protocols that represent a privacy-efficiency trade-off. DMS-P$^{2}$CQ$_{1}$is a lightweight protocol inspired by OPRF-based PSI. It achieves identifier privacy and hides the identifier-to-server membership relation from the querying party via a two-stage OPRF with an aggregation/re-randomization server. However, it reveals the aggregate count to a randomly selected leader server and relies on a non-collusion assumption between two special servers. DMS-P$^{2}$CQ$_{2}$strengthens privacy by secret-sharing the count so that no single party learns the true aggregate count and removes the need for a trusted re-randomization server. We prove the security of two protocols under the semi-honest model. Experimental results on our local testbed show that with 20 servers and a dataset size of$2^{20}$, the runtimes for DMS-P$^{2}$CQ$_{1}$and DMS-P$^{2}$CQ$_{2}$are approximately 8.034s and 16.697s, respectively. Huihui Zhu 0001, Fei Tang 0001, Jinyong Shan, Ping Wang 0086, Yulun Song, Yunlong Xie |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | A Federated Recommendation System Framework Based on Variational Autoencoder With Mixture of ExpertsabstractRecommender systems enhance user experience by delivering personalized suggestions derived from users' historical behavior. However, conventional approaches face challenges in processing large-scale data while simultaneously preserving user privacy and maintaining stable training. To address these issues, we propose Fed-MWAE, a novel federated variational autoencoder (VAE) framework for recommendation tasks. The framework incorporates a sparsely activated Mixture-of-Experts (MoE) module to model diverse user behavior patterns across expert subnetworks. A top-$k$gating mechanism selectively aggregates expert outputs, thereby improving computational efficiency without compromising accuracy. Furthermore, Fed-MWAE employs VAEs to capture complex latent structures and replaces the conventional Kullback-Leibler (KL) divergence with the Wasserstein distance, enabling smoother optimization and more stable convergence. Training is conducted in a federated learning setting, where local clients perform on-device updates to safeguard data privacy, and the updates are aggregated using the Federated Averaging (FedAvg) algorithm to enhance scalability and communication efficiency. Extensive experiments on four public datasets demonstrate that Fed-MWAE consistently outperforms strong baselines, achieving improvements of 5.46% in NDCG, 0.66% in Recall@20, 4.85% in Recall@50, and a 2.99% reduction in loss. These results validate the effectiveness of Fed-MWAE in balancing accuracy, efficiency, stability, and privacy in federated recommender systems. Yunpeng Xiao 0001, Fei Tang 0001, Rong Wang 0003, Guoyin Wang 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | Knowledge Sharing Enhanced Clustered Federated Learning for Heterogeneous Client DataabstractClustered Federated Learning (CFL) is a machine learning paradigm that balances local and global training to address limited local data and reduce the negative effects of data heterogeneity on the global model. However, data heterogeneity and insufficient samples in small clusters remain key challenges in CFL, and existing methods often overlook the potential of cross-cluster knowledge sharing, hindering further performance gains. To address these challenges, a clustered federated learning framework with knowledge sharing, termed KS-CFL (Knowledge-Sharing Clustered Federated Learning), is proposed. First, to tackle client data heterogeneity, local model gradients are used to extract representative features, and a data-driven heterogeneity metric is designed to identify client differences and guide cluster formation. Second, a divisive iterative clustering method is introduced to adjust cluster structures during training dynamically, improving client clustering precision. Finally, a weight-sharing mechanism inspired by multitask learning is introduced to mitigate data scarcity in small clusters, enhance model performance, and accelerate convergence. Experimental results show that KS-CFL outperforms state-of-the-art CFL methods on the CIFAR-10 and FEMNIST datasets. In the FEMNIST-D2 scenario, KS-CFL improves accuracy by 3.69% over FLT and reduces variance, enhancing fairness. On CIFAR-10-D1 and CIFAR-10-D2, it achieves accuracy gains of 2.18% and 2.66%, respectively, with lower variance. These results highlight the effectiveness of KS-CFL in heterogeneous data environments. Yunpeng Xiao 0001, Haonan Mo, Fei Tang 0001, Rong Wang 0003, Guoyin Wang 0001 |
IEEE Internet Things J. | 4 |
| 2025 | Ultra-Fast Private Set Intersection From Efficient Oblivious Key-Value StoresabstractPrivate Set Intersection (PSI) enables us to compute the intersection of private sets without leaking additional data. The state-of-the-art PSI protocol$\mathsf {RR22}$(CCS 2022) is derived from an Oblivious Pseudo-Random Function (OPRF) protocol based on Oblivious Key-Value Stores (OKVS). However, the existing OKVS suffers either low computation efficiency or high encoding redundancy. In this work, we propose a new efficient bucket-based OKVS with only 1% redundancy. The encoding algorithm of our OKVS is 4 to 15 times faster than the recent state-of-the-art OKVS (USENIX Security 2023). Specifically, our OKVS can encode$2^{24}$key-value pairs in only 2.1 to 8.5 seconds, corresponding to 30% to 1% redundancy, while the latter takes about 30 seconds with at least 3%. We can then obtain a new ultra-fast PSI protocol with lower communication from our OKVS in both semi-honest and malicious settings. Furthermore, we implemented our PSI protocol and conducted an extensive evaluation, which shows that it outperforms the existing PSI protocols, such as$\mathsf {KKRT16}$(CCS 2016),$\mathsf {CM20}$(Crypto 2020),$\mathsf {RS21}$(EuroCrypt 2021),$\mathsf {RR22}$(CCS 2022), and$\mathsf {KBM23}$(NDSS 2023). Since our PSI features an ultra-low communication overhead, it has overall advantages for the network environment with a small bandwidth. For example, our PSI takes only about 468 and 476 seconds in semi-honest and malicious settings with the input size of$2^{24}$when the bandwidth is 10 Mbps, while the state-of-the-art$\mathsf {RR22}$requires about 541 and 625 seconds. Our implementation is available onhttps://github.com/ShallMate/fastpsi. Guowei Ling, Peng Tang 0002, Fei Tang 0001, Shifeng Sun 0001, Shouling Ji, Weidong Qiu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Privacy-Preserving Authorized Set Matching via Dishonest Majority Multiparty ComputationabstractPrivate Set Intersection (PSI) enables each party with a private set to compute the intersection without disclosing other information. However, even in maliciously secure PSI, it does not guarantee input authenticity and output integrity, which becomes problematic in certain scenarios. For instance, in Web 3.0, one of the essential requirements is to find common certifiers among the parties. However, if certifier identities are meant to be protected, some parties may attempt to forge certifier identities or intentionally exclude a particular certifier during protocol execution. Recently, the Private Certifier Intersection (PCI), a variant of PSI, has been proposed to address this problem. Nevertheless, it incurs significantly high computational and communication overhead. This work proposes thePrivate Identity Intersection(PII), which takes private identifiers and corresponding anonymous signatures from mutually distrusting parties as input, verifies them, and delivers the intersection of the successfully verified identifiers to all parties while ensuring the integrity of the output. Furthermore, PII can naturally extend from two to multiple-party settings while resisting the collusion attack. To achieve the ideal functionality of PII, we implement a user-friendly MPC framework called$\mathsf {Oryx}$without third-party libraries. Based on$\mathsf {Oryx}$, we instantiate PII with two digital signature schemes, one proposed in this paper. Compared to existing work, our PII protocols reduce the computation overhead by up to$163\times$and the communication overhead by up to$190\times$, representing an improvement of two orders of magnitude. To demonstrate the practicality of our work, we evaluate its performance in WAN environments with bandwidths of 100 Mbps and 500 Mbps, under a fixed latency of 20 ms. Guowei Ling, Peng Tang 0002, Fei Tang 0001, Shifeng Sun 0001, Jinyong Shan, Liyao Xiang, Weidong Qiu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | More Efficient, Privacy-Enhanced, and Powerful Privacy-Preserving Feature Retrieval Private Set IntersectionabstractPrivate Set Intersection (PSI) allows two parties, the sender and the receiver, each possessing a private set, to compute the intersection of their sets, with only the receiver learning the intersection and without revealing any additional information. Privacy-Preserving Feature Retrieval PSI (P2FRPSI) is a variant of PSI. In P2FRPSI, the receiver designs a predicate and obtains the intersection of private sets that satisfy this predicate, while the sender learns nothing about the predicate. However, the existing two PRFPSI protocols (TIFS 2024), based respectively on the DH key agreement and Oblivious Pseudo- Random Function (OPRF), are not highly efficient due to their reliance on expensive homomorphic encryption. Moreover, the existing DH-based P2FRPSI protocol reveals the output size and the original intersection size to the sender. We also observed that the existing P2FRPSI protocols do not support threshold retrieval and the logical connective OR and can only work when feature values of the sender have very low dimensionality. This paper also proposes two new P2FRPSI protocols, one based on DH key agreement and the other based on OPRF, to fully address the issues present in existing P2FRPSI protocols. Our DH-based P2FRPSI is 30× faster than the existing DH-based protocol, with only a 36% increase in communication overhead. Furthermore, our OPRF-based P2FRPSI protocol is 2× as fast as existing OPRF-based protocol and reduces communication overhead by a factor of 4.6. Our DH-based P2FRPSI protocol completely eliminates the leakage of the original intersection size and the output size. Meanwhile, our protocols support the logical connective OR for linking sub-predicates and also enable threshold-based retrieval. They are proven to be secure in the semi-honest model. Our open-source implementations can be found at https://github.com/ShallMate/pfrpsi, which can help readers understand our protocols and reproduce the experiments. Guowei Ling, Peng Tang 0002, Jinyong Shan, Fei Tang 0001, Weidong Qiu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Improved dynamic Byzantine Fault Tolerant consensus mechanism
Fei Tang 0001, Jinlan Peng, Ping Wang 0086, Huihui Zhu 0001, Tingxian Xu |
Comput. Commun. | 1 |
| 2024 | TP-PBFT: A Scalable PBFT Based on Threshold Proxy Signature for IoT-Blockchain ApplicationsabstractConsensus protocol is one of the core technologies of Internet of Things (IoT)-blockchain applications, which is used to ensure the consistency of data between terminal devices that do not trust each other. Practical Byzantine fault tolerance (PBFT) is a typical consensus algorithm. Due to its advantages of low computational power and complexity, PBFT is deemed more suitable for IoT-blockchain applications. PBFT can tolerate 1/3 faulty nodes in a blockchain network, which can be malicious or unresponsive. In this work, if a node does not respond to messages from other nodes, it can be regarded as an offline node. Therefore, when more than a third of the nodes go offline, the blockchain network breaks down. However, in IoT applications, this situation is likely to occur and greatly limits the security and stability of IoT-blockchain networks. In order to solve the above problem, we propose a novel threshold proxy signature-based PBFT (TP-PBFT) consensus for IoT-blockchain applications. We construct a new threshold proxy signature scheme that enables the proxy signers to sign messages on behalf of the offline nodes. In addition, we design a “two-step clustering” method to construct a double-layer architecture that improves the scalability of PBFT. Meanwhile, a reputation mechanism is introduced to evaluate the quality of the nodes. The experimental results show that our TP-PBFT consensus protocol can reach consensus when the number of offline nodes more than 1/3. Fei Tang 0001, Tingxian Xu, Jinlan Peng, Ning Gan |
IEEE Internet Things J. | 1 |
| 2024 | P²FRPSI: Privacy-Preserving Feature Retrieved Private Set IntersectionabstractPrivate Set Intersection (PSI) protocols can securely compute the intersection of the private sets on the server and the client without revealing additional data. This work introduces the concept of Privacy-Preserving Feature Retrieved Private Set Intersection ($\mathsf {P^{2}FRPSI}$). In$\mathsf {P^{2}FRPSI}$protocols, the client can obtain the intersection that satisfies a given predicate without revealing the predicate and additional data. We formally define the$\mathsf {P^{2}FRPSI}$protocol, including its inputs, outputs, functionality, and security. To achieve the privacy guarantee in$\mathsf {P^{2}FRPSI}$protocols, a new two-party protocol is designed, namely Secure Secret Shared Retrieval ($\mathsf {S^{3}R}$), which can be used to securely determine whether each item on the server satisfies the predicate. We construct an$\mathsf {S^{3}R}$protocol and prove its security in the semi-honest model. On the basis of this, we design an efficient OT-based$\mathsf {P^{2}FRPSI}$protocol and an easy-to-implement DH-based$\mathsf {P^{2}FRPSI}$protocol and prove that they are secure in the semi-honest model. Our implementation shows that the OT-based$\mathsf {P^{2}FRPSI}$protocol can perform the matching for about 1000K items in 3.8 seconds with a single thread. Moreover, the DH-based$\mathsf {P^{2}FRPSI}$can perform the matching for about 7000K items in one hour with four threads, with communication totaling 1456 MB, while the OT-based$\mathsf {P^{2}FRPSI}$protocol requires 1673 MB. Guowei Ling, Fei Tang 0001, Chaochao Cai, Jinyong Shan, Haiyang Xue, Wulu Li, Peng Tang 0002, Xinyi Huang 0001, Weidong Qiu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Cycle-Fed: A Double-Confidence Unlabeled Data Augmentation Method Based on Semisupervised Federated LearningabstractThe Internet of Things (IoT) generates a substantial volume of unlabeled personal privacy data in finance and healthcare, distributed across diverse locations and networks, which is currently underutilized. Semisupervised federated learning emerges as a promising solution by conducting model training on local devices without transmitting raw data to a central server. This approach enhances the security and efficiency of IoT systems. First, to overcome traditional data augmentation limitations in simulating raw data distribution, we introduce a data augmentation module using a uniformly distributed dropout (Uout) layer. This module enhances data diversity by mitigating sensitivity to variance shifts. Furthermore, considering the insufficiency of pseudo-label availability under the condition of low-density separation, we propose the Cycle-Fed model with dual-reliability. This model enhances its performance through the effects of data augmentation by incorporating pseudo-labeled positive samples subjected to secondary validation by discriminators provided by the data augmentation module. Finally, we propose a client-side optimal value avoidance strategy based on an adaptive local proximal term, which is denoted as$\mu _{t}$. Experimental results on a public dataset indicate that the Cycle-Fed model surpasses the baseline with a 4.52%-8.76% reduction in loss, 1.62%-6.09% accuracy improvement, and a 1.285%-1.396% increase in area under the curve. Yunpeng Xiao 0001, Qunqing Zhang, Fei Tang 0001, Rong Wang 0003, Qian Li 0009, Guoyin Wang 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Efficient Privacy-Preserving Multi-Dimensional Range Query for Cloud-Assisted Ehealth SystemsabstractIn cloud-assisted electronic health (eHealth) systems, the exponential growth of electronic health records (EHRs) has prompted healthcare organizations to move it to the cloud. However, EHRs are encrypted before being outsourced for privacy. Although searchable encryption schemes for EHRs have been proposed, their search efficiency and functionality for massive EHRs with high-dimensional are still insufficient. In this paper, we adopt an attribute hierarchy structure for medical datasets, enabling efficient multi-dimensional range search and reducing high-dimensional EHRs to low-dimensional vectors. To further improve search efficiency, we design an index tree that require no additional storage and computational overhead, significantly improving efficiency in search, trapdoor generation, and index building. Our scheme is well-suited for large-scale medical data scenarios, especially in dealing with high-dimensional and massive datasets. Extensive experiments demonstrate the superiority of our scheme over existing solutions, particularly in large-scale medical data scenarios. Compared to the classic EDMRS scheme, our scheme has a computational overhead in index building and search that is only about 1/500 and 1/10 of EDMRS when the number of keywords and electronic health records is 3,000 and 6,000, respectively. Moreover, as medical data and keywords increase, our scheme shows slower computational overhead growth compared to EDMRS. Fei Tang 0001, Xujun Zhou, Haining Luo, Guowei Ling, Jinyong Shan, Yunpeng Xiao 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2023 | IHVFL: a privacy-enhanced intention-hiding vertical federated learning framework for medical dataabstractAbstract Vertical Federated Learning (VFL) has many applications in the field of smart healthcare with excellent performance. However, current VFL systems usually primarily focus on the privacy protection during model training, while the preparation of training data receives little attention. In real-world applications, like smart healthcare, the process of the training data preparation may involve some participant’s intention which could be privacy information for this participant. To protect the privacy of the model training intention, we describe the idea of Intention-Hiding Vertical Federated Learning (IHVFL) and illustrate a framework to achieve this privacy-preserving goal. First, we construct two secure screening protocols to enhance the privacy protection in feature engineering. Second, we implement the work of sample alignment bases on a novel private set intersection protocol. Finally, we use the logistic regression algorithm to demonstrate the process of IHVFL. Experiments show that our model can perform better efficiency (less than 5min) and accuracy (97%) on Breast Cancer medical dataset while maintaining the intention-hiding goal. Fei Tang 0001, Shikai Liang, Guowei Ling, Jinyong Shan |
Cybersecur. | 1 |
| 2023 | Solving Small Exponential ECDLP in EC-Based Additively Homomorphic Encryption and ApplicationsabstractAdditively Homomorphic Encryption (AHE) has been widely used in various applications, such as federated learning, blockchain, and online auctions. Elliptic Curve (EC) based AHE has the advantages of efficient encryption, homomorphic addition, scalar multiplication algorithms, and short ciphertext length. However, EC-based AHE schemes require solving a small exponential Elliptic Curve Discrete Logarithm Problem (ECDLP) when running the decryption algorithm, i.e., recovering the plaintext$m\in \{0,1\}^{\ell} $from$m \ast G$. Therefore, the decryption of EC-based AHE schemes is inefficient when the plaintext length$\ell > 32$. This leads to people being more inclined to use RSA-based AHE schemes rather than EC-based ones. This paper proposes an efficient algorithm called$\mathsf {FastECDLP}$for solving the small exponential ECDLP at 128-bit security level. We perform a series of deep optimizations from two points: computation and memory overhead. These optimizations ensure efficient decryption when the plaintext length$\ell $is as long as possible in practice. Moreover, we also provide a concrete implementation and apply$\mathsf {FastECDLP}$to some specific applications. Experimental results show that$\mathsf {FastECDLP}$is far faster than the previous works. For example, the decryption can be done in 0.35 ms with a single thread when$\ell = 40$, which is about 30 times faster than that of Paillier. Furthermore, we experiment with$\ell $from 27 to 54, and the existing works generally only consider$\ell \leq 32$. The decryption only requires 1 second with 16 threads when$\ell = 54$. In the practical applications, we can speed up model training of existing vertical federated learning frameworks by 4 to 14 times. At the same time, the decryption efficiency is accelerated by about 140 times in a blockchain financial system (ESORICS 2021) with the same memory overhead. Fei Tang 0001, Guowei Ling, Chaochao Cai, Jinyong Shan, Xuanqi Liu, Peng Tang 0002, Weidong Qiu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Multiauthority Traceable Ring Signature Scheme for Smart Grid Based on BlockchainabstractAs the next‐generation power grid system, the smart grid can realize the balance of supply and demand and help in communication security and privacy protection. However, real‐time power consumption data collection might expose the users’ privacy information, such as their living habits and economic conditions. In addition, during the process of data transmission, it may lead to data inconsistency between the user side and the storage side. Blockchain provides tamper‐resistant and traceable characteristics for solving these problems, and ring signature schemes provide an anonymous authentication mechanism. Therefore, in this work, we consider the applications of ring signature scheme in smart grid based on blockchain. We introduce the notion of multi‐authority traceable ring signature (MA‐TRS) scheme for distributed setting. In our scheme, there is an auditing node that can distinguish the identity of the real signer from the ring without any secret information. Last but not least, we prove that the proposed scheme is unforgeable, anonymous, and traceable. Fei Tang 0001, Junjie Pang, Kefei Cheng, Qianhong Gong |
Wirel. Commun. Mob. Comput. | 1 |
| 2020 | A New User Revocable Ciphertext-Policy Attribute-Based Encryption with Ciphertext UpdateabstractThe revocable ciphertext-policy attribute-based encryption (R-CP-ABE) is an extension of ciphertext-policy attribute-based encryption (CP-ABE), which can realize user direct revocation and maintain a short revocation list. However, the revoked users can still decrypt the previously authorized encrypted data with their old key. The R-CP-ABE scheme should provide a mechanism to protect the encrypted data confidentiality by disqualifying the revoked users from accessing the previously encrypted data. Motivated by practical needs, we propose a new user R-CP-ABE scheme that simultaneously supports user direct revocation, short revocation list, and ciphertext update by incorporating the identity-based and time-based revocable technique. The scheme provides a strongly selective security proof under the modified decisional q -parallel bilinear Diffie–Hellman Exponent problem, where “strongly” means that the adversary can query the secret key of a user whose attribute set satisfies the challenge ciphertext access structure and whose identity is in the revocation list. Zhe Liu 0034, Fuqun Wang, Kefei Chen, Fei Tang 0001 |
Secur. Commun. Networks | 4 |
| 2020 | Identity-Based Identification Scheme without Trusted Party against Concurrent AttacksabstractIdentification schemes support that a prover who holding a secret key to prove itself to any verifier who holding the corresponding public key. In traditional identity-based identification schemes, there is a key generation center to generate all users’ secret keys. This means that the key generation center knows all users’ secret key, which brings the key escrow problem. To resolve this problem, in this work, we define the model of identity-based identification without a trusted party. Then, we propose a multi-authority identity-based identification scheme based on bilinear pairing. Furthermore, we prove the security of the proposed scheme in the random oracle model against impersonation under passive and concurrent attacks. Finally, we give an application of the proposed identity-based identification scheme to blockchain. Fei Tang 0001, Jiali Bao, Yonghong Huang, Fuqun Wang |
Secur. Commun. Networks | 1 |