VLDB 2026 Research / reviewers in the wild / expert
Jianhong Zhang 0001
dblp:72/1748-1
· DBLP profile ↗
48ranked-venue papers
38as first author
22since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 15 first-author · 11 since 2021Computer networks · 12 · 10 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 6 first-author · 3 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 3 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Quantum-resistant and extractable bilateral fine-grained access control for EMRs sharing
Chenghe Dong, Guangquan Xu, Guohua Xin, Jianhong Zhang 0001, Cong Wang 0004 |
Expert Syst. Appl. | 4 |
| 2026 | Verifiable and Fault-Tolerant Privacy-Preserving Data Aggregation for MEC-Enabled Consumer IoT
Jianhong Zhang 0001, Miao Xue, Xinyu Bai |
IEEE Internet Things J. | 1 |
| 2026 | LB-CLAA: An Anonymous and Efficient Postquantum Certificateless Aggregate Authentication Scheme for VANET
Jianhong Zhang 0001, Miao Xue, Xinyan Cui |
IEEE Internet Things J. | 1 |
| 2026 | On the Security of Sequential Multi-Signer Ring Signature for Secure Medical Data Sharing in IoMTabstractIn the Internet of Medical Things (IoMT), transmitted medical data contain sensitive patient information. To protect patient identity privacy and address the adaptability limitations of traditional ring signatures, Xu et al. proposed the anonymous sequential multi-signature ring signature (ASMR) to enable secure medical data sharing in the IoMT (IEEE Transactions on Information Forensics and Security, DOI 10.1109/TIFS.2025.3574959). Although Xu et al. claim that the ASMR scheme is secure, our analysis demonstrates that it is insecure, as it is existentially and universally forgeable, allowing any entity to generate a valid ring signature for arbitrary messages. Following the presentation of the attack, we analyze the causes of these vulnerabilities and propose corresponding countermeasures. Jianhong Zhang 0001, Chuming Shi |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | An Enhanced-Security Certificateless Aggregate Signcryption for Secure Data Transmission in Resource-Constrained NetworksabstractThe terminal devices in resource-constrained networks face significant challenges in ensuring data privacy and integrity during transmission. Signcryption, which simultaneously provides both data confidentiality and authentication, offers a promising solution with reduced computational costs in such networks. Recently, three efficient pairing-avoiding CertificateLess Aggregate SignCryption (CLASC) schemes were introduced to enhance privacy and authenticity in vehicular sensor networks, the Industrial Internet of Thing, and 5G wireless network scenarios. These schemes achieve lower computational costs compared to previous schemes. However, further security analysis reveals that these CLASC schemes fail to meet their claimed security properties. Specifically, two of them are vulnerable to Type I attacks, while the third one is susceptible to Type II attacks. To address these vulnerabilities, we propose a new CLASC scheme with enhanced security. It not only resists Type I and Type II attacks in the random oracle model but also achieves Girault’s Level-3 security. Finally, our experimental assessments demonstrate that the proposed scheme outperforms several recent CLASC schemes. It maintains similar computational costs and communication overheads compared to state-of-the-art CLASC schemes, while providing stronger security guarantees. Jianhong Zhang 0001, Chuming Shi |
IEEE Internet Things J. | 1 |
| 2025 | Efficient Privacy-Preserving Federated Learning for IIoT Using Dual Proxy Re-EncryptionabstractThe Industrial Internet of Things (IIoT) is revolutionizing industries such as smart grids, healthcare, and predictive maintenance by harnessing big data and deep learning technologies. However, limited datasets in IIoT devices often result in suboptimal model performance and overfitting. Federated deep learning can mitigate this issue by leveraging distributed datasets across devices, but data privacy concerns persist, especially in sensitive applications like smart healthcare and energy management. rgb0.00,0.00,0.00Although numerous privacy-preserving federated learning schemes have been proposed, their vulnerabilities hinder widespread adoption due to insufficient guarantees for participant data privacy and the security of global model parameters. To address these challenges, we propose a novel deep learning framework that leverages proxy re-encryption techniques to enhance data privacy. Our scheme employs a dual proxy re-encryption mechanism to enhance data security, enabling each participant to securely access global model parameters without relying on a proxy server during training rounds. This not only prevents unauthorized access by the parameter server, but also resists collusion attacks between the parameter server and participants. Furthermore, the confidentiality of the proxy server’s private key is maintained, even in cases of collusion involving the parameter server and participants. A comparative analysis with existing schemes highlights the advantages of our approach, including reduced communication overhead and computational complexity, as demonstrated by experimental results. Jianhong Zhang 0001, Chuming Shi |
IEEE Internet Things J. | 1 |
| 2025 | Secure and Lightweight Signcryption Scheme With Group Equality Test for Heterogeneous WBANabstractWireless body area network (WBAN) integrates body sensors to collect and upload various health indicators, which facilitates timely remote healthcare. To realize the real-time monitoring of the patient’s health status while ensuring the security of sensitive data, signcryption schemes with equality test provide a feasible solution. Nevertheless, most of the existing schemes suffer from heavy computational burdens and are vulnerable to some inherent threats, such as offline message recovery attack and known session temporary key attack. Additionally, some of them cannot provide the essential security properties. To cope with these problems, this paper constructs a secure and lightweight signcryption scheme with group equality test, which is suitable for the heterogeneous environment. To formally define the resistance to offline message recovery attack and known session temporary key attack, we first propose two corresponding security models. Then, we introduce a group mechanism to the equality test to support the aforementioned security properties. Besides, we adopt the online/offline construction to avert the time-consuming operations in the real-time data processing phase. Furthermore, our scheme supports message aggregation to reduce the computational overhead of handling multiple messages. Formal security proof shows that our scheme satisfies confidentiality and unforgeability. Compared to several recent schemes, the experimental results demonstrate that our scheme enjoys the best performance in terms of both computational overhead and communication cost. With implementation, our scheme is proved to be feasible for lightweight devices in real-world applications. Qijia Zhang, Jianhong Zhang 0001, Youliang Tian |
IEEE Internet Things J. | 2 |
| 2025 | Efficient Secure Data Aggregation for Real-Time Smart Grid Monitoring: A Lightweight Privacy-Preserving ApproachabstractData aggregation protocols play a crucial role in enabling real-time monitoring of the smart grid's operational status by the power control center. To ensure robust security, a data aggregation protocol should provide features such as data privacy, fault tolerance, lightweight computation, and fine-grained data aggregation. However, existing data aggregation protocols employing techniques such as homomorphic encryption, masking, or differential privacy fail to deliver these features concurrently. To address this challenge, we propose a novel lightweight privacy-preserving data aggregation scheme based on proxy reencryption and asymmetric scalar product-preserving encryption, in which encryption operations only involve addition and multiplication over the integer field, thus avoiding time-consuming exponentiation and pairing operations and achieving lightweight computation. Furthermore, through the use of an asymmetric scalar-product-preserving encryption scheme, we effectively align aggregation policies while maintaining the privacy of power consumption data. Finally, when compared to three recent data aggregation schemes with analogous structures, experimental results demonstrate that our proposed scheme outperforms others regarding computational and communication overheads, thus enhancing its efficiency. Jianhong Zhang 0001, Chuming Shi |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2025 | Two-Round Certificateless Multi-Signatures With Key Aggregation in Smart ContractsabstractMulti-signatures have recently garnered considerable attention, particularly within the domain of smart contracts in blockchain ecosystems, as they enhance account security and mitigate single points of failure by requiring the approval of multiple key holders for transaction execution. However, most existing multi-signature schemes heavily rely on traditional Public Key Infrastructure (PKI), which requires a trusted authority and conflicts with the decentralized nature of blockchain technology. Certificateless multi-signature (CLMS) schemes, which eliminate the requirement for a trusted authority, represent promising solutions to address this issue. Nevertheless, existing CLMS schemes encounter challenges that limit their suitability for smart contract applications, including high communication overhead, expensive verification costs, and “loose" security reductions. To address these challenges, we propose two novel two-round certificateless multi-signature schemes. These schemes not only support key aggregation but also optimize the signing process with two-round communication, maintaining fixed computational overhead during verification. Furthermore, the security proofs for the proposed schemes are independent of the Forking lemma, resulting in tighter security reductions and strengthened security assurance. Finally, experimental results demonstrate that the proposed schemes significantly reduce both communication and computational overhead compared to existing CLMS schemes, making them more efficient and practical for blockchain-based smart contract applications. Jianhong Zhang 0001, Chuming Shi |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Corrections to "On the Security of a Revocable Cross-Domain Anonymous Authentication in IIoT"abstractWith the rapid growth of the Industrial Internet of Things (IIoT), secure and efficient collaboration among devices from different domains is essential for achieving collaborative production tasks. Recently, Zeng et al. proposed a dynamic group signature scheme using dynamic accumulators and zero-knowledge proofs. Although they claim that their scheme ensures unlinkability of signatures, our analysis shows that their scheme is vulnerable and fails to provide unlinkability. After presenting our attack, we analyze the underlying causes of these vulnerabilities and propose an improvement to address them. Jianhong Zhang 0001, Chuming Shi |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Short Ciphertext-Size Privacy-Preserving Aggregation Against Malicious Aggregators
Jianhong Zhang 0001, Chuming Shi |
ICIC (5) | 1 |
| 2024 | Efficient Pairing-Free Certificateless Signcryption Scheme for Secure Data Transmission in IoMTabstractThe Internet of Medical Things (IoMT) builds a bridge between patients and doctors, facilitating patients’ being diagnosed and monitored by uploading physiological indicators without visiting the hospital. However, physiological indicators are sensitive data of patients, making it a challenge to achieve verifiability of data sources while ensuring data privacy during data transmission of IoMT. Due to its ease of deployment and the ability to provide both encryption and signature, certificateless signcryption (CLSC) is suitable for designing secure data-transfer protocol in IoMT. Nevertheless, internal adversaries “malicious users” and “malicious KGC,” capable of launching Type I and Type II attacks, threaten the security of present CLSC schemes, making most of them insecure. In this work, after giving an example of a recent CLCS scheme suffering Type I attack, we propose an efficient pairing-free CLCS scheme suitable for secure data transmission in IoMT based on the idea of zero-knowledge proof. It not only provides confidentiality and unforgeability of transmitted data under the Type I and Type II attacks but also achieves lower computational and communication overhead, and public verifiability. Finally, compared with the five recent CLSC schemes, theoretical analysis and experimental testing results show that the proposed scheme outperforms the other five schemes in terms of computation and communication costs as well as security. Therefore, our scheme is better suited for constructing secure data transmission in IoMT scenarios. Jianhong Zhang 0001, Chenghe Dong, Yi-Ning Liu 0002 |
IEEE Internet Things J. | 1 |
| 2024 | PFDAM: Privacy-Preserving Fine-Grained Data Aggregation Scheme Supporting Multifunctionality in Smart GridabstractIn smart grids, fine-grained data aggregation with multi-functionality is essential for utilities to accurately predict power supply-and-demand balance and perform secure data processing. Constructing such a powerful privacy-preserving data aggregation scheme, requires considerations for fine-grained data aggregation, data privacy, integrity, unlinkability, and fault tolerance of the protocol. However, existing data aggregation schemes fail to provide all these functionalities because the introduction of certain technologies in these schemes make some functions incompatible with each other, such as digital signatures guarantee data integrity but lead to data linkability. Therefore, it is a challenge to construct a data aggregation scheme that satisfies the above functionalities. To address it, by combining HMAC and public key encryption with equality testing, we propose a fine-grained privacy-preserving data aggregation scheme supporting multi-functionality (PFDAM). The proposed scheme can provide the above functionalities and resist malicious data mining attacks launched by internal or external attackers. Detailed security proofs and performance analysis show that our PFDAM system satisfies the smart grid systems desired security properties and efficiency. Finally, compared with several recent schemes, experimental results indicate that our PFDAM is practically applicable in terms of performance. Jianhong Zhang 0001 |
IEEE Internet Things J. | 1 |
| 2024 | On the Security of Multi-Receiver Certificateless Generalized Signcryption Scheme for WBANsabstractIn Wireless body area networks(WBANs), the physiological parameters monitored by wearable devices are sensitive data of patients. To ensure the privacy of such data, Shenet alproposed a multi-receiver certificateless generalized signcryption scheme to support multidisciplinary team treatment. Although they claim that their scheme can resist Type I attacks and provide the unlinkability of ciphertext, our analysis found that their scheme is insecure. Specifically, it is neither resistant to public key replacement in Type I attacks, nor does it satisfy the claimed unlinkability of ciphertext. After giving the corresponding attacks, we analyze the reasons underlying these attacks and provide the corresponding suggestions to overcome them. Chenghe Dong, Jianhong Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | On the Security of Lightweight and Escrow-Free Certificate-Based Data Aggregation for Smart GridabstractRecently, to eliminate complex certificate maintenance and key escrow issue, Verma et al. proposed the first certificate-based(CB-based) data aggregation scheme for smart grids, in which a lightweight CB-based signature is proposed to ensure the integrity of the transmitted data. Although they claimed that the proposed certificate-based signature scheme is secure against attacks by a malicious certification authority (CA), unfortunately, by analyzing the security of Verma et al.'s scheme, we show that their scheme is insecure. It can not provide data integrity since a malicious CA can forge a message's signature in the name of any entity. After giving the corresponding attacks, we analyze the reasons for producing such attacks and provide the corresponding suggestions to overcome them. Jianhong Zhang 0001, Chenghe Dong |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | On the Security of Privacy-Enhanced Authentication Protocol for Federated Learning in VANETsabstractIn federated learning for VANET, Yuan et al. proposed a privacy-enhanced authentication protocol to balance training efficiency and vehicle privacy. They claimed that their protocol provides both unforgeability and traceability, asserting that it is secure against unforgeable attacks from Type I adversaries and allows Trust Authorities (TAs) to trace the real identities of malicious vehicles. Unfortunately, our analysis reveals that Yuan et al.’s protocol is insecure in the presence of malicious vehicles. Specifically, malicious vehicles can forge the signatures of arbitrary messages through public key replacement attacks by Type I adversaries. Furthermore, the real identities of malicious vehicles cannot be effectively traced. Consequently, the authenticity and integrity of the collected model parameters cannot be guaranteed. After analyzing the reasons for these vulnerabilities, we offer corresponding suggestions to overcome them. Jianhong Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Lightweight Hierarchical Deterministic Wallet Supporting Stealth Address for IoTabstractWith the advancement of cryptocurrencies, hierarchical deterministic wallets (HDW) are widely used due to their advantages of easy backup, offline storage, and convenient address management. However, most present HDW schemes are vulnerable to privilege escalation attacks, which pose a tremendous risk to user privacy. As an effective technique for protecting user identity privacy, stealth addresses allow payers to generate a unique address for each transaction in a noninteractive manner. Integrating stealth addresses into HDW can help improve the security of HDW schemes. Based on the above idea, we propose a novel lightweight Hierarchical Deterministic Wallet Supporting Stealth Address (HDWSA) scheme, which not only provides all standard wallet functions but also guarantees the privacy of user identities. Since the proposed scheme is based on the generic elliptic curve cryptosystem, time-consuming pairing operations are avoided, which makes it directly applicable to the current blockchain structure. Finally, the new scheme is proven to be secure in the random oracle. Chenghe Dong, Jianhong Zhang 0001, Zongyi Lv, Ruxuan Zhang |
TrustCom | 2 |
| 2023 | SE-P²μm: Secure and Efficient Privacy-Preserving User-Profile Matching Protocol for Social NetworksabstractBy matching attributes in user profiles, social networking services (SNSs) are able to create certain social relationships between different users. However, user profiles often contain sensitive information about users. If data matching is done in plaintext, users’ privacy and security will face serious challenges. Most recently, the hacking incident of Ashley Madison website, which incurred more than 60 GB of data being leaked, has prompted researchers to explore the privacy of user data in social networks urgently. Existing schemes may be able to achieve privacy-preserving user profile matching, but they require high communication bandwidth and complex computational costs. To address them, we proposed a private user profile matching protocol for social networks using$t$-out-of-$n$matching servers. Applying the Chinese remainder theorem (CRT), Bloom filter technique, and skyline computation idea, the matching users are efficiently returned with the help of any$t$matching server without disclosing their identities. In addition, our scheme allows up to$t$matching servers to collude while simultaneously ensuring user profile privacy and query privacy. Finally, compared with two recent user profile matching protocols, the performance results demonstrate that our scheme outperforms them. Jianhong Zhang 0001, Haoting Hao, Hongwei Su |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2023 | Comment on "Secure and Lightweight Conditional Privacy-Preserving Authentication for Securing Traffic Emergency Messages in VANETs"abstractIn the above paper, Wei et al. proposed a lightweight conditional privacy-preserving authentication protocol in VANET to achieve both ultra-low transmission delay and SSK updating. To decrease communication overhead, their scheme adopts a signature scheme with message recovery to achieve message authentication. And they claimed that the adopted signature was secure against adaptively chosen message attacks, and gave the detailed security proof. Unfortunately, in this work, by analyzing the security of Wei et al. scheme, we show that their scheme is insecure, and it is universally forgeable, i.e., anyone can forge a valid signature on any message; it also makes their scheme does not satisfy conditional privacy. Finally, after analyzing the reasons to produce the attack, we give the corresponding suggestion to overcome the attacks. Jianhong Zhang 0001, Qijia Zhang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Corrigendum to "Randomization-Based Dynamic Programming Offloading Algorithm for Mobile Fog Computing"abstractcoauthors Rajiv Kumar has no contribution and was added incorrectly. e correct author list is shown above. Wenle Bai, Zhongjun Yang, Jianhong Zhang 0001 |
Secur. Commun. Networks | 3 |
| 2021 | Randomization-Based Dynamic Programming Offloading Algorithm for Mobile Fog ComputingabstractOffloading to fog servers makes it possible to process heavy computational load tasks in local devices. However, since the generation problem of offloading decisions is an N-P problem, it cannot be solved optimally or traditionally, especially in multitask offloading scenarios. Hence, this paper has proposed a randomization-based dynamic programming offloading algorithm, based on genetic optimization theory, to solve the offloading decision generation problem in mobile fog computing. The algorithm innovatively designs a dynamic programming table-filling approach, i.e., iteratively generates a set of randomized offloading decisions. If some in these sets improve the decisions in the DP table, then they will be merged into the table. The iterated DP table is also used to improve the set of decisions generated in the iteration to obtain the optimal offloading approximate solution. Extensive simulations show that the proposed DPOA can generate decisions within 3 ms and the benefit is especially significant when users are in multitask offloading scenarios. Wenle Bai, Zhongjun Yang, Jianhong Zhang 0001, Rajiv Kumar 0001 |
Secur. Commun. Networks | 3 |
| 2021 | Efficient Cloud-Based Private Set Intersection Protocol with Hidden Access Attribute and Integrity Verification
Jianhong Zhang 0001 |
Secur. Commun. Networks | 1 |
| 2020 | A Fog-Assisted Privacy-Preserving Task Allocation in CrowdsourcingabstractAs a people-centric sensing paradigm, crowdsourcing has attracted considerable attention since it can solve a complicated task by gathering the wisdom of a crowd of workers. To increase the efficiency of task allocating and recruit suitable workers, the crowdsourcing server needs to obtain information related to task content and worker profiles, which poses a threat to privacy leaks of both tasks and workers. Although several privacy-preserving crowdsourcing mechanisms with simultaneously achieving task privacy and worker privacy have been proposed, there are two problems for these schemes, either the ability of workers is not taken into account or they are computationally intensive. To address the above problems simultaneously, fog-assisted privacy-preserving task allocation in crowdsourcing is proposed by means of the advantages of fog computing, which can not only achieve privacy protection of both the task and the worker but also alleviate the workers' computational burden by offloading partial computation to the fog node. By applying threshold secret sharing technology, the proposed scheme enables that only workers satisfying task requirements can decrypt the task content, which achieves the verification of the workers' ability and resists the attacks of the greedy workers. Then, rigorous security proofs about privacy properties are given in the proposed scheme. Finally, the proposed scheme is estimated through theoretical analysis and experiments. The experimental results show that compared with the current state-of-the-art scheme, the proposed scheme has more advantages in terms of computational cost and storage overhead. Especially for a worker, it only requires one pairing and two multiplication operations in the decrypting phase. Jianhong Zhang 0001, Qijia Zhang, Shenglong Ji |
IEEE Internet Things J. | 1 |
| 2020 | Identity-based data storage scheme with anonymous key generation in fog computing
Jianhong Zhang 0001, Wenle Bai, Xianmin Wang |
Soft Comput. | 1 |
| 2019 | Improvement of ID-based proxy re-signature scheme with pairing-free
Jianhong Zhang 0001 |
Wirel. Networks | 1 |
| 2018 | On the Security of a Pairing-Free Certificateless Signcryption SchemeabstractUnforgeability is an important security property in signcryption. Recently, Yu et al. proposed a pairing-free and secure certificateless signcryption scheme and demonstrated their scheme was provably secure in the random oracle model. Unfortunately, in this letter, we show their scheme is insecure against the malicious KGC and the malicious sender through proposing two concrete attacks. Jianhong Zhang 0001 |
Comput. J. | 1 |
| 2017 | Co-Check: Collaborative Outsourced Data Auditing in Multicloud EnvironmentabstractWith the increasing demand for ubiquitous connectivity, wireless technology has significantly improved our daily lives. Meanwhile, together with cloud-computing technology (e.g., cloud storage services and big data processing), new wireless networking technology becomes the foundation infrastructure of emerging communication networks. Particularly, cloud storage has been widely used in services, such as data outsourcing and resource sharing, among the heterogeneous wireless environments because of its convenience, low cost, and flexibility. However, users/clients lose the physical control of their data after outsourcing. Consequently, ensuring the integrity of the outsourced data becomes an important security requirement of cloud storage applications. In this paper, we present Co-Check, a collaborative multicloud data integrity audition scheme, which is based on BLS (Boneh-Lynn-Shacham) signature and homomorphic tags. According to the proposed scheme, clients can audit their outsourced data in a one-round challenge-response interaction with low performance overhead. Our scheme also supports dynamic data maintenance. The theoretical analysis and experiment results illustrate that our scheme is provably secure and efficient. Wenqian Tian, Hanjun Ma, Jingdong Bian, Jianwei Liu 0001, Jianhong Zhang 0001 |
Secur. Commun. Networks | 8 |
| 2016 | ID-based Data Integrity Auditing Scheme from RSA with Resisting Key Exposure
Jianhong Zhang 0001, Pengyan Li, Zhibin Sun |
ProvSec | 1 |
| 2016 | Collaborative Outsourced Data Integrity Checking in Multi-Cloud Environment
Hanjun Ma, Jianhong Zhang 0001 |
WASA | 5 |
| 2016 | Efficient ID-based public auditing for the outsourced data in cloud storage
Jianhong Zhang 0001, Qiaocui Dong |
Inf. Sci. | 1 |
| 2016 | Attack on Chen et al.'s certificateless aggregate signature schemeabstractAbstract Certificateless aggregate signature can provide an efficient way to verify a large amount of signatures from different users. This feature makes it very useful in the environments with low bandwidth communication, low storage, and low computability. Recently, Chen et al. proposed a new certificateless aggregate signature scheme. They claim that their scheme is provably secure under the computational Diffie–Hellman problem. Unfortunately, this paper shows that Chen et al.'s scheme is insecure, it cannot resist Type I and Type II adversaries, and the corresponding attacks are given. Furthermore, we also show their scheme exists a more powerful attack, namely, anyone can forge a certificateless signature on an arbitrary message in this attack. Finally, we discuss the reason to produce such attacks and give the corresponding suggestions to resist such attacks. Copyright © 2015 John Wiley & Sons, Ltd. Jianhong Zhang 0001, Xubing Zhao |
Secur. Commun. Networks | 1 |
| 2015 | A novel authenticated encryption scheme and its extension
Jianhong Zhang 0001, Xubing Zhao |
Inf. Sci. | 1 |
| 2011 | Forgeability Attack of Two Special Signature Schemes
Jianhong Zhang 0001, Yuanbo Cui, Xi Wu 0002 |
ICIC (1) | 1 |
| 2010 | An efficient secure proxy verifiably encrypted signature scheme
Jianhong Zhang 0001, Chenglian Liu, Yixian Yang |
J. Netw. Comput. Appl. | 1 |
| 2009 | Cryptoanalysis of Two Signcryption SchemesabstractCertificateless PKC and self-certified PKC are two new public key systems. They remove the necessity of certificate to ensure the authentication of the user's public key in CB-PKC and also overcome the inherent key escrow problem in IB-PKC. Recently, Zhang et.al proposed a self-certified signcryption scheme, and Wu et.al gave a certificateless signcryption scheme. However, in this paper, we analyze the security of Zhang et.al's self-certified signcryption scheme and Wu et.al certificateless signcryption scheme, and show that the two signcryption schemes are insecure though the two schemes were proven to be secure under the random oracle model. In the self-certified signcryption scheme, a malicious user can forge a signcryption on an arbitrary message m without CA's authentication. In Wu et.al's certificateless signcryption scheme, confidentiality of signcryption is not satisfied. Namely, the scheme is not against chosen ciphertext attack. Finally, we give the corresponding attack, and to overcome the above flaws, we also discuss the corresponding improved method, respectively. Jianhong Zhang 0001, Qin Geng |
IAS | 1 |
| 2009 | On the Linkability and Security Analysis of Two Schnorr-Type Blind Signature SchemesabstractAs a special digital signature, the blindness of blind signatures can protect the signed contents, this property makes it to distinguish from the other signatures. And it makes it play an important role in plays a central role in applications such as electronic voting and electronic cash system. Recently, Huang et. al and Wang et. al propose a Schnorr-type blind signature schemes, respectively. And they claimed that these schemes were secure. In the paper, we discuss the security Huang et.al's scheme and Wang et.al's scheme. And the result shows that the two blind signature schemes are insecure. Huang et.al's scheme is universally forgeable, namely, any one can produce a forged signature on arbitrary a message. And Wang et.al's scheme is linkable. Namely, it doesn't't satisfy the blindness of blind signature. It means that the signer is able to link a valid message-signature pair obtained by some user. Finally, we give the corresponding attack on the two schemes and analyze the reasons to produce such attack, then give an improved blind signature scheme. Jianhong Zhang 0001, Shengnan Gao |
DASC | 1 |
| 2009 | Efficient Provable Secure ID-Based Directed Signature Scheme without Random Oracle
Jianhong Zhang 0001, Yixian Yang, Xinxin Niu |
ISNN (3) | 1 |
| 2009 | On the Security of a Certificate-Based Signature Scheme and Its Improvement with Pairings
Jianhong Zhang 0001 |
ISPEC | 1 |
| 2009 | A novel identity-based multi-signcryption scheme
Jianhong Zhang 0001 |
Comput. Commun. | 1 |
| 2007 | An Efficient Identity-Based Ring Signature Scheme and Its Extension
Jianhong Zhang 0001 |
ICCSA (2) | 1 |
| 2007 | A Novel Verifiably Encrypted Signature Scheme Without Random Oracle
Jianhong Zhang 0001 |
ISPEC | 1 |
| 2005 | An Improved Group Signature Scheme
Jianhong Zhang 0001, Jiancheng Zou, Yumin Wang |
TrustBus | 1 |
| 2005 | A Convertible Limited Verifier Signature Scheme
Jianhong Zhang 0001, Jilin Wang |
WAIM | 1 |
| 2004 | Provably Secure and ID-Based Group Signature SchemeabstractThere are two important directions in group signature scheme: ID-based group signature scheme and provably secure group signature scheme. We first analyze the advantages and flaws of these two directions, and propose a provably secure ID-based group signature scheme basing on the ACJT group signature scheme. Compared with prior ID-Based group signature scheme, our scheme is provably secure in random oracle model. Compared with the ACJT scheme, our scheme is ID-Based and strong nonrepudiation. Zewen Chen, Jiwu Huang, Daren Huang, Jianhong Zhang 0001, Yumin Wang |
AINA (2) | 4 |
| 2004 | An Improved Nominative Proxy Signature Scheme for Mobile CommunicationabstractRecently, Seung-Hyun et al proposed a nominative proxy signature scheme for mobile communication. However, we show that the scheme hasn't nonrepudiation, note that a malicious original signer can forge the proxy signer to sign on any message. Finally, we also present a modification of the scheme to repair the security flaw. Jianhong Zhang 0001, Qianhong Wu, Jilin Wang, Yumin Wang |
AINA (2) | 1 |
| 2003 | Practical t-out-n Oblivious Transfer and Its Applications
Qianhong Wu, Jianhong Zhang 0001, Yumin Wang |
ICICS | 2 |
| 2003 | A Novel Efficient Group Signature Scheme with Forward Security
Jianhong Zhang 0001, Qianhong Wu, Yumin Wang |
ICICS | 1 |
| 2003 | Security analysis of the improved group signatureabstractWe show that the improved group signature (Yuh-Min Tseng and Jinn-ke Jan, Electron. Lett., vol.35, no.16, p.1324, 1999) has an essential flaw: universal forgery. An adversary can forge a group membership certificate to sign any message without being traced by the group manager. Jianhong Zhang 0001, Xiaofeng Chen 0001, Yumin Wang |
ITW | 1 |