Qiaoyan Wen

dblp:64/854 · also Qiao-Yan Wen · DBLP profile ↗
← Back
81ranked-venue papers
0as first author
20since 2021 · last 2025
0000-0001-7142-9726ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 20 · 4 since 2021Security and privacy · 16 · 1 since 2021Artificial intelligence and machine learning · 10 · 5 since 2021Computer networks · 10 · 3 since 2021Databases, data management, data science and information retrieval · 8 · 4 since 2021Software engineering, systems software and programming languages · 7 · 5 since 2021Systems, architecture and hardware · 6 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3Human-computer interaction and ubiquitous computing · 2Theory of computation · 2
YearPublicationVenuePosition
2025 Quantum-Assisted Hierarchical Fuzzy Neural Network for Image Classification
abstract
Deep learning is a powerful technique for data-driven learning in the era of Big Data. However, most deep learning models are deterministic models that ignore the uncertainty of data. Fuzzy neural networks are proposed to tackle this type of problem. In this article, we proposed a novel quantum assisted hierarchical fuzzy neural network (QA-HFNN). Different from classical fuzzy neural networks, QA-HFNN uses quantum neural networks (QNNs) to learn fuzzy membership functions. The model is a multifeature fusion learning algorithm with a parallel structural design that integrates quantum and classical neural networks. The classical network is used to capture high-dimensional neural features, the QNNs are designed to capture fuzzy logic features of the data, then, the two features are fused to form the final features to be classified. The experiment is performed on a classical computer, and the quantum circuit is built through a simulated quantum environment. The results indicate that the accuracy of QA-HFNN can equal to or even surpass classical methods in image classification tasks. The quantum circuit utilizes only a single qubit which is easy to implement. In addition, the fidelity of quantum circuit in a quantum noise environment is assessed, demonstrating that QA-HFNN has strong robustness. The time and computational complexity of QNNs was analyzed, further proving the effectiveness of the model.
Shengyao Wu, Yanqi Song, Su-Juan Qin, Qiaoyan Wen, Fei Gao 0001
IEEE Trans. Fuzzy Syst.5
2024 Understanding and Detecting Real-World Safety Issues in Rust
abstract
Rust is a relatively new programming language designed for systems software development. Its objective is to combine the safety guarantees typically associated with high-level languages with the performance efficiency often found in executable programs implemented in low-level languages. The core design of Rust is a set of strict safety rules enforced through compile-time checks. However, to support more low-level controls, Rust also allows programmers to bypass its compiler checks by writingunsafecode. As the adoption of Rust grows in the development of safety-critical software, it becomes increasingly important to understand what safety issues may elude Rust’s compiler checks and manifest in real Rust programs.In this paper, we conduct a comprehensive, empirical study of Rust safety issues by close, manual inspection of 70 memory bugs, 100 concurrency bugs, and 110 programming errors leading to unexpected execution panics from five open-source Rust projects, five widely-used Rust libraries, and two online security databases. Our study answers three important questions: what memory-safety issues real Rust programs have, what concurrency bugs Rust programmers make, and how unexpected panics in Rust programs are caused. Our study reveals interesting real-world Rust program behaviors and highlights new issues made by Rust programmers. Building upon the findings of our study, we design and implement five static detectors. After being applied to the studied Rust programs and another 12 selected Rust projects, our checkers pinpoint 96 previously unknown bugs and report a negligible number of false positives, confirming their effectiveness and the value of our empirical study.
Boqin Qin, Hua Zhang 0001, Qiaoyan Wen, Linhai Song, Yiying Zhang 0005
IEEE Trans. Software Eng.5
2023 Quantum Attacks on 1K-AES and PRINCE
abstract
Abstract By introducing the BHT algorithm into the slide attack on 1K-AES and the related-key attack on PRINCE, we present the corresponding quantum attacks in this paper. In the proposed quantum attacks, we generalize the BHT algorithm to the situation where the number of marked items is unknown ahead of time. Moreover, we give an implementation scheme of classifier oracle based on Quantum Phase Estimation algorithm in presented quantum attacks. The complexity analysis shows that the query complexity, time complexity and memory complexity of the presented quantum attacks are all $\mathcal{O}(2^{n/3})$ when the success probability is about $63\%$, where $n$ is the block size. Compared with the corresponding classical attacks, the proposed quantum attacks can achieve subquadratic speed-up under the same success probability no matter on query complexity, time complexity or memory complexity. Furthermore, the query complexity of the proposed quantum slide attack on 1K-AES is less than Grover search on 1K-AES by a factor of $2^{n/6}.$ When compared with the Grover search on PRINCE, the query complexity of the presented quantum attack on PRINCE is reduced from $\mathcal{O}(2^{n})$ to $\mathcal{O}(2^{n/2}).$ When compared with the combination of Grover and Simon’s algorithms on PRINCE, the query complexity of our quantum attack on PRINCE is reduced from $\mathcal{O}(n\cdot 2^{n/2})$ to $\mathcal{O}(2^{n/2}).$ Besides, the proposed quantum slide attack on 1K-AES indicates that the quantum slide attack could also be applied on Substitution-Permutation Network construction, apart from the iterated Even-Mansour cipher and Feistel constructions.
Binbin Cai, Su-Juan Qin, Fei Gao 0001, Qiaoyan Wen
Comput. J.6
2023 An Improved Conditional Privacy Protection Scheme Based on Ring Signcryption for VANETs
abstract
Vehicular ad hoc networks (VANETs) can effectively provide vehicle driving safety, high-speed data communication, intelligent traffic management, and vehicle entertainment. However, compared with traditional networks, VANETs are more vulnerable to attacks from adversaries, such as eavesdropping, tampering, tracking users’ privacy, etc. In order to provide security and privacy protection for VANET communication, many conditional privacy protection (CPP) authentication schemes have been reported. In 2021, Cai et al. designed a novel CPP scheme based on ring signcryption suitable for VANETs. They proved that their scheme enjoys confidentiality, unforgeability, anonymity of sender’s identity, and traceability of malicious vehicle users. But we demonstrate their scheme has some defects in construction and security. First, there is a small flaw in the ring signcryption algorithm in the scheme, which makes a legitimate receiver unable to get the original message sent by the sender from the received valid ciphertext. Second, Cai et al.’s scheme cannot provide anonymous protection of an honest sender’s identity. At the same time, it is unable to reveal the identity of a malicious vehicle user. Finally, we present an improved scheme of Cai et al.’s scheme and supply its security proofs in the random oracle model, and analyze its performance. Ours is superior to the original scheme in security and efficiency. It is very suitable for providing security and privacy protection for vehicular users in VANETs.
Hongzhen Du, Qiaoyan Wen, Mingchu Gao
IEEE Internet Things J.2
2023 Privacy Protection Data Retrieval Scheme With Inverted Index for IoT Based on Blockchain
abstract
In the 6G era, Internet of Things (IoT) devices can form a blockchain network, which also faces the problems of data sharing. The data transmitted and stored through the network have the risk of privacy leaking. Encrypting the shared data can satisfy the need of the privacy, and retrieving the encrypted data can make the data used efficiently. However, to enable users to retrieve encrypted data and perform fine-grained authorization on their encrypted files is still a great challenge. Although attribute-based keyword search (ABKS) is a well-received solution to the challenge, there are still privacy and efficiency issues if the traditional ABKS schemes are directly used in blockchain data sharing. In order to solve the problems, this article proposes privacy protection data retrieval scheme with an inverted index, which is an application of attribute-based encryption. First, our scheme is proved secure against the outside keyword guessing attack (KGA) and chosen keyword attack (CKA) under the semitrusted model. Second, the scheme returns a multikeywords ranked result. Third, we analyze the efficiency of our scheme and verify it by simulation. The results show that our scheme has improvement in efficiency and can meet the data sharing needs of the blockchain network composed of IoT devices.
Wenmin Li 0001, Yang Chen 0042, Fei Gao 0001, Shuo Zhang 0008, Hua Zhang 0001, Qiaoyan Wen
IEEE Internet Things J.6
2023 Secure and Efficiently Searchable IoT Communication Data Management Model: Using Blockchain as a New Tool
abstract
With the rapid development of the Internet of Things (IoT), more IoT devices are connected in the same network and communicate frequently for sharing data and switching instructions. So that the traditional centralized security architecture of IoT will be limited in terms of data storage space, data reliability, scalability, and operating costs. In this article, we propose a novel communication data management model based on blockchain technology. Specifically, all encrypted IoT communication data files are uploaded to the public cloud server for obtaining enough storage space, but the key information extracted from these data files (called “communication logs”) will be recorded in an “IoT ledger” maintained by all IoT devices. In fact, the IoT ledger is a kind of blockchain structured distributed database, which can solve the problem of data reliability, scalability and would not involve high operating costs. Besides, in order to efficiently search communication logs and not reveal any sensitive information of communication data, we design a secure search scheme over such blockchain database, the asymmetric scalar-product-preserving encryption (ASPE) approach is exploited to guarantee the data security, and the two layers index improves the search efficiency. Security analysis and experiments on synthetic data set show that our scheme is secure and efficient.
Hua Zhang 0001, Xin Zhang 0120, Ziqing Guo, Huawei Wang 0001, Qiaoyan Wen
IEEE Internet Things J.6
2023 Scalable Fuzzy Keyword Ranked Search Over Encrypted Data on Hybrid Clouds
abstract
Searchable encryption (SE) is a powerful technology that enables keyword-based search over encrypted data becomes possible. However, most SE schemes focus on exact keyword search which can not tolerate misspellings and typos. Existing fuzzy keyword search schemes only support fuzzy search within a limited similarity threshold$d$, the storage cost will grow exponentially or the precision of search results will greatly decrease as$d$increases. Moreover, the current fuzzy keyword ranked search schemes consider only the keyword weight, and disregard the influence of keyword morphology similarity on the ranking. In this article, we propose a scalable fuzzy keyword ranked search scheme over encrypted data under hybrid clouds architecture. We use the edit distance to measure the similarity of keywords and design an edit distance algorithm over encrypted data, in which our scheme achieves fuzzy keyword search for any similarity threshold$d$with a constant storage size and accurate search results. Furthermore, we design a two-factor ranking function combining keyword weight with keyword morphology similarity, which is utilized to rank the search results and enhance system usability. Extensive experiments are performed to demonstrate the trade-off of efficiency and security of the proposed scheme.
Hua Zhang 0001, Shaohua Zhao, Ziqing Guo, Qiaoyan Wen, Wenmin Li 0001, Fei Gao 0001
IEEE Trans. Cloud Comput.4
2022 Jasmine: A Static Analysis Framework for Spring Core Technologies
abstract
The Spring framework is widely used in developing enterprise web applications. Spring core technologies, such as Dependency Injection and Aspect-Oriented Programming, make development faster and easier. However, the implementation of Spring core technologies uses a lot of dynamic features. Those features impose significant challenges when using static analysis to reason about the behavior of Spring-based applications. In this paper, we propose Jasmine, a static analysis framework for Spring core technologies extends from Soot to enhance the call graph’s completeness while not greatly affecting its performance. We evaluate Jasmine’s completeness, precision, and performance using Spring micro-benchmarks and a suite of 18 real-world Spring programs. Our experiments show that Jasmine effectively enhances the state-of-the-art tools based on Soot and Doop to better support Spring core technologies. We also add Jasmine support to FlowDroid and discovered twelve sensitive information leakage paths in our benchmarks. Jasmine is expected to provide significant benefits for many program analyses scenes of Spring applications where more complete call graphs are required.
Tengfei Tu, Hua Zhang 0001, Qiaoyan Wen, Weihang Wang 0001
ASE4
2022 Secure and Differentiated Fog-Assisted Data Access for Internet of Things
abstract
Abstract The ability of Fog computing to admit and process huge volumes of heterogeneous data is the catalyst for the fast expansion of Internet of things (IoT). The critical challenge is secure and differentiated access to the data, given limited computation capability and trustworthiness in typical IoT devices and Fog servers, respectively. This paper designs and develops a new approach for secure, efficient and differentiated data access. Secret sharing is decoupled to allow the Fog servers to assist the IoT devices with attribute-based encryption of data while preventing the Fog servers from tampering with the data and the access structure. The proposed encryption supports direct revocation and can be decoupled among multiple Fog servers for acceleration. Based on the decisional $q$-parallel bilinear Diffie–Hellman exponent assumption, we propose a new extended $q$-parallel bilinear Diffie–Hellman exponent (E$q$-PBDHE) assumption and prove that the proposed approach provides ‘indistinguishably chosen-plaintext attacks secure’ data access for legitimate data subscribers. As numerically and experimentally verified, the proposed approach is able to reduce the encryption time by 20% at the IoT devices and by 50% at the Fog network using parallel computing as compared to the state of the art .
Wei Ni 0001, Hua Zhang 0001, Ren Ping Liu 0001, Qiaoyan Wen, Wenmin Li 0001, Fei Gao 0001
Comput. J.5
2022 A rORAM scheme with logarithmic bandwidth and logarithmic locality
abstract
Oblivious Random Access Machine (ORAM) is a kind of cryptographic primitive that allows a client to access its private data from the server without disclosing the access pattern. To deal with consecutive requested blocks at a time efficiently, range ORAM (rORAM) is presented. In the previous rORAM scheme, the locality, namely, the number of discontinuous seeks to complete a request, is reduced to O(log2 N), nevertheless, the bandwidth cost is increased to the poly-logarithmic level. Hence, there exists an open question, that is, whether rORAM can be constructed with the same bandwidth efficiency as a regular ORAM, that is, O(log N)-block? In this paper, we propose a new rORAM scheme, called L2-rORAM. In our scheme, a compatible superblock technique is proposed, and it is combined together with an eviction technique for range blocks, so that it avoids duplication of multiple copies and extra dummy access. As a result, it obtains O(log N)-block bandwidth cost, which affirmatively answers the above open question. Meanwhile, the data locality is reduced to O(log N). In addition, the client storage is maintained at the small level of O(log N)-block, and the server storage is maintained at the unexpanded level of O(N)-block. Finally, experimental results show that the average response time of our L2-rORAM is reduced by one order of magnitude over the state-of-the-art rORAM scheme.
Yunping Gong, Fei Gao 0001, Wenmin Li 0001, Hua Zhang 0001, Zhengping Jin, Qiaoyan Wen
Int. J. Intell. Syst.6
2022 Label specificity attack: Change your label as I want
abstract
Graph neural networks (GNN) have been widely used in many machine learning tasks, such as text classification, sequence labeling, protein interface prediction, and knowledge graph. With increasing security concerns, GNN have been proved to be vulnerable and unreliable. Recent years, inspired by adversarial model in computer vision, various attacks on graph data begin to emerge. However, the exist attacks mostly focus on security violation and attack specificity, and very few attacks concern error specificity. In this paper, we focus on dealing with this kind of attack on one node of the graph by slightly manipulating the graph structure. Our goal is to change the label of the node to what we want after attack. We formulate this case as label specificity attack problem. The biggest challenge in solving this problem is the lack of theoretical guidance to perform this attack. For this, we reinterpret structural entropy and define differential structural entropy (DS-entropy) to guide the manipulation. Based on DS-entropy, we propose the target-label principle and max-degree principle to execute our attack, and then design the corresponding algorithm DSEM. We compare our algorithm DSEM with two benchmarks on three classical graph data sets. Results show that our algorithm is effective in performing label specificity attacks.
Huawei Wang 0001, Peng Yin 0005, Hua Zhang 0001, Qiaoyan Wen
Int. J. Intell. Syst.6
2022 Forward privacy multikeyword ranked search over encrypted database
abstract
Dynamic searchable encryption (SE) aims at achieving varied search function over encrypted database in dynamic setting, which is a trade-off in efficiency, security, and functionality. Recent work proposes a file-injection attack which can successfully attack by utilizing some information leaked in the update process. To mitigate this attack, some SE schemes with forward privacy are proposed. However, these schemes are designed to achieve single keyword or conjunctive keyword search, which cannot support multikeyword search. Moreover, these schemes do not consider the function of results ranking. In this paper, we propose a forward privacy multikeyword ranked search scheme over encrypted database. We design a forward privacy multikeyword search scheme based on the classic MRSE scheme. Our scheme makes the cloud cannot obtain the actual match results of the past query with the newly updated files by adding the well-chosen dummy elements to the original index and query vectors. We rank the search results based on the matched keyword number and the T F × I D F $TF\times IDF$ rule in the dynamic setting. Our scheme uses only the symmetric encryption primitive. We implement our scheme for COVID-19 data set and the experimental evaluation results show that the proposed scheme is secure and efficient.
Shaohua Zhao, Hua Zhang 0001, Xin Zhang 0120, Wenmin Li 0001, Fei Gao 0001, Qiaoyan Wen
Int. J. Intell. Syst.6
2022 Generating natural adversarial examples with universal perturbations for text classification
Hua Zhang 0001, Xingguo Yang, Wenmin Li 0001, Fei Gao 0001, Qiaoyan Wen
Neurocomputing6
2022 Efficient Encrypted Range Query on Cloud Platforms
abstract
In the Internet of Things (IoT) era, various IoT devices are equipped with sensing capabilities and employed to support clinical applications. The massive electronic health records (EHRs) are expected to be stored in the cloud, where the data are usually encrypted, and the encrypted data can be used for disease diagnosis. There exist some numeric health indicators, such as blood pressure and heart rate. These numeric indicators can be classified into multiple ranges, and each range may represent an indication of normality or abnormity. Once receiving encrypted IoT data, the CS maps it to one of the ranges, achieving timely monitoring and diagnosis of health indicators. This article presents a new approach to identify the range that an encrypted numeric value corresponds to without exposing the explicit value. We establish the sufficient and necessary condition to convert a range query to matchings of encrypted binary sequences with the minimum number of matching operations. We further apply the minimization of range queries to design and implement a secure range query system, where numeric health indicators encrypted independently by multiple IoT devices can be cohesively stored and efficiently queried by using Lagrange polynomial interpolation. Comprehensive performance studies show that the proposed approach can protect both the health records and range query against untrusted cloud platforms and requires less computational and communication cost than existing techniques.
Wei Ni 0001, Ren Ping Liu 0001, Hua Zhang 0001, Qiaoyan Wen
ACM Trans. Cyber Phys. Syst.6
2022 Practical Attribute-Based Multi-Keyword Ranked Search Scheme in Cloud Computing
abstract
Attribute-based keyword search (ABKS) has a broad developing prospect in providing search service for users and realizing fine-grained access control over ciphertext in the background of cloud computing. However, two open problems prevent further development and application of ABKS. First, most of ABKS schemes suffer from inside keyword guessing attack (KGA) inherently, which is a great threat to the security of the scheme. Second, the existing ABKS schemes focus on single or conjunctive keyword search, these inflexible retrieval modes may lead to efficiency loss caused by inaccurate positioning of user’s interest and greatly reduce user search experience. In this article, we introduce a semi-trusted server and build a dual server model. Based on the dual server model and our proposed techniques, we are the first to put forward an attribute-based multi-keyword ranked search scheme against inside keyword guessing attack (ABKRS-KGA) to solve the mentioned two problems simultaneously. In our scheme, the queries of users contain weighted keywords and the returned files can be ranked according to user’s query interest. We provide strict security definitions for two types of adversaries and we are the first to prove that the construction is adaptively secure against both chosen-keyword attack (CKA) and KGA. Finally, all-side simulation with real-world data set is implemented for the proposed scheme, and the simulation results show that the efficiency of the proposed scheme is acceptable.
Yang Chen 0042, Wenmin Li 0001, Fei Gao 0001, Qiaoyan Wen, Hua Zhang 0001, Huawei Wang 0001
IEEE Trans. Serv. Comput.4
2022 Dynamic Proof of Data Possession and Replication With Tree Sharing and Batch Verification in the Cloud
abstract
Cloud storage attracts a lot of clients to join the paradise. For a high data availability, some clients require their files to be replicated and stored on multiple servers. Because clients are generally charged based on the redundancy level required by them, it is critical for clients to obtain convincing evidence that all replicas are stored correctly and are updated to the up-to-date version. In this article, we propose a dynamic proof of data possession and replication (DPDPR) scheme, which is proved to be secure in the defined security model. Our scheme shares a single authenticated tree across multiple replicas, which reduces the tree's storage cost significantly. Our scheme allows for batch verification for multiple challenged leaves and can verify multiple replicas in a single batch way, which considerably save bandwidth and computation resources during audit process. We also evaluate the DPDPR's performance and compare it with the most related scheme. The evaluation results show that our scheme saves almost 66 percent tree's storage cost for three replicas, and obtains almost 60 and 80 percent efficiency improvements in terms of the overall bandwidth and computation costs, respectively, when three replicas are checked and each challenged with 460 blocks.
Wei Guo 0042, Su-Juan Qin, Fei Gao 0001, Hua Zhang 0001, Wenmin Li 0001, Zhengping Jin, Qiaoyan Wen
IEEE Trans. Serv. Comput.7
2021 Lightweight Public Key Encryption With Equality Test Supporting Partial Authorization in Cloud Storage
abstract
Abstract Public key encryption with equality test (PKEET) can check whether two ciphertexts are encrypted from the same message or not without decryption. This attribute enables PKEET to be increasingly utilized in cloud storage, where users store their encrypted data on the cloud. In traditional PKEET, the tester is authorized by the data receiver to perform equality test on its ciphertexts. However, the tester can only test one ciphertext or all ciphertexts of one receiver with one authorization. It means that the receiver cannot adaptively authorize the test right of any number of ciphertexts to the tester. A trivial solution is authorizing one ciphertext each time and repeating multiple times. The corresponding size of trapdoor in this method is linear with the number of authorized ciphertexts. This will incur storage burden for the tester. To solve the aforementioned problem, we propose the concept of PKEET supporting partial authentication (PKEET-PA). We then instantiate the concept to a lightweight PKEET-PA, which achieves constant-size trapdoor. Besides, we prove the security of our PKEET-PA scheme against two types of adversaries. Compared with other PKEET schemes that can be used in trivial solution, our PKEET-PA is more efficient in receivers’ computation and has lower trapdoor size.
Zhen Zhao 0005, Fei Gao 0001, Willy Susilo, Qiaoyan Wen, Fuchun Guo, Yijie Shi
Comput. J.5
2021 Efficient Anonymous Data Authentication for Vehicular Ad Hoc Networks
abstract
Vehicular ad hoc network (VANET) encounters a critical challenge of efficiently and securely authenticating massive on-road data while preserving the anonymity and traceability of vehicles. This paper designs a new anonymous authentication approach by using an attribute-based signature. Each vehicle is defined by using a set of attributes, and each message is signed with multiple attributes, enabling the anonymity of vehicles. First, a batch verification algorithm is developed to accelerate the verification processes of a massive volume of messages in large-scale VANETs. Second, replicate messages captured by different vehicles and signed under different sets of attributes can be dereplicated with the traceability of all the signers preserved. Third, the malicious vehicles forging data can be traced from their signatures and revoked from attribute groups. The security aspects of the proposed approach are also analyzed by proving the anonymity of vehicles and the unforgeability of signatures. The efficiency of the proposed approach is numerically verified, as compared to the state of the art.
Wei Ni 0001, Guangsheng Yu, Hua Zhang 0001, Ren Ping Liu 0001, Qiaoyan Wen
Secur. Commun. Networks6
2021 An Improved Quantum Algorithm for Ridge Regression
abstract
Ridge regression (RR) is an important machine learning technique which introduces a regularization hyperparameter$\alpha$to ordinary multiple linear regression for analyzing data suffering from multicollinearity. In this paper, we present a quantum algorithm for RR, where the technique of parallel Hamiltonian simulation to simulate a number of Hermitian matrices in parallel is proposed and used to develop a quantum version of$K$-fold cross-validation approach, which can efficiently estimate the predictive performance of RR. Our algorithm consists of two phases: (1) using quantum$K$-fold cross-validation to efficiently determine a good$\alpha$with which RR can achieve good predictive performance, and then (2) generating a quantum state encoding the optimal fitting parameters of RR with such$\alpha$, which can be further utilized to predict new data. Since indefinite dense Hamiltonian simulation has been adopted as a key subroutine, our algorithm can efficiently handle non-sparse data matrices. It is shown that our algorithm can achieve exponential speedup over the classical counterpart for (low-rank) data matrices with low condition numbers. But when the condition numbers of data matrices are large to be amenable to full or approximately full ranks of data matrices, only polynomial speedup can be achieved.
Chao-Hua Yu, Fei Gao 0001, Qiaoyan Wen
IEEE Trans. Knowl. Data Eng.3
2021 Privacy-Preserving Linear Region Search Service
abstract
Due to a variety of advantages of data outsourcing, some Location Based Services (LBS) providers are motivated to outsource the geographic data and query service to commercial cloud. However, for protecting data confidentiality, the valuable data should be encrypted before outsourcing, which obstructs the utilization like geographic information query. To address this problem, some previous works regarding to secure search on encrypted database could be applied in outsourced LBS scenario directly, but none of them is tailor-made for linear region search (LRS). The LRS is a kind of LBS that widely used in navigation system, it finds the nearby points of interest (POI) for a query segment. In this paper, for the first time, we explore and solve the challenging problem of privacy-preserving linear region search. Specifically, we choose the quadtree structure to build index for POI database, then the results of LRS can be efficiently obtained by finding out the rectangular regions that query segment passes through. In order to preserve the privacy of both LBS providers and users, according to computational geometry and Asymmetric Scalar-product Preserving Encryption (ASPE) approach, we design a novel algorithm for accurately determining whether a segment intersects with a rectangle on ciphertext. Moreover, this algorithm also provides a new idea to solve other computational problems in encrypted 2-dimensional geometry space. Based on different privacy requirements of two threat models, we propose two privacy-preserving LRS schemes and corresponding dynamic update operations. Security analysis and experiments on real-world dataset show that our schemes are secure and efficient.
Hua Zhang 0001, Ziqing Guo, Shaohua Zhao, Qiaoyan Wen
IEEE Trans. Serv. Comput.4
2020 A new provably secure certificateless signature scheme for Internet of Things
Hongzhen Du, Qiaoyan Wen, Mingchu Gao
Ad Hoc Networks2
2020 Practical Attribute-Based Conjunctive Keyword Search Scheme
abstract
Abstract To date cloud computing may provide considerable storage and computational power for cloud-based applications to support cryptographic operations. Due to this benefit, attribute-based keyword search (ABKS) is able to be implemented in cloud context in order to protect the search privacy of data owner/user. ABKS is a cryptographic primitive that can provide secure search services for users but also realize fine-grained access control over data. However, there have been two potential problems that prevent the scalability of ABKS applications. First of all, most of the existing ABKS schemes suffer from the outside keyword guessing attack (KGA). Second, match privacy should be considered while supporting multi-keyword search. In this paper, we design an efficient method to combine the keyword search process in ABKS with inner product encryption and deploy several proposed techniques to ensure the flexibility of retrieval mode, the security and efficiency of our scheme. We later put forward an attribute-based conjunctive keyword search scheme against outside KGA to solve the aforementioned problems. We provide security notions for two types of adversaries and our construction is proved secure against chosen keyword attack and outside KGA. Finally, all-side simulation with real-world data set is implemented for the proposed scheme, and the results of the simulation show that our scheme achieves stronger security without yielding significant cost of storage and computation.
Yang Chen 0042, Wenmin Li 0001, Fei Gao 0001, Kaitai Liang, Hua Zhang 0001, Qiaoyan Wen
Comput. J.6
2020 Improved Proofs Of Retrievability And Replication For Data Availability In Cloud Storage
abstract
Abstract For a high level of data availability and reliability, a common strategy for cloud service providers is to rely on replication, i.e. storing several replicas onto different servers. To provide cloud users with a strong guarantee that all replicas required by them are actually stored, many multi-replica integrity auditing schemes were proposed. However, most existing solutions are not resource economical since users need to create and upload replicas of their files by themselves. A multi-replica solution called Mirror is presented to overcome the problems, but we find that it is vulnerable to storage saving attack, by which a dishonest provider can considerably save storage costs compared to the costs of storing all the replicas honestly—while still can pass any challenge successfully. In addition, we also find that Mirror is easily subject to substitution attack and forgery attack, which pose new security risks for cloud users. To address the problems, we propose some simple yet effective countermeasures and an improved proofs of retrievability and replication scheme, which can resist the aforesaid attacks and maintain the advantages of Mirror, such as economical bandwidth and efficient verification. Experimental results show that our scheme exhibits comparable performance with Mirror while achieving high security.
Wei Guo 0042, Su-Juan Qin, Fei Gao 0001, Zhengping Jin, Qiaoyan Wen, Daniele Sgandurra
Comput. J.6
2020 New Blind Filter Protocol: An Improved Privacy-Preserving Scheme for Location-Based Services
abstract
Abstract Location-based services have attracted much attention in both academia and industry. However, protecting user’s privacy while providing accurate service for users remains challenging. In most of the existing research works, a semi-trusted proxy is employed to act on behalf of a user to minimize the computation and communication costs of the user. However, user privacy, e.g. location privacy, cannot be protected against the proxy. In this paper, we design a new blind filter protocol where a user can employ a semi-trusted proxy to determine whether a point of interest is within a circular area centered at the user’s location. During the protocol, neither the proxy nor the location-based service provider can obtain the location of the user and the query results. Moreover, each type of query is controlled by an access tree and only the users whose attributes satisfy this access tree can complete the specific type of query. Security analysis and efficiency experiments validate that the proposed protocol is secure and efficient in terms of the computation and communication overhead.
Wenmin Li 0001, Fei Gao 0001, Hua Zhang 0001, Zhengping Jin, Qiaoyan Wen
Comput. J.7
2020 Searchain: Blockchain-based private keyword search in decentralized storage
Peng Jiang 0007, Fuchun Guo, Kaitai Liang, Jianchang Lai, Qiaoyan Wen
Future Gener. Comput. Syst.5
2020 A survey on the security of blockchain systems
Xiaoqi Li 0001, Peng Jiang 0007, Ting Chen 0002, Xiapu Luo, Qiaoyan Wen
Future Gener. Comput. Syst.5
2020 Self-Testing of Symmetric Three-Qubit States
abstract
Self-testing refers to a device-independent way to uniquely identify an unknown quantum device based only on the observed statistics. Earlier results on self-testing of multipartite state were restricted either to Dicke states or Graph states. In this paper, we propose self-testing schemes for a large family of symmetric three-qubit states, namely the superposition of W state and GHZ state. We first propose and analytically prove a self-testing criterion for the special symmetric state with equal coefficients of the canonical bases, by designing subsystem self-testing of partially and maximally entangled state simultaneously. Then we demonstrate for the general case, the states can be self-tested numerically by the swap method combining semidefinite programming (SDP) in high precision.
Yunguang Han, Su-Juan Qin, Fei Gao 0001, Qiaoyan Wen
IEEE J. Sel. Areas Commun.6
2020 Error Tolerance Bound in QKD-Based Quantum Private Query
abstract
Most existing quantum private query (QPQ) protocols can hardly work in the presence of noise. The user Alice may obtain a false database item in noisy environments and both participants may cheat under the disguise of noise, so dealing with the noise needs an overall consideration of error correction, user privacy and database security. However, the only two existing protocols aiming to correct errors in QPQ lack such an overall consideration (at least one party's privacy can be revealed), and they did not estimate what extent of errors can be tolerated (actually, noise is seldom discussed in quantum two-party secure computations, and to the best of our knowledge, relevant bounds on tolerable errors remain unattainable so far). To solve this problem, we first exemplify how one participant reveals the other party's privacy in the existing QPQ protocols aiming to correct errors. Then we propose a practical protocol which can really work via noisy channel, that is, the error rate of the retrieved database item is reduced significantly and both parties' privacy are well protected. Besides, we deduce that the final error rate, user privacy and database security are pairwise in a “trade-off” relationship. By balancing them according to the required level of security and reliability, we obtain an upper bound on tolerable errors.
Chunyan Wei 0001, Xiao-Qiu Cai, Su-Juan Qin, Fei Gao 0001, Qiaoyan Wen
IEEE J. Sel. Areas Commun.6
2020 Adaptively secure broadcast encryption with authenticated content distributors
Dianli Guo, Qiaoyan Wen, Wenmin Li 0001, Hua Zhang 0001, Zhengping Jin
Multim. Tools Appl.2
2020 Comments on "Provable Multicopy Dynamic Data Possession in Cloud Computing Systems"
abstract
Replication is a fundamental solution for the cloud service provider (CSP) to guarantee data availability. To provide users with convincing evidence that the copies required by them are all stored correctly, a number of multi-copy integrity auditing schemes were presented. Recently, Barsoum and Hasan proposed a map-based provable multi-copy dynamic data possession scheme (IEEE Transactions on Information Forensics and Security, vol. 10, no. 3, pp. 485-497, 2015), which was claimed to be secure and can ensure that the CSP possesses all copies required by the contract. However, in this letter, we show that the scheme is easily subject to a copy-summation attack and a single-copy attack, by which a cheating CSP only needs to invest a storage cost of a single copy-while can still pass the verifier's challenge at all times. Therefore, the scheme is no longer secure in this case. Furthermore, we propose some simple but effective countermeasures and give a repaired scheme which is free from the above two attacks.
Wei Guo 0042, Su-Juan Qin, Fei Gao 0001, Hua Zhang 0001, Wenmin Li 0001, Zhengping Jin, Qiaoyan Wen
IEEE Trans. Inf. Forensics Secur.7
2020 An Adaptive Encryption-as-a-Service Architecture Based on Fog Computing for Real-Time Substation Communications
abstract
The recent outbreak of industrial cyberattacks indicates that the current industrial network security architecture is under serious challenges. As one of the critical industrial networks, the heterogeneous and real-time substation network lacks compatibility with the conventional cryptography architecture represented by secure sockets layer/transport layer security (SSL/TLS) and public key infrastructure (PKI). To enhance the security of smart substations under the premise of low latency, in this article, we present a novel encryption-as-a-service architecture based on fog computing in this article. The architecture offloads encryption to dedicated devices and makes certificate and key management available through unified web services on the fog and cloud layers. Based on this architecture, we propose MX-SORTS, maximizing security on real-time communication of different services, an algorithm for adaptive configuration of encrypting and signing substation network traffic. By the contrast experiments with the conventional cryptography architecture, we prove that the encryption-as-a-service architecture can significantly improve the real-time and security performance of substation networks.
Hua Zhang 0001, Boqin Qin, Tengfei Tu, Ziqing Guo, Fei Gao 0001, Qiaoyan Wen
IEEE Trans. Ind. Informatics6
2019 Efficient Attribute-Based Data Sharing Scheme with Hidden Access Structures
abstract
Abstract Online data sharing has become a research hotspot while cloud computing is getting more and more popular. As a promising encryption technique to guarantee the security shared data and to realize flexible fine-grained access control, ciphertext-policy attribute-based encryption (CP-ABE) has drawn wide attentions. However, there is a drawback preventing CP-ABE from being applied to cloud applications. In CP-ABE, the access structure is included in the ciphertext, and it may disclose user’s privacy. In this paper, we find a more efficient method to connect ABE with inner product encryption and adopt several techniques to ensure the expressiveness of access structure, the efficiency and security of our scheme. We are the first to present a secure, efficient fine-grained access control scheme with hidden access structure, the access structure can be expressed as AND-gates on multi-valued attributes with wildcard. We conceal the entire attribute instead of only its values in the access structure. Besides, our scheme has obvious advantages in efficiency compared with related schemes. Our scheme can make data sharing secure and efficient, which can be verified from the analysis of security and performance.
Yang Chen 0042, Wenmin Li 0001, Fei Gao 0001, Wei Yin 0004, Kaitai Liang, Hua Zhang 0001, Qiaoyan Wen
Comput. J.7
2019 Outsourced dynamic provable data possession with batch update for secure cloud storage
Wei Guo 0042, Hua Zhang 0001, Su-Juan Qin, Fei Gao 0001, Zhengping Jin, Wenmin Li 0001, Qiaoyan Wen
Future Gener. Comput. Syst.7
2019 An efficient blind filter: Location privacy protection and the access control in FinTech
Wenmin Li 0001, Qiaoyan Wen, Jiageng Chen, Wei Yin 0004, Kaitai Liang
Future Gener. Comput. Syst.3
2019 Authenticated public key broadcast encryption with short ciphertexts
Dianli Guo, Qiaoyan Wen, Zhengping Jin, Hua Zhang 0001, Wenmin Li 0001
Multim. Tools Appl.2
2018 A New Insight - Proxy Re-encryption Under LWE with Strong Anti-collusion
Wei Yin 0004, Qiaoyan Wen, Wenmin Li 0001, Hua Zhang 0001, Zhengping Jin
ISPEC2
2018 Secure multi-keyword ranked search over encrypted cloud data for multiple data owners
Ziqing Guo, Hua Zhang 0001, Caijun Sun, Qiaoyan Wen, Wenmin Li 0001
J. Syst. Softw.4
2018 Attribute-based fuzzy identity access control in multicloud computing environments
Wenmin Li 0001, Qiaoyan Wen, Xuelei Li, Debiao He
Soft Comput.2
2018 An Anonymous Authentication Protocol Based on Cloud for Telemedical Systems
abstract
Telecare medical information systems (TMIS) enable patients to access healthcare delivery services conveniently. With the explosive development occurring in cloud computing and services, storage of personal medical and health information outsourcing to cloud infrastructure has been a potential alternative. However, this has entailed many considerable security and privacy issues. In order to address the security loopholes, we propose a promising solution satisfying the requirements of cloud computing scenarios for telemedical systems. The proposed scheme could provide both data confidentiality and message authenticity while preserving anonymity. Furthermore, the formal security proof demonstrates that the proposed scheme is resistant to various attacks. The performance comparisons show the proposal’s workability and it is well suited to adoption in telemedical services.
Wenmin Li 0001, Shuo Zhang 0008, Qiaoyan Wen, Yang Chen 0042
Wirel. Commun. Mob. Comput.4
2018 Dynamic Outsourced Proofs of Retrievability Enabling Auditing Migration for Remote Storage Security
abstract
Remote data auditing service is important for mobile clients to guarantee the intactness of their outsourced data stored at cloud side. To relieve mobile client from the nonnegligible burden incurred by performing the frequent data auditing, more and more literatures propose that the execution of such data auditing should be migrated from mobile client to third‐party auditor (TPA). However, existing public auditing schemes always assume that TPA is reliable, which is the potential risk for outsourced data security. Although Outsourced Proofs of Retrievability (OPOR) have been proposed to further protect against the malicious TPA and collusion among any two entities, the original OPOR scheme applies only to the static data, which is the limitation that should be solved for enabling data dynamics. In this paper, we design a novel authenticated data structure called bv23Tree, which enables client to batch‐verify the indices and values of any number of appointed leaves all at once for efficiency. By utilizing bv23Tree and a hierarchical storage structure, we present the first solution for Dynamic OPOR (DOPOR), which extends the OPOR model to support dynamic updates of the outsourced data. Extensive security and performance analyses show the reliability and effectiveness of our proposed scheme.
Lu Rao, Tengfei Tu, Hua Zhang 0001, Qiaoyan Wen
Wirel. Commun. Mob. Comput.4
2017 A privacy-preserving authenticated key agreement protocol with smart cards for mobile emergency services
abstract
With the today's the rapid developing of wireless mobile networks, various types of mobile devices have emerged and a variety of applications have been developed. People's desire for more convenient life and more efficient collaboration may be coming true in this era. Meanwhile there are lots of security challenges in wireless mobile networks. To resist conventional attacks and obtain stronger securities in the scenarios of mobile emergency services, we propose a privacy-preserving authenticated key agreement protocol with smart cards which requires no verification tables stored by the server and provides both perfect forward security and user anonymity. Emergency notifications are modeled as emergency message codes that are provided with security and anonymity by the protocol.
Ya-Jun Fan, Xuesong Qiu 0001, Qiaoyan Wen
CSCWD3
2017 Secure-channel free keyword search with authorization in manager-centric databases
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen
Comput. Secur.4
2017 Rough approximations based on bisimulations
Ping Zhu 0001, Huiyang Xie, Qiaoyan Wen
Int. J. Approx. Reason.3
2017 Private Keyword-Search for Database Systems Against Insider Attacks
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen
J. Comput. Sci. Technol.4
2017 Flexible CP-ABE Based Access Control on Encrypted Data for Mobile Users in Hybrid Cloud System
Wenmin Li 0001, Xuelei Li, Qiaoyan Wen, Shuo Zhang 0008, Hua Zhang 0001
J. Comput. Sci. Technol.3
2017 Privacy-Preserving Outsourced Auditing Scheme for Dynamic Data Storage in Cloud
abstract
As information technology develops, cloud storage has been widely accepted for keeping volumes of data. Remote data auditing scheme enables cloud user to confirm the integrity of her outsourced file via the auditing against cloud storage, without downloading the file from cloud. In view of the significant computational cost caused by the auditing process, outsourced auditing model is proposed to make user outsource the heavy auditing task to third party auditor (TPA). Although the first outsourced auditing scheme can protect against the malicious TPA, this scheme enables TPA to have read access right over user’s outsourced data, which is a potential risk for user data privacy. In this paper, we introduce the notion of User Focus for outsourced auditing, which emphasizes the idea that lets user dominate her own data. Based on User Focus, our proposed scheme not only can prevent user’s data from leaking to TPA without depending on data encryption but also can avoid the use of additional independent random source that is very difficult to meet in practice. We also describe how to make our scheme support dynamic updates. According to the security analysis and experimental evaluations, our proposed scheme is provably secure and significantly efficient.
Tengfei Tu, Lu Rao, Hua Zhang 0001, Qiaoyan Wen
Secur. Commun. Networks4
2017 Succinct multi-authority attribute-based access control for circuits with authenticated outsourcing
Jie Xu 0038, Qiaoyan Wen, Wenmin Li 0001, Jian Shen 0001, Debiao He
Soft Comput.2
2017 A unified view of consistent functions
Ping Zhu 0001, Huiyang Xie, Qiaoyan Wen
Soft Comput.3
2016 Public Key Encryption with Authorized Keyword Search
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen
ACISP (2)4
2016 A strongly secure pairing-free certificateless authenticated key agreement protocol under the CDH assumption
Haiyan Sun, Qiaoyan Wen, Wenmin Li 0001
Sci. China Inf. Sci.2
2016 Online/Offline Ciphertext Retrieval on Resource Constrained Devices
abstract
The ciphertext retrieval is of paramount importance for data confidentiality and utilization in mobile cloud environment. The receiver, usually equipped with resource constrained devices, retrieves data stored in the cloud server by submitting a confidential request (or trapdoor) to the cloud. Previous schemes need at least one exponentiation operation in group |$\mathbb {G}$| for each keyword to generate the trapdoor, which is quite burdensome for mobile devices to support such computational cost. The computational cost of trapdoor generation limits the application of ciphertext retrieval, especially in a wireless environment. In this paper, we propose the first online/offline ciphertext retrieval (OOCR) scheme, where the trapdoor generation is split into two phases: offline phase and online phase . Most of the computation of the trapdoor could be performed in the offline phase prior to knowing the keyword. The generation of the real trapdoor with keyword can be done efficiently in the online phase. The most challenging task is to resist the so-called insider attacks, which is about keyword guessing attacks from the untrusted cloud server. We also build a novel framework to resist insider attacks and propose an OOCR scheme against insider attacks. Our semantic security proof and performance analysis demonstrate that the proposal is practical for mobile cloud applications.
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen
Comput. J.5
2016 Linear complexity of generalised cyclotomic quaternary sequences of length 2p m+1 q n+1
abstract
Sequences with high linear complexity play a fundamental part in cryptography. In this study, the authors construct general forms of Whiteman's generalised cyclotomic quaternary sequences with period 2 p m +1 q n +1 of order two over 𝔽 4 and give the linear complexity of the proposed sequences. The conclusions reveal that such sequences have good balance property and high linear complexity.
Zuling Chang, Qiaoyan Wen, Jie Zhang 0004
IET Inf. Secur.3
2016 Circuit Ciphertext-Policy Attribute-Based Hybrid Encryption with Verifiable Delegation in Cloud Computing
abstract
In the cloud, for achieving access control and keeping data confidential, the data owners could adopt attribute-based encryption to encrypt the stored data. Users with limited computing power are however more likely to delegate the mask of the decryption task to the cloud servers to reduce the computing cost. As a result, attribute-based encryption with delegation emerges. Still, there are caveats and questions remaining in the previous relevant works. For instance, during the delegation, the cloud servers could tamper or replace the delegated ciphertext and respond a forged computing result with malicious intent. They may also cheat the eligible users by responding them that they are ineligible for the purpose of cost saving. Furthermore, during the encryption, the access policies may not be flexible enough as well. Since policy for general circuits enables to achieve the strongest form of access control, a construction for realizing circuit ciphertext-policy attribute-based hybrid encryption with verifiable delegation has been considered in our work. In such a system, combined with verifiable computation and encrypt-then-mac mechanism, the data confidentiality, the fine-grained access control and the correctness of the delegated computing results are well guaranteed at the same time. Besides, our scheme achieves security against chosen-plaintext attacks under the k-multilinear Decisional Diffie-Hellman assumption. Moreover, an extensive simulation campaign confirms the feasibility and efficiency of the proposed solution.
Jie Xu 0038, Qiaoyan Wen, Wenmin Li 0001, Zhengping Jin
IEEE Trans. Parallel Distributed Syst.2
2015 Controlling the key by choosing the detection bits in quantum cryptographic protocols
Bin Liu 0027, Fei Gao 0001, Wei Huang 0002, Qiaoyan Wen
Sci. China Inf. Sci.5
2015 An anonymous and efficient remote biometrics user authentication scheme in a multi server environment
Peng Jiang 0007, Qiaoyan Wen, Wenmin Li 0001, Zhengping Jin, Hua Zhang 0001
Frontiers Comput. Sci.2
2015 Cryptanalysis and improvement of a certificateless partially blind signature
abstract
Partially blind signature is an important technique in secure electronic cash (e‐cash) system. The first concrete certificateless partially blind signature (CLPBS) scheme for e‐cash was constructed in 2011. Recently it was found that this construction had a security weakness and a rescued scheme was given. Unfortunately, the formal security proof was not given. In this study, the authors first give cryptanalysis of their rescued scheme. They demonstrate that a malicious user in their rescued scheme can forge a signature on any message by replacing the signer's public key. In an e‐cash system, blind signatures issued by the bank are viewed as e‐cash. Once they apply their scheme to an untraceable e‐cash system, a malicious user can forge valid electronic coins (i.e. valid signatures) without being detected by the bank. It will result in loss of the bank. Then, they propose a newly improved CLPBS scheme which achieves the strongest security level and has higher computational efficiency than the rescued scheme published earlier. Finally, they give an example of potential application to e‐cash systems using their scheme.
Lin Cheng 0002, Qiaoyan Wen
IET Inf. Secur.2
2015 Cryptanalysis and improvement of a certificateless aggregate signature scheme
Lin Cheng 0002, Qiaoyan Wen, Zhengping Jin, Hua Zhang 0001
Inf. Sci.2
2015 A general two-party bi-input private function evaluation protocol
abstract
Abstract In the past, researchers have discussed the problem of two‐party single‐input private function evaluation (PFE), where P1 holds a private input x while P2 holds a private circuit Cf, and their goal is to securely compute Cf(x) without revealing x and Cf. Herein, we further consider a more general case, two‐party bi‐input PFE, where P2 also participates in the PFE by contributing a private input y. The research in this general case is of great value not only in theory but also in practice. In this paper, we focus on this problem and propose the first constant‐round two‐party bi‐input PFE protocol, which is with linear complexity and without relying on universal circuit or fully homomorphic encryption. Copyright © 2015 John Wiley & Sons, Ltd.
Yi Sun 0006, Qiaoyan Wen
Secur. Commun. Networks2
2015 A strongly secure identity-based authenticated key agreement protocol without pairings under the GDH assumption
abstract
Among the existing identity-based authenticated key agreement ID-AKA protocols, there are only a few of them that can resist to leakage of ephemeral secret keys, which is about the protection of the session secret key after the ephemeral secret keys of users are compromised. However, all these ID-AKA protocols with leakage of ephemeral secret keys resistance require expensive bilinear pairing operations. In this paper, we present a pairing-free ID-AKA protocol with ephemeral secrets leakage resistance. We also provide a full proof of its security in the extended Canetti-Krawczyk model, which not only can capture resistance to leakage of ephemeral secret keys but also can capture other basic security properties such as master key forward security and key compromise impersonation resistance. Compared with the existing ID-AKA protocols, our scheme is a good trade-off between security and efficiency. Copyright © 2015 John Wiley & Sons, Ltd.
Haiyan Sun, Qiaoyan Wen, Hua Zhang 0001, Zhengping Jin
Secur. Commun. Networks2
2014 Cryptanalysis and improvement of a certificateless encryption scheme in the standard model
Lin Cheng 0002, Qiaoyan Wen, Zhengping Jin, Hua Zhang 0001
Frontiers Comput. Sci.2
2014 A lattice-based signcryption scheme without random oracles
Xiuhua Lu, Qiaoyan Wen, Zhengping Jin, Chunli Yang
Frontiers Comput. Sci.2
2014 A Unified Definition of Consistent Functions
abstract
In recent years, homomorphisms have been exploited to compare the structures and properties of two generalized information systems. Some of these homomorphisms are based on consistent functions, which are a class of special mappings between universal sets. The purpose of this paper is to unify and extend the consistent functions in the literature into the framework of neighborhood systems. After introducing the notion of consistent functions with respect to neighborhood systems, we explore some important properties of the extended consistent functions such as preserving the inverse images and the intersections of neighborhoods. Our results provide a sound basis for further investigating neighborhood systems via homomorphisms.
Ping Zhu 0001, Huiyang Xie, Qiaoyan Wen
Fundam. Informaticae3
2014 Security analysis of two certificateless short signature schemes
abstract
Certificateless public key cryptography (CL‐PKC) combines the advantage of both traditional PKC and identity‐based cryptography (IBC) as it eliminates the certificate management problem in traditional PKC and resolves the key escrow problem in IBC. Recently, Choi et al . and Tso et al . proposed two different efficient CL short signature schemes and claimed that the two schemes are secure against super adversaries and satisfy the strongest security. In this study, the authors show that both Choi et al .’s scheme and Tso et al .’s scheme are insecure against the strong adversaries who can replace users’ public keys and have access to the signing oracle under the replaced public keys.
Hongzhen Du, Qiaoyan Wen
IET Inf. Secur.2
2014 Constructions of resilient rotation symmetric boolean functions on given number of variables
abstract
In this study, the properties of the support tables of rotation symmetric Boolean functions (RSBFs for simplicity) are studied, and two sufficient and necessary conditions for RSBFs being 1‐ and 2‐resilient are obtained, respectively. Based on the relations between resilient functions and orthogonal arrays, with the help of the properties about the support tables of RSBFs, it is shown that the constructions of 1‐resilient RSBFs on given number of variables are equivalent to solving an equation system, and the number of functions is equal to the number of solutions of the equation system. Moreover, similar results are also obtained for 2‐resilient RSBFs. Lastly, a simple example is given to demonstrate our method. The results indicate that the constructions of n ‐variable 1‐resilient RSBFs are equivalent to studying the cyclotomic cosets C s modulo 2 n − 1 with respect to 2.
Jiao Du, Qiaoyan Wen, Jie Zhang 0004, Shanqi Pang
IET Inf. Secur.2
2014 Certificateless proxy multi-signature
Hongzhen Du, Qiaoyan Wen
Inf. Sci.2
2013 A novel privacy preserving keyword searching for cloud storage
abstract
In cloud storage environment, clients no longer have physical possession of their data, it indicates that their data may be leaked maliciously by cloud provider. To avoid the security risks, we propose a privacy preserving keyword searching scheme whose encryption procedure needs no pairing operation. Our scheme allows users to encrypt their data before uploading to the cloud, and retrieve them by searching the encrypted keywords, besides it enables the cloud service provider to participate in decipherment which reduces the computational overhead of the client's decryption. Performance analysis shows our new scheme is more efficient and more adaptable to the cloud environment than the existing schemes. In addition, the new scheme is proved to be semantically secure in the random oracle model.
Lin Cheng 0002, Zhengping Jin, Qiaoyan Wen, Hua Zhang 0001
PST3
2013 A novel pairing-free certificateless authenticated key agreement protocol with provable security
Haiyan Sun, Qiaoyan Wen, Hua Zhang 0001, Zhengping Jin
Frontiers Comput. Sci.2
2012 A smart card-based secure software distribution scheme for mobile application market
abstract
Nowadays, with the rapid development of the wireless mobile networks and the related technologies, the range of interpersonal collaboration and communication has been expanded to almost all corners of the world. And the applications in the mobile application markets greatly enrich the functions of mobile devices in wireless mobile networks. In general, the applications with collaborative functions require the secure measures of high level to protect their important information. In this paper, we analyze the ideal role of the mobile application markets and propose a smart card-based secure software distribution scheme for mobile application market which provides perfect forward secrecy for distributed applications, resists several kinds of attacks on customers' password and protects the installed applications by a practical secure method based on smart card.
Ya-Jun Fan, Qiaoyan Wen
CSCWD2
2012 On the construction of multi-output Boolean functions with optimal algebraic immunity
Jie Zhang 0004, ShouChao Song, Jiao Du, Qiaoyan Wen
Sci. China Inf. Sci.4
2012 An efficient and secure mobile payment protocol for restricted connectivity scenarios in vehicular ad hoc network
Wenmin Li 0001, Qiaoyan Wen, Zhengping Jin
Comput. Commun.2
2012 A Novel Steganographic Method with Four-Pixel Differencing and Modulus Function
abstract
To improve the stego-image quality and provide a larger embedding capacity, a novel steganographic method based on four-pixel differencing and modulus function is presented. We process a block of four neighboring pixels, and form three two-pixel groups to record the information of secret data. In each group, the difference value between two pixels is exploited to estimate how many secret bits will be embedded. Two pixels will be adjusted so that the sum of the remainders of them is equal to secret data. In order to extract the secret data exactly, four pixel values in a block are adjusted synchronously by using modulus function. An optimization problem is formulated to minimize the embedding distortion. A theoretical proof is given to ensure the solvability of the problem. The experimental results show the proposed method not only has a larger embedding capacity but also provides better stego-image quality.
Xin Liao 0001, Qiaoyan Wen, Ze-li Zhao, Jie Zhang 0004
Fundam. Informaticae2
2012 Entropy and co-entropy of a covering approximation space
Ping Zhu 0001, Qiaoyan Wen
Int. J. Approx. Reason.2
2012 Information-theoretic measures associated with rough set approximations
Ping Zhu 0001, Qiaoyan Wen
Inf. Sci.2
2011 Certificateless multi-proxy signature
Zhengping Jin, Qiaoyan Wen
Comput. Commun.2
2011 A steganographic method for digital images with four-pixel differencing and modified LSB substitution
Xin Liao 0001, Qiaoyan Wen, Jie Zhang 0004
J. Vis. Commun. Image Represent.2
2010 Some improved results on communication between information systems
Ping Zhu 0001, Qiaoyan Wen
Inf. Sci.2
2010 Multi-party covert communication with steganography and quantum secret sharing
Xin Liao 0001, Qiaoyan Wen, Jie Zhang 0004
J. Syst. Softw.2
2006 Results on Almost Resilient Functions
Pinhui Ke, Jie Zhang 0004, Qiaoyan Wen
ACNS3
2006 New Constructions of Large Binary Sequences Family with Low Correlation
Jie Zhang 0004, Qiaoyan Wen
Inscrypt3
2005 Constructions of Almost Resilient Functions
Pinhui Ke, Tailin Liu, Qiaoyan Wen
CANS3
2005 Construction of nonbinary quantum cyclic codes by using graph method
Tailin Liu, Qiaoyan Wen
Sci. China Ser. F Inf. Sci.2