VLDB 2026 Research / reviewers in the wild / expert
Kuo-Hui Yeh
dblp:63/204
· DBLP profile ↗
45ranked-venue papers
8as first author
27since 2021 · last 2026
0000-0003-0598-761XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 1 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 3 first-author · 9 since 2021Systems, architecture and hardware · 8 · 1 first-author · 3 since 2021Computer networks · 7 · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SemLink: A Semantic-Aware Automated Test Oracle for Hyperlink Verification using Siamese Sentence-BERT
Guan-Yan Yang, Wei-Ling Wen, Shu-Yuan Ku, Farn Wang, Kuo-Hui Yeh |
ICST | 5 |
| 2026 | Uncovering Bluetooth vulnerabilities with binary coverage-guided fuzz testing and controller emulation
Zhao Min Chen, Tien-Chih Lin, Guan-Yan Yang, Farn Wang, Kuo-Hui Yeh |
Comput. Secur. | 6 |
| 2026 | Blockchain-enabled heterogeneous communication protocol with identifiable abort in federated learning for artificial intelligence of things
Hu Xiong, Qiyong Xian, Kuo-Hui Yeh |
J. Inf. Secur. Appl. | 3 |
| 2026 | Enabling trust and learner agency in lifelong learning: A dual-chain, privacy-preserving credential architecture
Jiageng Chen, Kuo-Hui Yeh, Yang Xiang 0001 |
J. Inf. Secur. Appl. | 4 |
| 2026 | Guest Editorial Introduction to the Special Issue on Federated Learning and Digital Twins for Intelligent Transportation System
Kuo-Hui Yeh, Yong Xiang 0001, Yingjiu Li, Chien-Ming Chen 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2025 | Enhancing FIDO2 Authentication Security through Markov Decision Process-Based Risk Assessment
Yu-Jen Wang, Kuo-Hui Yeh, Taif Khalifah Alghufaily |
ISPEC | 2 |
| 2025 | ArtPerception: ASCII art-based jailbreak on LLMs with recognition pre-test
Guan-Yan Yang, Tzu-Yu Cheng, Ya-Wen Teng, Farn Wang, Kuo-Hui Yeh |
J. Netw. Comput. Appl. | 5 |
| 2025 | Federated Learning With Adaptive Regularization for Efficient Edge Data Corruption Detection in Edge IntelligenceabstractEdge intelligence is an emerging distributed computing paradigm that has been driven by the rapid proliferation of Internet of Things (IoT) devices, along with the advancements in edge computing and artificial intelligence. With latency-sensitive data commonly cached across multiple Edge Servers (ESs), efficient Edge Data Integrity Verification (EDIV) has become increasingly critical. Traditional ‘challenge-response’ EDIV methods incur substantial computation and communication costs by indiscriminately verifying all ESs, even though not all ESs may be simultaneously corrupted. A recent Federated Learning (FL)-based framework partially addressed this inefficiency by identifying potentially corrupted ESs early, considering only homogeneous ES activity data. However, due to heterogeneous activity data across diverse ESs, this approach suffers from reduced detection accuracy of potentially corrupted ESs, slower FL convergence, and unclear guidance for subsequent verification rounds, thus limiting the overall reduction in EDIV computation and communication costs. To that end, we proposeFederated learning withAdaptiveRegularizer-basedEdgeDataIntegrityVerification (FedAR-EDIV), which is an effective FL-based framework integrating an adaptive objective regularization strategy specifically designed to handle heterogeneous data distributions. FedAR-EDIV efficiently identifies potentially corrupted ESs during the FL process, achieves faster convergence, and significantly reduces computation and communication costs in the final EDIV procedure. It achieves up to 16× communication speedup and 9.1× computation cost reduction compared to baseline EDIV methods, and reaches FL-based detection accuracy exceeding 99.78% under heterogeneous conditions using KDD99 activity data. Additionally, FedAR-EDIV incorporates a dynamic reputation mechanism after each EDIV round to strategically guide subsequent verification rounds, ensuring fewer checks for trustworthy ESs and greater scrutiny for suspicious ones, thus further minimizing EDIV-related costs. We provide a theoretical analysis that demonstrates the convergence of FedAR-EDIV during FL training, as well as correctness, efficiency, and security during the EDIV process. Extensive experiments conducted on two different heterogeneous activity datasets validated that FedAR-EDIV substantially outperforms baseline methods in terms of corrupted ES detection accuracy, FL convergence speed, and overall EDIV computation and communication costs. Md Palash Uddin, Yong Xiang 0001, Kuo-Hui Yeh, Lu Liu 0001, Jonathan Kua |
IEEE Trans. Cloud Comput. | 4 |
| 2025 | Heterogeneous Privacy-Preserving Blockchain-Enabled Federated Learning for Social FintechabstractSocial fintech integrates financial technology with social networking to enhance financial services’ accessibility and personalization by leveraging social interactions and user data. This approach raises privacy security concerns, particularly in application based on centralized artificial intelligence systems. To address these issues, blockchain-enabled federated learning (BEFL) offers a decentralized solution, improving robustness and privacy but facing challenges such as privacy attacks and heterogeneous crypto system. In response, a novel PKI and identity-based heterogeneous authenticated asymmetric group key agreement (PKI-IB-HAAGKA) protocol was proposed, which resolves crypto system heterogeneity issues. What's more, a PKI and identity-based heterogeneous batch multisignature (PKI-IB-HBMS) was proposed as a building block of PKI-IB-HAAGKA. This article presents the heterogeneous privacy-preserving blockchain-enabled federated learning (HPP-BEFL) system, designed to enhance privacy, security, and efficiency in social fintech applications. It effectively mitigates man-in-the-middle and inference attacks while improving overall system performance. Through security analysis and experiment results, it is demonstrated that the proposed PKI-IB-HAAGKA, PKI-IB-HBMS, and HPP-BEFL are provably secure and highly efficient, which can be applied to large-scale heterogeneous privacy-preserving model training scenarios. Hu Xiong, Yaxin Zhao, Abubaker Wahaballa, Kuo-Hui Yeh |
IEEE Trans. Comput. Soc. Syst. | 5 |
| 2025 | Multi-Authority CP-ABE Scheme With Cryptographic Reverse Firewalls for Internet of VehiclesabstractInternet of vehicles, featured with widely distributed vehicle nodes and limited computing power, usually have high performance requirements. Because of this feature, efficient and reliable access control has raised a challenge in Internet of vehicles. Ciphertext-policy attribute-based encryption (CP-ABE) could be denoted as an efficient solution for this problem. However, directly applying traditional single-authority CP-ABE schemes may result in single-point performance bottleneck. Besides, the secrets of the whole system may be leaked if any node is attacked. To solve these challenging tasks, we proposed MA-CP-ABE-CRF, a multi-authority CP-ABE scheme with cryptographic reverse firewalls. The system is designed to grant vehicles fine-grained access control by encrypting data under vehicle attributes. Besides, load balancing of authorization in distributed systems is achieved based on the characteristic of multi-authority. Meanwhile, specific nodes are equipped with cryptographic reverse firewalls (CRFs) to prevent information leakage. As the first scheme with the above features for Internet of vehicles, the system achieves adaptive CPA-security and ASA-security. Through rigorous theoretical analysis and experimental comparison, MA-CP-ABE-CRF is proved to be highly efficient and practical. Hu Xiong, Hui Su, Kuo-Hui Yeh |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2025 | Decentralized Data Integrity Auditing in Vehicular Cloud ComputingabstractAs Vehicular Cloud Computing (VCC) evolves, ensuring data integrity and availability becomes a critical challenge due to the vast amount of data being shared and stored. These properties are vital for preserving confidence in cloud services, guaranteeing that data is kept intact and readily available when needed. Traditional data auditing mechanisms, such as Proofs of Retrievability (PoR) and Provable Data Possession (PDP), are effective but often rely on centralized models that pose risks like single-point failures and susceptibility to collusion. To mitigate these risks, we introduce a blockchain-assisted protocol that leverages the decentralized and tamper-proof characteristics of blockchain to enhance the security of data auditing in VCC. Our approach incorporates a dynamic key update mechanism to counter key exposure issues prevalent in VCC and introduces a multi-replica mechanism to ensure data redundancy and reliability across different storage nodes. This feature significantly reduces the risk of data loss and improves trust in cloud services by distributing data storage responsibilities and preventing single-point failures. We conduct formal security analysis and implement a prototype of our protocol on the Ethereum blockchain. Experimental evaluations on both Ganache and Sepolia testnets validate its feasibility in decentralized environments. The results demonstrate that our scheme supports stable challenge-response latency, moderate gas consumption, and reliable multi-replica consistency—making it well-suited for VCC deployments with dynamic conditions and limited resources. Tianang Yao, Hu Xiong, Kuo-Hui Yeh, Yong Xiang 0001, Changhai Nie |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2025 | DA-FL: Blockchain Empowered Secure and Private Federated Learning With Anonymous AuthenticationabstractFederated learning (FL) is a secure multiparty machine learning that addresses the issue of data silos by allowing nodes to train locally. Nonetheless, the lack of trusted environments, node supervision, and privacy protection measures in centralized FL limit its large-scale promotion. To address these issues, a blockchain-based decentralized FL framework is proposed, namely, decentralized federated learning with node anonymous authentication (DA-FL). Specifically, DA-FL introduces blockchain for local model storage and global model aggregation in the absence of centralized server, and uses differential privacy to reduce the risk of model privacy leakage. In addition, a consensus mechanism proof of accuracy is designed to effectively reduce the computational load of consensus and mitigate the impact of low-quality models on the aggregation results. To achieve node supervision, distributed key generation and revocable ring signature technologies are being integrated. This ensures the anonymous authentication of nodes while also allowing for the revocation of the anonymity of malicious nodes when necessary. Finally, the security and functionality of DA-FL are evaluated through simulation experiments conducted on real datasets. The numerical results show that the proposed FL scheme has significant performance advantages over other schemes. Hu Xiong, Yaxin Zhao, Kuo-Hui Yeh |
IEEE Trans. Reliab. | 5 |
| 2024 | Heterogeneous and plaintext checkable signcryption for integrating IoT in healthcare system
Abdalla Hadabi, Kuo-Hui Yeh, Chien-Ming Chen 0001, Saru Kumari, Hu Xiong |
J. Syst. Archit. | 3 |
| 2024 | Detecting Adversarial Examples of Fake News via the Neurons Activation StateabstractDue to the development of technologies, such as the Internet and mobile communication, news production is increasing day by day. Proper news delivery can lead to a thriving economy and disseminate knowledge. However, in addition to disrupting the existing order, fake news may create incorrect values and even beliefs. Therefore, detecting the authenticity of news is an extremely important issue. At present, many scholars have used artificial intelligence (AI) to detect fake news, achieving excellent results. However, once humans become dependent on AI, adversarial examples (AEs) can deceive the AI model and allow humans to receive false information. We have discovered that samples from different categories result in distinct and independent activation state distributions for each neuron. Therefore, this study proposes a method that detects adversarial samples of fake news by observing the activation states of neurons and modeling them as a Poisson distribution. The results of the experiment showed that our method can effectively detect AEs mixed in normal data and remove them, thereby improving the classification accuracy of the model by about 17%. The experimental results show that the method proposed in this article can improve the detection accuracy of fake news AEs. Fan-Hsun Tseng, Jiang-Yi Zeng, Hsin-Hung Cho, Kuo-Hui Yeh, Chi-Yuan Chen |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2024 | A Conditional Privacy-Preserving Mutual Authentication Protocol With Fine-Grained Forward and Backward Security in IoVabstractWith the rise of intelligent transportation, various mobile value-added services can be provided by the service provider (SP) in the Internet of Vehicles (IoV). To guarantee the dependability of services, it is essential to implement a mutual authentication protocol between the vehicles and the SP. Existing mutual authentication protocols to secure the communication between the SP and the vehicle raise challenges such as providing fine-grained forward security for the SP and achieving backward security for the vehicle. To handle these challenges, this paper proposes a conditional privacy-preserving mutual authentication protocol featured with fine-grained forward security and backward security for IoV, which can be implemented via two building blocks we have constructed. Specifically, we present a new puncturable signature (PS) scheme without false-positive probability and the update of the public key as well as the first proxy re-signature scheme with parallel key-insulation (PKI-PRS). What’s more, both the proposed PKI-PRS and PS still have interest beyond this protocol. Then, an anonymous mutual authentication protocol with resistance to key leakage is constructed by incorporating the above signature schemes. The proposed protocol not only provides fine-grained forward security for the SP, but also ensures forward security as well as backward security for the vehicles. Besides, the approach to achieving anonymous authentication can efficiently provide conditional privacy-preserving for the vehicles. With the support of the random oracle model and experimental simulations, the formal security proof and the superiority of the proposed protocol is explicitly given. Hu Xiong, Ting Yao 0002, Yaxin Zhao, Lingxiao Gong, Kuo-Hui Yeh |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2023 | Designing a Mobile Payment-Driven Mobility-as-a-Service Architecture for Bus TransportationabstractThis paper proposes a comprehensive architecture for a Mobility-as-a-Service (MaaS) platform, focusing on service browsing, ticketing, and payment, with a specific emphasis on integrating MaaS into bus payment systems. The proposed architecture aims to enhance user experience and convenience in accessing and paying for various transportation services while providing support for MaaS startups, offering a novel approach to MaaS, addressing challenges related to service discovery, ticketing, and payment through a unified system. The proposed MaaS platform holds the potential to improve mobility, reduce congestion, and promote sustainable transportation. Kuongho Chen, Tzu-Yuan Kao, Kuo-Hui Yeh |
KES | 3 |
| 2023 | Scalable and Revocable Attribute-Based Data Sharing With Short Revocation List for IIoTabstractThe cooperative works between connected smart devices in the Industrial Internet of Things (IIoT) have greatly made the growth in productivity and economics for the conventional industry. However, due to the introduction of the communication network, the budding IIoT also confronts the unprecedented cyber threats. To prevent the data from being intercepted by malicious intruders, we propose an efficient and fully secure data sharing work with a short revocation list (DS-SRL) for IIoT. The DS-SRL not only enables flexible access control to the massive data in IIoT but also provides a direct revocation approach for handling the potential issues of key disclosure and membership expiring in application scenarios. Particularly, compared with existing directly revocable ABE works, the revocation list in the DS-SRL scheme will keep constant size even with the increasing number of users. Thus, the consumption for computing and disseminating the revoke-related part of ciphertext are low. This resource-saving merit makes our DS-SRL scheme suitable for IIoT where the smart devices are weak in the ability of both processing and storage. The DS-SRL works without boundary such that the public parameters involved in the system require no predefinitions and can be dynamically adjusted after deployment. Furthermore, the proposed DS-SRL work is demonstrated to be fully secure under the decisional linear assumption. Hence, it owns high flexibility, scalability, and security, which are essential and desirable in real-life applications. Finally, the superior feasibility, efficiency, as well as effectiveness of our DS-SRL work are fairly confirmed by the detailed performance evaluation. Jun Feng 0007, Hu Xiong, Yang Xiang 0001, Kuo-Hui Yeh |
IEEE Internet Things J. | 5 |
| 2023 | Trusting Computing as a Service for Blockchain ApplicationsabstractRecently, blockchain and smart contracts have been one of most popular technology to establish trustworthy applications in several fields. However, due to the transparency and publicity of blockchain, the information processed by a smart contract is visible to every party in a blockchain. In light of this, this study proposes a trusted computing as a service (TCaaS) framework based on the blockchain. One of the critical component is the Execution Environment for Secured Smart Contract Computing (ESC)2 node. In the proposed framework, people can deploy (ESC)2 nodes in a blockchain. Users can upload general-purposed programs and associated parameters and discover an (ESC)2 node for execution via related smart contracts. The programs and parameters are encrypted so that only selected (ESC)2 node can decrypt the data. Then the execution environment calculates the result and returns it to the blockchain. We evaluate our concept with the ESP32 microcontroller with the ATECC508A security chip and the Quorum blockchain platform. Therefore, the study contributes to ensure faithful execution of programs without losing confidentiality. Wen-Wei Li, Weizhi Meng 0001, Kuo-Hui Yeh, Shi-Cho Cha 0001 |
IEEE Internet Things J. | 3 |
| 2023 | A task-oriented neural dialogue system capable of knowledge accessing
Mengjuan Liu, Kuo-Hui Yeh |
J. Inf. Secur. Appl. | 4 |
| 2023 | Revocable and Unbounded Attribute-Based Encryption Scheme With Adaptive Security for Integrating Digital Twins in Internet of ThingsabstractInternet of Things (IoTs) has been a burgeoning field that transforms the ubiquitous objects to interconnected devices and intelligent system. Today, with the emerging of innovative technologies such as cloud computing, the IoT sector is in a race to leverage these novel technologies to achieve optimal performance. Naturally the Digital Twins (DTs) architecture acts as an indispensable intermediary bridge to couple the IoT domain with these lastest technologies together. However, a tremendous obstacle is that the current Revocable Attribute-Based Encryption (RABE) schemes applied in the DTs paradigm fail to balance the efficiency, security and scalability simultaneously. In this paper, we tackle this challenge by presenting an unbounded and efficient direct RABE scheme with adaptive security. Compared with the previous schemes in this domain, our approach achieves revocable and fine-grained access control efficiently by employing the arithmetic span program (ASP) as the access structure. In this way, the expensive bilinear pairing and exponentiation operations are reduced significantly. Moreover, the unbounded property is satisfied in our scheme since the parameters are not required to be predefined in the setup phase. At last, with the support of the Matrix Decisional Diffie-Hellman (MDDH) assumption, the proposed scheme is proved to achieve adaptive security by adopting dual system encryption methodology. Theoretical comparison and implementation results demonstrate our proposed scheme possesses prominent practicability, scalability and efficiency. Hu Xiong, Kuo-Hui Yeh |
IEEE J. Sel. Areas Commun. | 4 |
| 2023 | Enhancing OAuth With Blockchain Technologies for Data PortabilityabstractTo satisfy the requirement of data portability, current service providers (or resource servers) usually provide OAuth-based schemes for third party applications (or clients) to access user data with the user's consent. To shoulder the costs of maintaining relationships with potential third party applications, a service provider may adopt delegate the task of authentication and authorization to an authorization server. However, current OAuth specification does not specify the interactions between an authorization server and a resource server. To address this limitation, this study proposes the MyDataChain framework to enhance the existing OAuth specification with blockchain technology. The proposed framework utilizes smart contracts to establish the standard interface to support the processes of authorization requesting, granting, and revocation. As blockchain technologies can ensure data integrity, the framework can use the data stored in the blockchain to resolve disputes among different parities. Moreover, as the proposed framework uses the Non-Interactive Zero-Knowledge (NIZK) scheme, the proposed framework can achieve its purpose without storing any personal identifiable or traceable data in the blockchain. Therefore, people cannot utilize information stored in the blockchain to compromise user privacy. Furthermore, this study implements a prototype system using Quorum blockchain technology. The experimental results show that the framework can be realized with existing blockchain technologies. Therefore, this study can provide a feasible privacy preserving means of achieving data portability and providing individuals the rights to be forgotten considering dispute resolution. Shi-Cho Cha 0001, Chun-Lin Chang, Yang Xiang 0001, Tzu-Jia Huang, Kuo-Hui Yeh |
IEEE Trans. Cloud Comput. | 5 |
| 2023 | Attribute-Based Data Sharing Scheme With Flexible Search Functionality for Cloud-Assisted Autonomous Transportation SystemabstractThe existing group public key encryption with equality test schemes could only support one-to-one data sharing and are not suitable for cloud-assisted autonomous transportation systems, which demand one-to-many data sharing. To tackle this problem efficiently, in this article, we put forward the group-attribute-based encryption with equality test (G-ABEET) scheme. The presented G-ABEET allows sensors equipped in vehicles to encrypt traffic data with an expressive access policy before sharing it. Only users with attributes required by the access policy ought to access the shared ciphertexts, thus achieving selective one-to-many data sharing. Meanwhile, the authorized cloud server could provide group users with equality tests over the ciphertexts, realizing ciphertext search ability. Furthermore, with the group mechanism, the G-ABEET scheme could resist offline message recovery attacks. Besides, in the standard model, we give rigorous security proof of the G-ABEET construction. The feasibility and efficiency of G-ABEET are demonstrated by experimental simulations. Hu Xiong, Hanxiao Wang 0002, Weizhi Meng 0001, Kuo-Hui Yeh |
IEEE Trans. Ind. Informatics | 4 |
| 2023 | Towards Intelligent Attack Detection Using DNA ComputingabstractIn recent years, frequent network attacks have seriously threatened the interests and security of humankind. To address this threat, many detection methods have been studied, some of which have achieved good results. However, with the development of network interconnection technology, massive amounts of network data have been produced, and considerable redundant information has been generated. At the same time, the frequently changing types of cyberattacks result in great difficulty collecting samples, resulting in a serious imbalance in the sample size of each attack type in the dataset. These two problems seriously reduce the robustness of existing detection methods, and existing research methods do not provide a good solution. To address these two problems, we define an unbalanced index and an optimal feature index to directly reflect the performance of a detection method in terms of overall accuracy, feature subset optimization, and detection balance. Inspired by DNA computing, we propose intelligent attack detection based on DNA computing (ADDC). First, we design a set of regular encoding and decoding features based on DNA sequences and obtain a better subset of features through biochemical reactions. Second, nondominated ranking based on reference points is used to select individuals to form a new population to optimize the detection balance. Finally, a large number of experiments are carried out on four datasets to reflect real-world cyberattack situations. Experimental results show that compared with the most recent detection methods, our method can improve the overall accuracy of multiclass classification by up to 10%; the imbalance index decreased by 0.5, and 1.5 more attack types were detected on average; and the optimal index of the feature subset increased by 83.8%. ZengRi Zeng, Baokang Zhao, Han-Chieh Chao, Ilsun You, Kuo-Hui Yeh, Weizhi Meng 0001 |
ACM Trans. Multim. Comput. Commun. Appl. | 5 |
| 2022 | Security, Trust and Privacy for Cloud, Fog and Internet of Things
Chien-Ming Chen 0001, Shehzad Ashraf Chaudhry, Kuo-Hui Yeh, Muhammad Naveed Aman |
Secur. Commun. Networks | 3 |
| 2022 | On the Design of Blockchain-Based ECDSA With Fault-Tolerant Batch Verification Protocol for Blockchain-Enabled IoMTabstractThe blockchain-enabled internet of medical things (IoMT) is an emerging paradigm that could provide strong trust establishment and ensure the traceability of data sharing in the IoMT networks. One of the fundamental building blocks for Blockchain is Elliptic Curve Digital Signature Algorithm (ECDSA). Nevertheless, when processing a large number of transactions, the verification of multiple signatures will incur cumbersome overhead to the nodes in Blockchain. Although batch verification is able to provide a promising approach that verifies multiple signatures simultaneously and efficiently, the upper bound of batch size is limited to small-scale and the efficiency will drop rapidly as the batch size grows in the state-of-the-art ECDSA batch schemes. Meanwhile, most of the existing researches only focus on improving the efficiency of batch verification algorithms in various cryptosystem while ignoring the identification of invalid signatures, which could cause severe performance degradation when the batch verification fails. Motivated by these observations, this paper proposes an efficient and large-scale batch verification scheme with group testing technology based on ECDSA. The application of the presented protocols in Bitcoin and Hyperledger Fabric has been analyzed as supportive and effective. When the batch verification returns a false result, we utilize group testing technology to improve the efficiency of identifying invalid signatures. Comprehensive simulation results demonstrate that our protocol outperforms the related ECDSA batch verification schemes. Hu Xiong, Chuanjie Jin, Mamoun Alazab, Kuo-Hui Yeh, Hanxiao Wang 0002, G. Thippa Reddy, Weizheng Wang 0001, Chunhua Su |
IEEE J. Biomed. Health Informatics | 4 |
| 2021 | Blockchain for edge-enabled smart cities applications
Mian Ahmad Jan, Kuo-Hui Yeh, Zhiyuan Tan 0001, Yulei Wu |
J. Inf. Secur. Appl. | 2 |
| 2021 | Efficient access control with traceability and user revocation in IoTabstractAbstract With the universality and availability of Internet of Things (IoT), data privacy protection in IoT has become a hot issue. As a branch of attribute-based encryption (ABE), ciphertext policy attribute-based encryption (CP-ABE) is widely used in IoT to offer flexible one-to-many encryption. However, in IoT, different mobile devices share messages collected, transmission of large amounts of data brings huge burdens to mobile devices. Efficiency is a bottleneck which restricts the wide application and adoption of CP-ABE in Internet of things. Besides, the decryption key in CP-ABE is shared by multiple users with the same attribute, once the key disclosure occurs, it is non-trivial for the system to tell who maliciously leaked the key. Moreover, if the malicious mobile device is not revoked in time, more security threats will be brought to the system. These problems hinder the application of CP-ABE in IoT. Motivated by the actual need, a scheme called traceable and revocable ciphertext policy attribute-based encryption scheme with constant-size ciphertext and key is proposed in this paper. Compared with the existing schemes, our proposed scheme has the following advantages: (1) Malicious users can be traced; (2) Users exiting the system and misbehaving users are revoked in time, so that they no longer have access to the encrypted data stored in the cloud server; (3) Constant-size ciphertext and key not only improve the efficiency of transmission, but also greatly reduce the time spent on decryption operation; (4) The storage overhead for traceability is constant. Finally, the formal security proof and experiment has been conducted to demonstrate the feasibility of our scheme. Wei Zhang 0205, Hu Xiong, Zhiguang Qin, Kuo-Hui Yeh |
Multim. Tools Appl. | 5 |
| 2020 | bleRPC: A plug-and-play RPC framework over BLE
Shi-Cho Cha 0001, Kuo-Hui Yeh, Zijia Huang |
Comput. Commun. | 2 |
| 2020 | Special Issue on FinTech Security and Privacy
Kuo-Hui Yeh, Robert H. Deng, Hiroaki Kikuchi |
Future Gener. Comput. Syst. | 1 |
| 2020 | A secure and efficient certificateless batch verification scheme with invalid signature identification for the internet of things
Hu Xiong, Yan Wu 0014, Chunhua Su, Kuo-Hui Yeh |
J. Inf. Secur. Appl. | 4 |
| 2019 | Partially policy-hidden attribute-based broadcast encryption with secure delegation in edge computing
Hu Xiong, Yanan Zhao 0002, Kuo-Hui Yeh |
Future Gener. Comput. Syst. | 5 |
| 2019 | Lightweight IoT-based authentication scheme in cloud computing circumstance
Lu Zhou 0002, Xiong Li 0002, Kuo-Hui Yeh, Chunhua Su, Wayne Chiu |
Future Gener. Comput. Syst. | 3 |
| 2019 | Privacy Enhancing Technologies in the Internet of Things: Perspectives and ChallengesabstractInternet of Things (IoT) devices have brought much efficiency and convenience to our daily life. However, the devices may collect a myriad of data from people without their consent. Controlling the large amount of data generated from the devices from being misused is critical to mitigate privacy risks. Therefore, privacy protection on personal data has become an important factor in the development of the IoT. Historically, privacy enhancing technologies (PETs) can effectively enhance the privacy and protect users' personally identifiable information. To date, many researchers have stressed the importance of PETs and proposed solutions relevant to different application fields of the IoT. However, to the best of our knowledge, none of the research has analyzed the PETs in IoT from the aspects of privacy threat issues and privacy legislation. As a result, this paper surveys on the solutions of PETs in the field of IoT, which has filtered down from the large number of published academic papers to the 120 primary studies published between 2014 and 2017. After collecting the papers, we categorized them based on the functions and the coverage of privacy protection, and analyzed them from different aspects, ranging from high-level principles of general data protection regulations and ISO/IEC 29100:2011 requirements to the actual resolution of privacy threats in IoT. Thus, we aim to identify the current state of development of the PETs in various fields and examine whether the existing PETs comply with the latest legal principles and privacy standards and reduce the threats to privacy. Finally, recommendations for future research are given based on the results. Shi-Cho Cha 0001, Tzu-Yang Hsu, Yang Xiang 0001, Kuo-Hui Yeh |
IEEE Internet Things J. | 4 |
| 2019 | A Lightweight Cryptographic Protocol with Certificateless Signature for the Internet of ThingsabstractThe universality of smart-devices has brought rapid development and the significant advancement of ubiquitous applications for the Internet of Things (IoT). Designing new types of IoT-compatible cryptographic protocols has become a more popular way to secure IoT-based applications. Significant attention has been dedicated to the challenge of implementing a lightweight and secure cryptographic protocol for IoT devices. In this study, we propose a lightweight cryptographic protocol integrating certificateless signature and bilinear pairing crypto-primitives. In the proposed protocol, we elegantly refine the processes to account for computation-limited IoT devices during security operations. Rigorous security analyses are conducted to guarantee the robustness of the proposed cryptographic protocol. In addition, we demonstrate a thorough performance evaluation, where an IoT-based test-bed, i.e., the Raspberry PI, is simulated as the underlying platform of the implementation of our proposed cryptographic protocol. The results show the practicability of the proposed protocol. Lu Zhou 0002, Chunhua Su, Kuo-Hui Yeh |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2018 | Seeing Is Believing: Authenticating Users with What They See and Remember
Wayne Chiu, Kuo-Hui Yeh, Akihito Nakamura |
ISPEC | 2 |
| 2018 | Special Issue on Advanced Persistent Threat
Jiageng Chen, Chunhua Su, Kuo-Hui Yeh, Moti Yung |
Future Gener. Comput. Syst. | 3 |
| 2018 | A robust NFC-based personalized IPTV service system
Kuo-Hui Yeh, Nai-Wei Lo, Chun-Kai Wang |
Multim. Tools Appl. | 1 |
| 2015 | A lightweight authentication scheme with user untraceabilityabstractWith the rapid growth of electronic commerce and associated demands on variants of Internet based applications, application systems providing network resources and business services are in high demand around the world. To guarantee robust security and computational efficiency for service retrieval, a variety of authentication schemes have been proposed. However, most of these schemes have been found to be lacking when subject to a formal security analysis. Recently, Chang et al. (2014) introduced a formally provable secure authentication protocol with the property of user-untraceability. Unfortunately, based on our analysis, the proposed scheme fails to provide the property of user-untraceability as claimed, and is insecure against user impersonation attack, server counterfeit attack, and man-in-the-middle attack. In this paper, we demonstrate the details of these malicious attacks. A security enhanced authentication scheme is proposed to eliminate all identified weaknesses. Kuo-Hui Yeh |
Frontiers Inf. Technol. Electron. Eng. | 1 |
| 2015 | An efficient certificateless signature scheme without bilinear pairings
Kuo-Hui Yeh, Kuo-Yu Tsai, Chuan-Yen Fan |
Multim. Tools Appl. | 1 |
| 2013 | Efficient and secure three-party authenticated key exchange protocol for mobile environmentsabstractYang and Chang (2009) proposed a three-party authenticated key exchange protocol for securing communications in mobile-commerce environments. Their protocol reduces computation and communication costs by employing elliptic curve cryptosystems. However, Tan (2010) pointed out that Yang and Chang (2009)’s protocol cannot withstand impersonation and parallel attacks, and further proposed an enhanced protocol to resist these attacks. This paper demonstrates that Tan (2010)’s approach still suffers from impersonation attacks, and presents an efficient and secure three-party authenticated key exchange protocol to overcome shown weaknesses. Chih-ho Chou, Kuo-Yu Tsai, Tzong-Chen Wu, Kuo-Hui Yeh |
J. Zhejiang Univ. Sci. C | 4 |
| 2013 | Analysis and design of a smart card based authentication protocolabstractNumerous smart card based authentication protocols have been proposed to provide strong system security and robust individual privacy for communication between parties these days. Nevertheless, most of them do not provide formal analysis proof, and the security robustness is doubtful. Chang and Cheng (2011) proposed an efficient remote authentication protocol with smart cards and claimed that their proposed protocol could support secure communication in a multi-server environment. Unfortunately, there are opportunities for security enhancement in current schemes. In this paper, we identify the major weakness, i.e., session key disclosure, of a recently published protocol. We consequently propose a novel authentication scheme for a multi-server environment and give formal analysis proofs for security guarantees. Kuo-Hui Yeh, Kuo-Yu Tsai, Jia-Li Hou |
J. Zhejiang Univ. Sci. C | 1 |
| 2010 | De-synchronization attack on RFID authentication protocolsabstractIn order to protect privacy of RFID tag against malicious tag tracing activities, many RFID authentication protocols with the secret key update scheme have been proposed to support forward security. These proposals are symmetric key based in common due to the lack of computational resource to perform heavy asymmetric cryptographic operations in low-cost tags. In this paper, we have demonstrated that four RFID authentication protocols are vulnerable to a de-synchronization attack. The secret values shared between any given tag and the backend server can easily be de-synchronized through a series of attack process (or incomplete protocol runs). Our results indicate that these four schemes are naturally limited by their essential design and more rigorous security analyses are accordingly required. In addition, any extension from these four protocols may incur the insecurity owing to the same underlying protocol design. Nai-Wei Lo, Kuo-Hui Yeh |
ISITA | 2 |
| 2010 | Two robust remote user authentication protocols using smart cards
Kuo-Hui Yeh, Chunhua Su, Nai-Wei Lo, Yingjiu Li, Yi-Xiang Hung |
J. Syst. Softw. | 1 |
| 2009 | Improvement of an EPC Gen2 Compliant RFID Authentication ProtocolabstractRecently, lightweight RFID authentication protocol has been investigated extensively due to the awareness of practical requirements on individual privacy, robust system security and resource limitation of low-cost tags. Research studies have demonstrated major advancements in the direction of designing a secure access control mechanism for RFID system with resource-constrained tags. In 2008, Burmester and Medeiros developed an EPC Class 1 Generation 2 (EPC Gen2) compliant authentication protocol, called TRAP-3, to support tag anonymity, data confidentiality and forward security in which only primitive computation functions such as 32-bit pseudo random generator and simple exclusive-or operation are required. Nevertheless, TRAP-3 is vulnerable to desynchronization attack. The secret key value, which is shared between the tag and the backend database, can be out of synchronization by just performing a series of challenge-response operations. To remedy this authentication flaw, in this study we develop a countermeasure mechanism and accordingly gain security enhancement for TRAP-3. Kuo-Hui Yeh, Nai-Wei Lo |
IAS | 1 |
| 2008 | New mutual agreement protocol to secure mobile RFID-enabled devices
Nai-Wei Lo, Kuo-Hui Yeh, Chan Yeob Yeun |
Inf. Secur. Tech. Rep. | 2 |