VLDB 2026 Research / reviewers in the wild / expert
Kefei Chen
dblp:66/5496
· DBLP profile ↗
140ranked-venue papers
1as first author
41since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 64 · 1 first-author · 19 since 2021Applied, interdisciplinary, general and emerging computing · 22 · 4 since 2021Databases, data management, data science and information retrieval · 15Systems, architecture and hardware · 13 · 5 since 2021Computer networks · 12 · 8 since 2021Artificial intelligence and machine learning · 6 · 1 since 2021Theory of computation · 4 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A blind signature-based authorization scheme for enhancing the privacy of Cloud-Assisted private set intersection
Yunhao Yang, Bin Lian, Xiaotie Wang, Jialin Cui, Xianghong Zhao, Fuqun Wang, Kefei Chen |
Comput. Networks | 9 |
| 2026 | Lightweight Attribute-Based Matchmaking Encryption Scheme for Healthcare IoTabstractThe healthcare Internet of Things (IoT), which relies on wearable devices to collect patient health data and aggregate it on cloud server, plays a key role in modern healthcare system. How to achieve bidirectional access control while ensuring secure information transmission is a significant challenge facing the healthcare industry. Identity-based matchmaking encryption (IB-ME) and attribute-based matchmaking encryption (AB-ME) show great research potential in achieving these functions. However, IB-ME schemes are typically limited to one-to-one scenarios. While AB-ME enables flexible many-to-many communication, its high communication overhead made it difficult for direct application in resource-constrained environments. Therefore, striking a balance between functionality and efficiency is crucial. Moreover, in healthcare IoT system, user deletion or revocation of decryption permission may be necessary due to the possibility of malicious behavior, organization changes, or discontinuing subscription services. To address these issues, this paper proposes an efficient revocable attribute-based matchmaking encryption (RAB-ME) scheme for healthcare IoT systems. This scheme not only supports bilateral access control but also enables user permission revocation while maintaining high efficiency. We analyzed the privacy and authenticity of this scheme based on the random oracle model. Through extensive comparisons and experimental simulations, our scheme outperforms existing approaches. Xueling Wang, Huige Wang, Kefei Chen, Jiayuan Wei |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | TBFL: blockchain-enabled trusted byzantine-robust federated learning framework for photovoltaic power generation forecastingabstractAbstract Precise forecasting of photovoltaic (PV) power generation upholds flexibility and reliability within the power grid. Due to the data security dilemma of previous forecasting methods, federated learning (FL) has been widely studied for its ability to train models without sharing training data. However, the incorrect behavior from untrusted devices and servers in traditional FL frameworks can undermine the integrity of the global model, precipitating inaccurate power generation forecasting. Therefore, we propose a blockchain-enabled trusted Byzantine-robust FL framework, called TBFL, designed for decentralized and privacy-preserving PV power generation forecasting. Specifically, this framework features a trusted supervision mechanism, which can effectively eliminate malicious gradients to achieve a high-quality model. In addition, a multilevel differential privacy scheme is designed to strike a balance between privacy protection and model accuracy. Finally, a model clipping algorithm based on neuronal similarity is implemented to optimize both the duration and consumption associated with local device training. Comprehensive experimental outcomes demonstrate that the framework TBFL can successfully improve robustness, and achieve similar efficiency as FedAvg while maintaining a high forecasting accuracy. Liangliang Wang 0001, Yiyuan Luo, Kai Zhang 0016, Yu Long 0001, Kefei Chen |
Comput. J. | 6 |
| 2025 | Load-aware switch migration for controller load balancing in edge-cloud architectures
Yong Liu 0045, Kefei Chen, Zhonghua Shen |
Future Gener. Comput. Syst. | 3 |
| 2025 | A Multiserver Authentication Protocol With Integrated Monitoring for IoMT-Based Healthcare SystemabstractInternet of Medical Things-based healthcare system (IoMTHS) is a kind of industrial information system that integrates life monitoring, pathological inference and drug therapy. However, the sensitive nature and high value of its data make it a prime target for cyberattacks. Although many multiserver authentication protocols have been studied in recent years to ensure that only authorized users can access medical services, new vulnerabilities are always identified and covertly utilized by the smarter adversary due to lack of continuous monitoring and dynamic authentication, reducing the trustworthiness of IoMTHS. To address above challenges, in this article, we propose a multiserver authentication scheme with integrated monitoring (MAIM) for IoMTHS, which achieves user locked access control by strictly and continuously binding system access permissions and user behavior. MAIM consists of a three-factor-based static authentication (TFSA) and a deep learning-based continuous authentication (DLCA). TFSA utilizes double-anonymity strategy to protect users’ privacy and track their malicious behaviors, and uses physical unclonable function (PUF) to protect the security of privacy information in users’ devices and servers, which achieves lightweight and three-factor secrecy. The DLCA trains a deep neural network to recognize the legitimacy of users based on the user behavior transmitted by their sensing devices. TFSA is provably secure under the random oracle model, whereas DLCA exhibits high feasibility with experimental accuracy reaching 100%. Qi Xie 0001, Qingyun Xie, Xiumei Li, Debiao He, Kefei Chen |
IEEE Internet Things J. | 6 |
| 2025 | BPRM: Blockchain-Based Privacy Preserving and Robust Data Aggregation Supporting Multifunctionality for Fog-Assisted Smart GridabstractWhile the collection of users’ live or periodic electricity consumption data brings significant advantages for the operation of smart grids, it also heightens the risk of user privacy leakage. Numerous data aggregation schemes have been proposed to address this issue. However, most of these schemes either fail to accommodate the need for multifunctional data analysis or rely on a trusted third party (TTP). Given the efficient data processing capabilities offered by fog computing, we propose a blockchain-based privacy-preserving data aggregation (BPRM) scheme supporting multifunctionality for fog-assisted smart grid without TTP. This scheme ensures data confidentiality and data integrity while providing various statistical functions. In addition, we implement a consensus mechanism between smart meters, further enhancing the security and robustness of the smart grid system. Moreover, not only does the proposed the batch verification reduce the authentication costs but also support error detection in signatures. With BPRM, data center can calculate multiple statistical functions, achieving a win-win strategy. Extensive security and performance analyses demonstrate that BPRM can withstand various security threats and effectively protect user privacy while maintaining efficiency in both computational and communication overhead. Chuankun Zhao, Liangliang Wang 0001, Zhiquan Liu 0001, Kai Zhang 0016, Weiwei Li 0007, Kefei Chen |
IEEE Internet Things J. | 7 |
| 2025 | ALB-TP: Adaptive Load Balancing based on Traffic Prediction using GRU-Attention for Software-Defined DCNs
Kefei Chen, Zhonghua Shen |
J. Netw. Comput. Appl. | 3 |
| 2025 | LPbT-SSO: Password-Based Threshold Single-Sign-On Authentication From LWEabstractIn networks, clients access various servers. Servers need to authenticate clients' identities and provide services to clients who pass the authentication. Password-based threshold single-sign-on authentication (PbT-SSO) delegates multiple identity servers to authenticate a client with the client's password, and issue a token for subsequent access. However, existing PbT-SSO schemes are based on conventional hardness problems, which are vulnerable to adversaries equipped with quantum computers in the near future. Once quantum computers are accessible, adversaries can retrieve passwords by off-line dictionary guessing attacks (DGA) from the credentials of clients' passwords. Moreover, quantum adversaries can derive identity servers' secret from public information and further forge tokens with the secret. Motivated by these issues, we propose a password-based threshold single-sign-on authentication from learning with errors problem (LWE), dubbed LPbT-SSO, which is resistant to quantum attacks. LPbT-SSO evaluates a one-way function of passwords, and takes the function outputs as credentials. Since the function is grounded on LWE problem intractable for quantum computation, quantum adversaries cannot recover passwords by off-line DGA. Additionally, LPbT-SSO leverages a lattice-based threshold signature scheme to issue tokens, and guarantees that no adversary can forge a valid token. The comprehensive performance evaluation demonstrates that LPbT-SSO is efficient in terms of computation, storage, and communication costs. Chenchen Cao, Chunxiang Xu, Changsong Jiang, Zhao Zhang 0026, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Post-Quantum Secure Identity-Based Matchmaking EncryptionabstractMatchmaking encryption constructed in the identity-based encryption setting, named identity-based matchmaking encryption (IB-ME), requires both sender and receiver to specify target identity simultaneously for each other for message decryption. The IB-ME schemes can not only ensure the privacy of the sender and the message but also provide authentication for the data source. In order to resist quantum-attacks, we put forward a post-quantum secure IB-ME scheme. Compared with Ateniese et al.'s scheme and Francati et al.'s scheme, our approach eliminates the use of functional encryption, predicate encryption and signature scheme, and only uses a more simple preimage sampling function and an IBE scheme in the way of non-black-box. Compared with post-quantum secure IB-MEs proposed currently, our scheme is the first non-black-box construction based on standard lattice assumptions such as LWE and ISIS. Huige Wang, Kefei Chen, Qi Xie 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | An Efficient Fuzzy Certificateless Signature-Based Authentication Scheme Using Anonymous Biometric Identities for VANETsabstractVehicular ad hoc networks (VANETs) are essential technologies to ensure safe road traffic management and enhance driving convenience. Nowadays, diversified authentication schemes have been developed in VANETs for the purpose of safer communication between nodes. For instance, biometric technology which employs biometric information as users’ authentic identity is widely adopted in message authentication due to its visible benefits. Nonetheless, there is a significant problem in current biometric identity-based authentication schemes that noise is inevitable in each collection of biometric information, making these schemes lack critical error tolerance. Additionally, anonymous biometric identity is difficult to be realized, which fails to meet the basic standard of VANETs. For solving the above key issues, we propose the first efficient fuzzy certificateless signature-based (FCLS) authentication scheme using anonymous biometric identities for VANETs. In virtue of its superior error tolerance, it enables authentication between two identities represented by two attribute sets within a certain Hamming distance. Besides, the newly developed authentication scheme realizes effective conditional privacy so that drivers’ real biometric identities can be ensured. Through the formal security proof, this FCLS scheme is existentially unforgeable against adaptive chosen message attack (EU-CMA) in the random oracle model (ROM), which reaches the higher security. Compared with current advanced schemes, the new authentication scheme is more efficient in computation and communication according to performance analysis. Liangliang Wang 0001, Jiangwei Xu, Baodong Qin, Mi Wen, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | An Efficient Privacy-Preserving Scheme for Weak Password Collection in Internet of Things Against Perpetual LeakageabstractPassword-based authentication is widely applied in Internet of Things (IoT). It allows IoT devices to identify users with passwords to resist unauthorized access. However, choices of weak passwords, especially popular ones, might violate users’ privacy and lead to large-scale network attacks. Collection of popular passwords among IoT devices to establish blocklists via a service provider can prevent use of weak passwords. To protect unpopular passwords during collection, existing privacy-preserving schemes rely on expensive cryptographic primitives (e.g., garbled circuits and zero-knowledge proofs), which would impose heavy communication and computation burdens on constrained devices and hinder wide deployment of these schemes. In this paper, we propose EAGER+, an efficient privacy-preserving scheme for weak password collection in IoT against perpetual leakage. EAGER+ is mainly built on secret sharing and symmetric encryption, thereby enabling lightweight computation and communication on IoT devices. In EAGER+, we conceive a password-locked encryption with conditional decryption mechanism to efficiently identify popular passwords, where a password is essentially locked under itself in the encryption to guarantee its security, and the password can be revealed from the ciphertext by the service provider only if a sufficient number of devices exploit it. The mechanism is integrated with a servers-aided password-hardening mechanism to resist offline dictionary guessing attacks. Moreover, EAGER+ uses a key renewal mechanism to periodically update secrets for password hardening on key servers to thwart perpetual leakage towards the secrets. We formally analyze the security of EAGER+, and conduct experimental evaluations to show that EAGER+ is more efficient than existing schemes. Changsong Jiang, Chunxiang Xu, Kefei Chen, Guomin Yang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Blockchain-based immunization against kleptographic attacks
Changsong Jiang, Chunxiang Xu, Kefei Chen |
Sci. China Inf. Sci. | 4 |
| 2024 | TAAC: Secure and Efficient Time-Attribute-Based Access Control Scheme in SDN-IoTabstractThe convergence of software‐defined networking (SDN) and the Internet of Things (IoT) provides a scalable method for handling the considerable volumes of data produced by IoT devices. However, the lack of appropriate security measures can lead to unauthorized access to sensitive data, potential breaches, and privacy violations, as well as time‐consuming and inefficient data retrieval methods in SDN‐IoT systems that require decrypting the entire dataset. To address these challenges, this article proposes the time‐attribute‐based access control scheme in SDN‐IoT (TAAC). The TAAC scheme combines ciphertext‐policy attribute‐based encryption with a novel time‐attribute‐based access tree to ensure fine‐grained access control on time and attributes, enabling secure ciphertext interaction and information sharing across domains. Furthermore, the TAAC scheme also incorporates searchable encryption, which enhances the efficiency of data retrieval. By implementing searchable encryption techniques, the data receiver can generate trapdoors to search and retrieve specific encrypted data without the need to decrypt the entire dataset. In summary, the TAAC scheme improves storage efficiency and computation, enhances scalability, and provides robust security, offering an efficient and secure solution for ciphertext sharing in SDN‐IoT environments. Experimental results have demonstrated that the TAAC scheme shows excellent performance and outperforms other attribute‐based searchable encryption algorithms. Zhonghua Shen, Kefei Chen, Fuqun Wang, Yong Liu 0053 |
IET Inf. Secur. | 3 |
| 2024 | Trusted Location Sharing on Enhanced Privacy-Protection IoT Without Trusted CenterabstractMany IoT applications require users to share their devices’ location, and enhanced privacy-protection means sharing location anonymously, unlinkably and without relying on any administrators. But under such protection, it is difficult to trust shared location data, which may be from unregistered devices or from the same one’s multiple logins or from the cloned device ID, even be generated by an attacker without any devices! Such untrusted location sharing cheats system, misleads users, even attacks system. To the best of our knowledge, such problems have not been solved in a decentralized system. To solve them in one scheme, we put forward the first decentralized accumulator for device registration and construct the first practical decentralized anonymous authentication for device login. When logging in, the device provides a special knowledge proof, which integrates zero-knowledge (for privacy) with knowledge-leakage (for identifying abnormal behaviors) designing for blockchain (for decentralization). Therefore, in our system, only registered IoT devices can upload location data and their logins are anonymous and unlinkable, while login exceeding${K}$times in a system period or cloning ID to login concurrently can be identified and tracked without any trusted centers. In addition, we provide the security proofs and the application examples of the proposed scheme. And the efficiency analysis and experimental data show that the performance of our scheme can meet the needs of real-world location sharing on IoT. Bin Lian, Jialin Cui, Hongyuan Chen, Xianghong Zhao, Fuqun Wang, Kefei Chen, Maode Ma |
IEEE Internet Things J. | 6 |
| 2024 | A Security-Enhanced Conditional Privacy-Preserving Certificateless Aggregate Signature Scheme for Vehicular Ad-Hoc NetworksabstractVehicular ad-hoc networks (VANETs) can help facilitate traffic flow, reduce accidents, and enhance the driving experience. However, VANETs have some problems in terms of the authenticity and integrity of transmitted information and the preservation of vehicles’ privacy. Many certificateless aggregate signature (CLAS) schemes have been proposed to address these concerns. Nevertheless, most of these schemes suffer from security and efficiency challenges, such as the inability to resist forgery attacks and high computation costs. Recently, an efficient CLAS scheme with conditional privacy protection has been put forward by Chen et al. However, there is a security flaw in this scheme. In this paper, we give a specific attack algorithm to indicate that Chen et al.’s proposal cannot resist a public key replacement attack initiated by external adversaries and then put forward a security-enhanced scheme. Furthermore, an efficient invalid signature identification algorithm is designed to identify invalid signatures after an aggregate verification has failed. Through rigorous security analysis, it has been verified that the scheme put forward can satisfy the fundamental security requirements of VANETs. Compared with other related schemes, our proposal improves efficiency while providing privacy and security guarantees for VANETs. Liangliang Wang 0001, Yiyuan Luo, Yu Long 0001, Kai Zhang 0016, Hailun Yan, Kefei Chen |
IEEE Internet Things J. | 7 |
| 2024 | A blockchain-based framework for federated learning with privacy preservation in power load forecasting
Qifan Mao, Liangliang Wang 0001, Yu Long 0001, Lidong Han, Kefei Chen |
Knowl. Based Syst. | 6 |
| 2024 | A Secure Two-Factor Authentication Key Exchange SchemeabstractTwo-factor authentication key exchange (AKE) is an effective way to strengthen the security of password-authenticated key exchange. Most two-factor AKE schemes using smart cards as the second factor require users to have the second factor with them any time, which causes users inconveniences. Biometrics provide a user-friendly manner to achieve two-factor AKE since they need not be carried. However, biometrics may have less entropy than expected and would suffer from offline guessing attacks. In this paper, we propose a secure two-factor authentication key exchange scheme TAKE that resists offline guessing attacks against biometrics and passwords. In TAKE, a user generates a combined factor of his/her biometrics and password. To protect the combined factor, the user and the server leverages secure two-party computation to blind it with a key which is protected in a trusted execution environment. Thus, TAKE prevents an adversary from eavesdropping on the combined factor, and simultaneously guarantees that he cannot recover the combined factor from blinded one to undertake offline guessing attacks even if he compromises the server and obtains the blinded combined factor. We provide the formal security proof of TAKE. The experiments show that TAKE is efficient in terms of storage, computation, and communication overhead. Yunxia Han, Chunxiang Xu, Changsong Jiang, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | TSAPP: Threshold Single-Sign-On Authentication Preserving PrivacyabstractSingle-sign-on (SSO) authentication enables a user to gain a token from the identity server, with which the user accesses multiple services. To address single-point-of-failure of SSO, threshold SSO, where a group of identity servers issue a user with a token in the threshold manner, is introduced. SSO including threshold schemes suffers from privacy disclosure. One can learn a user's identity and access pattern from her/his token. Recent works focus on privacy preservation of SSO. However, these works merely consider scenarios of one single identity server SSO. No works that address privacy preservation of threshold SSO have emerged. In this work, we propose TSAPP, a threshold SSO authentication scheme preserving privacy. Each identity server issues a user with a partial token which is a signature on the user's pseudonym. With a threshold number of partial tokens, the user constructs a token, blinds the token with random numbers and accesses services with blinded tokens. Such mechanism preserves the user's identity, simultaneously protects the user's access pattern since adversaries cannot link the user's accesses, even if identity servers are corrupted. Security analysis demonstrates that TSAPP satisfies properties of anonymity, unlinkability, unforgeability and password-safety. The performance evaluation demonstrates that TSAPP is efficient in practice. Zhao Zhang 0026, Chunxiang Xu, Changsong Jiang, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Two-Factor Authenticated Key Exchange From Biometrics With Low Entropy RatesabstractMulti-factor authenticated key exchange (AKE) enables a user to be authenticated by a server using multiple factors and negotiate a shared session key to protect subsequent communications. Most existing multi-factor AKE schemes utilize biometrics as one factor due to their uniqueness and invariance properties. To support matching for noisy biometrics and protect them, fuzzy extractors are employed to extract a constant random string from varying biometric measurements without disclosing biometric data. However, the fuzzy extractors used in these schemes merely work on biometrics with an entropy rate greater than the error rate. Hence these schemes are unsuitable for biometrics with low entropy rates. In this paper, we propose a secure two-factor AKE scheme dubbed AHEAD from passwords and biometrics, which eliminates the limitation of biometric entropy rates. In AHEAD, we conceive a matching mechanism to simultaneously check whether an input biometric measurement with low entropy rates is close enough to the registered one, and whether an input password exactly matches the registered password. The mechanism allows a valid user to generate a secret element shared with the server in an oblivious way. By adopting a randomization technique, the secret element can be randomized for derivation of session keys. The security and efficiency of AHEAD are demonstrated by formal security proofs and experimental evaluations. Changsong Jiang, Chunxiang Xu, Yunxia Han, Zhao Zhang 0026, Kefei Chen |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | DCIRM: Dynamic and Controllable Image Retrieval Scheme in Multi-Owner Multi-User SettingsabstractThe proliferation of cloud computing technology has led to a significant number of users opting to store image data on the cloud. To ensure the confidentiality of image data, it is recommended to apply encryption techniques prior to uploading them to cloud servers. However, the traditional encrypted image retrieval schemes prove inadequate for practical application scenarios due to limitations in supporting multi-owner and multi-user settings, inefficient access control, and a lack of dynamic verifiability. To address the challenges presented by practical application scenarios, in this paper, we propose a Dynamic and Controllable Image Retrieval scheme in the Multi-owner multi-user settings (DCIRM). First of all, we realize the usability in multi-owner and multi-user scenarios through re-encryption settings. Then, we realize the verifiability of dynamic data by applying the dynamic authentication constructed by the chameleon hash function. Finally, we realize lightweight access control through the polynomial-based access strategy. The DCIRM scheme has been demonstrated to be privacy-preserving, efficient, and feasible through rigorous security analysis and experimentation with authentic datasets. Chenyang Mao, Zhonghua Shen, Kefei Chen, Yong Liu 0053, Fuqun Wang |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | An Efficient Privacy-Preserving Scheme for Weak Password Collection in Internet of Things
Changsong Jiang, Chunxiang Xu, Kefei Chen |
Inscrypt (2) | 3 |
| 2023 | A Publicly Verifiable Leveled Fully Homomorphic Signcryption SchemeabstractWith the deepening of research, how to construct a fully homomorphic signcryption scheme based on standard assumptions is a problem that we need to solve. For this question, recently, Jin et al. proposed a leveled fully homomorphic signcryption scheme from standard lattices. However, when verifying, it is supposed to unsigncrypt first as they utilize sign‐then‐encrypt method. This leads to users being unable to verify the authenticity of the data first, which resulting in the waste of resources. This raises another question of how to construct an fully homomorphic signcryption (FHSC) scheme with public verifiability. To solve this problem, we propose a leveled fully homomorphic signcryption scheme that can be publicly verified and show its completeness, IND‐CPA security, and strong unforgeability. Zhaoxuan Bian, Fuqun Wang, Renjun Zhang, Bin Lian, Lidong Han, Kefei Chen |
IET Inf. Secur. | 6 |
| 2023 | Backdoor-Resistant Public Data Integrity Verification Scheme Based on Smart ContractsabstractThis article analyzes existing smart contract-based public data integrity verification schemes and identifies certain weaknesses. First, the fair arbitration mechanism deployed in these schemes fails to meet the users’ requirements as it may not promptly notify users of data corruption or loss. Second, to ensure outsourced data confidentiality, existing data integrity schemes use a conventional encrypted method, where each user randomly selects a key to encrypt the outsourced data. Such a method results in varying ciphertexts for the same data by different users, leading to additional storage costs for the cloud server. Third, users’ devices, if poorly designed or even intentionally backdoored, can potentially exfiltrate secrets and compromise the security of schemes. To address these issues, we propose the first backdoor-resistant public data integrity verification scheme based on smart contracts (ASSIST). The key idea is to introduce a new entity (a whistleblower) to periodically monitor the state of verification results recorded in the blockchain. This allows for timely notification of data corruption to users. ASSIST requires users to encrypt their data with a cryptographic primitive called message-locked encryption (MLE), which motivates different users to produce the same ciphertext for the same data and reduces storage costs for cloud servers. We also deploy a cryptographic reverse firewall between users’ devices and the external to rerandomize interactive messages, making the exfiltration impossible. We provide rigorous security proofs to demonstrate the security of ASSIST. The performance evaluation shows that ASSIST is efficient regarding computation and communication costs. Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Yicong Du, Anjia Yang, Xinsheng Wen, Kefei Chen |
IEEE Internet Things J. | 7 |
| 2023 | ttPAKE: Typo tolerance password-authenticated key exchange
Yunxia Han, Chunxiang Xu, Shanshan Li 0004, Changsong Jiang, Kefei Chen |
J. Inf. Secur. Appl. | 5 |
| 2023 | GAIN: Decentralized Privacy-Preserving Federated Learning
Changsong Jiang, Chunxiang Xu, Chenchen Cao, Kefei Chen |
J. Inf. Secur. Appl. | 4 |
| 2023 | SR-PEKS: Subversion-Resistant Public Key Encryption With Keyword SearchabstractPublic key encryption with keyword search (PEKS) provides secure searchable data encryption in cloud storage. Users can outsource encrypted data and keywords to a cloud server, and search target one without disclosing sensitive information. To achieve resistance against off-line keyword guessing attacks, existing practical PEKS schemes employ independent key server(s) to assist users in producing keywords to be encrypted (called server-derived keywords) in an online manner. In this article, we analyze server-aided PEKS schemes and reveal a potential threat: vulnerability against subversion attacks, where algorithms in server-aided PEKS might be maliciously implemented to undermine security. In a subverted encryption implementation, a subliminal channel is established to control randomness generation such that biased ciphertexts covertly leak plaintext information. We further present a specific subversion attack against generation of server-derived keywords to violate keywords’ confidentiality. To address these issues, we propose SR-PEKS, a subversion-resistant PEKS scheme based on cryptographic reverse firewalls (CRF). In SR-PEKS, CRF sanitizes messages transmitted in server-derived keyword generation to resist the presented subversion attack. CRF also participates in a collaborative randomness generation protocol to yield unbiased randomness for encryption, thereby eliminating the subliminal channel. Provable security and high efficiency of SR-PEKS are demonstrated by comprehensive analyses and performance evaluations. Changsong Jiang, Chunxiang Xu, Zhao Zhang 0026, Kefei Chen |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | Blockchain-Based Transparent Integrity Auditing and Encrypted Deduplication for Cloud StorageabstractIn this paper, we introduce a concept of transparent integrity auditing and propose a concrete scheme based on the blockchain, which goes one step beyond existing public auditing schemes, since the auditing does not rely on third-party auditors while freeing users from heavy communication costs on auditing the data integrity. Then we construct a secure transparent deduplication scheme based on the blockchain that supports deduplication over encrypted data and enables users to attest the deduplication pattern on the cloud server. Such a scheme allows users to directly benefit from data deduplication and protects data content against anyone who does not own the data. Finally, we integrate the proposed transparent integrity auditing scheme and transparent deduplication scheme into one system, dubbed BLIND. We evaluate BLIND from security and efficiency, which demonstrates that BLIND achieves a strong security guarantee with high efficiency. Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Yicong Du, Kefei Chen |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | Provable Data Possession Schemes from Standard Lattices for Cloud ComputingabstractAbstract Provable Data Possession (PDP) is of crucial importance in public cloud storage since it allows users to check the integrity of their outsourced data without downloading it. However, the existing PDP schemes, which are based on classical number-theoretic assumptions, are insecure under quantum attacks. In this paper, we propose the first PDP scheme from standard lattices, using a specific leveled fully homomorphic signature (FHS) scheme. To remove the complex key management of PDP cryptosystem on the public key infrastructure (PKI) setting, we employ a specific leveled identity-based (ID-based) FHS scheme to construct the first ID-based PDP scheme from standard lattices. Our two PDP schemes are secure under the standard small integer solution (SIS) assumption, which is conjectured to withstand quantum attacks. Furthermore, we conduct experimental evaluations to validate the feasibility of the proposed PDP schemes in practice. Saif M. Al-Kuwari, Changlu Lin, Fuqun Wang, Kefei Chen |
Comput. J. | 5 |
| 2022 | Efficient Certificateless Online/Offline Signcryption Scheme for Edge IoT DevicesabstractThe emergence of edge computing brings data processing and storage to the vicinity of terminal equipment, which can quickly respond to user needs and reduce the computational burden of the traditional centralized cloud computing model, resulting in a model of edge computing-assisted cloud computing. In this architecture, how to prevent other untrusted entities from leaking user privacy has become one of the most critical concerns. To address this concern, many cryptographic schemes supporting the traditional cloud model to protect the data security sharing of IoT devices have been proposed. However, resource-constrained devices are an essential component of the Internet of Things (IoT). Its characteristics are one of the main reasons that affect the efficiency of schemes, and traditional cryptographic schemes are not suitable for edge computing. Therefore, in order to ensure secure data sharing between IoT devices, we come up with an improved certificateless online/offline signcryption (CLOOSC) scheme and achieve lower computational overhead, when offline calculation is not considered, the resource-constrained IoT device under the cloud-edge collaboration architecture requires only one point multiplication, while only one bilinear pairing is required in the verification phase. In the random oracle model, our scheme is proved to be IND-CCA2 secure. The experiment results show our scheme can be lightweight in terms of time cost. Liangliang Wang 0001, Mi Wen, Kai Zhang 0016, Kefei Chen |
IEEE Internet Things J. | 5 |
| 2022 | A sanitizable signcryption scheme with public verifiability via chameleon hash function
Renjun Zhang, Fuqun Wang, Kefei Chen, Bin Lian, Gongliang Chen |
J. Inf. Secur. Appl. | 4 |
| 2022 | A blockchain-based dynamic and traceable data integrity verification scheme for smart homes
Chunliang Chen, Liangliang Wang 0001, Yu Long 0001, Yiyuan Luo, Kefei Chen |
J. Syst. Archit. | 5 |
| 2022 | An efficient conditional privacy-preserving authentication scheme with scalable revocation for VANETs
Leyan Shen, Liangliang Wang 0001, Kai Zhang 0016, Jinguo Li, Kefei Chen |
J. Syst. Archit. | 5 |
| 2022 | On the Security of Verifiable Searchable Encryption SchemesabstractWith cloud services, data users can retrieve encrypted data while preserving data confidentiality. However, this new paradigm suffers from many security concerns. A major concern is how to avoid insider Keyword-Guessing Attacks (KGA), which implies that the internal attackers can guess the candidate keywords successfully in an off-line manner. To address this issue, recently, two verifiable searchable encryption schemes (published in IEEE Transactions on Cloud Computing, doi: 10.1109/TCC.2020.2989296) in cloud storage were proposed which enjoys many desirable features. In this letter, we demonstrate that the schemes are insecure against insider keyword-guessing attack. Specifically, we show that the adversary can derive the keywords in an off-line manner. Chuang Li 0008, Chunxiang Xu, Shanshan Li 0004, Kefei Chen, Yinbin Miao |
IEEE Trans. Cloud Comput. | 4 |
| 2021 | Compressible Multikey and Multi-Identity Fully Homomorphic EncryptionabstractWith the development of new computing models such as cloud computing, user’s data are at the risk of being leaked. Fully homomorphic encryption (FHE) provides a possible way to fundamentally solve the problem. It enables a third party who does not know anything about the secret key and plaintexts to homomorphically perform any computable functions on the corresponding ciphertexts. In 2009, Gentry proposed the first FHE scheme. After that, its inefficiency has always been a bottleneck of the development of practical schemes and applications. At TCC 2019, Gentry and Halevi proposed the first compressible FHE scheme that enables the ratio of plaintext size to the ciphertext size (i.e., the compression rate) to reach 1−ε for any small ε>0 under the standard learning with errors (LWE) assumption. However, it is only a single-key one, where the homomorphic evaluation can only be performed over ciphertexts encrypted under the same key. Compared with single-key FHE, multikey FHE is more practical. Multikey FHE enables ciphertexts encrypted under different public keys to be homomorphically computed without having to decrypt these ciphertexts using their own private keys. In addition, in a multi-identity FHE scheme, only identity information and public parameters are required when encrypting, which simplifies certificate-based key management in public key infrastructure. In this paper, a new compressible ciphertext expansion technique is proposed. Then, we use this technique to construct a compressible multikey FHE scheme and a compressible multi-identity FHE scheme to overcome the bottleneck of bandwidth inefficiency in the multikey and multi-identity settings. The two schemes proposed in this paper make it possible that the objects of homomorphic operation can be the ciphertexts encrypted under different keys or different identities before compression, thus solving the single-key defect of the work of Gentry and Halevi. Tongchen Shen, Fuqun Wang, Kefei Chen, Zhonghua Shen, Renjun Zhang |
Secur. Commun. Networks | 3 |
| 2021 | CLE against SOA with Better Data Security Storage to Cloud 5GabstractCloud 5G and Cloud 6G technologies are strong backbone infrastructures to provide high data rate and data storage with low latency for preserving QoS (Quality of Service) and QoE (Quality of Experience) in applications such as driverless vehicles, drone-based deliveries, smart cities and factories, remote medical diagnosis and surgery, and artificial-intelligence-based personalized assistants. There are many techniques to support the aforementioned applications, but for privacy preservation of Cloud 5G, the existing methods are still not sufficient. Public key encryption (PKE) scheme is an important means to protect user data privacy in Cloud 5G. Currently, the most common PKE used in Cloud 5G is CCA or CPA secure ones. However, its security level maybe not enough. SOA security is a stronger security standard than CPA and CCA. Roughly speaking, PKE with SOA security means that the adversary is allowed to open a subset of challenger ciphertexts and obtains the corresponding encrypted messages and randomness, but the unopended messages and randomness remain secure in the rest of the challenger ciphertexts. Security against SOA in PKEs has been a research hotspot, especially with the wide discussion in Cloud 5G. We revisited the SOA-CLE and proposed a new security proof, which is more concise and user friendly to understand privacy preservation in Cloud 5G applications. Huige Wang, Xing Chang, Kefei Chen |
Secur. Commun. Networks | 3 |
| 2021 | Attribute-based proxy re-encryption from standard lattices
Saif M. Al-Kuwari, Fuqun Wang, Kefei Chen |
Theor. Comput. Sci. | 4 |
| 2021 | CPA/CCA2-secure PKE with squared-exponential DFR from low-noise LPN
Shengfeng Xu, Xiangxue Li, Haifeng Qian, Kefei Chen |
Theor. Comput. Sci. | 4 |
| 2021 | Multi-Client Sub-Linear Boolean Keyword Searching for Encrypted Cloud Storage with Owner-Enforced AuthorizationabstractTo date, cloud computing has emerged as a primary utility for providing remote data storage services for users, since users can thus be relieved from cumbersome document maintenance. Despite of the benefits brought by data outsourcing, the unexpected data breaches raise concerns about data confidentiality and privacy. To deal with this, a straightforward and convincing strategy is to encrypt data before outsourcing them to the cloud. However, securely sharing and searching over outsourced encrypted data has turned into a challenge due to the hindrance led by data encryption. To address the challenge, this article proposes a new highly-scalable searchable encryption scheme for encrypted cloud storage. The scheme achieves sub-linear Boolean keyword searching, and moreover allows the data owner to authorize which clients could search or access the documents in the cloud. Technically, we revisit searchable symmetric encryption primitive by non-trivially combining it with a novel access control technique, and build an inverted index data structure for both attribute-based access control and sub-linear search process. Furthermore, we introduce a formalized security definition for the system, and prove its security in the simulation-based security model. Finally, we conduct a couple of experiments over a representative real-world dataset to show practicality. Kai Zhang 0016, Mi Wen, Rongxing Lu, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Cryptoanalysis of an Authenticated Data Structure Scheme With Public Privacy-Preserving AuditingabstractIn this letter, we point out that the privacy-preserving adaptive trapdoor hash authentication tree scheme (published in IEEE TIFS, doi: 10.1109/TIFS.2020.2986879) can be invalidated by an adversarial cloud server: if the outsourced data is arbitrarily modified, the cloud server still can pass the third-party auditor's auditing. Shiyu Li 0002, Yuan Zhang 0006, Chunxiang Xu, Kefei Chen |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Security Analysis of a Path Validation Scheme With Constant-Size ProofabstractWe analyze a path validation scheme with constant-size proof (published in IEEE Transactions on Information Forensics and Security) and demonstrate that this scheme fails to achieve unforgeability. An adversary can forge a valid proof with a non-negligible probability. Changsong Jiang, Chunxiang Xu, Kefei Chen |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Explaining similarity for SPARQL queries
Meng Wang 0009, Kefei Chen, Hongxu Chen 0002, Sen Wang 0001 |
World Wide Web | 2 |
| 2020 | Blockchain-Based Efficient Public Integrity Auditing for Cloud Storage Against Malicious Auditors
Shanshan Li 0004, Chunxiang Xu, Yuan Zhang 0006, Anjia Yang, Xinsheng Wen, Kefei Chen |
Inscrypt | 6 |
| 2020 | Reusable Fuzzy Extractor Based on the LPN AssumptionabstractAbstract A fuzzy extractor derives uniformly random strings from noisy sources that are neither reliably reproducible nor uniformly random. The basic definition of fuzzy extractor was first formally introduced by Dodis et al. and has achieved various applications in cryptographic systems. However, it has been proved that a fuzzy extractor could become totally insecure when the same noisy random source is extracted multiple times. To solve this problem, the reusable fuzzy extractor is proposed. In this paper, we propose the first reusable fuzzy extractor based on the LPN assumption, which is efficient and resilient to linear fraction of errors. Furthermore, our construction serves as an alternative post-quantum reusable fuzzy extractor. Shengli Liu 0001, Dawu Gu, Kefei Chen |
Comput. J. | 4 |
| 2020 | Functional encryption with application to machine learning: simple conversions from generic functions to quadratic functions
Huige Wang, Kefei Chen, Yuan Zhang 0006, Yunlei Zhao |
Peer-to-Peer Netw. Appl. | 2 |
| 2020 | A New User Revocable Ciphertext-Policy Attribute-Based Encryption with Ciphertext UpdateabstractThe revocable ciphertext-policy attribute-based encryption (R-CP-ABE) is an extension of ciphertext-policy attribute-based encryption (CP-ABE), which can realize user direct revocation and maintain a short revocation list. However, the revoked users can still decrypt the previously authorized encrypted data with their old key. The R-CP-ABE scheme should provide a mechanism to protect the encrypted data confidentiality by disqualifying the revoked users from accessing the previously encrypted data. Motivated by practical needs, we propose a new user R-CP-ABE scheme that simultaneously supports user direct revocation, short revocation list, and ciphertext update by incorporating the identity-based and time-based revocable technique. The scheme provides a strongly selective security proof under the modified decisional q -parallel bilinear Diffie–Hellman Exponent problem, where “strongly” means that the adversary can query the secret key of a user whose attribute set satisfies the challenge ciphertext access structure and whose identity is in the revocation list. Zhe Liu 0034, Fuqun Wang, Kefei Chen, Fei Tang 0001 |
Secur. Commun. Networks | 3 |
| 2020 | Practical CCA-Secure Functional Encryptions for Deterministic FunctionsabstractFunctional encryption (FE) can implement fine-grained control to encrypted plaintext via permitting users to compute only some specified functions on the encrypted plaintext using private keys with respect to those functions. Recently, many FEs were put forward; nonetheless, most of them cannot resist chosen-ciphertext attacks (CCAs), especially for those in the secret-key settings. This changed with the work, i.e., a generic transformation of public-key functional encryption (PK-FE) from chosen-plaintext (CPA) to chosen-ciphertext (CCA), where the underlying schemes are required to have some special properties such as restricted delegation or verifiability features. However, examples for such underlying schemes with these features have not been found so far. Later, a CCA-secure functional encryption from projective hash functions was proposed, but their scheme only applies to inner product functions. To construct such a scheme, some nontrivial techniques will be needed. Our key contribution in this work is to propose CCA-secure functional encryptions in the PKE and SK environment, respectively. In the existing generic transformation from (adaptively) simulation-based CPA- (SIM-CPA-) secure ones for deterministic functions to (adaptively) simulation-based CCA- (SIM-CCA-) secure ones for randomized functions, whether the schemes were directly applied to CCA settings for deterministic functions is not implied. We give an affirmative answer and derive a SIM-CCA-secure scheme for deterministic functions by making some modifications on it. Again, based on this derived scheme, we also propose an (adaptively) indistinguishable CCA- (IND-CCA-) secure SK-FE for deterministic functions. The final results show that our scheme can be instantiated under both nonstandard assumptions (e.g., hard problems on multilinear maps and indistinguishability obfuscation (IO)) and under standard assumptions (e.g., DDH, RSA, LWE, and LPN). Huige Wang, Kefei Chen, Tianyu Pan 0002, Yunlei Zhao |
Secur. Commun. Networks | 2 |
| 2020 | Privacy-Preserving Location-Based Services Query Scheme Against Quantum AttacksabstractLocation-based service (LBS) provides more and more conveniences to people. However, it also brings potential threats of offending users' privacy. How to protect users' privacy in LBS schemes has aroused increasing research interests in recent years. Most of the existing privacy-preserving LBS schemes are based on the hardness of traditional number-theoretic problems such as the integer factorization or the discrete logarithm problems. However, with the development of large scale quantum computers, these traditional problems can be easily solved by Shor's algorithms, hence the security of these LBS schemes is greatly threatened. In this paper, we solve this problem by constructing a privacy-preserving LBS scheme against quantum attacks from an LWE-based key-homomorphic pseudorandom functions (PRF). In our scheme, due to the key-homomorphic property of the PRF, an LBS user only has to compute one PRF value of the target location and the remaining computation is outsourced to a cloud server, which releases the user from heavy computation burden. In addition, by dividing the key encrypting LBS data into two parts and assigning the two parts to the cloud sever and each user respectively, our scheme avoids the threats of key abuse and information leaking of LBS data. Moreover, we use this PRF to realize an authenticated protocol, which protects the communications between the LBS users and the cloud server. We stress that the security of our scheme is based only on the security of the LWE-based key-homomorphic PRF, hence our scheme is the first LBS scheme secure against quantum attacks. Ziyuan Hu, Shengli Liu 0001, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | On the Security of a Key Agreement and Key Protection SchemeabstractWe point out that the key agreement and key protection scheme (published in IEEE Transactions on Information Forensics and Security, doi: 10.1109/TIFS.2018.2850299) fails to achieve the two-factor security. We demonstrate that in the scheme, if an adversary can control the master device of a target user, he can impersonate the user to pass the server's authentication. Yunxia Han, Chunxiang Xu, Debiao He, Kefei Chen |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | Certificateless Identity-Concealed Authenticated Encryption Under Multi-KGC
Chuang Li 0008, Chunxiang Xu, Yunlei Zhao, Kefei Chen |
Inscrypt | 4 |
| 2019 | An efficient \(\mathcal{iO}\) -based data integrity verification scheme for cloud storage
Lixue Sun, Chunxiang Xu, Yuan Zhang 0006, Kefei Chen |
Sci. China Inf. Sci. | 4 |
| 2019 | A new VRSA-based pairing-free certificateless signature scheme for fog computingabstractSummary Fog computing is composed of various computers with weak performance instead of servers with strong performance. As history has shown, there has not been a general pairing‐free certificateless signature scheme that is mainly designed with modular exponentiation and modular multiplication that can possess resistance to Type I and Type II adversaries. The lightweight certificateless signature algorithm with low requirements for computing and storage capabilities, which can be practicably implemented in fog computing, needs to be studied. Therefore, a new hard mathematic problem is firstly defined in this paper, which is called variant of RSA problem. Then, a new general pairing‐free certificateless signature scheme is proposed based on the variant of RSA problem and the discrete logarithm problem. Fortunately, the proposed scheme is the first RSA‐based certificateless signature scheme that can possess resistance to Type I and Type II adversaries. A formal security proof is provided to demonstrate that, under adaptively chosen message attacks, the scheme is provably secure against Type I and Type II adversaries in the random oracle model. When compared with other known pairing‐free certificateless signature schemes of the same type, the computation cost of our scheme is slightly higher; however, a higher security level can be achieved. Liangliang Wang 0001, Mi Wen, Kefei Chen, Zhongqin Bi, Yu Long 0001 |
Concurr. Comput. Pract. Exp. | 3 |
| 2019 | Fully homomorphic encryption based on the ring learning with rounding problemabstractAlmost all existing well‐known fully homomorphic encryption (FHE) schemes, which are based on either the learning with errors (LWE) or the ring LWE problem, require expensive Gaussian noise sampling. In this study, the authors propose an FHE scheme based on the ring learning with rounding (RLWR) problem. The learning with rounding (LWR) problem was proposed as a deterministic variant of LWE, while the RLWR is a variant of LWR. Sampling an LWR instance does not require Gaussian noise sampling process, and neither does an RLWR instance. Thus, our FHE scheme can be instantiated without the need for Gaussian noise sampling. To implement homomorphic operations, we devise a specific relinearisation method. Furthermore, we also prove that our RLWR‐based FHE scheme is IND‐CPA secure under RLWR assumption. Fuqun Wang, Kunpeng Wang 0001, Kefei Chen |
IET Inf. Secur. | 4 |
| 2019 | A more efficient leveled strongly-unforgeable fully homomorphic signature scheme
Fuqun Wang, Kunpeng Wang 0001, Kefei Chen |
Inf. Sci. | 4 |
| 2019 | Functional broadcast encryption with applications to data sharing for cloud storage
Huige Wang, Yuan Zhang 0006, Kefei Chen, Guangye Sui, Yunlei Zhao, Xinyi Huang 0001 |
Inf. Sci. | 3 |
| 2019 | Detailed analysis and improvement of an efficient and secure identity-based public auditing for dynamic outsourced data with proxy
Jining Zhao, Chunxiang Xu, Kefei Chen |
J. Inf. Secur. Appl. | 3 |
| 2019 | Double-authentication-preventing signatures revisited: new definition and construction from chameleon hashabstractDouble-authentication-preventing signature (DAPS) is a novel signature notion proposed at ESORICS 2014. The double-authentication-preventing property means that any pair of signatures on two different messages with the same subject will result in an immediate collapse of the signature system. A few potential applications of DAPS have been discussed by its inventors, such as providing a kind of self-enforcement to discourage certificate authority (CA) from misbehaving in public key infrastructure and offering CA some cryptographic arguments to resist legal coercion. In this study, we focus on some fundamental issues on DAPS. We propose a new definition, which is slightly weakened but still reasonable and strong enough to capture the DAPS concept. We develop the new notion of invertible chameleon hash functions with key exposure. Then we propose a generic DAPS scheme, which is provably secure if the underlying invertible chameleon hash function with key exposure is secure. We instantiate this general construction to obtain the DAPS schemes respectively based on the well-known assumptions of integer factorization, Rivest-Shamir-Adleman (RSA), and computational Diffie-Hellman (CDH). They are more efficient than previous DAPS schemes. Furthermore, unlike previous constructions, the trusted setup condition is not needed by our DAPS schemes based on RSA and CDH. Fei Li 0006, Wei Gao 0007, Guilin Wang, Kefei Chen, Chunming Tang 0003 |
Frontiers Inf. Technol. Electron. Eng. | 4 |
| 2018 | Revocable Identity-Based Encryption from the Computational Diffie-Hellman Problem
Ziyuan Hu, Shengli Liu 0001, Kefei Chen, Joseph K. Liu |
ACISP | 3 |
| 2018 | Leakage-Resilient Chosen-Ciphertext Secure Functional Encryption from Garbled Circuits
Huige Wang, Kefei Chen, Joseph K. Liu, Ziyuan Hu |
ISPEC | 2 |
| 2018 | Secure searchable public key encryption against insider keyword guessing attacks from indistinguishability obfuscation
Lixue Sun, Chunxiang Xu, Mingwu Zhang, Kefei Chen, Hongwei Li 0001 |
Sci. China Inf. Sci. | 4 |
| 2018 | LR-RRA-CCA secure functional encryption for randomized functionalities from trapdoor HPS and LAF
Huige Wang, Kefei Chen, Baodong Qin, Ziyuan Hu |
Sci. China Inf. Sci. | 2 |
| 2018 | Efficient identity-based threshold decryption scheme from bilinear pairings
Wei Gao 0007, Guilin Wang, Kefei Chen |
Frontiers Comput. Sci. | 3 |
| 2018 | Access control encryption with efficient verifiable sanitized decryption
Huige Wang, Kefei Chen, Joseph K. Liu, Ziyuan Hu, Yu Long 0001 |
Inf. Sci. | 2 |
| 2018 | A new randomized message-locked encryption in the standard model
Huige Wang, Kefei Chen, Yu Long 0001, Junyao Ye, Liangliang Wang 0001 |
Peer-to-Peer Netw. Appl. | 2 |
| 2018 | LWR-Based Fully Homomorphic Encryption, RevisitedabstractVery recently, Costache and Smart proposed a fully homomorphic encryption (FHE) scheme based on the Learning with Rounding (LWR) problem, which removes the noise (typically, Gaussian noise) sampling needed in the previous lattices-based FHEs. But their scheme did not work, since the noise of homomorphic multiplication is complicated and large, which leads to failure of decryption. More specifically, they chose LWR instances as a public key and the private key therein as a secret key and then used the tensor product to implement homomorphic multiplication, which resulted in a tangly modulus problem. Recall that there are two moduli in the LWR instances, and then the moduli will tangle together due to the tensor product. Inspired by their work, we built the first workable LWR-based FHE scheme eliminating the tangly modulus problem by cleverly adopting the celebrated approximate eigenvector method proposed by Gentry et al. at Crypto 2013. Roughly speaking, we use a specific matrix multiplication to perform the homomorphic multiplication, hence no tangly modulus problem. Furthermore, we also extend the LWR-based FHE scheme to the multikey setting using the tricks used to construct LWE-based multikey FHE by Mukherjee and Wichs at Eurocrypt 2016. Our LWR-based multikey FHE construction provides an alternative to the existing multikey FHEs and can also be applied to multiparty computation with higher efficiency. Fuqun Wang, Kunpeng Wang 0001, Kefei Chen |
Secur. Commun. Networks | 5 |
| 2017 | Anonymous handover authentication protocol for mobile wireless networks with conditional privacy preservation
Debiao He, Ding Wang 0002, Qi Xie 0001, Kefei Chen |
Sci. China Inf. Sci. | 4 |
| 2017 | An efficient pairing-free certificateless signature scheme for resource-limited systems
Liangliang Wang 0001, Kefei Chen, Yu Long 0001, Huige Wang |
Sci. China Inf. Sci. | 2 |
| 2017 | A new construction on randomized message-locked encryption in the standard model via UCEs
Huige Wang, Kefei Chen, Baodong Qin, Xuejia Lai, Yunhua Wen |
Sci. China Inf. Sci. | 2 |
| 2017 | Insight of the protection for data security under selective opening attacks
Zhengan Huang, Shengli Liu 0001, Xianping Mao, Kefei Chen, Jin Li 0002 |
Inf. Sci. | 4 |
| 2017 | Comparable Encryption Scheme over Encrypted Cloud Data in Internet of EverythingabstractUser authentication has been widely deployed to prevent unauthorized access in the new era of Internet of Everything (IOE). When user passes the legal authentication, he/she can do series of operations in database. We mainly concern issues of data security and comparable queries over ciphertexts in IOE. In traditional database, a Short Comparable Encryption (SCE) scheme has been widely used by authorized users to conduct comparable queries over ciphertexts, but existing SCE schemes still incur high storage and computational overhead as well as economic burden. In this paper, we first propose a basic Short Comparable Encryption scheme based on sliding window method (SCESW), which can significantly reduce computational and storage burden as well as enhance work efficiency. Unfortunately, as the cloud service provider is a semitrusted third party, public auditing mechanism needs to be furnished to protect data integrity. To further protect data integrity and reduce management overhead, we present an enhanced SCESW scheme based on position-aware Merkle tree, namely, PT-SCESW. Security analysis proves that PT-SCESW and SCESW schemes can guarantee completeness and weak indistinguishability in standard model. Performance evaluation indicates that PT-SCESW scheme is efficient and feasible in practical applications, especially for smarter and smaller computing devices in IOE. Jianfeng Ma 0001, Kefei Chen, Yinbin Miao |
Secur. Commun. Networks | 3 |
| 2017 | Provably Secure Dynamic ID-Based Anonymous Two-Factor Authenticated Key Exchange Protocol With Extended Security ModelabstractAuthenticated key exchange (AKE) protocol allows a user and a server to authenticate each other and generate a session key for the subsequent communications. With the rapid development of low-power and highly-efficient networks, such as pervasive and mobile computing network in recent years, many efficient AKE protocols have been proposed to achieve user privacy and authentication in the communications. Besides secure session key establishment, those AKE protocols offer some other useful functionalities, such as two-factor user authentication and mutual authentication. However, most of them have one or more weaknesses, such as vulnerability against lost-smart-card attack, offline dictionary attack, de-synchronization attack, or the lack of forward secrecy, and user anonymity or untraceability. Furthermore, an AKE scheme under the public key infrastructure may not be suitable for light-weight computational devices, and the security model of AKE does not capture user anonymity and resist lost-smart-card attack. In this paper, we propose a novel dynamic ID-based anonymous two-factor AKE protocol, which addresses all the above issues. Our protocol also supports smart card revocation and password update without centralized storage. Further, we extend the security model of AKE to support user anonymity and resist lost-smart-card attack, and the proposed scheme is provably secure in extended security model. The low-computational and bandwidth cost indicates that our protocol can be deployed for pervasive computing applications and mobile communications in practice. Qi Xie 0001, Duncan S. Wong, Guilin Wang, Xiao Tan 0003, Kefei Chen, Liming Fang 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2016 | Homomorphic Linear Authentication Schemes from (ε)-Authentication CodesabstractProofs of Data Possession/Retrievability (PoDP/PoR) schemes are essential to cloud storage services, since they can increase clients' confidence on the integrity and availability of their data. The majority of PoDP/PoR schemes are constructed from homomorphic linear authentication (HLA) schemes, which decrease the price of communication between the client and the server. In this paper, a new subclass of authentication codes, named ε-authentication codes, is proposed, and a modular construction of HLA schemes from ε-authentication codes is presented. We prove that the security notions of HLA schemes are closely related to the size of the authenticator/tag space and the successful probability of impersonation attacks (with non-zero source states) of the underlying ε-authentication codes. We show that most of HLA schemes used for the PoDP/PoR schemes are instantiations of our modular construction from some ε-authentication codes. Following this line, an algebraic-curves-based ε-authentication code yields a new HLA scheme. Shuai Han 0001, Shengli Liu 0001, Fangguo Zhang, Kefei Chen |
AsiaCCS | 4 |
| 2016 | A Firewall of Two Clouds: Preserving Outsourced Firewall Policy Confidentiality with HeterogeneityabstractIt is increasingly common for enterprises and other organizations to outsource firewalls to public clouds in order to reduce the cost and complexity in deploying and maintaining dedicated hardware middleboxes. However, this poses a serious threat to the enterprise network security because sensitive network policies, such as firewall rules, are revealed to cloud providers, which may be leaked and exploited by attackers. In this paper, we design and implement a SE- FWaaS, a secured system that enables cloud providers to support middlebox (e.g., firewall) outsourcing while preserving the network policy confidentiality. The key ingredients in our SE-FWaaS are the distribution of the firewall primitives, namely policy checking and verdict enforcing, to two independent public clouds, and the enabling techniques of efficient firewall rule obfuscation and oblivious rule-matching. Our SE-FWaaS provides the maximum achievable level of protection of network policies by enforcing the principle of the least privilege and removing the threat of offline probing attacks. We evaluate the proposed system over real-world firewall rules and demonstrate its effectiveness and feasibility. Lingbo Wei, Chi Zhang 0001, Yanmin Gong 0001, Yuguang Fang, Kefei Chen |
GLOBECOM | 5 |
| 2016 | Cryptanalysis of a certificateless aggregate signature schemeabstractAbstract An aggregate signature refers to a signature, by which n signatures σ1,...,σn corresponding to n messages m1,...,mn and n users u1,...,un can be transformed into a single short signature . Besides, anyone can be convinced by the single short signature that the n messages m1,...,mn were definitely signed by the n users u1,...,un correspondingly. The concept of certificateless cryptography is proposed, so as to settle the key escrow problem in ID‐based cryptography and eliminate the demand for certificates in certified cryptography. A certificateless signature scheme was proposed by Chen et al. in 2014, which was extended into a certificateless aggregate signature scheme. In this paper, two attacks are firstly provided, so as to indicate that the certificateless signature scheme is insecure against a Type I adversary and a Type II adversary. And then, it is demonstrated that the certificateless aggregate signature scheme is not able to achieve the security levels they claimed due to the weaknesses of the certificateless signature scheme. Copyright © 2016 John Wiley & Sons, Ltd. Liangliang Wang 0001, Kefei Chen, Yu Long 0001, Huige Wang |
Secur. Commun. Networks | 2 |
| 2016 | Certificateless encryption secure against selective opening attackabstractAbstract The notion of selective opening attacks (SOAs) was first introduced by Dworket al. at FOCS'99. Informally, an encryption scheme is SOA secure if an adversary is given a vector of ciphertexts and can adaptively corrupt some fraction of them by obtaining not only their messages but also their randomness, the uncorrupted ciphertexts retain secure. Provably achieving security against SOA has been proven extremely challenging. In this paper, we propose a security model to capture simulation‐based selective opening chosen‐plaintext attacks (SIM‐SO‐CPA) for certificateless encryption. We provide a concrete construction and prove its security in our simulation‐based selective opening chosen‐plaintext attack security model, based on the real or random and computational Diffie–Hellman assumptions. Compared with previous SOA‐secure public key encryption and identity‐based encryption, our certificateless encryption scheme is more simple and efficient. Copyright © 2017 John Wiley & Sons, Ltd. Huige Wang, Kefei Chen, Baodong Qin |
Secur. Commun. Networks | 2 |
| 2016 | Fuzzy certificateless signatureabstractAccording to the inspirations from history, we introduce a new cryptography primitive called fuzzy certificateless signature, which not only eliminates the key escrow problem inherently existed in fuzzy identity-based signature but also possesses the error tolerance property of fuzzy identity-based signature that allows for a set of attributes ω to verify a signature produced with a private key for an identity ω′ if and only if the distance between the two identities ω and ω′ is within a certain threshold. In this paper, the concept of fuzzy certificateless signature is first proposed, and then, the syntax and security model of fuzzy certificateless signature are formally defined. In the next step, so far, the first concrete fuzzy certificateless signature scheme is proposed, which may be practicably implemented in biometric identification. In addition, a formal security proof is provided, so as to demonstrate that in the random oracle model, our newly proposed scheme is existentially unforgeable against Types I and II chosen message attacks formalized in the security model under the computational Diffie–Hellman assumption. Copyright © 2016 John Wiley & Sons, Ltd. Liangliang Wang 0001, Junzuo Lai, Hu Xiong, Kefei Chen, Yu Long 0001 |
Secur. Commun. Networks | 4 |
| 2016 | Generic and Efficient Constructions of Attribute-Based Encryption with Verifiable Outsourced DecryptionabstractAttribute-based encryption (ABE) provides a mechanism for complex access control over encrypted data. However in most ABE systems, the ciphertext size and the decryption overhead, which grow with the complexity of the access policy, are becoming critical barriers in applications running on resource-limited devices. Outsourcing decryption of ABE ciphertexts to a powerful third party is a reasonable manner to solve this problem. Since the third party is usually believed to be untrusted, the security requirements of ABE with outsourced decryption should include privacy and verifiability. Namely, any adversary including the third party should learn nothing about the encrypted message, and the correctness of the outsourced decryption is supposed to be verified efficiently. We propose generic constructions of CPA-secure and RCCA-secure ABE systems with verifiable outsourced decryption from CPA-secure ABE with outsourced decryption, respectively. We also instantiate our CPA-secure construction in the standard model and then show an implementation of this instantiation. The experimental results show that, compared with the existing scheme, our CPA-secure construction has more compact ciphertext and less computational costs. Moreover, the techniques involved in the RCCA-secure construction can be applied in generally constructing CCA-secure ABE, which we believe to be of independent interest. Xianping Mao, Junzuo Lai, Qixiang Mei, Kefei Chen, Jian Weng 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2015 | Non-malleability Under Selective Opening Attacks: Implication and Separation
Zhengan Huang, Shengli Liu 0001, Xianping Mao, Kefei Chen |
ACNS | 4 |
| 2015 | Generic Construction of Certificate-Based Encryption from Certificateless Encryption RevisitedabstractCertificateless public key encryption (CLE) and certificate-based encryption (CBE) are motivated to simultaneously solve the heavy certificate management problem inherent in the traditional public key encryption (PKE) and the key escrow problem inherent in the identity-based encryption (IBE). Al-Riyami and Paterson proposed a general conversion from CLE to CBE, which is neat and natural. Kang and Park pointed out a flaw in their security proof. Wu et al. proposed another generic conversion from CLE to CBE which additionally involves collision resistant hash functions. It remains an open problem whether the generic conversion due to Al-Riyami and Paterson is provably secure or not. We are motivated to solve this open problem. Our basic idea is to enhance Type II adversary's power a little by allowing it to conditionally replace a user's public key. We first formalize a new security model of CLE in this way. Then, we succeed in proving that the Al-Riyami–Paterson generic conversion from CLE to CBE is secure, if the CLE scheme is secure in our new security model. Finally, a concrete provably secure CBE scheme is presented to demonstrate the applicability of our result. Wei Gao 0007, Guilin Wang, Kefei Chen |
Comput. J. | 4 |
| 2015 | Optimal assignment schemes for general access structures based on linear programming
Qiang Li 0026, Xiangxue Li, Xuejia Lai, Kefei Chen |
Des. Codes Cryptogr. | 4 |
| 2015 | Efficient chosen-ciphertext secure public-key encryption scheme with high leakage-resilienceabstractA leakage‐resilient public‐key encryption (PKE) scheme provides security even if an adversary obtains some information on the secret key. In recent years, much attention has been focused on designing provably secure PKE in the presence of key‐leakage and almost all the constructions rely on an important building block namely hash proof system (HPS). However, in the setting of adaptive chosen‐ciphertext attacks (CCA2), there are not many HPS‐based leakage‐resilient PKE schemes available. Moreover, most of them have an unsatisfactory leakage rate. In this study, the authors propose a new method of constructing leakage‐resilient CCA2‐secure PKE scheme from any tag‐based strongly universal 2 HPS. The striking advantage of the authors scheme is the leakage rate, which is the best one among all known HPS‐based indistinguishability key leakage CCA2‐secure constructions. In particular, they present an instantiation under the n ‐linear assumption. In the cases of n = 1 (resp. n = 2), they actually obtain a decisional Diffie–Hellman (DDH)‐based [resp. decisional linear (DLIN)‐based] PKE scheme, where the leakage rate can be made to 1/4 (resp. 1/6). The authors DDH‐based scheme achieves the best leakage rate among all known DDH‐based (Cramer–Shoup‐type) schemes. Their DLIN‐based scheme is the first one that can achieve leakage of L /6 bits without pairing, where L is the length of the secret key. Baodong Qin, Shengli Liu 0001, Kefei Chen |
IET Inf. Secur. | 3 |
| 2015 | n-Evasive all-but-many lossy trapdoor function and its constructionsabstractIn this paper, we propose the notion of n-evasive all-but-many lossy trapdoor functions ABM-LTFs, which is an extended abstraction of all-but-n lossy trapdoor functions ABN-LTFs proposed by Hemenway et al. in Asiacrypt 2011 and, at the same time, is a special case of ABM-LTFs proposed by Hofheinz in Eurocrypt 2012. We show two constructions of n-evasive ABM-LTFs. The first one is based on the decisional composite residuosity DCR assumption, and the second one is from chameleon hash functions and ABN-LTFs. Both of the constructions are based on reasonable assumptions with tight security reductions. Similar to ABN-LTFs and ABM-LTFs, n-evasive ABM-LTFs can be employed to construct indistinguishability-based selective opening chosen-ciphertext secure public-key encryption PKE schemes and may have other applications in cryptography. The instantiation of n-evasive ABM-LTFs can be based on the well-known assumption, for example, DCR, and the security reduction is much tighter than that of ABM-LTFs. On the other hand, the black-box PKE construction from n-evasive ABM-LTFs is more general than that from ABN-LTFs. Copyright © 2014 John Wiley & Sons, Ltd. Zhengan Huang, Shengli Liu 0001, Kefei Chen |
Secur. Commun. Networks | 3 |
| 2015 | Efficient revocable identity-based encryption from multilinear mapsabstractAbstract In Identity‐Based Encryption (IBE) systems, there is a widespread concern over the issue on how to provide an efficient revocation mechanism. We develop a new approach in constructing an efficient revocable IBE scheme. Our approach utilizes recent advances in multilinear maps and combines a two‐level hierarchical IBE scheme with a revocation encryption system. In our revocable IBE scheme, both the public parameters and the private key are constant‐size. Simultaneously, the size of the update key at some time is only proportional to the number of revoked users at the time. Our proposed scheme is proven secure in the selective revocation list model without relying on random oracles. Copyright © 2015 John Wiley & Sons, Ltd. Xianping Mao, Junzuo Lai, Kefei Chen, Jian Weng 0001, Qixiang Mei |
Secur. Commun. Networks | 3 |
| 2014 | Proofs of Retrievability Based on MRD Codes
Shuai Han 0001, Shengli Liu 0001, Kefei Chen, Dawu Gu |
ISPEC | 3 |
| 2014 | Cryptanalysis of a signcryption scheme with fast online signing and short signcryptext
Dehua Zhou, Jian Weng 0001, Chaowen Guan, Robert H. Deng, Min-Rong Chen, Kefei Chen |
Sci. China Inf. Sci. | 6 |
| 2014 | Public-key encryption scheme with selective opening chosen-ciphertext security based on the Decisional Diffie-Hellman assumptionabstractSUMMARY Chosen‐ciphertext security has been well‐accepted as a standard security notion for public‐key encryption. But in a multi‐user surrounding, it may not be sufficient, because the adversary may corrupt some users to obtain the random coins as well as the plaintexts used to generate ciphertexts. The attack is named ‘selective opening attack’. We study how to achieve full‐fledged chosen‐ciphertext security in selective opening setting directly from the Decisional Diffie–Hellman assumption. Our construction is actually a tag‐based public‐key encryption scheme free of chameleon hashing and has a tight security reduction to the Decisional Diffie–Hellman assumption and the collision‐resistant assumption of hash functions. The tag for each ciphertext is generated in a flexible way to serve the chosen‐ciphertext security proof in selective opening settings. Copyright © 2013 John Wiley & Sons, Ltd. Shengli Liu 0001, Fangguo Zhang, Kefei Chen |
Concurr. Comput. Pract. Exp. | 3 |
| 2014 | Attribute-based key-insulated signature and its applications
Jianhong Chen, Yu Long 0001, Kefei Chen |
Inf. Sci. | 3 |
| 2013 | Expressive search on encrypted dataabstractDifferent from the traditional public key encryption, searchable public key encryption allows a data owner to encrypt his data under a user's public key in such a way that the user can generate search token keys using her secret key and then query an encryption storage server. On receiving such a search token key, the server filters all or related stored encryptions and returns matched ones as response. Junzuo Lai, Xuhua Zhou, Robert H. Deng, Yingjiu Li, Kefei Chen |
AsiaCCS | 5 |
| 2012 | A Generic Construction of Accountable Decryption and Its Applications
Xuhua Zhou, Xuhua Ding, Kefei Chen |
ACISP | 3 |
| 2012 | Selective Opening Chosen Ciphertext Security Directly from the DDH Assumption
Shengli Liu 0001, Fangguo Zhang, Kefei Chen |
NSS | 3 |
| 2012 | Accountable authority key policy attribute-based encryption
Yongtao Wang, Kefei Chen, Yu Long 0001 |
Sci. China Inf. Sci. | 2 |
| 2011 | Lightweight Delegated Subset Test with Privacy Protection
Xuhua Zhou, Xuhua Ding, Kefei Chen |
ISPEC | 3 |
| 2011 | Self-generated-certificate public key encryption without pairing and its application
Junzuo Lai, Weidong Kou, Kefei Chen |
Inf. Sci. | 3 |
| 2011 | Key updating technique in identity-based encryption
Shengli Liu 0001, Yu Long 0001, Kefei Chen |
Inf. Sci. | 3 |
| 2011 | Restrictive partially blind signature for resource-constrained information systems
Weidong Qiu, Bozhong Liu, Yu Long 0001, Kefei Chen |
Knowl. Inf. Syst. | 5 |
| 2010 | CCA-secure unidirectional proxy re-encryption in the adaptive corruption model without random oracles
Jian Weng 0001, Min-Rong Chen, Yanjiang Yang, Robert H. Deng, Kefei Chen, Feng Bao 0001 |
Sci. China Inf. Sci. | 5 |
| 2010 | Efficient chosen-ciphertext secure certificateless threshold key encapsulation mechanism
Yu Long 0001, Kefei Chen |
Inf. Sci. | 2 |
| 2010 | Chosen-ciphertext secure bidirectional proxy re-encryption schemes without pairings
Jian Weng 0001, Robert H. Deng, Shengli Liu 0001, Kefei Chen |
Inf. Sci. | 4 |
| 2009 | Extended PEG Algorithm for High Rate LDPC CodesabstractProgressive Edge-Growth(PEG) Algorithm is a good candidate to generate Tanner Graphs with a large girth by establishing edges or connections between symbol and check nodes in an edge-by-edge manner. In this paper, we propose an extended PEG algorithm for constructing Low-Density Parity-Check (LDPC) codes with very high rate when given a lower bound of girth. Simulation results show the bit error rates of constructed LDPC codes with very high rate or large girth. Xiangxue Li, Dong Zheng 0001, Kefei Chen |
ISPA | 4 |
| 2009 | How to Break LU Matrix Based Key Predistribution Schemes for Wireless Sensor NetworksabstractA key predistribution scheme for Wireless Sensor Networks was proposed by Choi and Youn in 2005, which is based on LU decomposition of symmetric matrix. After that, several key predistribution schemes were designed on the basis of Choi and Youn's original scheme. In this paper, we carefully investigate a mathematical theorem about symmetric matrix, by following which adversaries could easily obtain the secret keys deployed via Choi and Youn's scheme. We also analyze all the schemes derived from Choi and Youn's and point out their vulnerabilities. In addition, we propose a revised scheme avoiding the security flaw. Yanfei Zheng, Yaowei Zhou, Kefei Chen |
MASS | 4 |
| 2009 | When is a key establishment protocol correct?abstractAbstract This paper presents sufficient and necessary conditions to guarantee the security of a Key Establishment (KE) protocol based on our formalism of the belief multisets. The formalism is used to express the security of a KE protocol and to reason about beliefs in the protocol. We observe that a freshness identifier such as a nonce may not be fresh for a legitimate party in a particular protocol run, hence we distinguish a trusted freshness identifier from the commonly used freshness identifier in the sense of a participant's beliefs about the security. A central ingredient in our approach is that all the beliefs should be established on the basis of a trusted freshness identifier. The reasoning results of our approach, comparing with the security conditions, can either establish the correctness of a KE protocol when the protocol is in fact correct, or identify the absence of the security properties, which leads to the structure to construct attacks directly. Two examples, the Kerberos pair‐key agreement approach in distributed sensor networks and the Needham—Schroeder public key protocol, are given to show the usability and the efficiency of our approach. Copyright © 2009 John Wiley & Sons, Ltd. Ling Dong, Kefei Chen, Xuejia Lai, Mi Wen |
Secur. Commun. Networks | 2 |
| 2008 | Chosen-Ciphertext Secure Proxy Re-encryption without Pairings
Robert H. Deng, Jian Weng 0001, Shengli Liu 0001, Kefei Chen |
CANS | 4 |
| 2008 | Identity-Based Threshold Key-Insulated Encryption without Random Oracles
Jian Weng 0001, Shengli Liu 0001, Kefei Chen, Dong Zheng 0001, Weidong Qiu |
CT-RSA | 3 |
| 2008 | A Tamper-Evident Voting Machine Resistant to Covert Channels
Tao Hao, Dong Zheng 0001, Kefei Chen, Xiaofeng Chen 0001 |
ProvSec | 4 |
| 2008 | A synthetic indifferentiability analysis of some block-cipher-based hash functions
Xuejia Lai, Kefei Chen |
Des. Codes Cryptogr. | 3 |
| 2008 | A tabu search approach for the minimum sum-of-squares clustering problem
Yongguo Liu, Zhang Yi 0001, Mao Ye 0001, Kefei Chen |
Inf. Sci. | 5 |
| 2007 | Efficient Blind Signatures from Linear Feedback Shift Register
Xiangxue Li, Dong Zheng 0001, Kefei Chen |
CDVE | 3 |
| 2007 | Efficient Linkable Ring Signatures and Threshold Signatures from Linear Feedback Shift Register
Xiangxue Li, Dong Zheng 0001, Kefei Chen |
ICA3PP | 3 |
| 2007 | Identity-Based Threshold Decryption Revisited
Shengli Liu 0001, Kefei Chen, Weidong Qiu |
ISPEC | 2 |
| 2007 | Pirate decoder for the broadcast encryption schemes from Crypto 2005
Jian Weng 0001, Shengli Liu 0001, Kefei Chen |
Sci. China Ser. F Inf. Sci. | 3 |
| 2007 | Certificateless threshold cryptosystem secure against chosen-ciphertext attack
Yu Long 0001, Kefei Chen |
Inf. Sci. | 2 |
| 2006 | Identity-Based Key-Insulated Signature with Secure Key-Updates
Jian Weng 0001, Shengli Liu 0001, Kefei Chen, Xiangxue Li |
Inscrypt | 3 |
| 2006 | Efficient Partially Blind Signature Scheme with Provable Security
Xiangxue Li, Kefei Chen |
COCOON | 3 |
| 2006 | Enforcing Trust in Pervasive Computing with Trusted Computing Technology
Shiqun Li, Shane Balfe, Jianying Zhou 0001, Kefei Chen |
CRITIS | 4 |
| 2006 | A Practical Clumped-Tree Multicast Encryption Scheme
Ling Dong, Kefei Chen |
ISPEC | 2 |
| 2006 | Rights Protection for Data Cubes
Yingjiu Li, Robert H. Deng, Kefei Chen |
ISC | 4 |
| 2006 | Comments on an access control model in semantic grid
Libin Wang 0002, Kefei Chen |
Future Gener. Comput. Syst. | 2 |
| 2006 | Comments on a theorem on grid access control
Libin Wang 0002, Kefei Chen |
Future Gener. Comput. Syst. | 2 |
| 2005 | Clustering with Noising Method
Yongguo Liu, Kefei Chen |
ADMA | 3 |
| 2005 | Efficient Identity-Based Signatures and Blind Signatures
Zhenjie Huang, Kefei Chen, Yumin Wang |
CANS | 2 |
| 2005 | A Novel Clustering Technique Based on Improved Noising Method
Yongguo Liu, Dong Zheng 0001, Kefei Chen |
CIARP | 4 |
| 2005 | A Tabu Clustering Method with DHB Operation and Mergence and Partition Operation
Yongguo Liu, Dong Zheng 0001, Shiqun Li, Libin Wang 0002, Kefei Chen |
Discovery Science | 5 |
| 2005 | Multiplex Encryption: A Practical Approach to Encrypting Multi-recipient Emails
Xuhua Ding, Kefei Chen |
ICICS | 3 |
| 2005 | An Authentication Protocol for Pervasive Computing
Shiqun Li, Jianying Zhou 0001, Xiangxue Li, Kefei Chen |
ISPA | 4 |
| 2005 | Efficient and Proactive Threshold Signcryption
Changshe Ma, Kefei Chen, Dong Zheng 0001, Shengli Liu 0001 |
ISC | 2 |
| 2005 | A Hybrid Tabu Search Based Clustering Algorithm
Yongguo Liu, Libin Wang 0002, Kefei Chen |
KES (2) | 4 |
| 2005 | An Efficient Asynchronous Proactive RSA SchemeabstractIn this paper, we present an efficient asynchronous proactive RSA scheme. This paper has three contributions. Firstly, we present an asynchronous verifiable secret sharing protocol. Secondly, we propose an efficient asynchronous threshold RSA signature generation protocol. Thirdly, we propose an efficient asynchronous share refreshing protocol Ruishan Zhang, Kefei Chen |
PDCAT | 2 |
| 2005 | Improvements on the WTLS protocol to avoid denial of service attacks
Ruishan Zhang, Kefei Chen |
Comput. Secur. | 2 |
| 2005 | Some new characters on the wire-tap channel of type IIabstractThe noiseless wire-tap channel of type II with coset coding scheme was provided by Ozarow and Wyner. In this correspondence, the user is split into multiple parties who are coordinated in coding their data symbols by using the same encoder. The adversary can tap not only partial transmitted symbols but also partial data symbols. We are interested in the equivocation of the data symbols to this adversary who has more power than that of Ozarow and Wyner. The generalized Hamming weight of Wei and the dimension/length profile (DLP) of Forney are extended to two-code formats: relative generalized Hamming weight and relative dimension/length profile (RDLP). Upper and lower bounds of the new concepts are investigated. They are useful to design a perfect secrecy coding scheme for the coordinated multiparty model. Under a general secrecy standard, the coordinated model can provide a higher transmission rate than an uncoordinated (time-sharing) model. Luo Yuan, Chaichana Mitrpant, A. J. Han Vinck, Kefei Chen |
IEEE Trans. Inf. Theory | 4 |
| 2004 | ID-Based Proxy Blind SignatureabstractBlind signature is the concept to ensure anonymity of e-coin. Untracebility and unlinkability are two main properties of real coin, which require mimicking electronically. Proxy signature schemes allow a proxy signer to generate a proxy signature on behalf of an original signer. All the previous proxy signature schemes are based on ElGamal-type schemes. We propose a new proxy blind signature scheme based on an ID-based signature scheme, which uses bilinear pairings of elliptic curves or hyperelliptic curves. Dong Zheng 0001, Huang Zheng, Kefei Chen, Weidong Kou |
AINA (2) | 3 |
| 2004 | Proxy Structured Multisignature Scheme from Bilinear Pairings
Xiangxue Li, Kefei Chen, Longjun Zhang, Shiqun Li |
ISPA | 2 |
| 2004 | Multi-proxy Signature and Proxy Multi-signature Schemes from Bilinear Pairings
Xiangxue Li, Kefei Chen, Shiqun Li |
PDCAT | 2 |
| 2004 | On the orders of transformation matrices (mod n) and two types of generalized arnold transformation matrices
Lizhen Yang, Kefei Chen |
Sci. China Ser. F Inf. Sci. | 2 |
| 2004 | Authenticating Tripartite Key Agreement Protocol with Pairings
Shengli Liu 0001, Fangguo Zhang, Kefei Chen |
J. Comput. Sci. Technol. | 3 |
| 2004 | A genetic clustering method for intrusion detection
Yongguo Liu, Kefei Chen, Xiaofeng Liao 0001 |
Pattern Recognit. | 2 |
| 2003 | A Typed Theory for Access Control and Information Flow Control in Mobile Systems
Libin Wang 0002, Kefei Chen |
ACISP | 2 |
| 2003 | Multimedia Tampering Localization Based on the Perturbation in Reverse Processing
Xianfeng Zhao, Weinong Wang, Kefei Chen |
WAIM | 3 |
| 2003 | Attacks on the (enhanced) Yang-Shieh authentication
Kefei Chen, Sheng Zhong 0002 |
Comput. Secur. | 1 |
| 2002 | A New Offline Privacy Protecting E-cash System with Revokable Anonymity
Weidong Qiu, Kefei Chen, Dawu Gu |
ISC | 2 |
| 2002 | Exploiting the Intrinsic Irreversibility of Adaptive Technologies to Enhance the Security of Digital Watermarking
Xianfeng Zhao, Weinong Wang, Kefei Chen |
WAIM | 3 |
| 2002 | Multiparty Authentication Services and Key Agreement Protocols with Semi-Trusted Third Party
Dong Zheng 0001, Kefei Chen, Jinyuan You |
J. Comput. Sci. Technol. | 2 |