Lei Zhang 0009

dblp:64/5666-9 · DBLP profile ↗
← Back
68ranked-venue papers
29as first author
23since 2021 · last 2026
0000-0001-8786-4562ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 29 · 11 first-author · 10 since 2021Computer networks · 13 · 6 first-author · 5 since 2021Databases, data management, data science and information retrieval · 9 · 5 first-authorSystems, architecture and hardware · 8 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Verifiable Private Federated Learning Achieving Low-Communication With CUR Decomposition
abstract
Federated learning (FL) allows multiple clients to collaboratively train a shared machine learning model without sharing local data. Despite its advantages, FL faces serious security and privacy threats. Many existing solutions rely on cryptographic methods to protect data and ensure verifiability, but these approaches often enlarge the model or impose high communication costs. They also overlook FL's limited uplink and downlink bandwidth and rarely account for practical issues such as client dropouts. To address these gaps, we propose LC-VPFL, a federated learning framework that ensures data privacy, verifiability, low communication overhead, and dropout tolerance. Our approach leverages secret sharing and masking to protect data privacy, while homomorphic hashing detects malicious server behavior. To minimize communication costs, we apply quantization and CUR matrix decomposition, optimizing both uplink and downlink transmissions. We formally prove the security of LC-VPFL and provide a theoretical analysis demonstrating that, for a corruption threshold of$t$, the communication complexity of partial clients remains$O(t)$and tolerates arbitrary client dropouts. Experimental results show that LC-VPFL reduces uplink communication costs by over 50% in most scenarios and downlink communication costs to less than 12.5% of those in FedAvg, with an accuracy loss within 3%.
Changti Wu, Lulu Wang 0015, Lei Zhang 0009
IEEE Trans. Dependable Secur. Comput.3
2026 An Insider Attack Resistant Threshold Anonymous Traffic Violation Reporting Scheme for Fog-Assisted VANETs
abstract
Traffic violation reporting schemes for fog-assisted vehicular ad hoc networks are generally designed to support traffic management centers (TMCs) in detecting traffic violations so that appropriate actions can be taken against the involved vehicle owners. However, there are ongoing challenges such as ensuring accuracy or accountability with minimal privacy dis closure (e.g., accurate and reliable detection of traffic violations without disclosing the contents of the incident, achieving identity authentication while protecting the privacy of reporters), and how to guarantee the reports are correctly processed complicate the design of such schemes. To address these challenges, we propose a threshold anonymous traffic violation reporting (TATVR) scheme under the assumptions that the fog nodes (i.e., roadside units) and the TMC are semi-trusted, and the number of colluding vehicles is limited. We then extend the TATVR scheme (i.e., extended TATVR or E-TATVR) that does not rely on these assumptions. We explain how TMC can process the received reports more efficiently using the proposed E-TATVR scheme. We also evaluate the security of both proposed schemes and demonstrate that they simultaneously support (strong) confidentiality, non-frameability, conditional unlinkability, unforgeability, and conditional anonymity. In particular, we show that both schemes guarantee strong confidentiality, and the E-TATVR scheme additionally supports report traceability.
Yafang Yang, Lei Zhang 0009, Yunlei Zhao, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.2
2025 Dual-Server Privacy-Preserving Collaborative Deep Learning: A Round-Efficient, Dynamic and Lossless Approach
abstract
To address limitations in existing privacy-preserving collaborative deep learning (CDL) schemes, we propose a dual-server privacy-preserving CDL scheme based on homomorphic encryption and amasking technique. Specifically, in our scheme a random seed is used to initialize a pseudorandom generator that produces multiple pseudorandom numbers. These pseudorandom numbers, along with a random noise, are utilized to generate masks that are added to all parameters of a participant's locally trained model. By using homomorphic encryption, the random noise can be encrypted and eventually used to remove the masks with low message expansion. This also ensures that the global model is lossless in accuracy. Furthermore, if participants join or leave the system, only the time required to complete both model update aggregation and encrypted masks aggregation is affected. We demonstrate that our scheme is round-efficient, dynamic and lossless. We also show that it is secure against inference attacks and can resist collusion attacks of up to$t-2$participants and one of the two servers, where$t$is a security parameter indicating the minimum number of participants that participate in an aggregation round.
Lulu Wang 0015, Lei Zhang 0009, Kim-Kwang Raymond Choo, Josep Domingo-Ferrer, Mauro Conti
IEEE Trans. Dependable Secur. Comput.2
2025 Certificateless Signature Scheme With Batch Verification for Secure and Privacy-Preserving V2V Communications in VANETs
abstract
The importance of designing efficient and secure vehicular ad hoc networks (VANETs), for example to address pressing traffic-related challenges in busy cities, is crucial but challenging. For example, existing approaches may suffer from vehicle-to-vehicle (V2V) communication-related limitations such as certificate management, key escrow, and performance. Seeking to contribute to the knowledge gap, we propose a new secure and privacy-preserving scheme for V2V communications. Our proposal is based on a new provably secure certificateless signature scheme with batch verification, which eliminates the need for certificates while ensuring better efficiency. Our performance and security evaluations demonstrate that the proposed approach overcomes our previously discussed limitations while achieving both message authentication and conditional privacy. In addition, we also shown that it incurs low overhead.
Lei Zhang 0009, Yafang Yang, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.2
2025 PriVeriFL: Privacy-Preserving and Aggregation-Verifiable Federated Learning
abstract
Federated learning provides a collaborative way to build machine learning models without sharing private data. However, attackers might infer private information from model updates submitted by participants, and the aggregator might maliciously forge the final aggregation results. Federated learning still faces data privacy and aggregation integrity challenges. In this paper, we combine inference attacks and information theory to analyze the sensitivity of different bits of model parameters. We conclude that not all bits of model parameters will leak privacy. This realization inspires us to propose a novel low-expansion homomorphic aggregation scheme based on Paillier homomorphic encryption (PHE) for safeguarding participants’ data privacy. Building upon this, we develop PriVeriFL-A, a privacy-preserving and aggregation-verifiable federated learning scheme that combines homomorphic hash function and signature. To prevent collusion attacks between the aggregator and malicious participants, we further improve our PHE-based scheme into a threshold PHE-based one, named PriVeriFL-B. Compared with the privacy-preserving federated learning scheme based on classic PHE, PriVeriFL-A reduces the communication overhead to 1.65%, and the encryption/decryption computation overhead to 0.88%. Both PriVeriFL-A and PriVeriFL-B can effectively verify the integrity of the global model, while maintaining an almost negligible communication overhead for integrity verification and protecting the privacy of participants’ data.
Lulu Wang 0015, Mirko Polato, Alessandro Brighente, Mauro Conti, Lei Zhang 0009, Lin Xu 0010
IEEE Trans. Serv. Comput.5
2024 Privacy-Preserving Serverless Federated Learning Scheme for Internet of Things
abstract
Federated learning (FL) when deployed in an Internet of Things (IoT) ecosystem can facilitate the collaborative training of a global model involving different IoT local systems. However, there are a number of challenges in such deployments, and examples include single point of failure / attack, lack of fault tolerance, vulnerability to collusion attacks and accuracy loss. Therefore, we propose a privacy-preserving serverless FL scheme for IoT based on secure multi-party computation. Specifically, in our scheme, no central sever is required to coordinate the generation of global models. In doing so, we avoid the single point of failure / attack limitation. We also mitigate the fault tolerance limitation by using secret sharing. Finally, we provide a formal security proof that demonstrates the resilience of our scheme against collusion attacks, thereby establishing its effectiveness in achieving robust data privacy. Simulations are also implemented to show that our scheme does not suffer from accuracy loss.
Changti Wu, Lei Zhang 0009, Lin Xu 0010, Kim-Kwang Raymond Choo, Liangyu Zhong
IEEE Internet Things J.2
2024 Message Linkable Group Signature With Information Binding and Efficient Revocation for Privacy- Preserving Announcement in VANETs
abstract
In vehicular ad hoc networks (VANETs), the broadcasting of fake announcement messages by malicious vehicles can potentially misguide nearby vehicles. Ensuring the trustworthiness of announcement messages while preserving the privacy of vehicles is a significant challenge in the design of an announcement scheme for VANETs. To address this challenge, we propose a privacy-preserving announcement scheme with strong trustworthiness based on a new security tool called message linkable group signature with information binding and efficient revocation. Compared with the existing privacy-preserving announcement schemes, our proposed scheme not only achieves the traditional trustworthiness requirement of an announcement message but also provides strong trustworthiness, which makes it resistant to sybil and collusive attacks. To the best of our knowledge, our scheme realizes strong trustworthiness for the first time. Simulations were also performed to show the practicability of the scheme.
Lei Zhang 0009, Jiangtao Li 0003, Yafang Yang
IEEE Trans. Dependable Secur. Comput.1
2024 Rebuttal to "On the Unforgeability of 'Privacy-Preserving Aggregation-Authentication Scheme for Safety Warning System in Fog-Cloud Based VANET"'
abstract
Lin recently claimed that the privacy-preserving aggregation authentication scheme (PPAAS) based on a certificateless aggregation signcryption scheme (CASS) proposed in our paper (IEEE Transactions on Information Forensics and Security, vol.17, pp.317-331, Jan.2022) suffers from a forgery attack from type II adversary. In this paper, we show that this attack is not valid since the adversary outputs a trivial forged ciphertext. Specifically, the adversary has the master secret key and randomly selects the secret values of all users.
Yafang Yang, Lei Zhang 0009, Yunlei Zhao, Kim-Kwang Raymond Choo, Yan Zhang 0103
IEEE Trans. Inf. Forensics Secur.2
2024 Secure Channel Establishment Scheme for Task Delivery in Vehicular Cloud Computing
abstract
Vehicular cloud computing (VCC) is a network architecture that allows a group of entities (i.e., vehicles/roadside infrastructures) to share their resources with other entities. Task delivery in VCC involves the delegation of computation/storage task from a cloud user to some or all the cloud members within a vehicular cloud (VC) for processing. This process inevitably raises concerns regarding how to protect the confidentiality of the task content and the privacy of vehicles. To tackle these challenges, the establishment of a secure channel for task delivery becomes essential. However, the existing secure channel establishment schemes for task delivery in VCC suffer from a few problems including the reliance on a trusted dealer, sender restriction, recipient un-flexibility, or the ignorance of recipient privacy. In this paper, we propose a novel secure channel establishment scheme for task delivery in VCC. It allows a group of entities close to each other to form a VC dynamically without a trusted dealer and allows any entity to be a cloud user who can flexibly select favorable cloud members within a VC to handle its task. The secure channel established by our scheme not only protects the confidentiality of the content of the task but also the privacy of vehicles. Formal security analysis and simulation validate the security and efficiency of our scheme.
Lei Zhang 0009, Jianying Zhou 0001
IEEE Trans. Inf. Forensics Secur.2
2024 Dual-Server-Based Lightweight Privacy-Preserving Federated Learning
abstract
Federated learning (FL) allows multiple users to collaboratively train global machine learning models by keeping their data sets local. However, the existing privacy-preserving FL schemes suffer from several limitations, e.g., loss of accuracy, high communication/computation cost, failure to support dynamic users, and insecurity against collusion attacks. To solve these limitations, we propose a lightweight privacy-preserving FL scheme based on a dual-server architecture. Our scheme involves only lightweight cryptographic operations, i.e., hash and symmetric encryption operations, and it has low communication overhead. Thus, it is computationally lightweight and round-efficient. Further, it allows users to join/quit an FL task and it is accuracy-lossless. We formally prove that our scheme remains secure even in case of collusion attacks. In particular, if an attacker colludes with one of the servers and all the users who participate in an FL task except two, the privacy of user gradients stays unviolated. The reported experimental results demonstrate that our scheme incurs only a marginal increase in total communication overhead compared to the FL scheme without any privacy protection. In terms of computation overhead, the cost per user remains stable as the number of users grows, while the cost for the server is comparable to that of the FL scheme without any privacy protection.
Liangyu Zhong, Lulu Wang 0015, Lei Zhang 0009, Josep Domingo-Ferrer, Lin Xu 0010, Changti Wu
IEEE Trans. Netw. Serv. Manag.3
2023 Practical privacy-preserving mixing protocol for Bitcoin
abstract
The privacy of Cryptocurrencies are of great concern in various fields. Researches has shown that pseudonyms, which are used in Bitcoin, only provide weak privacy. The privacy of users may be put at risk under deanonymization attacks. The exisiting schemes typically require a trusted-third party to achieve anonymity, however this usually faces a single-point fault. In addition, existing schemes suffer from high communication complexity and impracticality. This paper proposes a practical privacy-preserving mixing protocol for Bitcoin to achieve unlink-ability of input and output address of transactions. Compared to existing schemes, our protocol improves practicality. The communication complexity of our protocol is linearly related to the number of peers. Moreover, our protocol is scalable as it works not only for Bitcoin, but also for other cryptocurrencies.
Qianqian Chang, Lin Xu 0010, Lei Zhang 0009
CSCWD3
2023 Dynamic Authenticated Asymmetric Group Key Agreement With Sender Non-Repudiation and Privacy for Group-Oriented Applications
abstract
Group-oriented applications generally support communications for multiple entities (e.g., users and/or devices) through open networks. Typical requirements of group communications include secrecy, authentication, sender non-repudiation, and sender privacy. However, conventional approaches such as group key agreement and broadcast encryption are generally not designed to achieve all these requirements simultaneously or efficiently. In this article, we propose a one-round dynamic authenticated asymmetric group key agreement with sender non-repudiation and privacy (DAAGKAwSNP) protocol. A key building block of our DAAGKAwSNP protocol is our proposed batch multi-signature scheme with strong unforgeability. We prove that the DAAGKAwSNP protocol achieves secrecy under chosen ciphertext attacks – CCA, assuming the intractability of the computational Diffie-Hellman and k-Bilinear Diffie-Hellman exponent problem. We also evaluate DAAGKAwSNP’s performance to demonstrate its utility.
Lei Zhang 0009, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.2
2023 Identity-Based Key Management Scheme for Secure Discussion Group Establishment in DOSNs
abstract
Distributed online social network (DOSN) solves the challenges of single-point failure and user data privacy faced by traditional online social network (OSN). Online discussion group, allowing a user to facilitate the communications with other users, is one of the most important components of (D)OSN. Key management is the key technology to ensure the secure establishment of discussion groups in DOSNs. However, the existing key management schemes for secure discussion group establishment in DOSNs cannot meet the requirements of sender non-restriction, receiver controllability, round optimal, certificate freeness simultaneously. In this paper, we propose a novel key management scheme for secure discussion group establishment in DOSNs. In our scheme, any user could use our key management scheme to initialize a discussion group with a piece of discussion group information. Users who are interested in the group topic contained in the discussion group information can join and leave the discussion group at any time once the discussion group is initialized with one-round communication. Any user/sender can find the users that he/she wants to communicate with by looking up the discussion group information of a discussion group and then send encrypted messages to some or all of the users in the discussion group. Therefore, our scheme achieves sender non-restriction, receiver controllability, round optimal, certificate freeness simultaneously. Security analysis also shows that our scheme achieves confidentiality, authentication, full collusion resistance, known-key security and perfect forward security.
Lei Zhang 0009, Wendie Han, Lulu Wang 0015
IEEE Trans. Inf. Forensics Secur.1
2023 Privacy-Preserving and Reliable Decentralized Federated Learning
abstract
Conventional federated learning (FL) approaches generally rely on a centralized server, and there has been a trend of designing asynchronous FL approaches for distributed applications partly to mitigate limitations associated with conventional (synchronous) FL approaches (e.g., single point of failure / attack). In this paper, we first introduce two new tools, namely: a quality-based aggregation method and an extended dynamic contribution broadcast encryption (DConBE). Building on these two new tools and local differential privacy, we then propose a privacy-preserving and reliable decentralized FL scheme, designed to support batch joining/leaving of clients while incurring minimal delay and achieving high model accuracy. In other words, our scheme seeks to ensure an optimal trade-off between model accuracy and data privacy, which is also demonstrated in our simulation results. For example, the results show that our aggregation method can effectively avoid low-quality updates in the sense that the scheme guarantees high model accuracy even in the presence of bad clients who may submit low-quality updates. In addition, our scheme incurs a lower loss and the extended DConBE only slightly affects the efficiency of our scheme. With the extended dynamic contribution broadcast encryption, our scheme can efficiently support batch joining/leaving of clients.
Lei Zhang 0009, Lulu Wang 0015, Kim-Kwang Raymond Choo
IEEE Trans. Serv. Comput.2
2022 CRFs for Digital Signature and NIZK Proof System in Web Services
Burong Kang, Lei Zhang 0009, Yafang Yang
ICA3PP2
2022 A Secure and Receiver-Unrestricted Group Key Management Scheme for Mobile Ad-hoc Networks
abstract
Mobile Ad-hoc Networks (MANETs) have attracted lots of concerns with its widespread use. In MANETs, wireless nodes usually self-organize into groups to complete collaborative tasks and communicate with one another via public channels which are vulnerable to attacks. Group key management is generally employed to guarantee secure group communication in MANETs. However, most existing group key management schemes for MANETs still suffer from some issues, e.g., receiver restriction, relying on a trusted dealer and heavy certificates overheads. To address these issues, we propose a group key management scheme for MANETs based on an identity-based authenticated dynamic contributory broadcast encryption (IBADConBE) protocol which builds on an earlier work. Our scheme abandons the certificate management and does not need a trusted dealer to distribute a secret key to each node. A set of wireless nodes are allowed to negotiate the secret keys in one round while forming a group. Besides, our scheme is receiver-unrestricted which means any sender can flexibly opt for any favorable nodes of a group as the receivers. Further, our scheme satisfies the authentication, confidentiality of messages, known-security, forward security and backward security concurrently. Performance evaluation shows our scheme is efficient.
Wendie Han, Lei Zhang 0009, Lulu Wang 0015
WCNC3
2022 Fast Secure and Anonymous Key Agreement Against Bad Randomness for Cloud Computing
abstract
In cloud computing, resources are usually in cloud service provider’s network and typically accessed remotely by the cloud users via public channels. Key agreement enables secure channel establishment over a public channel for the secure communications between a cloud user and a cloud service provider. Existing key agreement protocols for cloud computing suffer from some challenges, e.g., realizing low connection delay, eliminating certificate management problem, enhancing user privacy and avoiding bad randomness. To tackle these challenges, we propose a certificateless 0-RTT anonymous AKA protocol against bad randomness for secure channel establishment in cloud computing. As a 0-RTT protocol, it significantly speeds up the efficiency of the secure channel establishment process. Further, our protocol does not need for the certificates to bind a public key with an entity’s identity and hence solves the certificate management problem. Finally, concrete security analysis of the protocol is also proposed. The protocol not only satisfies the traditional security attributes (e.g., known-key security, unknown key-share), but also strong security guarantees, i.e., user privacy and bad randomness resistance.
Lei Zhang 0009, Burong Kang
IEEE Trans. Cloud Comput.2
2022 Privacy-Preserving Aggregation-Authentication Scheme for Safety Warning System in Fog-Cloud Based VANET
abstract
As cities become smarter, the importance of vehicular ad hoc networks (VANETs) will be increasingly pronounced. To support latency- and time-sensitive applications, there have been attempts to utilize fog-cloud computing in VANETs. There are, however, a number of limitations in existing fog-cloud based VANET deployments, ranging from computation and communication bottlenecks to privacy leakage to costly certificate/ pseudonym management to key escrow, and so on. Therefore, in this paper we propose a privacy-preserving aggregation authentication scheme (PPAAS). The scheme is designed for deployment in a safety warning system for fog-cloud based VANETs. Specifically, the PPAAS scheme is realized using a novel efficient anonymous certificateless aggregation signcryption scheme (CASS) proposed in this paper, and allows a fog node to aggregate signcrypted traffic-related messages from surrounding vehicles into an aggregated ciphertext and unsigncrypt them in a batch. We then evaluate the security of PPAAS and demonstrate that it supports confidentiality, authentication, and (efficient) conditional privacy, and key escrow freeness. In particular, our scheme is the first in the literature to achieve efficient conditional privacy, which avoids the need for costly pseudonym management. We also demonstrate that the scheme is practical, based on our simulation results.
Yafang Yang, Lei Zhang 0009, Yunlei Zhao, Kim-Kwang Raymond Choo, Yan Zhang 0103
IEEE Trans. Inf. Forensics Secur.2
2022 Cryptographic Solutions for Cloud Storage: Challenges and Research Opportunities
abstract
While cloud computing is relatively mature and its potential benefits well understood by individual, industry and government consumers, a number of security and privacy concerns remain. Unsurprisingly, designing cryptographic solutions to ensure the security of cloud services and the privacy of data outsourced to the cloud remains an ongoing research area. This paper provides a critique of the wide range of cryptographic schemes designed for securing sensitive data in the cloud computing environment, as well as outlining the research opportunities in the use of cryptographic techniques in cloud computing.
Lei Zhang 0009, Hu Xiong, Qiong Huang 0001, Jiguo Li 0001, Kim-Kwang Raymond Choo, Jiangtao Li 0003
IEEE Trans. Serv. Comput.1
2021 Privacy-Preserving and Reliable Federated Learning
Lei Zhang 0009, Lulu Wang 0015
ICA3PP (3)2
2021 Secure and Reliable Parking Protocol Based on Blockchain for VANETs
abstract
With the development of vehicular ad hoc network (VANET) technology, more and more smart parking systems in VANETs are presented. However, existing solutions suffer from the challenges of dishonest parking lots that may claim there are more empty spots than they actually have, malicious occupation of parking spots and multi-reservation attack, etc. To address these challenges, we propose a secure and reliable smart parking protocol based on blockchain and linkable group signatures. For the security of our scheme, it not only realizes traditional authentication, privacy preservation and message confidentiality requirements but also prevents multi-reservation attack and the dishonest parking lots that claim more empty spots than they actually have.
Yan Zhang 0103, Lei Zhang 0009, Burong Kang
WCNC2
2021 Blockchain-Based Key Management Scheme in Fog-Enabled IoT Systems
abstract
There are a number of benefits associated with the deployment of fog computing, for example, by analyzing and computing data from Internet-of-Things (IoT) devices at the fog nodes reduce the bandwidth, computational, and storage overheads at the cloud servers and improve user quality of experience (e.g., due to reduced latency). However, there are also additional security implications and requirements. For example, secure keys are needed to establish secure channels among these distributed fog nodes. Therefore, to facilitate fog nodes in managing secure keys and establishing secure group channels, we present a novel fog system and propose a blockchain-based group key management scheme that builds on an earlier work. We also design a new resource authentication mechanism based on Proof of Work (PoW), and when deployed in our fog system facilitates resource authentication (i.e., a fog node in a fog system can evaluate the capability of a fog device’s computing power before the device is permitted to enter the system). Findings from our simulations and secure analysis demonstrate the utility of our system.
Lei Zhang 0009, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2021 Key Management Scheme for Secure Channel Establishment in Fog Computing
abstract
Fog computing is a promising extension of cloud computing, and enables computing directly at the edge of the network. Due to the decentralized and distributed nature of fog nodes, secure communication channels have to be supported in fog computing, which are generally realized through secure keys. Key management schemes are usually employed to generate, distribute and maintain the secret keys. In this paper, we propose a key management scheme called dynamic contributory broadcast encryption (DConBE) for secure channel establishment in fog computing. It allows a group of fog nodes that want to establish a fog system to negotiate a public encryption key and each node’s decryption key in one round without a trusted dealer. Any end user may encrypt messages under the public encryption key with short ciphertexts to any subset of the fog nodes in the system. Only selected fog nodes in the system can decrypt the encrypted messages using their respective decryption key. Our new key management scheme also achieves the properties of fog node dynamics, fully collusion-resistant and stateless.
Lei Zhang 0009
IEEE Trans. Cloud Comput.1
2020 Key-Free Authentication Protocol Against Subverted Indoor Smart Devices for Smart Home
abstract
Smart homes are an increasingly common concept, particularly in technologically advanced countries. In these settings, the smart devices [also commonly referred to as the Internet of Things (IoT) devices] typically communicate via the radio frequency (RF) channel. In such an open communication channel, key establishment protocols are used to generate a session key between the command senders and the command receivers. The commands or messages are then encrypted using the session key. However, not all the smart home devices have sufficient computational capability to generate and store session keys. Therefore, in this article, we construct a communication protocol using the home limited channel (HLC). The protocol constructed in this article takes into account the existence of malicious indoor smart devices and the need to defend against such malicious indoor smart devices.
Lei Zhang 0009, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2020 Privacy-Preserving Cloud Establishment and Data Dissemination Scheme for Vehicular Cloud
abstract
Vehicular cloud (VC) extends cloud computing to vehicles participating in vehicular ad hoc networks, aiming to provide computing and storage services at low cost to vehicles, improve traffic efficiency and safety, ensure real-time services, etc. Due to the highly dynamic nature of VC, it is challenging to efficiently form a dynamic VC securely and anonymously or to securely deliver messages to the dynamic VC without potentially violating the privacy of cloud users. In this paper, we present a concrete secure and privacy-preserving communication scheme for VC establishment and data dissemination. Our scheme allows a group of vehicles that are geographically close to each other to form a VC securely, anonymously and dynamically. This allows vehicle resources to be integrated and shared securely. Once a VC is formed, any cloud user may deliver messages to be securely and anonymously processed in the VC.
Lei Zhang 0009, Kim-Kwang Raymond Choo, Yuanfei Zhang, Feifei Dai
IEEE Trans. Dependable Secur. Comput.1
2019 Group Signatures with Decentralized Tracing
Jiangtao Li 0003, Lei Zhang 0009, Kwok-Yan Lam
Inscrypt3
2018 Secure intelligent traffic light control using fog computing
Jian Liu 0007, Jiangtao Li 0003, Lei Zhang 0009, Feifei Dai, Yuanfei Zhang, Jian Shen 0001
Future Gener. Comput. Syst.3
2017 Sender dynamic, non-repudiable, privacy-preserving and strong secure group communication protocol
Jiangtao Li 0003, Lei Zhang 0009
Inf. Sci.2
2017 OTIBAAGKA: A New Security Tool for Cryptographic Mix-Zone Establishment in Vehicular Ad Hoc Networks
abstract
Location privacy is one of the major challenges in vehicular ad hoc networks. Due to the open and broadcast nature of wireless communication, the safety messages of vehicles can be easily collected by malicious eavesdroppers to continuously track vehicles. Cryptographic mix-zone (CMIX) is a promising tool to enhance vehicle privacy, in which the safety messages of vehicles are encrypted using a group secret key. In that way, any outsider cannot monitor the safety messages broadcasted by the vehicles in the CMIX. Existing CMIX protocols need fully trusted dealers to distribute group secret keys and/or suffer from the problem of efficient key update. This paper proposes a novel method based on a new security tool referred to as one-time identity-based authenticated asymmetric group key agreement to create CMIXes which withstand malicious eavesdroppers. Different from the existing solutions, our proposal does not rely on the existence of fully trusted dealers and deals with efficient key update in CMIX for the first time. In our protocol, any vehicle in a CMIX could be a group secret key distributer. Furthermore, once the group secret key of the CMIX has to be updated, a vehicle in the CMIX just needs to broadcast a short ciphertext, then all the vehicles in the CMIX may refresh the group secret key to the new one efficiently.
Lei Zhang 0009
IEEE Trans. Inf. Forensics Secur.1
2017 Distributed Aggregate Privacy-Preserving Authentication in VANETs
abstract
Existing secure and privacy-preserving vehicular communication protocols in vehicular ad hoc networks face the challenges of being fast and not depending on ideal tamper-proof devices (TPDs) embedded in vehicles. To address these challenges, we propose a vehicular authentication protocol referred to as distributedaggregate privacy-preserving authentication. The proposed protocol is based on our new multiple trusted authority one-time identity-based aggregate signature technique. With this technique a vehicle can verify many messages simultaneously and their signatures can be compressed into a single one that greatly reduces the storage space needed by a vehicle or a data collector (e.g., the traffic management authority). Instead of ideal TPDs, our protocol only requires realistic TPDs and hence is more practical.
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer, Chuanyan Hu
IEEE Trans. Intell. Transp. Syst.1
2016 Cloud Cryptography: Theory, Practice and Future Research Directions
Kim-Kwang Raymond Choo, Josep Domingo-Ferrer, Lei Zhang 0009
Future Gener. Comput. Syst.3
2016 Contributory Broadcast Encryption with Efficient Encryption and Short Ciphertexts
abstract
Broadcast encryption (BE) schemes allow a sender to securely broadcast to any subset of members but require a trusted party to distribute decryption keys. Group key agreement (GKA) protocols enable a group of members to negotiate a common encryption key via open networks so that only the group members can decrypt the ciphertexts encrypted under the shared encryption key, but a sender cannot exclude any particular member from decrypting the ciphertexts. In this paper, we bridge these two notions with a hybrid primitive referred to as contributory broadcast encryption (ConBE). In this new primitive, a group of members negotiate a common public encryption key while each member holds a decryption key. A sender seeing the public group encryption key can limit the decryption to a subset of members of his choice. Following this model, we propose a ConBE scheme with short ciphertexts. The scheme is proven to be fully collusion-resistant under the decision n-Bilinear Diffie-Hellman Exponentiation (BDHE) assumption in the standard model. Of independent interest, we present a new BE scheme that is aggregatable. The aggregatability property is shown to be useful to construct advanced protocols.
Qianhong Wu, Lei Zhang 0009, Josep Domingo-Ferrer, Oriol Farràs, Jesús A. Manjón
IEEE Trans. Computers3
2016 Privacy-Preserving Vehicular Communication Authentication with Hierarchical Aggregation and Fast Response
abstract
Existing secure and privacy-preserving schemes for vehicular communications in vehicular ad hoc networks face some challenges, e.g., reducing the dependence on ideal tamper-proof devices, building efficient member revocation mechanisms and avoiding computation and communication bottlenecks. To cope with those challenges, we propose a highly efficient secure and privacy-preserving scheme based on identity-based aggregate signatures. Our scheme enables hierarchical aggregation and batch verification. The individual identity-based signatures generated by different vehicles can be aggregated and verified in a batch. The aggregated signatures can be re-aggregated by a message collector (e.g., traffic management authority). With our hierarchical aggregation technique, we significantly reduce the transmission/storage overhead of the vehicles and other parties. Furthermore, existing batch verification based schemes in vehicular ad hoc networks require vehicles to wait for enough messages to perform a batch verification. In contrast, we assume that vehicles will generate messages (and the corresponding signatures) in certain time spans, so that vehicles only need to wait for a very short period before they can start the batch verification procedure. Simulation shows that a vehicle can verify the received messages with very low latency and fast response.
Lei Zhang 0009, Chuanyan Hu, Qianhong Wu, Josep Domingo-Ferrer
IEEE Trans. Computers1
2016 Privacy-Preserving Public Auditing Protocol for Low-Performance End Devices in Cloud
abstract
Cloud storage provides tremendous storage resources for both individual and enterprise users. In a cloud storage system, the data owned by a user are no longer possessed locally. Hence, it is not competent to ensure the integrity of the outsourced data using traditional data integrity checking methods. A privacy-preserving public auditing protocol allows a third party auditor to check the integrity of the outsourced data on behalf of the users without violating the privacy of the data. However, existing privacy-preserving public auditing protocols assume that the end devices of users are powerful enough to compute all costly operations in real time when the data to be outsourced are given. In fact, the end devices may also be those with low computation capabilities. In this paper, we propose two lightweight privacy-preserving public auditing protocols. Our protocols are based on online/offline signatures, by which an end device only needs to perform lightweight computations when a file to be outsourced is available. Besides, our proposals support batch auditing and data dynamics. Experiments show that our protocols are hundreds of times more efficient than a recent proposal regarding to the computational overhead on user side.
Jiangtao Li 0003, Lei Zhang 0009, Joseph K. Liu, Haifeng Qian, Zheming Dong
IEEE Trans. Inf. Forensics Secur.2
2015 Non-interactive Revocable Identity-Based Access Control over e-Healthcare Records
Yunya Zhou, Jianwei Liu 0001, Lei Zhang 0009
ISPEC5
2015 Practical secure and privacy-preserving scheme for value-added applications in VANETs
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer
Comput. Commun.1
2015 Certificateless one-pass and two-party authenticated key agreement protocol and its extensions
Lei Zhang 0009
Inf. Sci.1
2015 Round-Efficient and Sender-Unrestricted Dynamic Group Key Agreement Protocol for Secure Group Communications
abstract
Modern collaborative and group-oriented applications typically involve communications over open networks. Given the openness of today's networks, communications among group members must be secure and, at the same time, efficient. Group key agreement (GKA) is widely employed for secure group communications in modern collaborative and group-oriented applications. This paper studies the problem of GKA in identity-based cryptosystems with an emphasis on round-efficient, sender-unrestricted, member-dynamic, and provably secure key escrow freeness. The problem is resolved by proposing a one-round dynamic asymmetric GKA protocol which allows a group of members to dynamically establish a public group encryption key, while each member has a different secret decryption key in an identity-based cryptosystem. Knowing the group encryption key, any entity can encrypt to the group members so that only the members can decrypt. We construct this protocol with a strongly unforgeable stateful identity-based batch multisignature scheme. The proposed protocol is shown to be secure under the k -bilinear Diffie-Hellman exponent assumption.
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer, Zheming Dong
IEEE Trans. Inf. Forensics Secur.1
2014 Who Is Touching My Cloud
Qianhong Wu, Lei Zhang 0009, Wenchang Shi
ESORICS (1)6
2014 Provably Secure Certificateless Authenticated Asymmetric Group Key Agreement
Lei Zhang 0009, Qianhong Wu, Jianwei Liu 0001, Wenchang Shi
ISPEC1
2014 Ciphertext-policy hierarchical attribute-based encryption with short ciphertexts
Qianhong Wu, Josep Domingo-Ferrer, Lei Zhang 0009, Jianwei Liu 0001, Wenchang Shi
Inf. Sci.5
2014 Signatures in hierarchical certificateless cryptography: Efficient constructions and provable security
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer
Inf. Sci.1
2013 A Generic Construction of Proxy Signatures from Certificateless Signatures
abstract
The primitive of proxy signatures allows the original signer to delegate proxy signers to sign on messages on behalf of the original signer. It has found numerous applications in distributed computing scenarios where delegation of signing rights is common. Certificate less public key cryptography eliminates the complicated certificates in traditional public key cryptosystems without suffering from the key escrow problem in identity-based public key cryptography. In this paper, we reveal the relationship between the two important primitives of proxy signatures and certificate less signatures and present a generic conversion from the latter to the former. Following the generic transformation, we propose an efficient proxy signature scheme with a recent certificate less signature scheme.
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer, Jianwei Liu 0001, Ruiying Du
AINA1
2013 Secure One-to-Group Communications Escrow-Free ID-Based Asymmetric Group Key Agreement
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer, Sherman S. M. Chow, Wenchang Shi
Inscrypt1
2013 Identity-based optimistic fair exchange in the standard model
abstract
ABSTRACT A fair exchange protocol allows two entities to exchange digital signatures over open networks in a fair way, so that either each entity obtains the other's signature or neither entity does. Fair exchange protocol plays an important role in electronic commerce in the case of exchanging digital contracts. In this paper, we propose a fair exchange protocol based on identity‐based verifiably encrypted signatures. Our protocol involves an offline trusted third party which is only required when one entity attempts to cheat or crashes. The underlining identity‐based verifiably encrypted signature scheme is proven secure under the computational Diffie–Hellman assumption and is the first identity‐based verifiably encrypted signature scheme provably secure against existential unforgeable under adaptive chosen message and identity attacks in the standard model. Copyright © 2012 John Wiley & Sons, Ltd.
Lei Zhang 0009, Qianhong Wu
Secur. Commun. Networks1
2013 Fast Transmission to Remote Cooperative Groups: A New Key Management Paradigm
abstract
The problem of efficiently and securely broadcasting to a remote cooperative group occurs in many newly emerging networks. A major challenge in devising such systems is to overcome the obstacles of the potentially limited communication from the group to the sender, the unavailability of a fully trusted key generation center, and the dynamics of the sender. The existing key management paradigms cannot deal with these challenges effectively. In this paper, we circumvent these obstacles and close this gap by proposing a novel key management paradigm. The new paradigm is a hybrid of traditional broadcast encryption and group key agreement. In such a system, each member maintains a single public/secret key pair. Upon seeing the public keys of the members, a remote sender can securely broadcast to any intended subgroup chosen in an ad hoc way. Following this model, we instantiate a scheme that is proven secure in the standard model. Even if all the nonintended members collude, they cannot extract any useful information from the transmitted messages. After the public group encryption key is extracted, both the computation overhead and the communication cost are independent of the group size. Furthermore, our scheme facilitates simple yet efficient member deletion/addition and flexible rekeying strategies. Its strong security against collusion, its constant overhead, and its implementation friendliness without relying on a fully trusted authority render our protocol a very promising solution to many applications.
Qianhong Wu, Lei Zhang 0009, Josep Domingo-Ferrer, Jesús A. Manjón
IEEE/ACM Trans. Netw.3
2012 Provably secure threshold public-key encryption with adaptive security and short ciphertexts
Qianhong Wu, Lei Zhang 0009, Oriol Farràs, Josep Domingo-Ferrer
Inf. Sci.3
2012 Delegation of signing rights using certificateless proxy signatures
Lei Zhang 0009, Futai Zhang, Qianhong Wu
Inf. Sci.1
2011 Bridging Broadcast Encryption and Group Key Agreement
Qianhong Wu, Lei Zhang 0009, Josep Domingo-Ferrer, Oriol Farràs
ASIACRYPT3
2011 Preserving Security and Privacy in Large-Scale VANETs
Qianhong Wu, Josep Domingo-Ferrer, Lei Zhang 0009
ICICS4
2011 APPA: Aggregate Privacy-Preserving Authentication in Vehicular Ad Hoc Networks
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer
ISC1
2011 Fully Distributed Broadcast Encryption
Qianhong Wu, Lei Zhang 0009, Josep Domingo-Ferrer
ProvSec3
2011 Asymmetric group key agreement protocol for open networks and its application to broadcast encryption
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer, Úrsula González-Nicolás
Comput. Networks1
2011 Provably secure one-round identity-based authenticated asymmetric group key agreement protocol
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer
Inf. Sci.1
2010 Ad hoc broadcast encryption
abstract
Numerous applications in ad hoc networks, peer-to-peer networks, and on-the-fly data sharing call for confidential broadcast without relying on a dealer. To cater for such applications, we propose a new primitive referred to as ad hoc broadcast encryption (AHBE), in which each user possesses a public key and, upon seeing the public keys of the users, a sender can securely broadcast to any subset of them, so that only the intended users can decrypt. We implement a concrete AHBE scheme proven secure under the decision Bilinear Diffie-Hellman Exponentiation (BDHE) assumption. The resulting scheme has sub-linear complexity, comparable to up-to-date broadcast systems which have also sub-linear complexity but require a fully trusted dealer.
Qianhong Wu, Lei Zhang 0009, Josep Domingo-Ferrer
CCS3
2010 Identity-Based Authenticated Asymmetric Group Key Agreement Protocol
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer
COCOON1
2010 Hierarchical Certificateless Signatures
abstract
Certificateless cryptography eliminates the key escrow problem in identity-based cryptography. Hierarchical cryptography exploits a practical security model to mirror the organizational hierarchy in the real world. In this paper, to incorporate the advantages of both types of cryptosystems, we instantiate hierarchical certificate less cryptography by formalizing the notion of hierarchical certificate less signatures. Furthermore, we propose an HCLS scheme which, under the hardness of the computational Diffie-Hellman (CDH) problem, is proven to be existentially unforgeable against adaptive chosen-message attacks in the random oracle model. As to efficiency, our scheme has constant complexity, regardless of the depth of the hierarchy. Hence, the proposal is secure and scalable for practical applications.
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer
EUC1
2010 Authenticated Asymmetric Group Key Agreement Protocol and Its Application
abstract
A recent primitive known as asymmetric group key agreement allows a group of users to negotiate a common encryption key which is accessible to any entities while each user holds her respective secret decryption key. This concept not only enables confidential communications among group users but also permits any outsider to send encrypted messages to the group. The existing instantiation is only secure against passive adversaries. In this paper, we first propose an authenticated asymmetric group key agreement protocol which captures the practical security properties against active attacks. Based on our protocol, we then propose a broadcast encryption system without relying on a trusted dealer to distribute the secret keys to the users. Our system has also short ciphertexts. Furthermore, the proposal is equipped with the perfect forward security property.
Lei Zhang 0009, Qianhong Wu
ICC1
2010 Threshold Public-Key Encryption with Adaptive Security and Short Ciphertexts
Qianhong Wu, Lei Zhang 0009, Josep Domingo-Ferrer
ICICS3
2010 Secure compression of privacy-preserving witnesses in vehicular ad hoc networks
abstract
Vehicular ad hoc networks (VANETs) are designed to improve traffic safety and efficiency. To this end, the traffic communication must be authenticated to guarantee trustworthiness for guiding drivers and establishing liability in case of traffic accident investigation. Cryptographic authentication techniques have been extensively exploited to secure VANETs. Applying cryptographic authentication techniques such as digital signatures raises challenges to efficiently store signatures on messages growing with time. To alleviate the conflict between traffic liability investigation and limited storage capacity in vehicles, this paper proposes to aggregate signatures in VANETs. Our proposal can preserve privacy for honest vehicles and trace misbehaving ones, and provides a practical balance between security and privacy in VANETs. With our proposal, cryptographic witnesses of safety-related traffic messages can be significantly compressed so that they can be stored for a long period for liability investigation. Our proposal allows a large number of traffic messages to be verified as if they were a single one, which speeds up the response of vehicles to traffic reports.
Qianhong Wu, Lei Zhang 0009, Josep Domingo-Ferrer
WiMob3
2010 Efficient many-to-one authentication with certificateless aggregate signatures
Lei Zhang 0009, Qianhong Wu, Futai Zhang
Comput. Networks1
2010 Certificateless threshold signature scheme from bilinear maps
Futai Zhang, Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Lei Zhang 0009
Inf. Sci.6
2010 Simulatable certificateless two-party authenticated key agreement protocol
Lei Zhang 0009, Futai Zhang, Qianhong Wu, Josep Domingo-Ferrer
Inf. Sci.1
2009 Certificateless One-Way Authenticated Two-Party Key Agreement Protocol
abstract
Key agreement is one of the fundamental cryptographic primitives in public key cryptography. It plays an important role for securing systems in practice. In this paper, we present the first certificateless one-way authenticated two-party key agreement protocol. The security of the proposed protocol is analyzed based on the intractability of the standard discrete logarithm (DL) and bilinear Diffie-Hellman (BDH) problems. For efficiency, our protocol enjoys low complexity in both communication and computation.
Wuping Chen, Lei Zhang 0009, Qianhong Wu, Huanguo Zhang
IAS2
2009 Identity-Based Verifiably Encrypted Signatures without Random Oracles
Lei Zhang 0009, Qianhong Wu
ProvSec1
2009 A new certificateless aggregate signature scheme
Lei Zhang 0009, Futai Zhang
Comput. Commun.1
2008 A New Provably Secure Certificateless Signature Scheme
abstract
Certificateless public key cryptography was introduced by Al-Riyami and Paterson to overcome the key escrow problem of ID-PKC. In this paper, we present an efficient certificateless signature scheme using bilinear maps. The scheme can be proved secure in the strongest security model of certificateless signature schemes. In terms of computational cost, totally, only two pairing operations are required for signing and verification. It is more efficient than the other existing certificateless signature schemes secure against a super type I/II adversary.
Lei Zhang 0009, Futai Zhang
ICC1
2007 A Provably Secure Ring Signature Scheme in Certificateless Cryptography
Lei Zhang 0009, Futai Zhang, Wei Wu 0001
ProvSec1