VLDB 2026 Research / reviewers in the wild / expert
Jiaxin Li 0001
dblp:69/327-1
· DBLP profile ↗
11ranked-venue papers
1as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 1 first-author · 5 since 2021Security and privacy · 4 · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BliChain: A Blockchain-Assisted and Lightweight Cross-Domain Authentication Scheme for 6G-Enabled VANETabstractIn the evolution of 6G-based Vehicular Ad-hoc Networks (VANETs) from closed single-domain environments to open cross-domain environments, several security challenges arise, including heterogeneous domain trust barriers, vehicle identity privacy leakage, and high authentication overhead in dynamic scenarios. Existing schemes based on centralized public key infrastructure (PKI) suffer from single point failure risks and have difficulty balancing low latency with conditional privacy preservation. Meanwhile, blockchain-assisted solutions are often constrained by on-chain storage expansion and high computational overhead. To address these issues, this paper proposes a blockchain-assisted anonymous authentication scheme for 6G-VANETs. The proposed scheme uses blockchain to construct distributed trust anchors and enable secure sharing of public parameters across domains. By generating lightweight authentication parameters based on Lagrange interpolation polynomials, the scheme supports direct mutual authentication and session key agreement between vehicles without requiring massive certificate-related on-chain transactions. In addition, a pseudo-identity mechanism is introduced to achieve conditional privacy preservation, thereby balancing vehicle identity privacy and traceability. Security analysis demonstrates that the proposed scheme satisfies the required security properties under the random oracle model. Performance evaluation shows that compared with existing solutions, the proposed scheme significantly reduces computational overhead by 22.31%, 11.02%, and 29.19%, respectively, and communication overhead by 51.2%, 20.08%, and 24.61%, respectively. Jiaxin Li 0001, Hong Zhong 0001, Lu Wei 0003, Irina Pavlovna Bolodurina, Jie Cui 0004 |
IEEE Internet Things J. | 1 |
| 2026 | Blockchain-Assisted Proxy Re-Encryption Scheme With Revocation for Federal DiagnosticsabstractFederated diagnosis, a concept emerging in Internet of Things (IoT)-based e-health systems, addresses the interconnectivity challenges of medical resources across different regions. Furthermore, flexible access control is required, which allows users to modify the access policy for encrypted data in the cloud without revealing sensitive information. Current solutions rely on third parties for policy modification, incur high computational overheads during user revocation, and expose user attributes to plaintext access policies. To address these issues, this study introduces a blockchain-assisted revocable federated diagnostic ciphertext policy attribute-based encryption (RFD-CPABE) scheme that enables policy conversion and revocation, which allows users to convert attribute-based encryption ciphertext to inner product encryption ciphertext swiftly and facilitates fast revocation using binary trees. This scheme enhances privacy protection by separating attribute names from values, thus concealing sensitive information within the access policies. Moreover, to reduce the computational burden on trusted institutions, the workload is decentralized utilizing a blockchain to minimize the pressure on the central servers. The formal security proof demonstrates the resilience of the scheme against selective chosen-plaintext attacks, and the experimental analysis confirms its superior efficiency compared to existing solutions. Qingyang Zhang 0001, Jie Cui 0004, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Internet Things J. | 5 |
| 2026 | Blockchain-Based Asynchronous Authentication and Key Agreement Scheme for Securing VANETsabstractIn vehicular ad hoc networks (VANETs), authentication and key agreement (AKA) protocols are crucial for establishing secure authentication and session keys for network communications, ensuring security for short-term vehicle interactions. However, traditional VANETs AKA schemes heavily rely on centralized trust architectures. This dependence raises significant concerns about overall system security and resilience, especially when these schemes operate over insecure wireless channels. Although recent studies have introduced decentralized architectures to mitigate this issue, a key limitation remains. These approaches typically assume synchronous network environments, which in practice limits their true decentralization capabilities in dynamic VANETs. To address these challenges, we propose a decentralized and asynchronous AKA scheme based on a consortium blockchain that enables the execution of the key agreement process in asynchronous VANETs environments. Furthermore, we employ lightweight cryptographic techniques combined with a Cuckoo filter to optimize computational efficiency, reduce communication overhead, and minimize on-chain storage costs. Security analyses and simulation experiments demonstrate that the proposed scheme delivers robust security and high performance under realistic network conditions. Lu Wei 0003, Yujia Zhong, Jie Cui 0004, Irina Pavlovna Bolodurina, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Runtime Threshold Signature-Based Unmanned Aerial Vehicle Swarm Authentication With Autonomous Splitting SupportabstractRecently, unmanned aerial vehicles (UAVs) have undergone rapid development, demonstrating significant potential in various fields, including logistics, military operations, and entertainment. By collaborating to form swarms, UAVs can undertake more complex tasks such as mapping and disaster relief. To address the limited flexibility of UAV swarm identity authentication and the requirement for swarm splitting during task execution, we propose a runtime threshold signature (RTS) scheme. Unlike traditional threshold signatures, RTS defers the selection of the threshold from the initialization phase to the signing phase, allowing verifiers to dynamically adjust the threshold as required, thus achieving an effective balance between efficiency and security. Moreover, the RTS has the same signature size as the Schnorr signature, which is a non-interactive threshold signature. Building on the RTS primitive, we designed a novel identity authentication scheme that supports the autonomous splitting of UAV swarms. This scheme enables secure swarm-level identity authentication while adapting naturally to dynamic swarm restructuring. Furthermore, we demonstrate that the proposed scheme satisfies unforgeability under the t-VCDH assumption. To evaluate its performance, we implemented our scheme in C++ on AmovLab Prometheus 600 (P600) UAVs and assessed it under varying network latency and bandwidth conditions. Comparative results with existing schemes demonstrate that our approach achieves lower computational overhead and high practical applicability. Notably, even with the threshold set to 128, the authentication process takes only 2.6 ms per UAV. Mingwei Zeng, Hong Zhong 0001, Qingyang Zhang 0001, Fengqun Wang, Jiaxin Li 0001, Jie Cui 0004 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Anonymous Integrity Auditing Scheme Based on Trusted Execution Environment for Distributed Edge ComputingabstractMulti-replica data storage is widely adopted in edge computing to improve both data availability and access efficiency for latency-sensitive applications. Integrity auditing is a critical mechanism for ensuring data reliability in this distributed setting. However, existing schemes face a trade-off between security and efficiency: ensuring replica authenticity typically requires users to generate unique tags for all copies, creating a bottleneck for resource-constrained devices. Delegation schemes reduce this burden but struggle to prevent collusion or on-the-fly generation attacks. Therefore, this study proposes ATRIA to resolve this dilemma. Uniquely, ATRIA leverages the Trusted Execution Environments (TEEs) not only for isolation but to securely offload the intensive replica tag generation from the user, ensuring authentic physical storage with minimal user overhead. By leveraging the hardware isolation of the TEEs, this mechanism ensures authentic physical storage and protects against on-the-fly and collusion attacks. In addition, the scheme incorporates a privacy-preserving identity management solution that balances anonymity and traceability. It employs a traceable anonymous identity mechanism whereby users interact via pseudonyms, hiding their real identities while allowing a trusted Key Generation Center (KGC) to perform identity tracing only when authorized. Our security analysis demonstrates that the proposed scheme achieves its security objectives and resists various attacks. Furthermore, a comprehensive performance evaluation demonstrates that ATRIA outperforms related schemes in terms of computational overhead. Qingyang Zhang 0001, Jie Cui 0004, Fengqun Wang, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Post-Quantum Secure Authenticated Key Agreement Scheme for Vehicular Digital Twin
Jie Cui 0004, Jiyu Liu, Lu Wei 0003, Irina Pavlovna Bolodurina, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2026 | Forward Secure Data Sharing Based on Proxy Re-Encryption in Industrial Internet of ThingsabstractIn the Industrial Internet of Things (IIoT), data is shared among different production segments for collaborative production. However, industrial production processes often involve corpus sensitive information, and during data sharing, every flow of data between different subjects increases its exposure to vulnerabilities. Proxy re-encryption offers a practical approach to enabling secure data exchange, thereby partially mitigating the tension between information sharing and privacy protection. Many scholars have proposed data-sharing schemes utilizing proxy re-encryption technologies. However, existing schemes still face issues, such as excessive communication and computational overhead, and cannot guarantee forward security. Therefore, this study proposes a lightweight and forward-secure data-sharing scheme. First, the proxy generates the re-encryption key, substantially alleviating the overhead on the data owner. Second, whenever the time node changes or a data user is revoked, the data user loses access to historical data, which effectively ensures forward security. The security proof confirms the scheme’s IND-CPA security under the DBDH assumption. Performance analyses reveals that the proposed scheme achieves higher security in data sharing with a lower computational overhead. Qingyang Zhang 0001, Siqi Fu, Jie Cui 0004, Fengqun Wang, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | Edge Computing-Based Anonymous Cross-Domain Authentication Scheme for VANETsabstractIn the vehicular ad-hoc networks (VANETs), crossdomain communication among vehicles significantly improves traffic efficiency and road safety. However, due to the vulnerabilities of vehicle communication, it faces numerous security challenges when performing cross-domain communication. Existing schemes rely on trusted third parties for cross-domain authentication, resulting in issues such as low computational efficiency and weak privacy protection for vehicles, which cannot meet the demands of large-scale vehicle cross-domain communication. To address these problems, we propose an efficient and anonymous cross-domain authentication scheme based on edge computing. By using edge gateways to manage vehicle groups and handle cross-domain event requests, we solve the performance bottleneck issues caused by centralized authentication. Additionally, the use of a batch authentication mechanism further improves computational efficiency during large-scale authentications and reduces authentication latency. Security and performance analyses show that the proposed scheme can meet the security and performance requirements for cross-domain vehicle communication. Hong Zhong 0001, Chengdong Gu, Jing Zhang 0024, Qingyang Zhang 0001, Jiaxin Li 0001, Jie Cui 0004 |
HPCC | 6 |
| 2025 | Achieving Fair and Efficient Revocable Access Control for IIoT Data Sharing: A Blockchain-Enabled ApproachabstractWith the advancement of computing and communication technologies, Industrial Internet of Things (IIoT) has emerged accordingly. In IIoT environments, efficient data sharing is achieved through collaboration among end devices, edge servers, and cloud servers. However, ensuring the security, efficiency, and fairness of service data access for end devices remains a significant challenge. To address this, we propose a fair and efficient revocable access control scheme based on blockchain. The proposed scheme leverages smart contracts to establish a fair payment mechanism, ensuring fairness for IIoT data sharing. In addition, a proxy-assisted decryption approach is employed to minimize the decryption overhead on end devices. Moreover, the scheme supports efficient user revocation without requiring updates to the private keys of end users. This enhances the overall security and usability of the system. Finally, a thorough security and performance analysis indicate that the proposed scheme fits well within IIoT scenarios. Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Jiaxin Li 0001, Jie Cui 0004 |
IEEE Internet Things J. | 5 |
| 2025 | Sustainable Learning-Based Intrusion Detection System for VANETsabstractVehicular intrusion detection systems (VIDSs) play a crucial role in protecting the security of vehicular ad hoc networks (VANETs). Recently, numerous researchers have proposed effective vehicular intrusion detection systems to protect the security of VANETs. However, some existing vehicle intrusion systems are susceptible to catastrophic forgetfulness in the process of implementing incremental updates to target novel attacks. Other solutions lack consideration for the continuous updating capabilities of vehicle intrusion detection systems. It is worth mentioning that in the real world, the network attacks suffered by vehicles are not constant, and fixed intrusion detection systems may struggle to detect new network attacks effectively. To address these challenges, we propose an incremental learning-based vehicular intrusion detection scheme that supports continuous updating of the intrusion detection system. Specifically, we design a sample gradient optimization algorithm to enhance the data quality of training samples. Additionally, we utilize locally stored historical data to balance the number of old attack classes for model distillation, thus mitigating the problem of forgetting the old classes as the model learns new classes. The comprehensive experimental results on the CICIDS2017, TON_IOT, and Veremi datasets demonstrate that the proposed vehicular intrusion detection system maintains superior detection accuracy during continuous updating and surpasses the state-of-the-art solution. Lu Wei 0003, Hulin Jin, Jie Cui 0004, Jiaxin Li 0001, Debiao He |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2024 | Device-Side Lightweight Mutual Authentication and Key Agreement Scheme Based on Chameleon Hashing for Industrial Internet of ThingsabstractSeveral authentication and key agreement (AKA) schemes have been proposed to ensure secure communication in the Industrial Internet of Things (IIoT). However, most of these schemes face two primary problems. First, they cannot resist various attacks, such as impersonation and device capture attacks. Second, these schemes overlook the resource-constrained IIoT devices, failing to guarantee lightweight overhead for device operations. Therefore, we propose a novel and efficient AKA scheme. Utilizing the chameleon hash function and physical unclonable function, the proposed scheme implements a lightweight overhead for both authentication parties while maintaining the overhead of the gateway within a reasonable range. Furthermore, we implement device anonymity based on lightweight operations such as hash and XOR. In addition, we perform a rigorous security analysis using the widely accepted Real-Or-Random model, BAN logic, and Proverif tool. Finally, through heuristic analysis and experiments, we substantiate that our scheme surpasses the compared schemes in terms of both security attributes and system overhead. Qingyang Zhang 0001, Hong Zhong 0001, Jie Cui 0004, Jiaxin Li 0001, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 5 |