VLDB 2026 Research / reviewers in the wild / expert
Huaqun Wang
dblp:73/4432
· DBLP profile ↗
125ranked-venue papers
36as first author
66since 2021 · last 2027
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 48 · 16 first-author · 22 since 2021Computer networks · 32 · 3 first-author · 17 since 2021Systems, architecture and hardware · 18 · 5 first-author · 13 since 2021Software engineering, systems software and programming languages · 10 · 6 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 5 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Linearly homomorphic signatures with adaptively sublinear public keys in the standard model
Jinpeng Hou, Mang Su, Yansong Gao 0001, Huaqun Wang, Anmin Fu, Willy Susilo |
Future Gener. Comput. Syst. | 4 |
| 2026 | Efficient Volume-Hiding Encrypted Conjunctive Search With Leakage Suppression for Cloud-Assisted IoTabstractIn resource-constrained environments such as IoT sensors and mobile devices, there is a strong demand for efficient conjunctive keyword search over privacy-sensitive data. However, existing schemes struggle to simultaneously suppress sterm equality leakage, the cross-query intersection pattern (IP), and the volume pattern without incurring prohibitive overhead. In this paper, we present XORCMM, a practical volume-hiding encrypted conjunctive multi-map (EMM) designed for robust leakage suppression. First, we shift the index construction from single keywords to global-ordering co-occurrence pairs, which ensures that search tokens are no longer tied to static keyword identities, thereby suppressing sterm equality leakage. Second, we integrate an incremental multiset hash aggregation mechanism directly into a fully padded Xor filter. This allows the server to aggregate multiple conjunctive results into a single, fixed length response, concealing both IP and volume patterns while eliminating the data redundancy of prior schemes. Third, we employ a prefix-constrained PRF to compactly encode keyword pairs, generating succinct query tokens whose size is independent of keyword volumes. Formal security analysis proves that XORCMM is adaptively secure with sterm equality, IP, and volume leakages hidden. Experimental results demonstrate that XORCMM achieves up to a 2.99× speedup in client setup, a 3.3× speedup in server query time, and reductions of 47% in response size and 84.61% in search token size, providing a stronger security guarantee with significantly higher efficiency. Yi Dou, Chaoran Zhou, Haiping Huang, Huaqun Wang, Hua Dai 0003, Man Ho Au |
IEEE Internet Things J. | 4 |
| 2026 | A Fast Intermittent Fault Diagnosis Algorithm for a Class of Data Center NetworksabstractAs a data center network (DCN) constructed using recursive modules, BCube enables efficient communication for decentralized machine learning systems. Its various variants, such as RCube and RRect, outperform BCube in certain performance metrics. To unify related research, BCube and its variants are integrated into a unified framework known as BCube-based DCNs (BDCN). In practical DCN deployments, efficient fault diagnosis is essential for reliability and stability. However, intermittent faults are more challenging to diagnose than permanent ones due to their randomness and uncertainty. Moreover, existing intermittent fault diagnosis algorithms generally rely on searching for the largest component, which leads to high time complexity. To address this issue, this paper systematically analyzes the intermittent fault diagnosability of BDCN under the PMC model, and proposes a fast intermittent fault diagnosis algorithm (FIFDA). The proposed algorithm significantly improves diagnosis efficiency by avoiding the need to search for the largest component. Extensive experimental results verify the applicability of FIFDA in both BDCN and other high-performance DCNs. Comparative analyses with existing algorithms show that FIFDA achieves higher diagnostic speed. Moreover, under comparable diagnosis times, FIFDA demonstrates superior diagnostic performance. In addition, simulation results demonstrate that FIFDA maintains outstanding performance in large-scale DCNs and under varying noise levels and fault probabilities, fully showcasing its efficiency and scalability in practical DCN environments. Huaqun Wang, Mengjie Lv, Weibei Fan |
IEEE Trans. Computers | 2 |
| 2026 | Blockchain-Enabled Efficient Deduplication and Mixed Auditing for Dynamic Cloud DataabstractAs cloud storage is extensively utilized in the contemporary digital age, assuring data integrity and conserving cloud storage space has become a priority for all. However, existing cross-user deduplication audit schemes conflict with the pay-as-you-go model, causing unnecessary costs and violating data isolation. Moreover, retaining a single copy of identical data across multiple users introduces maintenance challenges during data operations. To address these issues, we propose a new blockchain-enabled efficient deduplication and mixed auditing scheme which intricately integrates Message-Locked Encryption (MLE) to construct Homomorphic Verifiable Tags (HVTs), enabling deduplication without exposing confidential data. Our scheme supports single-user deduplication at both block and file levels, as well as plaintext-ciphertext mixed auditing, thereby preventing redundant payments while preserving data isolation to simplify maintenance during data operations and ownership transfers. By employing Elliptic Curve Cryptography (ECC) to encrypt keys and storing the encrypted keys on the blockchain, we ensure data confidentiality while reducing the burden of local key management. Leveraging blockchain-based smart contracts, we further design a self-auditing mechanism that eliminates reliance on trusted third-party auditors. Moreover, our scheme embraces dynamic data operations through an optimized Merkle Hash Tree (MHT) and enables secure cloud data ownership transfer via identity verification. Finally, we prove the correctness and security of our scheme and evaluate its performance through experiments and comparisons with state-of-the-art works, demonstrating its efficiency, particularly in the data upload phase. Chunfei Pan, Lei Zhou 0026, Anmin Fu, Zhenzhu Chen, Huaqun Wang, Yifeng Zheng 0001, Yansong Gao 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Enhancing Integrity Verification of Convolutional Neural Network Predictions in a Malicious ModelabstractThe widespread deployment of neural networks has raised significant concerns regarding the integrity and privacy of model predictions, especially in malicious environments. Current approaches have explored zero-knowledge proofs for integrity verification. However, they suffer from inefficiency in proving runtime and a lack of rigorous integrity verification for non linear operations. To address these issues, we present a trustwor thy framework for Enhancing Integrity Verification of Convolutional Neural Network predictions (EIV-CNN) in a malicious model, whose key contributions are an efficient optimized sum check protocol and a robust enhanced verification mechanism. Specifically, we first propose an algorithm that enables efficient proving of both batch and collaborative CNN predictions by com bining sumcheck claims of multiple matrix multiplications into one. Moreover, we introduce a non-interactive sumcheck protocol with malicious security (NM-Sumcheck) to serve as a building block for publicly verifying matrix multiplication operations. Furthermore, we introduce a verifiable method for transforming nonlinear operations into matrix operations, enabling their sub sequent evaluation with the NM-Sumcheck protocol. Our EIV CNN provides malicious security, guarantees public verifiability, and preserves model privacy. Empirical results demonstrate that our sumcheck framework achieves constant prover time, verifier time, and proof size. Compared to the state-of-the-art, it achieves up to a 128.56× reduction in prover time, along with significant reductions in communication overhead and enhanced scalability. Zhongkai Lu, Meng Li 0006, Jingjing Wang 0003, Huaqun Wang |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | Single Proof for Multi-Authentication: Decentralized Anonymous Functional Credentials Based on fNIZKabstractWeb3 has attracted considerable attention in fields including DeFi, DApps, and NFTs due to its decentralization, enhanced privacy, and user-centricity. However, interoperability and scalability challenges hinder its widespread adoption. While deploying anonymous credentials across Web3 networks to enable cross-network service access is a potential solution to these challenges, existing credential systems remain limited by centralized management, high energy consumption, and credential abuse, making them unsuitable for Web3 environments. To overcome these limitations, we propose a decentralized anonymous functional credential (DAFC) scheme that is efficient, privacy-preserving, and linkable. Unlike existing schemes, DAFC enables users to generate a single proof embedding attributes$x$for requesting services under different access policies. Each provider can use the functional key$sk_{F}$associated with their respective access policy$F$to extract$F(x)$for attribute verification. This significantly reduces authentication computational overhead. Furthermore, DAFC's linkability effectively mitigates credential abuse risks. As an additional contribution, we propose a novel construction of non-interactive zero-knowledge functional proof (fNIZK) based on one-out-of-many proofs and functional encryption for inner products, which is the building block of DAFC. Security analysis demonstrates that DAFC achieves anonymity, unforgeability, and linkability. Performance evaluation shows that DAFC outperforms prior schemes in both computational and communication overhead when requesting at least 6 services with distinct access policies. Tianyu Zhaolu, Huaqun Wang, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Matching Comes First: Efficient Certificateless Lattice-Based Bilateral Access Control With On-Demand MatchingabstractThe proliferation of data-driven services on cloud platforms, coupled with stringent regulatory frameworks like the General Data Protection Regulation (GDPR), necessitates crypto-graphic solutions that ensure secure and efficient data exchange. However, simultaneously achieving post-quantum security, bilateral access control, data authenticity, simplified key management and efficiency remains a critical challenge. To address these issues, this paper introduces a certificateless lattice-based matchmaking encryption (CLLME) to provide post-quantum security while obviating key escrow and certificate management. The proposed scheme enforces bilateral access control, allowing both data senders and receivers to specify matching access structures; decryption is thus contingent upon mutual authorization. Moreover, to prevent the costly decryption of numerous irrelevant ciphertexts, CLLME embeds a lightweight authenticity operation, which enables retrieval of useful data, effectively creating a high-performance filter for encrypted data streams. We formally prove that CLLME achieves indistinguishability against chosen-plaintext attacks and existential unforgeability against chosen-message attacks under lattice-based assumptions. Experimental evaluations demonstrate that CLLME maintains favorable communicational and computational efficiency, confirming its suitability for practical and scalable deployment in regulation-compliant, large-scale data sharing environments. Huaqun Wang, Hua Dai 0003, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Disjoint paths construction algorithm in the data center network DPCellabstractAbstract With the development of the fourth industrial revolution, the importance of data centers has significantly increased. Data centers are widely used in many fields due to their ability to provide efficient, secure, and reliable data storage and processing services. However, with the increasing amount of data, traditional data center networks (DCNs) are currently facing various challenges, prompting academia and industry to propose new DCN architectures. As a dual-port server-based DCN, DPCell has excellent scalability and bisection width, enabling it to meet the demands of large-scale data storage, processing, and computation in the digital revolution. In order to ensure the secure and reliable data communication in the DPCell, this paper designs a disjoint paths communication scheme based on the actual DCN routing requirements. This scheme constructs the optimal number of disjoint paths in DPCell, with a maximum path length of $2^{k}+3$, where $k$ represents the dimension of the DPCell. Furthermore, experiments have verified that the time complexity of this scheme is sublinear, making it more efficient than the current optimal maximum flow algorithm. To a certain extent, this scheme provides DPCell with the required high bandwidth, fault tolerance, and security for data communication. Huaqun Wang, Mengjie Lv, Weibei Fan |
Comput. J. | 2 |
| 2025 | Fault tolerance assessment of the data center network DPCell based on g-good-neighbor conditionsabstractAbstract Data center networks (DCNs) provide critical data storage and computing services for cloud computing. The continuous increase in demand for cloud computing has led to a surge in data volume, necessitating the continual expansion of DCNs. However, this expansion also heightens the risk of device failures. Therefore, it is particularly important to study the fault tolerance of DCNs, which refers to their ability to ensure reliable communication even in the presence of device failures. Among DCNs constructed using dual-port servers, DPCell achieves higher scalability and bisection width while maintaining a smaller diameter. This paper assesses the fault tolerance of DPCell using two metrics: connectivity and diagnosability. Recognizing the limitations of traditional connectivity and diagnosability, we investigate the connectivity and diagnosability of DPCell under the condition that each fault-free node in the network has at least $g$ fault-free neighbors. The results indicate that, under this condition, the connectivity and diagnosability of DPCell exceed its traditional metrics by more than $g$ times. Huaqun Wang, Mengjie Lv, Weibei Fan |
Comput. J. | 2 |
| 2025 | QCSAS: A Quasi-Constant and Synchronized Aggregate Signature Scheme for AMI NetworksabstractSmart grids must safeguard their critical infrastructures against both physical and cyber attacks. Therefore, real-time operation and cybersecurity are two fundamental requirements for smart grid systems. AMI (Advanced Metering Infrastructure) is a critical part of the smart grid that specifically deals with the measurement, collection, and analysis of electricity usage data. Digital signatures help prevent data tampering and ensure cybersecurity during AMI communications. However, as the number of smart meters and transactions in an AMI network increases, deploying digital signatures can lead to communication delays. This paper designs a quasi-constant and synchronized aggregate signature scheme (QCSAS), which can protect usage data without hash functions. The QCSAS scheme simplifies the synchronized aggregate signatures, and is proved secure against chosen message attacks in the random oracle model. The QCSAS scheme incorporates the features of synchronized aggregate signatures, such as the constant aggregate signature size, thereby minimizing the data management system’s storage space. Furthermore, the length of usage data does not exceed 12-bit, in compliance with existing governmental standards. The computational cost of multiplying a 12-bit integer is negligible compared to other cryptographic operations. Thus, the verification cost of the QCSAS scheme remains quasi-constant. Yujiao Sun, Zhiyuan Sui, Huaqun Wang, Hermann de Meer |
IEEE Internet Things J. | 3 |
| 2025 | Fed-HA: A Privacy-Preserving Robust Federated Learning Scheme based on Homomorphic Assessment
Wenxuan Xu 0002, Xiaolong Xu 0002, Huaqun Wang |
J. Inf. Secur. Appl. | 3 |
| 2025 | Reliable Communication Scheme Based on Completely Independent Spanning Trees in Data Center NetworksabstractWith technological advancements, real-time applications have permeated various aspects of human life, relying on fast, reliable, and low-latency data transmission for seamless user experiences. The development of data center networks (DCNs) has greatly advanced real-time applications, with network reliability being a key factor in ensuring high-quality network services. As a switch-centric DCN, DPCell has good scalability and the ability to achieve load balancing at different traffic levels. With the increasing demand for high availability, fault tolerance, and efficient data transmission, highly reliable communication for DPCell is essential. Completely independent spanning trees (CISTs) play a significant role in enhancing reliable communication performance in networks. This paper proposes an algorithm for constructing CISTs in DPCell, which has relatively low time and space consumption compared to other CISTs construction algorithms in DCNs, offering an efficiency advantage. Communication simulations validate the effectiveness of using paths provided by CISTs in DPCell for data transmission. Furthermore, experimental results show that a multi-protection routing scheme configured with multiple CISTs significantly enhances fault tolerance in DPCell. Huaqun Wang, Mengjie Lv, Weibei Fan |
IEEE Trans. Computers | 2 |
| 2025 | MISP: An Efficient Quantum-Resistant Misbehavior Preventing Scheme With Self-Enforcement for Vehicle-to-EverythingabstractIn the Vehicle-to-Everything (V2X) communication system, the presence of ambiguous warnings significantly increases the risk of severe accidents, posing a substantial threat to the safety of autonomous driving. It is crucial to detect such confusing warnings to avoid danger. Existing solutions to address this issue heavily rely on trust entities or are constructed based on number theory assumptions, leading to low efficiency and vulnerability to quantum attacks. In this paper, we leverage the double authentication-preventing signature scheme (DAPS) to present a revocable identity-based double-authentication preventing signature scheme (RIDAPS) and provides an instantiation from lattice. Furthermore, we propose a post-quantum secure misbehavior preventing scheme (Misp) based on our RIDAPS scheme. We give a detailed proof in the random oracle model (ROM) to demonstrate that our contribution achieves security requirements. Additionally, the efficiency evaluation results demonstrate that our scheme is suitable to be applied in V2X. Ying Chen 0030, Debiao He, Zijian Bao, Huaqun Wang, Min Luo 0002 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Invisible Warning Line: Efficient and Generic Regulation for Anonymous CryptocurrenciesabstractDecentralized finance based on blockchain has experienced rapid development. To safeguard the privacy of participants, decentralized anonymous payment (DAP) systems such as ZCash and Zether have emerged. These systems employ cryptographic techniques to conceal the trader addresses and payment amounts. However, this anonymity presents challenges in terms of regulation. To address this issue, we propose the Walsh-DAP (WDAP) scheme, an efficient and generic regulation scheme for decentralized anonymous payments that strikes a balance between regulation and privacy preservation. Our scheme introduces two regulation policies: first, users who have exceeded their spending limits within a certain period will be identified during the regulation process; second, the supervisor possesses the capability to trace any anonymous transaction. To implement regulation effectively, we have designed an innovative commitment scheme, Walsh commitment, which leverages the orthogonal properties of Walsh codes to achieve the features of aggregatability and extractability. The supervisor in WDAP only needs to deal with the aggregation result of the Walsh commitments instead of the huge amount of raw transactions information, which greatly increases the efficiency. In a DAP system with 256 users, 10 transactions per second and 30 days as a regulation period, we reduced the communication cost for regulation from 14 GB to 94.20 KB, and the computing cost from$\text{1.6}\times \text{10}^{\text{5}}$s to 2.17s. Both improvement is of over five orders of magnitude. We formally discussed the security of the whole system, and verified its feasibility and practicability in the ZCash system. Rui Gao 0007, Zhiguo Wan, Huaqun Wang, Shaoteng Luo |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | TERCT: A Traceable and Editable Ring Confidential Transaction for BlockchainabstractAnonymous cryptocurrency, as a distributed application utilizing blockchain technology, aims to enhance the level of anonymity in user transactions, but it may also be used for illegal activities. Existing anonymous transaction protocols lack effective public verification of transaction traceability, which means that malicious users have the ability to avoid being tracked by creating counterfeit incomplete evidence. In addition, there is a conflict between the immutability of blockchain and privacy regulations such as General Data Protection Regulation (GDPR), and revision of on-chain data is urgently needed. In order to solve above issues, we propose a trackable and editable anonymous transaction protocol TERCT, which is used to trace the addresses and transaction amounts of participants in anonymous transactions and enable editability of transaction content. Compared with previous work, TERCT enables the editability of transaction content while maintaining anonymity and publicly verifiable traceability of transactions. This ensures that users not only can edit usergenerated transaction content but also cannot fabricate pertinent evidence to evade tracing. We prove the proposed TERCT protocol satisfies unforgeability, balance, anonymity and traceability. We compare its effectiveness with the original RingCT protocol, Wolverine scheme and Trct scheme by experiments. The results show that TERCT has less additional computational overhead. Jiguo Li 0001, Ninghai Xie, Yichen Zhang 0003, Huaqun Wang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | PM-ABE: Puncturable Bilateral Fine-Grained Access Control From Lattices for Secret SharingabstractIn the era of flourishing sustainable smart cities, with the accessibility of Internet and the persistent evolution of distributed computing, there is an increasing reliance on cloud/fog computing environments and online data storage platforms for secure data sharing. However, existing cryptographic schemes fall short in simultaneously satisfying security requirements such as bilateral fine-grained access control, resilience to quantum attacks, assurance of the authenticity of decrypted data, and forward security for historical data. To tackle these challenges, we propose the innovative puncturable attribute-based matchmaking encryption scheme based on lattice cryptography. The method adeptly satisfies the aforementioned stringent security requirements concurrently, offering a triple-layered assurance for the secure implementation of secret sharing. The receiver, unable to successfully decrypt, remains uninformed about any specifics regarding ciphertexts and the access policy. Our PM-ABE scheme has manifested resilience against quantum attacks, collusion attacks, chosen plaintext attacks and ensuring unforgeability under chosen message attacks. Furthermore, our comprehensive efficiency analysis substantiates that our scheme maintains a favorable level of computational efficiency and storage consumption. Huaqun Wang, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | EPSRQ: Efficient Privacy-Preserving Spatial-Keyword Range Query Processing in Cloud
Mingfeng Jiang, Hua Dai 0003, Huaqun Wang, Rui Gao 0007, Geng Yang 0002, Fu Xiao 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | RLP-ABE: Puncturable CP-ABE for Efficient User Revocation From Lattices in Cloud StorageabstractCloud computing has become the predominant platform for data sharing due to its adaptability, cost-effectiveness, and ability to scale resources according to user demand. Ensuring secure and efficient data sharing has long been a central research focus, with attribute-based encryption (ABE) serving as a key cryptographic primitive. In real-world scenarios, user attributes often change, necessitating timely revocation of access rights. Common user revocation methods include direct and indirect revocation. Direct revocation is controlled by the data owner, who adds revocation information to a list and embeds it into ciphertext to revoke permissions. Indirect revocation is managed by an authorized authority or delegated third party, dynamically publishing revocation information and generating new keys and ciphertexts. Conventional direct and indirect revocation methods incur substantial communication and computation overheads, limiting their practical effectiveness, particularly in environments with frequent user access terminations. To address these challenges, we propose a novel puncturable ciphertext-policy ABE scheme based on lattice cryptography for user revocation, eliminating the need for key regeneration and revocation-list maintenance. The proposed approach effectively resists collusion, quantum, and chosen-plaintext attacks, and experimental evaluations demonstrate its advantages in storage consumption, communication cost, and computational overhead. Huaqun Wang, Debiao He, Jiankuo Dong |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | ABP-DKM: An Efficient Decentralized Key Management Scheme Based on Asymmetric Bivariate PolynomialabstractWith the development of the industrial Internet, industrial Internet data has been growing rapidly, and so has the need for secure communications. In the context of industrial communication, it is essential to establish an effective session key between untrusted nodes. The prevailing key management schemes concentrate on key negotiation with the assistance of a central node through a man-in-the-middle approach. However, industrial field environments are typically characterised by harsh conditions, and any node may be damaged or subject to malicious compromise. This can result in the complete paralysis of communication within the entire system. Consequently, existing key management schemes are unable to fulfil the requisite performance requirements. In contrast to previous centralized or polycentric schemes, we propose an asymmetric bivariate polynomials-based novel efficient decentralized key management scheme (ABP-DKM). ABP-DKM achieves threshold switching through a twice-distribution method, which is more secure than other existing schemes. During the whole key negotiation process, ABP-DKM is decentralized. ABP-DKM is capable of not only peer-to-peer communication but also intra-group communication with forward and backward secrecy. The proposed scheme is more secure and efficient than the existing schemes. Yang Shi 0002, Huaqun Wang, Tianyu Zhaolu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Post-Quantum Rollup: Falcon Signature Aggregation Based on SNARG With Enhanced GatesabstractBlockchain layer 2 solutions aim to address scalability issues in Layer 1 networks by improving transaction efficiency and alleviating congestion. The rollup, a well-known Layer 2 scaling protocol, uses an aggregate signature scheme based on the succinct non-interactive argument of knowledge (SNARG) to package transactions. The further promotion of rollup faces the challenge of balancing computation efficiency and communication costs. In addition, with the continuous development of quantum computing, a transition to post-quantum cryptography is considered crucial for long-term security. Our main contribution is an aggregate Falcon signature scheme for post-quantum rollup based on a novel SNARG scheme. The proposed SNARG is based on the Plonkish circuit with enhanced custom gates, referred to as the ECG circuit, and a post-quantum multilinear polynomial commitment scheme (PolyCom). The former can represent more complex operations while also controlling the witness scale. The latter realizes quantum-resistant security for the proposed SNARG and the aggregate signature. In comparison to the aggregate signature based on Orion, our scheme achieves lower aggregation and communication costs. Performance analysis indicates a 38 % decrease in aggregation time and a 88 % decrease in communication costs. As an additional contribution, we introduce a novel polynomial interactive oracle proof (PolyIOP) protocol for the ECG circuit, which can combine with a multilinear PolyCom scheme to form a SNARG protocol with lower computation and communication overhead compared to existing schemes. Tianyu Zhaolu, Zhiguo Wan, Huaqun Wang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Constructing completely independent spanning trees in the generalized hypercube network
Huaqun Wang, Mengjie Lv, Weibei Fan |
J. Supercomput. | 2 |
| 2025 | Verifiable privacy-preserving spatial-keyword range query in cloud
Mingfeng Jiang, Hua Dai 0003, Zhengkai Zhang, Huaqun Wang, Geng Yang 0002 |
J. Supercomput. | 4 |
| 2025 | Conditional privacy-preserving spectrum trading scheme based on traceable ring signature for DSS system
Luona Yin, Huaqun Wang |
J. Supercomput. | 2 |
| 2025 | Post-quantum anonymous authentication for Web3: a lattice-based decentralized linkable anonymous credential scheme
Tianyu Zhaolu, Huaqun Wang |
J. Supercomput. | 2 |
| 2025 | FHE-Based Publicly Verifiable Sealed-Bid Auction Protocol Atop Cross-BlockchainabstractOnline auctions, which are widely used on Internet advertising platforms, reduce the participation costs for buyers and sellers, and promote the flow of tens of billions of dollars in the global economy. However, Internet advertising platforms tend to be monopolistic and adopt a sealed bidding model. Therefore, when price is the sole determinant of the winner, how to publicly verify the correctness of auction results without disclosing bidding information has become a challenge. To address these issues, we propose a fully homomorphic encryption (FHE)-based sealed-bid auction protocol with public verifiability atop cross-blockchain. Through an approximate comparison algorithm, the proof of the winner consists of${m} \,\, -1$(or 1) homomorphic ciphertexts, significantly reducing communication costs, where m represents the number of bidders. Thus, anyone can check the winner’s proof and complete the public verification of correctness. Moreover, this paper designs a cross-blockchain auction system model, breaking the monopoly of platforms, and proposes a distributed private key sharing method, which realizes the auditing function of the relay chain. Finally, we formalize the security model, and verify the correctness, public verifiability and privacy of our scheme. The off-chain time overhead and on-chain gas consumption demonstrate the strong practicability of our protocol in large-scale auctions. Bo Yang 0069, Liquan Chen, Jiaorui Shen, Huaqun Wang |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | A Succinct Range Proof for Polynomial-based Vector CommitmentabstractA range proof serves as a protocol for the prover to prove to the verifier that a committed number lies in a specified range, such as [0,2n), without disclosing the actual value. Range proofs find extensive application in various domains. However, the efficiency of many existing schemes diminishes significantly when confronted with batch proofs encompassing multiple elements. Rui Gao 0007, Zhiguo Wan, Yuncong Hu, Huaqun Wang |
CCS | 4 |
| 2024 | Pay-Per-Proof: Decentralized Outsourced Multi-User PoR for Cloud Storage Payment Using BlockchainabstractCloud computing has been widely applied in data storage, but cloud computing is not armed with an efficient integrity check mechanism for users to learn whether their large volumes of data have been kept intact by the cloud. The concept of proofs of retrievability (PoR) was introduced to address such an issue by enabling users to check the integrity of their data stored by the cloud. But PoR requires users to regularly send queries to the cloud, and its integrity check method cannot be extended to share the verification responsibility in the multi-user setting where different users store the same data to the cloud. With such concerns in mind, we put forth a notion called outsourced multi-user proofs of retrievability ($\mathtt {OMTPoR}$) which allows users with the same data stored by the cloud to share the information for the integrity check, and a third party is required to regularly check data integrity on behalf of users using the shared information. We give a concrete construction of$\mathtt {OMTPoR}$based on the homomorphic property of an existing property and analyze its security. To enforce honest integrity checks, we build the concrete$\mathtt {OMTPoR}$construction over the blockchain using smart contracts to guarantee the honesty of participants, yielding a decentralized outsourced multi-user PoR solution that utilizes the blockchain miners as the third parties. Furthermore, our solution enables the cloud server to obtain payment for the storage service if the PoR is verified by the miners. We fully implement the$\mathtt {OMTPoR}$scheme over the blockchain to evaluate its performance, which demonstrates obvious superiority over traditional PoR schemes without the detection of data duplication. Hui Cui 0001, Zhiguo Wan, Tianyu Zhaolu, Huaqun Wang, Atsuko Miyaji |
IEEE Trans. Cloud Comput. | 4 |
| 2024 | Enabling Privacy-Preserving Parallel Computation of Linear Regression in Edge Computing NetworksabstractLinear regression is a classical statistical model with a wide range of applications. The function of linear regression is to predict the value of a dependent variable (the output) given an independent variable (the input). The training of a linear regression model is to find a linear relationship between the input and the output based on data samples. IoT applications usually require real-time data processing. Nonetheless, the existing schemes about privacy-preserving outsourcing of linear regression cannot fully meet the rapid response requirement for computation. To address this issue, we consider employing multiple edge servers to accomplish privacy-preserving parallel computation of linear regression. We propose two novel solutions based on edge servers in edge computing networks and construct two efficient schemes for linear regression. In the first scheme, we present a new blinding technique for data privacy protection. Two edge servers are employed to execute the encrypted linear regression task in parallel. To further enhance the efficiency, we design an adaptive parallel algorithm, which is adopted in the second scheme. Multiple edge servers are employed in the second scheme to achieve higher efficiency. We analyze the correctness, privacy, and verifiability of the proposed schemes. Finally, we assess the computational overhead of the proposed schemes and conduct experiments to validate the performance advantages of the proposed schemes. Wenjing Gao, Jia Yu 0003, Huaqun Wang |
IEEE Trans. Cloud Comput. | 3 |
| 2024 | Outsourced Privately Verifiable Proofs of Retrievability via BlockchainabstractOutsourced Proofs of Retrievability (OPoR) with private verification enables a third party verifier to periodically check cloud data on behalf of users. However, such a scheme requires the verifier to keep a copy of the user's data and generate tags for the data like the data owner. In other words, in addition to storing the data and tags from the user, the cloud server also needs to store tags uploaded by the verifier. To overcome this limitation, we propose a concrete construction of outsourced privately verifiable PoR (OPVPoR) without requiring the additional tag storage from the verifier. Furthermore, we extend the OPVPoR scheme to the multi-user setting and build a MOPVPoR scheme, where users storing the same data to the cloud server also share the tag information to further reduce the storage cost. Finally, we implement both schemes to evaluate their performance in practice. Hui Cui 0001, Zhiguo Wan, Rui Gao 0007, Huaqun Wang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Puncturable Attribute-Based Encryption From Lattices for Classified Document SharingabstractThe country’s governmental agencies bear the responsibility for overseeing and executing a wide range of national policies and initiatives, formulating pivotal determinations aimed at safeguarding national security and fostering long-term progress. Most of the decisions are highly confidential, encrypted and transmitted to diverse administrative regions, sectors, and individuals to facilitate execution. Hence, governmental agencies must formulate fine-grained access policies that support secure one-to-many document sharing. However, if the receivers’ keys were exposed, it could result in unauthorized access to document contents, posing a significant threat to national security. When facing keys exposure scenario, addressing the challenge of preventing document content theft while maintaining document archiving for convenient accountability becomes a complex and demanding task. To tackle the above issues, we propose an innovative lattice-based puncturable ciphertext-policy attribute-based encryption scheme. This scheme supports secure one-to-many document sharing, fine-grained access control, and empowers receivers to revoke the decryption capability for specific data according to their own choice after reviewing documents, thereby achieving dual-layer protection for documents. Our scheme has exhibited resilience against quantum attacks, chosen plaintext attacks and collusion attacks. Huaqun Wang, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Division of Regulatory Power: Collaborative Regulation for Privacy-Preserving BlockchainsabstractDecentralized anonymous payment schemes may be exploited for illicit activities, such as money laundering, bribery and blackmail. To address this issue, several regulatory-friendly decentralized anonymous payment schemes have been proposed. However, most of these solutions lack restrictions on the regulator’s authority, which could potentially result in power abuse and privacy breaches. In this paper, we present a decentralized anonymous payment scheme with collaborative regulation (DAPCR). Unlike existing solutions, DAPCR reduces the risk of power abuse by distributing regulatory authority to two entities: Filter and Supervisor, neither of which can decode transactions to access transaction privacy without the assistance of the other one. Our scheme enjoys three major advantages over others: 1) Universality, achieved by using zk-SNARK to extend privacy-preserving transactions for regulation. 2) Collaborative regulation, attained by adding the ring signature with controllable linkability to the transaction. 3) Efficient aggregation of payment amounts, achieved through amount tags. As a key technology for realizing collaborative regulation in DAPCR, the ring signature with controllable linkability (CLRS) is proposed, where a user needs to specify a linker and an opener to generate a signature. The linker can extract pseudonyms from signatures and link signatures submitted by the same signer based on pseudonyms, without leaking the signer’s identity. The opener can recover the signer’s identity from a given pseudonym. The experimental results reflect the efficiency of DAPCR. The time overhead for transaction generation is 1231.2ms, representing an increase of less than 50% compared to ZETH. Additionally, the time overhead for transaction verification is only 1.2ms. Tianyu Zhaolu, Zhiguo Wan, Huaqun Wang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Synchronous Blockchain-Based Distributed Provable Data Possession With Forward-SecurityabstractWith the rapid development of 5 G and 6 G technologies, vast amounts of data are being generated. To save costs and ensure data security, these data are typically uploaded to multiple cloud servers. For handling massive data, distributed storage is necessary. Additionally, remote data integrity checking is essential. To achieve this, the PDP paradigm (Provable Data Possession) has been proposed. Unfortunately, existing PDP schemes suffer from inefficiencies. The main cause is that the data must be divided into small blocks with a limited size, such as 160 bits for bilinear pairings-based PDP schemes. This approach incurs significant computation and communication costs.To address this issue, we propose a new model called synchronous blockchain-based DPDP (Distributed Provable Data Possession) with forward-security in multi-cloud storage. This new concept leverages blockchain, which is the foundation of cryptocurrency. The paper formalizes the system model and security model for the new concept. Furthermore, a concrete blockchain-based DPDP scheme is designed using blockchain and RSA. The proposed scheme is provably secure, and its performance is analyzed from both theoretical and implementation perspectives. Our analysis demonstrates that the proposed DPDP scheme is provably secure, synchronous, forward-secure, efficient, and practical. Huaqun Wang, Zhiguo Wan, Debiao He, Jia Yu 0003 |
IEEE Trans. Serv. Comput. | 1 |
| 2024 | PUL-ABE: An Efficient and Quantum-Resistant CP-ABE With Policy Update in Cloud StorageabstractWith data being the essential factor of production in the new smart city, the volume of data has exploded. The management and sharing of massive data produced by various industries have become an urgent problem nowadays. Cloud technology facilitates the storage of vast volumes of data and the delivery of precise services upon the requests of users, making it a practical choice for data storage. Data owners can share their data in a flexible and open environment by storing it on a cloud platform. However, the sensitive nature of personal data underscores the importance of ensuring data security and privacy. Attribute-Based Encryption (ABE) is a viable approach to address the above concerns as it supports end-to-end security, one-to-many data sharing and fine-grained access control. In addition, to accommodate significant increase in complexity of data sharing environments and maximize the value of data, data owners will adjust the access policy in real-time based on feedback from data receivers and changes in data usability. The emergence of quantum computers poses significant security challenges to classical cryptographic difficult problems. We first propose a Ciphertext-Policy ABE scheme from lattices that supports access policy update and resists attacks including quantum, collusion, and chosen plaintext. Huaqun Wang, Zhiguo Wan |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | A Group Signature Scheme With Selective Linkability and Traceability for Blockchain-Based Data Sharing Systems in E-Health ServicesabstractRecently, with the rapid improvement of e-health technology, a large amount of precious medical data has been accumulated in different entities, such as hospitals, clinics, and medical institutions, promoting the development of data sharing in e-health services. However, most of them lacks fine-grained functionalities: selective linkability and traceability, which are critical in an e-health environment. Furthermore, we observe that existing schemes mostly rely on centralized storage centers, which will lead to a single point of failure and privacy disclosure. In this article, we first construct a group signature schemeSLTGSsuitable for a data sharing environment. It supports selectively linking two different message-signature pairs to the same signer. Further, it provides an algorithm to trace the signer. Then, based on theSLTGSscheme, we leverage distributed technology (i.e., interplanetary file system (IPFS) and blockchain) and attribute-based encryption to propose a distributed data sharing scheme. We claim that our scheme meets anonymity, accountability, linkability, traceability, fine-grained and efficient access control, and distributed storage. Moreover, the proposed data sharing scheme yields a practical performance making it suitable for e-health applications. Zijian Bao, Debiao He, Huaqun Wang, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 3 |
| 2023 | Fault-tolerant unicast using conditional local safe model in the data center network BCube
Mengjie Lv, Huaqun Wang, Weibei Fan |
J. Parallel Distributed Comput. | 3 |
| 2023 | Designated-Verifier Aggregate Signature Scheme With Sensitive Data Privacy Protection for Permissioned Blockchain-Assisted IIoTabstractAggregate signatures enable the sensor nodes of Industrial Internet of Things to send their signatures to the aggregator to realize signature compression. Before being stored in the data center, sensitive data and non-sensitive data should adopt different data processing methods in the process of sensor data fusion. In the high security analysis scenario of Industrial Internet of Things, only the verifier with a specified high security level can verify the resulting aggregate signature. So far, no one has explored how to ensure sensitive data privacy in the designated-verifier aggregate signatures. Motivated by it, this paper proposes a designated-verifier aggregate signature scheme (named DVAS) based on permissioned blockchain to achieve sensitive data privacy. In this scheme, the aggregator can be used not only to aggregate signatures, but also to sanitize data. Through smart contracts, the aggregator can sanitize the sensitive data according to the contract, and convert the original signature of the sensitive data into a valid signature. Therefore, DVAS can achieve elastic sensitive data privacy, not limited to encryption operations. The security attributes of DVAS include conditional anonymity, unforgeability, immutability and protecting data privacy. At the same time, DVAS realizes accountability through signature verification. Finally, the formal security proof, performance evaluation and experiments indicate that DVAS is secure, effective and practical for Industrial Internet of Things. Tian Li 0008, Huaqun Wang, Debiao He, Jia Yu 0003 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Blockchain-Backed Searchable Proxy Signcryption for Cloud Personal Health RecordsabstractPatient-centered data management and sharing of personal health records (PHRs) are difficult to be realized as data is controlled by doctors/hospitals. In addition, security and privacy, oppressive costs, search and tracing unreliability, and complicated access authorization caused by traditional encryption severely hinder the widespread adoption of PHRs. To overcome these challenges, we propose a blockchain-backed data sharing framework for PHRs, where the blockchain achieves reliable search and tracing. Furthermore, we design a hybridblockchain-backedsearchableproxysigncryption scheme, namedBC-SPSC. Specifically, an identity-based proxy signature (IBPS) is utilized to perform the authorization from patients to doctors to achieve authentic patient-centricity, therefore the blockchain can relate data with associated patients and doctors during data tracing. Moreover, BC-SPSC supports two search modes. The first mode adopts attribute-based encryption with keyword-based search (SABE), where all legitimate users can implement searches, but only users whose attributes satisfy the access structure can successfully decrypt. By contrast, the second mode utilizes attribute-based searchable encryption (ABSE) to accomplish fine-grained authorization in both search and data access/decryption, that is, who can search is also constrained by data owners. Adequate performance comparisons and simulation experiments indicate significant advantages of the BC-SPSC scheme in storage and computation overheads. Suhui Liu, Liquan Chen, Ge Wu 0001, Huaqun Wang |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | Privacy-Preserving Classification in Multiple Clouds eHealthcareabstractInternet of Things (IoT) is increasingly being used in real life, especially in the eHealthcare field. Among eHealthcare, the application of predicting patients' health status based on their daily activity data which is collected by IoT equipment has attracted extensive attentions and researches. In this application, patients' data which are treated as time-series data are transmitted to healthcare center (HC), then HC makes predictions based on an established classification model. However, making predictions using classification models requires a lot of computing resources, while HC usually cannot afford such numerous calculations. The use of the cloud solves the problem of insufficient computing resources, but it causes another problem, namely the leakage of user privacy. In particular, not only patients' data leak patients' privacy information, the classification model also causes the privacy disclosure of patients and HC. We design a new system model and propose an algorithm which can protect patients' data and classification model from leakage and offload calculation to multiple clouds. Our algorithm can better protect privacy of patients and HC in more complex classification scene, and can effectively reduce the computational cost of the healthcare center Shenqing Wang, Chunpeng Ge 0001, Lu Zhou 0002, Huaqun Wang, Zhe Liu 0001, Jian Wang 0038 |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | Towards fully verifiable forward secure privacy preserving keyword search for IoT outsourced data
Jia Yu 0003, Ming Yang 0023, Wenqiang Hou, Huaqun Wang |
Future Gener. Comput. Syst. | 5 |
| 2022 | Enabling Privacy-Preserving Parallel Outsourcing Matrix Inversion in IoTabstractWith the rapid development of Internet of Things (IoT), edge computing has been widely applied as a novel computing paradigm. Securely outsourcing intensive tasks to edge servers is becoming increasingly pervasive. It is a nice approach for resource-limited IoT devices to accomplish heavy computing tasks. Matrix inversion is a basic but time-consuming operation, which has a wide range of applications in IoT. The current privacy-preserving outsourcing schemes for matrix inversion cannot support parallel computing based on multiple edge servers. As a result, they cannot well satisfy the requirement of fast response for computation in IoT. In order to deal with this problem, we propose two privacy-preserving parallel outsourcing schemes for matrix inversion in IoT. In the first scheme, we design a novel method to generate a random matrix, which is used to blind the inputted original matrix. In this scheme, two edge servers compute the inversion of the encrypted matrix in parallel to improve the computational efficiency. To further improve the efficiency, we design a novel subtasks partitioning and assignment strategy and propose the second scheme by balancing the computing load of edge servers. We analyze the correctness, security, and verifiability of the proposed schemes. And we provide theoretical analysis and experimental results to demonstrate the performance advantages of the proposed schemes. Wenjing Gao, Jia Yu 0003, Ming Yang 0023, Huaqun Wang |
IEEE Internet Things J. | 4 |
| 2022 | A Blockchain-Assisted Privacy-Aware Authentication Scheme for Internet of Medical ThingsabstractBenefiting from the progress of Internet of Things (IoT) technology, medical devices, wearables, sensors, and users can be connected with each other to form an Internet of Medical Things (IoMT) ecosystem. IoMT improves efficiency, increases accuracy, and reduces the costs of the traditional healthcare system. However, since IoMT involves different entities and heterogeneous networks and carries a large amount of private information, it is a challenging task to ensure data security and protect privacy in the IoMT ecosystem. In this article, we focus on the issue of privacy-aware authentication between entities. We first propose a blockchain-assisted authentication framework for IoMT applications in the fog computing paradigm. Furthermore, we present two privacy-preserving authentication protocols based on elliptic curve cryptography (ECC) and physically unclonable functions (PUFs), respectively, in terms of the capacity of involved entities. Security analysis and performance evaluation demonstrate that compared with several previous protocols, the proposed protocols have competitive computation and communication costs while achieving expected security requirements. Xiaoying Jia 0002, Min Luo 0002, Huaqun Wang, Jian Shen 0001, Debiao He |
IEEE Internet Things J. | 3 |
| 2022 | Decentralized Attribute-Based Server-Aid Signature in the Internet of ThingsabstractDevices of Internet of Things (IoT) play a significant role in people’s daily life. A large scale of data is generated, collected, and analyzed in these devices, which inevitably faces secure authentication and access control problem. Attribute-based signature (ABS), where a signer signs a message over a set of attributes, plays an elegant tool for privacy-preserving access control and data authentication. In multiauthority ABS scheme, multiple authorities distribute users’ private keys over their different attributes and these attribute authorities are managed by a central authority. Nevertheless, the whole ABS system can be broken if the central authority is compromised. Besides, the multiauthority ABS scheme needs a lot of pairing and exponentiation operations in the verification and signature algorithms. Therefore, it is very expensive for resource-limited devices (e.g., sensors in IoT) to utilize the ABS scheme. In order to solve above problems, we present a decentralized attribute-based server-aid signature (DABSAS) scheme. In the DABSAS scheme, a server can help users execute heavy computation in the signature and verification algorithms. The proposed scheme provides anonymity and unforgeability. In addition, our scheme mitigates the burden of the signature and verification phase. The proposed scheme is proved secure under the well-known computational co-Diffie–Hellman (co-CDH) assumption. Compared with the existing schemes, the presented DABSAS scheme is efficient. Jiguo Li 0001, Jinguang Han, Chengdong Liu, Yichen Zhang 0003, Huaqun Wang |
IEEE Internet Things J. | 6 |
| 2022 | Blockchain-Based Privacy-Preserving and Rewarding Private Data Sharing for IoTabstractThe Internet of Things (IoT) devices possessed by individuals produce massive amounts of data. The private data onto specific IoT devices can be combined with intelligent platform to provide help for future research and prediction. As an important digital asset, individuals can sell private data to get rewards. Problems, such as privacy, security, and access control prevent individuals from sharing their private data. The blockchain technology is widely used to build an anonymous trading system. In this article, we construct a blockchain-based privacy-preserving and rewarding private data-sharing scheme (BPRPDS) for IoT. A privacy issue worth considering is that the malicious cloud server may establish a behavior profile database of data users (DUs). In the case of anonymity, the transactions of private data sharing are easy to cause disputes. When anonymous DUs are framed, it is hard to protect their rights. With the help of the deniable ring signature and Monero, we realize the behavior profile building prevention and nonframeability of BPRPDS. At the same time, we utilize the licensing technology executed by smart contracts to ensure flexible access control of multisharing. The proposed BPRPDS is provably secure. Performance analysis and experimental results show that BPRPDS is efficient and practical. Tian Li 0008, Huaqun Wang, Debiao He, Jia Yu 0003 |
IEEE Internet Things J. | 2 |
| 2022 | Secure, Efficient, and Weighted Access Control for Cloud-Assisted Industrial IoTabstractIn the cloud-assisted Industrial Internet of Things (IIoT), ciphertext-policy attribute-based encryption (CP-ABE) could help the data owner (DO) share his sensitive data via the cloud under self-defined access structures. Among general CP-ABE schemes, the decryption overhead, the key generation cost, and the ciphertext length increase with the number of involved attributes. Additionally, only regular attributes are taking into consideration rather than weighted attributes. In this article, we proposed a secure, efficient, and weighted access control scheme (SEWAC) for cloud-assisted IIoT applications. SEWAC enables the DO to formulate any fine-grained access structure over weighted attributes without making it more complicated. Furthermore, such weighted attributes would not add the length of ciphertext. SEWAC also supports online/offline key generation to alleviate the computational cost of the authority from answering mass key requests in the online phase, while most computational tasks are executed in the offline phase. The heavy decryption overhead is offloaded to the cloud. To ensure the cloud to honestly execute the process of outsourced decryption, we design an efficient batch verification method, which allows the user to spend only three bilinear pairing operations in checking the correctness of batch results. We also give the formal security proof of the proposed scheme. Comprehensive comparisons and implementation results indicate that SEWAC can better achieve weighted access control, compressed ciphertext length, efficient key generation, and the assurance of the outsourced decryption result. Qi Li 0011, Haiping Huang, Wei Zhang 0122, Wei Chen 0006, Huaqun Wang |
IEEE Internet Things J. | 6 |
| 2022 | An Efficient Privacy-Preserving Aggregation Scheme for Multidimensional Data in IoTabstractInternet of Things (IoT) enables terminal devices connecting with the Internet and provides various intelligent applications by analyzing devices data. As a typical IoT technique, edge computing provides a three-tier architecture to reduce communications and improve efficiency. Specifically, edge nodes are responsible for collecting and aggregating device data, and then send processed results to the cloud for subsequent analysis. However, the data aggregation function will compromise the privacy of device data. In this article, we proposed an efficient privacy-preserving multidimensional data aggregation scheme for IoT, called PMDA. The scheme uses the Chinese remainder theorem to design a homomorphic encryption method that encryptes a multiple-dimensional small integer vector into one ciphertext and keeps linear homomorphic properties per dimension. Combining with the signature mechanism and the batch verification method, the scheme guarantees nonrepudiation of device data and enhance verification efficiency at edge nodes. Through theoretical analysis, we demonstrate that the proposed scheme can achieve correctness, privacy, authentication, and integrity. After performance evaluation, we demonstrate that our scheme is superior to other schemes in terms of computation and communication costs. In particular, as the message dimension increases, our scheme computation costs almost a tenth of others at the 80-bits security level. Cong Peng 0005, Min Luo 0002, Huaqun Wang, Muhammad Khurram Khan, Debiao He |
IEEE Internet Things J. | 3 |
| 2022 | A Secure and Efficient Multiserver Authentication and Key Agreement Protocol for Internet of VehiclesabstractInternet of Vehicles (IoV) being a subdivided application of the Internet of Things, is considered as one of the most prominent and emerging technologies for model transportation systems. However, security and privacy remain two key requirements for IoV networks, as communications between vehicles and other Internet-connected things are generally carried out over public channels. Some of the most typical attack issues for the IoV networks include hardware tampering, unauthorized data access, message modification, tracking vehicle locations, etc. Although there have been a number of solutions (e.g., mutual authentication and key agreement protocols) proposed to ensure the secure communication for IoV, most of them still suffer from some vulnerabilities, such as linkability, server spoofing, and replay attacks, in violation of the security requirements of IoV. Hence, it remains challenging to design secure and efficient solutions. In this article, we first take a recently proposed authentication protocol as an example and analyze the weaknesses of it with simple mathematical analysis. We then propose an improved multiserver-based authentication and key agreement protocol for IoV (called SeMAV), which applies the password and smart card to hide the private keys. We also present both formal and informal security proofs to confirm the robustness against those commonly known attacks. The theoretical comparative summary and simulation results also show that SeMAV can achieve a good performance when compared with some other related protocols in the literature. Jing Wang 0036, Huaqun Wang, Kim-Kwang Raymond Choo, Lianhai Wang, Debiao He |
IEEE Internet Things J. | 3 |
| 2022 | NPP: A New Privacy-Aware Public Auditing Scheme for Cloud Data Sharing with Group UsersabstractToday, cloud storage becomes one of the critical services, because users can easily modify and share data with others in cloud. However, the integrity of shared cloud data is vulnerable to inevitable hardware faults, software failures or human errors. To ensure the integrity of the shared data, some schemes have been designed to allow public verifiers (i.e., third party auditors) to efficiently audit data integrity without retrieving the entire users’ data from cloud. Unfortunately, public auditing on the integrity of shared data may reveal data owners’ sensitive information to the third party auditor. In this paper, we propose a new privacy-aware public auditing mechanism for shared cloud data by constructing a homomorphic verifiable group signature. Unlike the existing solutions, our scheme requires at leasttgroup managers to recover a trace key cooperatively, which eliminates the abuse of single-authority power and provides non-frameability. Moreover, our scheme ensures that group users can trace data changes through designated binary tree; and can recover the latest correct data block when the current data block is damaged. In addition, the formal security analysis and experimental results indicate that our scheme is provably secure and efficient. Anmin Fu, Shui Yu 0001, Yuqing Zhang 0001, Huaqun Wang, Chanying Huang |
IEEE Trans. Big Data | 4 |
| 2022 | Checking Only When It Is Necessary: Enabling Integrity Auditing Based on the Keyword With Sensitive Information Privacy for Encrypted Cloud DataabstractThe public cloud data integrity auditing technique is used to check the integrity of cloud data through the Third Party Auditor (TPA). In order to make it more practical, we propose a new paradigm called integrity auditing based on the keyword with sensitive information privacy for encrypted cloud data. This paradigm is designed for one of the most common scenario, that is, the user concerns the integrity of a portion of encrypted cloud files that contain his/her interested keywords. In our proposed scheme, the TPA who is only provided with the encrypted keyword, can audit the integrity of all encrypted cloud files that contain the user’s interested keyword. Meanwhile, the TPA cannot deduce the sensitive information about which files contain the keyword and how many files contain this keyword. These salient features are realized by leveraging a newly proposed Relation Authentication Label (RAL). The RAL can not only authenticate the relation that files contain the queried keyword, but also be used to generate the auditing proof without sensitive information exposure. We give concrete security analysis showing that the proposed scheme satisfies correctness, auditing soundness and sensitive information privacy. We also conduct the detailed experiments to show the efficiency of our scheme. Xiang Gao 0021, Jia Yu 0003, Yan Chang, Huaqun Wang, Jianxi Fan |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Efficient Certificateless Multi-Copy Integrity Auditing Scheme Supporting Data DynamicsabstractTo improve data availability and durability, cloud users would like to store multiple copies of their original files at servers. The multi-copy auditing technique is proposed to provide users with the assurance that multiple copies are actually stored in the cloud. However, most multi-replica solutions rely on Public Key Infrastructure (PKI), which entails massive overhead of certificate computation and management. In this article, we propose an efficient multi-copy dynamic integrity auditing scheme by employing certificateless signatures (named MDSS), which gets rid of expensive certificate management overhead and avoids the key escrow problem in identity-based signatures. Specifically, we improve the classic Merkle Hash Tree (MHT) to achieve batch updates for multi-copy storage, which allows the communication overhead incurred for dynamics to be independent of the replica number. To meet the flexible storage requirement, we propose a variable replica number storage strategy, allowing users to determine the replica number for each block. Based on the fact that auditors may frame Cloud Storage Servers (CSSs), we use signature verification to prevent malicious auditors from framing honest CSSs. Finally, security analysis proves that our proposal is secure in the random oracle model. Analysis and simulation results show that our proposal is more efficient than current state-of-the-art schemes. Lei Zhou 0026, Anmin Fu, Guomin Yang, Huaqun Wang, Yuqing Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Synchronized Provable Data Possession Based on Blockchain for Digital TwinabstractIn the digital twin environment, the fusion data onto physical entities in the physical space are mapped to multiple virtual spaces for digital modeling and intelligent simulation in different dimensions. In real intelligent manufacturing scenarios, heterogeneous multi-source fusion data are collected at the same time period. So they are consistent in time state. For the autonomous digital twin system, time states verification and integrity checking are basic security factors. Provable data possession technology can check the integrity of data onto virtual spaces. The blockchain can provide the synchronization interface to make distributed entities to obtain the trusted time state value. Considering the privacy, the blockchain can also provide anonymous services for entities. Therefore, we propose the blockchain-based synchronized provable data possession scheme (named BSPDP) for digital twin. In our scheme, the selection of verifier is flexible. Since virtual spaces may be maliciously framed to pay compensation, we use tag verification to prevent honest virtual spaces from being framed. Under the assumption of RSA, the proposed BSPDP is provably secure. Finally, the performance analysis demonstrates that BSPDP is practical. The experimental results show that BSPDP is effective and attractive for digital twin. Tian Li 0008, Huaqun Wang, Debiao He, Jia Yu 0003 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | VFL: A Verifiable Federated Learning With Privacy-Preserving for Big Data in Industrial IoTabstractDue to the strong analytical ability of big data, deep learning has been widely applied to model on the collected data in industrial Internet of Things (IoT). However, for privacy issues, traditional data-gathering centralized learning is not applicable to industrial scenarios sensitive to training sets, such as face recognition and medical systems. Recently, federated learning has received widespread attention, since it trains a model by only sharing gradients without accessing training sets. But existing research works reveal that the shared gradient still retains the sensitive information of the training set. Even worse, a malicious aggregation server may return forged aggregated gradients. In this article, we propose the VFL, a verifiable federated learning with privacy-preserving for big data in industrial IoT. Specifically, we use Lagrange interpolation to elaborately set interpolation points for verifying the correctness of the aggregated gradients. Compared with existing schemes, the verification overhead of VFL remains constant regardless of the number of participants. Moreover, we employ the blinding technology to protect the privacy of the privacy gradients. If no more than$\boldsymbol{n}$-2 of$\boldsymbol{n}$participants collude with the aggregation server, VFL could guarantee the encrypted gradients of other participants not being inverted. Experimental evaluations corroborate the practical performance of the presented VFL with high accuracy and efficiency. Anmin Fu, Xianglong Zhang, Naixue Xiong, Yansong Gao 0001, Huaqun Wang |
IEEE Trans. Ind. Informatics | 5 |
| 2022 | O³HSC: Outsourced Online/Offline Hybrid Signcryption for Wireless Body Area NetworksabstractWireless body area networks (WBAN) enable ubiquitous monitoring of patients, which can change the future of healthcare services overwhelmingly. As the collected data of patients usually contain sensitive information, how to collect, transfer, store and share data securely and properly has become a concerning issue. Attribute-based encryption (ABE) can achieve data confidentiality and fine-grained access control simultaneously. Identity-based ring signature (IBRS) allows patients to prove their identity without leaking any extra (private) information. However, the heavy computational burden of ABE and IBRS is intolerable for most power-limited mobile devices, which account for a large proportion of WBAN devices. This paper combines the attribute-based online/offline encryption (ABOOE) and IBRS to achieve an outsourced online/offline hybrid signcryption ($O^{3}$HSC) scheme. As far as we know, this scheme is the first signcryption scheme that adopts IBRS and satisfies online/offline signcryption simultaneously.$O^{3}$HSC divides the key generation and signcryption into offline and online phases to increase the throughput of the central authority and save the power resources of mobile devices, respectively. Besides, outsourced decryption and public signature verification are also realized.$O^{3}\mathrm {HSC}$achieves security under CCA and CMIA, and the performance analysis shows that$O^{3}\mathrm {HSC}$is a lightweight and applicable scheme for WBAN. Suhui Liu, Liquan Chen, Huaqun Wang, Shihui Fu |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | FASE: A Fast and Accurate Privacy-Preserving Multi-Keyword Top-k Retrieval Scheme Over Encrypted Cloud DataabstractWith the advance of cloud computing technology, increasingly more documents are encrypted before being outsourced to the cloud for great convenience and economic savings. Thus, how to design a fast and accurate multi-keyword ranked search scheme over encrypted cloud data is of paramount importance. In this article, we propose a fast and accurate searchable encryption (FASE) scheme that supports accurate top-k multi-keyword retrieval. We utilize a homomorphic order-preserving encryption algorithm to encrypt the index and query vectors. The encryption method supports homomorphic addition, homomorphic multiplication, and order comparison over encrypted data, and it implements the secure calculation of relevance score between encrypted index and query vectors. The encryption method can not only ensure that the calculation of relevance score ($SI_i * T$) is not exposed to the cloud server, but also protect the privacy of ranking operator. Compared to the traditional method, there are no dummy keywords added to the query vector and document vector, and the top-k search precision of the FASE scheme is 100 percent. To improve the search efficiency, a large number of irrelevant documents are effectively filtered by matching the document mark vector and query mark vector, and the time cost for calculating the relevance score and ranking is greatly reduced. Furthermore, according to the two-round ranking of the keyword matching degree and the relevance score, not only more accurate search result is returned, but the search efficiency is also further improved. The theoretical analysis and experimental results show that the FASE scheme can achieve fast and accurate multi-keyword ranking search. In addition to ensuring data privacy and security, it can also effectively improve the search efficiency and reduce the time cost of creating an index, and it can return ranking results which more satisfy the user needs. Guoxiu Liu, Geng Yang 0002, Shuangjie Bai, Huaqun Wang, Yang Xiang 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | A Keyword-Grouping Inverted Index Based Multi-Keyword Ranked Search Scheme Over Encrypted Cloud DataabstractWith the comprehensive development of cloud computing technology, more and more enterprises and individuals tend to outsource computing, data, and other resources to the cloud service providers to save the data management cost. Since the plaintext data outsourcing in the cloud could leak users’ private information, it is highly recommended to encrypt them before outsourcing. However, it is a challenge to perform searches over encrypted cloud data. In this paper, we adopt the keyword grouping idea into the traditional inverted index and propose a keyword-grouping inverted index (KGI-index). Based on the index, we propose a privacy-preserving KGI-index based multi-keywords ranked search scheme (KMRS). To improve the search efficiency, we adopt two strategies including grouping high relevant keywords and using the complete binary tree structure to optimize the index. The security analysis and experimental result show that the proposed scheme is a privacy-preserving and efficient multi-keyword ranked search scheme over encrypted cloud data. Hua Dai 0003, Maohu Yang, T. G. Yang, Yang Xiang 0001, Huaqun Wang |
IEEE Trans. Sustain. Comput. | 6 |
| 2021 | Fully Discover the Balance of Lightning Network Payment Channels
Chunpeng Ge 0001, Lu Zhou 0002, Huaqun Wang |
WASA (1) | 4 |
| 2021 | Toward Verifiable Phrase Search Over Encrypted Cloud-Based IoT DataabstractPhrase search encryption, as an important technique in cloud-based IoT system, allows users to retrieve encrypted IoT data that contains a set of consecutive keywords. It plays an important role in cloud-based e-healthcare diagnosis system, machine learning applications for cloud-based IoT system, etc. However, to the best of our knowledge, the existing phrase search encryption schemes cannot achieve the complete verification for search results. They either cannot verify whether the returned files correctly containing the query phrase or cannot verify whether all files containing this query phrase are returned. Result verification is very important for some cloud-based IoT applications. If the search result is incorrect in the cloud-based e-healthcare diagnosis system, it will lead to misdiagnosis even endanger the patient's life. In order to deal with this problem, this article explores how to achieve verifiable phrase search over encrypted cloud-based IoT data. Specifically, we design novel look-up tables which can be utilized to determine and verify the position relationship among keywords. Meanwhile, we adopt a two-phase query strategy. In the first query phase, the data user can know the identifiers of files containing the keywords in the query phrase, and generate the search trapdoor based on these identifiers for the next phase. In the second query phase, the data user can obtain the verification information to check whether all files containing the query phrase are correctly returned. We present the security analysis of our scheme and conduct extensive experiments. The results prove the high security and efficiency of our proposed scheme. Xinrui Ge, Jia Yu 0003, Fei Chen 0014, Fanyu Kong 0002, Huaqun Wang |
IEEE Internet Things J. | 5 |
| 2021 | Permissioned Blockchain-Based Anonymous and Traceable Aggregate Signature Scheme for Industrial Internet of ThingsabstractFor large-scale data transmission of the Industrial Internet of Things (IIoT), aggregate signature is an effective approach. It can compress the signatures of different senders to save bandwidth. In order to maintain the autonomous management of IIoT, massive sensing data are sent to the data center for intelligent analysis. The reliability of data is an important guarantee of the autonomous management of IIoT. Tracing abnormal senders is a challenge when hiding their real identity. Therefore, we design the first permissioned blockchain-based anonymous and traceable aggregate signature (PBATAS) scheme for IIoT. Smart contracts are used to authenticate anonymous sources and share cryptographic materials among entities, providing reliable regulatory support for IIoT. The regulator can quickly trace the abnormal data sources recorded on the blockchain, which is practical for the anonymous IIoT environment. Through the formal security proof of conditional anonymity, unforgeability, traceability, and resistance to coalition attacks, the proposed PBATAS is provably secure. Performance analysis demonstrates that PBATAS is effective. Tian Li 0008, Huaqun Wang, Debiao He, Jia Yu 0003 |
IEEE Internet Things J. | 2 |
| 2021 | An Efficient and Privacy-Preserving Outsourced Support Vector Machine Training for Internet of Medical ThingsabstractAs the use of machine learning in the Internet-of-Medical Things (IoMT) settings increases, so do the data privacy concerns. Therefore, in this article, we propose an efficient privacy-preserving outsourced support vector machine scheme (EPoSVM), designed for IoMT deployment. To securely train the support vector machine (SVM), we design eight secure computation protocols to allow the cloud server to efficiently execute basic integer and floating-point computations. The proposed scheme protects training data privacy and guarantees the security of the trained SVM model. The security analysis proves that our proposed protocols and EPoSVM satisfy both security and privacy protection requirements. Findings from the performance evaluation using two real-world disease data sets also demonstrate the efficiency and effectiveness of EPoSVM in achieving the same classification accuracy as a general SVM. Jing Wang 0036, Huaqun Wang, Kim-Kwang Raymond Choo, Debiao He |
IEEE Internet Things J. | 3 |
| 2021 | Application-Oriented Block Generation for Consortium Blockchain-Based IoT Systems With Dynamic Device ManagementabstractDue to its salient features, such as immutability and auditability, blockchain is becoming more integrated into the Internet of Things (IoT) for enhancing security and developing a decentralized IoT framework. However, different IoT applications require different transaction processing performance, which brings challenges to the convergence of blockchains in IoT. Moreover, the membership of a distributed IoT system may fluctuate when an IoT device joins or leaves the system. The dynamic nature of IoT systems also introduces new challenges for device management. Accordingly, we propose an application-oriented block generation (AOBG) scheme for blockchain-enabled IoT with dynamic device management and conditional traceability. Specifically, we first construct a framework for a consortium blockchain-based IoT system, including structures for application-oriented transactions and blocks, and consensus mechanism. We present different miners, respectively, for processing urgent and ordinary transactions adaptively with applications. Then, an AOBG protocol is proposed for this framework based on group signature. The group signature is used to achieve anonymity, traceability, and nonframeability. Combining time-bound keys in group signature with node accounts in blockchain, the proposed scheme can realize efficient transaction verification, dynamic device management, conditional traceability with data security, and privacy preservation. Extensive experiments demonstrate high efficiency of the proposed scheme. Aiqing Zhang, Peiyun Zhang, Huaqun Wang, Xiaodong Lin 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Blockchain-based multi-party proof of assets with privacy preservation
Huaqun Wang, Debiao He, Kim-Kwang Raymond Choo |
Inf. Sci. | 1 |
| 2021 | An efficient identity-based signature scheme with provable security
Jiguo Li 0001, Chengdong Liu, Jinguang Han, Huaqun Wang, Yichen Zhang 0003 |
Inf. Sci. | 5 |
| 2021 | Multicopy provable data possession scheme supporting data dynamics for cloud-based Electronic Medical Record system
Lei Zhou 0026, Anmin Fu, Yi Mu 0001, Huaqun Wang, Shui Yu 0001, Yinxia Sun |
Inf. Sci. | 4 |
| 2021 | RDIC: A blockchain-based remote data integrity checking scheme for IoT in 5G networks
Huaqun Wang, Debiao He, Jia Yu 0003, Naixue Xiong, Bin Wu 0011 |
J. Parallel Distributed Comput. | 1 |
| 2021 | Blockchain-Based Private Provable Data PossessionabstractRemote data secure storage is of crucial importance in cloud computing. In order to check remote data integrity, an important paradigm PDP (i.e., provable data possession) is proposed. All the existing PDP schemes make use of RSA or bilinear pairings. One large file has to be divided into a great many of blocks. For example, 1T (Terabit) file has to be divided into$1.0737 \times 10^9$blocks (RSA where the length of the index is 1024 bits) or$6.8719 \times 10^9$blocks (bilinear pairings where the order of the elliptic curve is 160 bits). The huge computation cost and communication cost incurs the inefficient PDP implementation. In other words, they are not practical. In order to solve the problem, we propose a new PDP model: blockchain-based private PDP. The new concept makes use of blockchain which is the core of cryptocurrency. For the new concept, the paper formalizes its system model and security model. Then, a concrete blockchain-based private PDP scheme is designed by making use of blockchain and RSA. The proposed blockchain-based private PDP scheme is provably secure. At the same time, we also analyze its performance from two parts: theory analysis and implementation prototype. Our analysis shows that the proposed PDP scheme is secure, efficient and practical. Huaqun Wang, Qihua Wang, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Fuzzy-Based Trustworthiness Evaluation Scheme for Privilege Management in Vehicular Ad Hoc NetworksabstractThe vehicular ad hoc network (VANET) is a type of mobile wireless networks, where vehicles are allowed to broadcast a message to its neighbors and access data from other participants. However, how to guarantee the reliability of these broadcast messages and prevent malicious vehicles from accessing the private data of the VANETs is still an open problem to be solved. As a countermeasure, a fuzzy-based trustworthiness evaluation scheme for privilege management in VANETs is proposed in this article. In the proposed scheme, to ensure the result of trustworthiness is valid, mutual authentication with conditional anonymity between the evaluator and the vehicle to be evaluated is first employed. Then, based on the vehicle's behavioral big data, the trustworthiness of each vehicle is evaluated by utilizing the fuzzy theory. Note that the privilege of a vehicle and the reliability of the vehicle's messages are determined by its trustworthiness. Moreover, the mobility of vehicles is also considered in this article, since the location of a vehicle is not constant and the monitoring area of an road side unit is limited. The results of theoretical and experimental analyses demonstrate that the proposed scheme performs well in terms of security and efficiency. Tiantian Miao, Jian Shen 0001, Chin-Feng Lai, Sai Ji, Huaqun Wang |
IEEE Trans. Fuzzy Syst. | 5 |
| 2021 | Provable Data Possession with Outsourced Data TransferabstractWith the rapid development of cloud computing, more and more enterprises would like to upload and store their data in the public cloud. When the parts of the business of an enterprise are purchased by another enterprise, the corresponding data will be transferred to the acquiring enterprise. For the usual case, how to outsource the computation cost of data transfer to the cloud? How to ensure the remote purchased data integrity? Thus, it is important to study provable data possession with outsourced data transfer (DT-PDP). In this paper, for the first time, we propose the novel concept: DT-PDP. By taking use of DT-PDP, the following three security requirements can be satisfied: (1) the other un-purchased data security of acquired enterprise can be ensured; (2) the purchased data integrity and privacy can be ensured; (3) the data transferability’s computation can be outsourced to the public cloud servers. For the security concept of DT-PDP, we give its motivation, system model and security model. Then, we design a concrete DT-PDP scheme based on the bilinear pairings. At last, we analyze the security, efficiency and flexibility of the concrete DT-PDP scheme. It shows that our scheme is provably secure and efficient. Huaqun Wang, Debiao He, Anmin Fu, Qi Li 0011, Qihua Wang |
IEEE Trans. Serv. Comput. | 1 |
| 2020 | Proxy Re-Encryption Scheme For Complicated Access Control Factors Description in Hybrid CloudabstractHybrid cloud has both the strong computing power of public cloud and easy control of private cloud. It provides users with robust services and convenience, meanwhile faces numerous security challenges. How to implement the effective access control is one of them, the purpose of which is deploying policy in private cloud to protect the ciphertext in public cloud. Furthermore, it becomes more and more difficult to describe the access control policy, which is suitable for multi-factor and dynamic updating. Considering the issues above, we propose a proxy re-encryption (PRE) scheme for complicated access control factors description in hybrid cloud. Firstly, we build the system model combining PRE with access control in hybrid cloud. Secondly, we design the algorithm for our scheme including the key construction with multi-factor and its weight, which achieve the target of dynamic updating. Finally, we analyze the security of this scheme by the mathematical method and performance by theory, experiment and comparisons with some other works. Our scheme has made the deployment of access control in hybrid cloud more reliable and scalable. Mang Su, Anmin Fu, Huaqun Wang, Chunyi Zhou 0001 |
ICC | 4 |
| 2020 | A Privacy-Preserving and Verifiable Federated Learning SchemeabstractDue to the complexity of the data environment, many organizations prefer to train deep learning models together by sharing training sets. However, this process is always accompanied by the restriction of distributed storage and privacy. Federated learning addresses this challenge by only sharing gradients with the server without revealing training sets. Unfortunately, existing research has shown that the server could extract information of the training sets from shared gradients. Besides, the server may falsify the calculated result to affect the accuracy of the trained model. To solve the above problems, we propose a privacy-preserving and verifiable federated learning scheme. Our scheme focuses on processing shared gradients by combining the Chinese Remainder Theorem and the Paillier homomorphic encryption, which can realize privacy-preserving federated learning with low computation and communication costs. In addition, we introduce the bilinear aggregate signature technology into federated learning, which effectively verifies the correctness of aggregated gradient. Moreover, the experiment shows that even with the added verification function, our scheme still has high accuracy and efficiency. Xianglong Zhang, Anmin Fu, Huaqun Wang, Chunyi Zhou 0001, Zhenzhu Chen |
ICC | 3 |
| 2020 | Designated-verifier proof of assets for bitcoin exchange using elliptic curve cryptography
Huaqun Wang, Debiao He, Yimu Ji 0001 |
Future Gener. Comput. Syst. | 1 |
| 2020 | Multi-party key generation protocol for the identity-based signature scheme in the IEEE P1363 standard for public key cryptographyabstractIdentity‐based cryptography (IBC) is considered as a promising mechanism in the Internet of Things and ad‐hoc networks, providing lightweight authentication and powerful access control. However, it suffers from two inherent problems, i.e. key escrow and the requirement of a secure channel, which are not always good properties in many realistic scenarios. Thus, an efficient key issuing protocol in a distributed setting without the assumption of the secure channel is needed. In this study, the authors give special attention to the IBC standardised in IEEE P1363 and design a multi‐party setup and key issuing protocol for it. Their protocol is proven to be malicious secure by simulation under weaker assumptions. Contrast to prior works that rely on a trusted party for key distribution or the strong assumption of a secure channel, they provide the first practical solution for the distributed architectures. Debiao He, Huaqun Wang, Ding Wang 0002, Xinyi Huang 0001 |
IET Inf. Secur. | 3 |
| 2020 | Privacy-Preserving and Distributed Algorithms for Modular Exponentiation in IoT With Edge Computing AssistanceabstractWith the development of Internet of Things (IoT) and 5G, edge computing, as a new computing paradigm, has been widely popularized in academia and industry. Due to the distributed architecture and being close to the user, edge computing can faster respond to the IoT device's request and provide a better quality of service for IoT applications. An important application of edge computing is to outsource the complicated computation task to the nearby edge nodes. Modular exponentiation is widely considered as one of the most common and expensive operations in cryptographic protocols. As far as we know, all secure outsourcing algorithms of modular exponentiation are based on the centralized cloud server, but not based on multiple edge nodes. In this article, we propose the first secure and distributed outsourcing algorithm for modular exponentiation (fixed base and variable exponent) under the multiple noncolluding edge node model. In our algorithm, the exponent is divided into a certain number of parts. In addition, we propose another secure and distributed outsourcing algorithm of modular exponentiation (variable base and variable exponent). The user can protect the privacy in the process of outsourcing and detect the invalid results from edge nodes with high probability. Finally, we provide the experimental evaluation to support that our proposed algorithms are efficient on both the user side and the edge node side. Jia Yu 0003, Hanlin Zhang 0001, Ming Yang 0023, Huaqun Wang |
IEEE Internet Things J. | 5 |
| 2020 | Efficient and Secure Outsourcing Scheme for RSA Decryption in Internet of ThingsabstractRivest-Shamir-Adleman (RSA) is one of the widely deployed public-key algorithms. Yet, its decryption facet is very time consuming for resource-constrained Internet-of-Thing (IoT) devices, as it is based on the modular exponentiation of a large number. Although several variants of RSA have been designed to accelerate decryption, the outcomes have been far from satisfactory. Therefore, it is of imminent importance to investigate how to securely outsource RSA decryption to computational powerful parties as an alternative solution. In this article, we introduce the first efficient and secure outsourcing scheme for RSA decryption in IoT. Though RSA decryption is achieved via modular exponentiation, existing secure outsourcing schemes for modular exponentiation either assume the modulus to be prime and are not applicable to RSA or incur massive computation costs and are heavy laden in practice. To address these issues, we have designed our scheme based on the Chinese remainder theorem (CRT). In our scheme, the private keys (including the exponent and the modulus) and the plaintext are concealed concurrently, and the proposed scheme is highly efficient for both client and cloud. In addition, our scheme enables the client to detect any misbehavior of the cloud server with a probability of 99.17%. To validate the effectiveness of our proposed scheme, we provide rigorous proofs of security and verifiability, as well as efficiency analysis. The effectiveness and efficiency of our scheme are further confirmed based on experimental results. Hanlin Zhang 0001, Jia Yu 0003, Chengliang Tian, Le Tong, Jie Lin 0002, Linqiang Ge, Huaqun Wang |
IEEE Internet Things J. | 7 |
| 2020 | Privacy-Preserving Federated Learning in Fog ComputingabstractFederated learning can combine a large number of scattered user groups and train models collaboratively without uploading data sets, so as to avoid the server collecting user sensitive data. However, the model of federated learning will expose the training set information of users, and the uneven amount of data owned by users in multiple users' scenarios will lead to the inefficiency of training. In this article, we propose a privacy-preserving federated learning scheme in fog computing. Acting as a participant, each fog node is enabled to collect Internet-of-Things (IoT) device data and complete the learning task in our scheme. Such design effectively improves the low training efficiency and model accuracy caused by the uneven distribution of data and the large gap of computing power. We enable IoT device data to satisfy ε -differential privacy to resist data attacks and leverage the combination of blinding and Paillier homomorphic encryption against model attacks, which realize the security aggregation of model parameters. In addition, we formally verified our scheme can not only guarantee both data security and model security but completely resist collusion attacks launched by multiple malicious entities. Our experiments based on the Fashion-MNIST data set prove that our scheme is highly efficient in practice. Chunyi Zhou 0001, Anmin Fu, Shui Yu 0001, Wei Yang 0008, Huaqun Wang, Yuqing Zhang 0001 |
IEEE Internet Things J. | 5 |
| 2020 | A novel proxy-oriented public auditing scheme for cloud-based medical cyber physical systems
Zhiyan Xu, Debiao He, Huaqun Wang, Pandi Vijayakumar, Kim-Kwang Raymond Choo |
J. Inf. Secur. Appl. | 3 |
| 2020 | RNN-DP: A new differential privacy scheme base on Recurrent Neural Network for Dynamic trajectory privacy protection
Anmin Fu, Jian Shen 0001, Shui Yu 0001, Huaqun Wang, Huaijiang Sun |
J. Netw. Comput. Appl. | 5 |
| 2020 | Secure outsourcing SIFT: Efficient and Privacy-Preserving Image Feature Extraction in the Encrypted DomainabstractMultimedia data needs huge storage space, and application of multimedia data needs powerful capability of computing. Cloud computing can help owner of multimedia data to deal with it. But, multimedia data on cloud may reveal privacy of data owner, such as sex, hobbies, address, looks, and so on. Data owner can encrypt multimedia data for confidentiality before uploading it to cloud. However, encrypted multimedia data makes its utilization difficult. In this paper, we first discover pre-existing schemes have problems of huge storage space, security and low efficiency due to their inefficient and insecure algorithms. Then, we provide an effective and practical privacy-preserving scale-invariant feature transform (SIFT) scheme for encrypted image. It uses leveled homomorphic encryption based on our new encoding schemes, our new homomorphic comparison, division and derivative encryption. Our new secure SIFT scheme can realize higher computing efficiency, greatly reduce communication costs and interactive times between user and server, and perform correct feature key point detection, accurate feature point description and image matching. We evaluate security and efficiency of our new secure SIFT scheme, and compare our new secure SIFT scheme with other schemes in detail. The result shows that it is closest to the original SIFT algorithm. Linzhi Jiang, Chunxiang Xu, Bo Luo, Huaqun Wang |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2020 | SecureNLP: A System for Multi-Party Privacy-Preserving Natural Language ProcessingabstractNatural language processing (NLP) allows a computer program to understand human language as it is spoken, and has been increasingly deployed in a growing number of applications, such as machine translation, sentiment analysis, and electronic voice assistant. While information obtained from different sources can enhance the accuracy of NLP models, there are also privacy implications in the collection of such massive data. Thus, in this paper, we design a privacy-preserving system SecureNLP, focusing on the instance of recurrent neural network (RNN)based sequence-to-sequence with attention model for neural machine translation. Specifically, for non-linear functions such as sigmoid and tanh, we design two efficient distributed protocols using secure multi-party computation (MPC), which are used to carry out the respective tasks in the SecureNLP. We also prove the security of these two protocols (i.e., privacy-preserving long short-term memory network PrivLSTM, and privacy-preserving sequence to sequence transformation PrivSEQ2SEQ) in the semi-honest adversary model, in the sense that any honest-butcurious adversary cannot learn anything else from the messages they receive from other parties. The proposed system is implemented in C++ and Python, and the findings from the evaluation demonstrate the utility of the protocols in cross-domain NLP. Debiao He, Zhe Liu 0001, Huaqun Wang, Kim-Kwang Raymond Choo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | VOD-ADAC: Anonymous Distributed Fine-Grained Access Control Protocol with Verifiable Outsourced Decryption in Public CloudabstractRemote data access control is of crucial importance in public cloud. Based on its own inclinations, the data owner predefines the access policy. When the user satisfies the data owner's access policy, it has the right to access the data owner's remote data. In order to improve flexibility and efficiency of remote data access control, attribute-based encryption (for short, ABE) is used to realize the remote data fine-grained access control. For the low-capacity terminals, verifiable outsourced decryption is a very attractive technique. In the real application scenarios, the user's attributes are usually managed by many authorities. When some authorized users access some sensitive remote data, they hope to preserve their identity privacy. From the two points, we propose an anonymous distributed fine-grained access control protocol with verifiable outsourced decryption in public cloud (for short, VOD-ADAC). VOD-ADAC is a novel concept which is proposed for the first time in the paper. By adopting the pseudonym technique, the user's high anonymity can be achieved by frequently changing the independent pseudonyms at some highly social spots. This paper formalizes the system model and security model of VOD-ADAC protocol. Then, by using hybrid encryption technique of distributed ABE and symmetric encryption, a concrete VOD-ADAC protocol is designed from the bilinear pairings. Through security analysis and performance analysis, our proposed VOD-ADAC protocol is provably secure and efficient. Huaqun Wang, Debiao He, Jinguang Han |
IEEE Trans. Serv. Comput. | 1 |
| 2019 | An Efficient and Provably Secure Authenticated Key Agreement Protocol for Fog-Based Vehicular Ad-Hoc NetworksabstractThe maturity of cloud computing, the Internet of Things technology, and intelligent transportation system has promoted the rapid development of vehicular ad-hoc networks (VANETs). To keep pace with real-world demands (mobility, low latency, etc.) in a practical VANETs deployment, there have been attempts to integrate fog computing with VANETs. To facilitate secure interaction in fog-based VANETs, we design a new authenticated key agreement protocol without bilinear pairing. This protocol achieves mutual authentication, generates a securely agreed session key for secret communication, and supports privacy protection. We also give a strict formal security proof and demonstrate how the proposed protocol meets the security requirements in the fog-based VANETs. We then evaluate the efficiency of the proposed protocol, and it shows the practicality of the protocol. Mimi Ma, Debiao He, Huaqun Wang, Neeraj Kumar 0001, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 3 |
| 2019 | BBARS: Blockchain-Based Anonymous Rewarding Scheme for V2G NetworksabstractIn vehicle-to-grid (V2G) networks, battery-powered vehicle (BV) provides service to the power grid. In order to encourage more BVs to provide the service for power grid, it is necessary to reward the BVs from the power grid. To extensively deploy V2G networks, some security and privacy problems must be solved. In this paper, for the first time, we propose the novel concept of blockchain-based anonymous rewarding scheme (BBARS) for V2G networks. The novel concept comes from the application requirement which has not been solved by now. We give the formal system model and security model of BBARS. Then, we design the concrete BBARS scheme by making use of two different public key cryptosystem. Through security analysis and performance analysis, the designed scheme is provably secure and efficient. The analysis results also show the designed BBARS scheme is practical for secure V2G networks in smart grid. Huaqun Wang, Qihua Wang, Debiao He, Qi Li 0011, Zhe Liu 0001 |
IEEE Internet Things J. | 1 |
| 2019 | Privacy-preserving incentive and rewarding scheme for crowd computing in social media
Huaqun Wang, Debiao He, Jia Yu 0003 |
Inf. Sci. | 1 |
| 2019 | A Distributed Access Control with Outsourced Computation in Fog ComputingabstractWith the rapid development of information technology and the Internet of Things Technology (IOT), data security and healthy privacy are getting a lot of attention. In order to store, access, and share electronic health records, storage of this data is transferred to a third-party-cloud server. The security and privacy of electronic health records stored at date center or cloud server are not guaranteed. Before being sent to date center or cloud server, this data should be encrypted. Designing an efficient and secure fine-grained access control strategy for personal health records is facing enormous challenges. Security and privacy for electronic health records are very important because the electronic health data which plays an important role in medical server and treatment is directly associated with a particular patient. Attribute-based encryption (ABE) can effectively achieve fine-grained access control. However, the computation of bilinear pairings requires a large amount of computation overhead in ABE scheme. In order to decrease the computational overhead and ensure the confidentiality of electronic health records, a distributed fine-grained access control scheme with outsourced computation for IOT is proposed in this paper. Little calculation is executed by the receiver and sender in our proposed scheme. Outsourcing computing reduces the computing burden. The analyses of safety and performance show that our proposed scheme is safe and effective compared with previous schemes. Qihua Wang, Huaqun Wang, Rui Guo 0005 |
Secur. Commun. Networks | 2 |
| 2019 | Incentive and Unconditionally Anonymous Identity-Based Public Provable Data PossessionabstractWhen the data is stored in public clouds, provable data possession (for short, PDP) is of crucial importance in cloud storage. PDP can make the users verify whether their outsourced data is kept intact without downloading the whole data. In some application scenarios, anonymity is very important in order to protect the user identity privacy. In order to encourage users to disclose bad event, the government or organization or individual may pay for the user who provides the precious data. Thus, incentive and unconditionally anonymous identity-based public PDP (for short, IAID-PDP) is a very important security concept. From the above requirements, for the first time, we propose the concept of IAID-PDP. We formalize its system model and security model. Based on the bilinear pairings, a concrete IAID-PDP protocol is presented. Based on the standard hard problems, the proposed IAID-PDP protocol is provably secure. IAID-PDP protocol eliminates the complex certificate management since it is designed in the identity-based public key cryptography. Through the performance analysis and security analysis, our IAID-PDP protocol satisfies the following properties: certification elimination, incentive, unconditional anonymity and remote data integrity checking. Huaqun Wang, Debiao He, Jia Yu 0003, Zhiwei Wang 0003 |
IEEE Trans. Serv. Comput. | 1 |
| 2018 | Anonymous biometrics-based authentication scheme with key distribution for mobile multi-server environment
Debiao He, Sherali Zeadally, Huaqun Wang |
Future Gener. Comput. Syst. | 4 |
| 2018 | PAT: A precise reward scheme achieving anonymity and traceability for crowdcomputing in public clouds
Huaqun Wang, Debiao He, Yanfei Sun, Neeraj Kumar 0001, Kim-Kwang Raymond Choo |
Future Gener. Comput. Syst. | 1 |
| 2018 | Anonymous and secure aggregation scheme in fog-based public cloud computing
Huaqun Wang, Zhiwei Wang 0003, Josep Domingo-Ferrer |
Future Gener. Comput. Syst. | 1 |
| 2018 | A Novel Secure Scheme for Supporting Complex SQL Queries over Encrypted Databases in Cloud ComputingabstractWith the advance of database-as-a-service (DaaS) and cloud computing, increasingly more data owners are motivated to outsource their data to cloud database for great convenience and economic savings. Many encryption schemes have been proposed to process SQL queries over encrypted data in the database. In order to obtain the desired data, the SQL queries contain some statements to describe the requirement, e.g., arithmetic and comparison operators ( + , - , × , < , > , and = ). However, to support different operators ( + , - , × , < , > , and = ) in SQL queries over encrypted data, multiple encryption schemes need to be combined and adjusted to work together. Moreover, repeated encryptions will reduce the efficiency of execution. This paper presents a practical and secure homomorphic order-preserving encryption (FHOPE) scheme, which allows cloud server to perform complex SQL queries that contain different operators (such as addition, multiplication, order comparison, and equality checks) over encrypted data without repeated encryption. These operators are data interoperable, so they can be combined to formulate complex SQL queries. We conduct security analysis and efficiency evaluation of the proposed scheme FHOPE. The experiment results show that, compared with the existing approaches, the FHOPE scheme incurs less overhead on computation and communication. It is suitable for large batch complex SQL queries over encrypted data in cloud environment. Guoxiu Liu, Geng Yang 0002, Huaqun Wang, Yang Xiang 0001, Hua Dai 0003 |
Secur. Commun. Networks | 3 |
| 2018 | A Provably-Secure Cross-Domain Handshake Scheme with Symptoms-Matching for Mobile Healthcare Social NetworkabstractWith rapid developments of sensor, wireless and mobile communication technologies, Mobile Healthcare Social Networks (MHSNs) have emerged as a popular means of communication in healthcare services. Within MHSNs, patients can use their mobile devices to securely share their experiences, broaden their understanding of the illness or symptoms, form a supportive network, and transmit information (e.g., state of health and new symptoms) between users and other stake holders (e.g., medical center). Despite the benefits afforded by MHSNs, there are underlying security and privacy issues (e.g., due to the transmission of messages via a wireless channel). The handshake scheme is an important cryptographic mechanism, which can provide secure communication in MHSNs (e.g., anonymity and mutual authentication between users, such as patients). In this paper, we present a new framework for the handshake scheme in MHSNs, which is based on hierarchical identity-based cryptography. We then construct an efficient Cross-Domain HandShake (CDHS) scheme that allows symptoms-matching within MHSNs. For example, using the proposed CDHS scheme, two patients registered with different healthcare centers can achieve mutual authentication and generate a session key for future secure communications. We then prove the security of the scheme, and a comparative summary demonstrates that the proposed CDHS scheme requires fewer computation and lower communication costs. We also implement the proposed CDHS scheme and three related schemes in a proof of concept Android app to demonstrate utility of the scheme. Findings from the evaluations demonstrate that the proposed CDHS scheme achieves a reduction of 18.14 and 5.41 percent in computation cost and communication cost, in comparison to three other related handshake schemes. Debiao He, Neeraj Kumar 0001, Huaqun Wang, Lina Wang 0001, Kim-Kwang Raymond Choo, Alexey V. Vinel |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2018 | Certificateless Provable Data Possession Scheme for Cloud-Based Smart Grid Data Management SystemsabstractThe smart grid is considered to be the next-generation power system because of its reliability, efficiency, and cost-effectiveness. In recent years, the smart grid technology has attracted a lot of attention from both academia and industry. Advances in smart grid technologies are enabling more data to be collected and analyzed in real-time for many kinds of smart grid applications. As the amount of data increases, the traditional smart grid data management system cannot provide sufficient storage and processing capacities. To address these challenges, cloud computing is being introduced into the power system and the cloud-based smart grid data management system has been proposed to better support smart grid applications. In this cloud-based system, the data are stored and analyzed by the remote cloud server according to the requirements of smart grid applications. However, the loss of physical control over the smart grid data makes it a significant challenge in ensuring the integrity of the data. Many provable data possession schemes have been proposed in the past few years. However, most of them suffer from serious security weaknesses or poor performance. We propose an efficient certificateless provable data possession (CL-PDP) scheme for cloud-based smart grid applications. Security analysis shows that the proposed scheme is provably secure in a robust security model and can satisfy several security requirements. Performance analysis demonstrates that the proposed scheme results in lower computation costs as compared to two recently proposed CL-PDP schemes. Debiao He, Neeraj Kumar 0001, Sherali Zeadally, Huaqun Wang |
IEEE Trans. Ind. Informatics | 4 |
| 2018 | Security and Privacy Challenges for Internet-of-Things and Fog Computing
Ximeng Liu, Yang Yang 0026, Kim-Kwang Raymond Choo, Huaqun Wang |
Wirel. Commun. Mob. Comput. | 4 |
| 2018 | An Anonymous Multireceiver with Online/Offline Identity-Based EncryptionabstractAnonymous multireceiver encryption scheme can not only protect the privacy of the receiver but also ensure the security of message. However, the computational cost of this scheme is very large. It is not suitable for the sender which has limited resources, such as mobile devices and sensor nodes. In this work, an anonymous multireceiver online/offline identity‐based encryption is proposed based on offline/online and identity‐based encryption (IBE). In identity‐based encryption scheme, the sender can encrypt the message using the unique information of the user (such as identity number or e‐mail address) as its public key. The receiver obtains the private key from a central authority. For mobile device with limited resource, the online/offline encryption scheme can reduce the computational cost. Compared to the previous anonymous multireceiver schemes, the proposed scheme can efficiently encrypt message with offline/online method and ensure the anonymity of receivers. The analysis results also show that our scheme is efficient in terms of computational cost by comparing to the previous works. Qihua Wang, Fagen Li, Huaqun Wang |
Wirel. Commun. Mob. Comput. | 3 |
| 2017 | Analysis of handover authentication protocols for mobile wireless networks using identity-based public key cryptography
Debiao He, Sherali Zeadally, Huaqun Wang |
Comput. Networks | 4 |
| 2017 | Balanced anonymity and traceability for outsourcing small-scale data linear aggregation in the smart gridabstractAlong with the development of information technology, the traditional electrical grid is moving to smart grid technology. By using the smart grid, the users and utility providers can more efficiently manage and generate power. Along with the advantages, the smart grid is also faced with new security concerns. In the smart grid, the user's citizen identity information should be preserved and the offensive user should be traced. For some low‐capacity devices, it is indispensable to perform complicated computation by using outsourcing computation. The authors provide the outsourcing computation through public cloud. Anonymity and traceability are two important security properties in the smart grid. They are the unity of opposites. On the basis of the security requirements, they propose the balanced anonymity and traceability for outsourcing small‐scale data linear aggregation (BAT‐LA) in the smart grid. The formal definition, system model and security model are presented. Then, a concrete BAT‐LA protocol is designed by using the elliptic curve cryptography and proxy re‐encryption. Through security analysis and performance analysis, the designed BAT‐LA protocol is provably secure and efficient. Huaqun Wang, Debiao He, Shibing Zhang |
IET Inf. Secur. | 1 |
| 2017 | Insecurity of an identity-based public auditing protocol for the outsourced data in cloud storage
Debiao He, Huaqun Wang, Lina Wang 0001 |
Inf. Sci. | 2 |
| 2017 | Efficient certificateless anonymous multi-receiver encryption scheme for mobile devices
Debiao He, Huaqun Wang, Lina Wang 0001, Jian Shen 0001, Xianzhao Yang |
Soft Comput. | 2 |
| 2017 | Strong Key-Exposure Resilient Auditing for Secure Cloud StorageabstractKey exposure is one serious security problem for cloud storage auditing. In order to deal with this problem, cloud storage auditing scheme with key-exposure resilience has been proposed. However, in such a scheme, the malicious cloud might still forge valid authenticators later than the key-exposure time period if it obtains the current secret key of data owner. In this paper, we innovatively propose a paradigm named strong key-exposure resilient auditing for secure cloud storage, in which the security of cloud storage auditing not only earlier than but also later than the key exposure can be preserved. We formalize the definition and the security model of this new kind of cloud storage auditing and design a concrete scheme. In our proposed scheme, the key exposure in one time period doesn’t affect the security of cloud storage auditing in other time periods. The rigorous security proof and the experimental results demonstrate that our proposed scheme achieves desirable security and efficiency. Jia Yu 0003, Huaqun Wang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Lightweight Data Aggregation Scheme against Internal Attackers in Smart Grid Using Elliptic Curve CryptographyabstractRecent advances of Internet and microelectronics technologies have led to the concept of smart grid which has been a widespread concern for industry, governments, and academia. The openness of communications in the smart grid environment makes the system vulnerable to different types of attacks. The implementation of secure communication and the protection of consumers’ privacy have become challenging issues. The data aggregation scheme is an important technique for preserving consumers’ privacy because it can stop the leakage of a specific consumer’s data. To satisfy the security requirements of practical applications, a lot of data aggregation schemes were presented over the last several years. However, most of them suffer from security weaknesses or have poor performances. To reduce computation cost and achieve better security, we construct a lightweight data aggregation scheme against internal attackers in the smart grid environment using Elliptic Curve Cryptography (ECC). Security analysis of our proposed approach shows that it is provably secure and can provide confidentiality, authentication, and integrity. Performance analysis of the proposed scheme demonstrates that both computation and communication costs of the proposed scheme are much lower than the three previous schemes. As a result of these aforementioned benefits, the proposed lightweight data aggregation scheme is more practical for deployment in the smart grid environment. Debiao He, Sherali Zeadally, Huaqun Wang, Qin Liu 0003 |
Wirel. Commun. Mob. Comput. | 3 |
| 2016 | An Efficient Dynamic Provable Data Possession Scheme in Cloud Storage
Ge Yao, Yong Li 0002, Linan Lei, Huaqun Wang, Changlu Lin |
GPC | 4 |
| 2016 | Efficient Dynamic Provable Data Possession from Dynamic Binary Tree
Changfeng Li, Huaqun Wang |
ProvSec | 2 |
| 2016 | Lightweight anonymous key distribution scheme for smart grid using elliptic curve cryptographyabstractDue to efficiency, security and reliability, the smart grid attracts more and more attentions from both industry and researchers. To implement secure communication in the smart grid, how to distribute secret keys among participants become an important issue. Several key distribution schemes for the smart grid have been proposed to guarantee secure communication. However, most of them cannot provide smart meter anonymity or have unsatisfactory performance. Based on the identity‐based cryptography, this study proposes an anonymous key distribution (AKD) scheme for the smart grid using the elliptic curve cryptography. The proposed AKD scheme can provide the smart meter anonymity and mutual authentication between two participants without any help of the trusted anchor. Due to the fact that no bilinear paring operation is involved in the execution, the proposed AKD scheme has much better performance than the latest AKD scheme proposed by Tsai and Lo. Detailed performance analysis shows that the computation and the communication costs of the authors’ AKD scheme is about 82.39 and 52.33% less than that of Tsai and Lo's AKD scheme. Besides, security analysis shows that the proposed AKD scheme is provably secure in the random oracle model. Debiao He, Huaqun Wang, Muhammad Khurram Khan, Lina Wang 0001 |
IET Commun. | 2 |
| 2016 | A group key-policy attribute-based encryption with partial outsourcing decryption in wireless sensor networksabstractAbstract Outsourcing decryption that enables the authorized users to obtain the original data without decryption computation is crucially important for wireless sensor networks in public data center. The existing outsourcing decryption schemes have been designed based on key‐policy attribute‐based encryption. The security of outsourcing decryption cannot be guaranteed, because the data center is not loyal, and existing schemes have high computational complexity and energy consumption. In this work, a novel partially outsourcing decryption scheme is proposed to guarantee data security and computational efficiency for resource‐constrained sensor nodes and terminal equipments. According to the attributes of cluster nodes in the proposed scheme, the encryption secret key is encrypted based on group key‐policy attribute‐based encryption and sent to data center, and authorized users who satisfy the attributes of the ciphertext can obtain the secret key to decrypt the ciphertext. Furthermore, in order to reduce the decryption overhead for users, the authorized users can simply decrypt the transformation ciphertext that is partially decrypted by the data center using token key. Compared with the previous decryption schemes, the proposed scheme efficiently decrypts ciphertext and enhances security of the data. The simulation results also indicate that the proposed scheme is efficient in terms of energy consumption and computation by comparing to previous work. Copyright © 2016 John Wiley & Sons, Ltd. Qihua Wang, James Chang Wu Yu, Fagen Li, Huaqun Wang, Lijie Cao |
Secur. Commun. Networks | 4 |
| 2016 | Identity-Based Proxy-Oriented Data Uploading and Remote Data Integrity Checking in Public CloudabstractMore and more clients would like to store their data to public cloud servers (PCSs) along with the rapid development of cloud computing. New security problems have to be solved in order to help more clients process their data in public cloud. When the client is restricted to access PCS, he will delegate its proxy to process his data and upload them. On the other hand, remote data integrity checking is also an important security problem in public cloud storage. It makes the clients check whether their outsourced data are kept intact without downloading the whole data. From the security problems, we propose a novel proxy-oriented data uploading and remote data integrity checking model in identity-based public key cryptography: identity-based proxy-oriented data uploading and remote data integrity checking in public cloud (ID-PUIC). We give the formal definition, system model, and security model. Then, a concrete ID-PUIC protocol is designed using the bilinear pairings. The proposed ID-PUIC protocol is provably secure based on the hardness of computational Diffie-Hellman problem. Our ID-PUIC protocol is also efficient and flexible. Based on the original client's authorization, the proposed ID-PUIC protocol can realize private remote data integrity checking, delegated remote data integrity checking, and public remote data integrity checking. Huaqun Wang, Debiao He, Shaohua Tang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Proxy Provable Data Possession with General Access Structure in Public Clouds
Huaqun Wang, Debiao He |
Inscrypt | 1 |
| 2015 | Private Certificate-Based Remote Data Integrity Checking in Public Clouds
Huaqun Wang, Jiguo Li 0001 |
COCOON | 1 |
| 2015 | Anonymous multi-receiver remote data retrieval for pay-TV in public cloudsabstractAlong with the rapid development of network‐based cloud computing, security has become an important element. When a media corporation stores its programs in public clouds, it is important to authorise the consumers to enjoy the stored program by electronic payment. To protect the consumers’ privacy and save the bandwidth, the authors propose an anonymous multi‐receiver remote data retrieval model for pay‐TV in public clouds. In the security model, they consider the malicious public cloud server (PCS), malicious corporation and malicious consumer. The authors’ scheme can withstand the malicious PCS, malicious corporation and malicious consumer. At last, the authors give the computation efficiency analysis, communication efficiency analysis and flexibility analysis. Their analysis shows that their scheme is provably secure and efficient. Huaqun Wang |
IET Inf. Secur. | 1 |
| 2015 | TPP: Traceable Privacy-Preserving Communication and Precise Reward for Vehicle-to-Grid Networks in Smart GridsabstractIn vehicle-to-grid (V2G) networks, service providers are battery-powered vehicles, and the service consumer is the power grid. Security and privacy concerns are major obstacles for V2G networks to be extensively deployed. In 2011, Yang et al. proposed a very interesting privacy-preserving communication and precise reward architecture for V2G networks in smart grids. In this paper, we enhance Yang et al.'s framework with the formal definitions of unforgeability and restrictiveness. Then, we propose a new traceable privacy-preserving communication and precise reward scheme with available cryptographic primitives. The proposed scheme is formally proven secure with well-established assumptions in the random oracle model. Thorough theoretical and experimental analyses demonstrate that our scheme is efficient and practical for secure V2G networks in smart grids. Huaqun Wang, Qianhong Wu, Li Xu 0002, Josep Domingo-Ferrer |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Identity-Based Distributed Provable Data Possession in Multicloud StorageabstractRemote data integrity checking is of crucial importance in cloud storage. It can make the clients verify whether their outsourced data is kept intact without downloading the whole data. In some application scenarios, the clients have to store their data on multicloud servers. At the same time, the integrity checking protocol must be efficient in order to save the verifier's cost. From the two points, we propose a novel remote data integrity checking model: ID-DPDP (identity-based distributed provable data possession) in multicloud storage. The formal system model and security model are given. Based on the bilinear pairings, a concrete ID-DPDP protocol is designed. The proposed ID-DPDP protocol is provably secure under the hardness assumption of the standard CDH (computational Diffie-Hellman) problem. In addition to the structural advantage of elimination of certificate management, our ID-DPDP protocol is also efficient and flexible. Based on the client's authorization, the proposed ID-DPDP protocol can realize private verification, delegated verification, and public verification. Huaqun Wang |
IEEE Trans. Serv. Comput. | 1 |
| 2014 | Provably Secure Anonymous Multi-receiver Identity-Based Encryption with Shorter CiphertextabstractAnonymous multi-receiver identity-based encryption (ID-MRE) can protect the receiver identity besides message confidentiality. It can be applied in many fields, such as VoIP (Voice over Internet Protocol) and pay-TV systems. Based on the bilinear pairings, this paper proposes an anonymous ID-MRE scheme. The proposed scheme satisfies the indistinguishability of encryptions under selective multi-identity, adaptive chosen ciphertext attacks (IND-sMID- CCA2). On the other hand, it also satisfies the anonymous indistinguishability of encryptions under selective multi-identity, adaptive chosen ciphertext attacks (ANON-sMID-CCA2). The security analysis and performance analysis show that our scheme is provably secure and efficient. Huaqun Wang |
DASC | 1 |
| 2014 | A Provably Secure Ring Signature Scheme with Bounded Leakage Resilience
Huaqun Wang, Qianhong Wu, Futai Zhang, Josep Domingo-Ferrer |
ISPEC | 1 |
| 2014 | Authentic and confidential policy distribution in software defined wireless networkabstractSoftware-defined networking (SDN) empowers network operators with more flexibility to program their networks. By separating the complexity of state distribution from network specification, SDN provides new ways to deal with age-old problems in networking, for example, routing. At the same time, SDN also brings about some new security problems, such as forged traffic flow, vulnerability, etc. In wireless SDN, the controller will send some policies to the switches. It is very important to remain these policies authentic and confidential due to the wireless and insecure channel. In this paper, we propose a secure and efficient policy distribution scheme in wireless SDN which can realize authentication and secrecy simultaneously. The proposed scheme takes use of the symmetric encryption/decryption algorithms, bilinear pairings and multi-linear map. Through security analysis and efficiency analysis, our scheme is provably secure and efficient in the random oracle model (ROM). Huaqun Wang |
IWCMC | 1 |
| 2014 | Insecurity of 'Improved Anonymous Multi-Receiver Identity-Based Encryption'abstractAnonymous multi-receiver identity-based encryption can protect the receiver identity privacy and message confidentiality. Thus, it can be used in many fields, such as Voice over Internet Protocol and pay-TV systems. In 2012, Chien improved an anonymous multi-receiver identity-based encryption scheme. This paper points out that Chien's scheme does not satisfy the indistinguishability of encryptions under selective multi-identity, chosen ciphertext attacks. The analysis is important for understanding the security risks. Huaqun Wang |
Comput. J. | 1 |
| 2014 | Identity-based remote data possession checking in public cloudsabstractChecking remote data possession is of crucial importance in public cloud storage. It enables the users to check whether their outsourced data have been kept intact without downloading the original data. The existing remote data possession checking (RDPC) protocols have been designed in the PKI (public key infrastructure) setting. The cloud server has to validate the users’ certificates before storing the data uploaded by the users in order to prevent spam. This incurs considerable costs since numerous users may frequently upload data to the cloud server. This study addresses this problem with a new model of identity‐based RDPC (ID‐RDPC) protocols. The authors present the first ID‐RDPC protocol proven to be secure assuming the hardness of the standard computational Diffie‐Hellman problem. In addition to the structural advantage of elimination of certificate management and verification, the authors ID‐RDPC protocol also outperforms the existing RDPC protocols in the PKI setting in terms of computation and communication. Huaqun Wang, Qianhong Wu, Josep Domingo-Ferrer |
IET Inf. Secur. | 1 |
| 2014 | FRR: Fair remote retrieval of outsourced private medical records in electronic health networks
Huaqun Wang, Qianhong Wu, Josep Domingo-Ferrer |
J. Biomed. Informatics | 1 |
| 2014 | An anonymous data aggregation scheme for smart grid systemsabstractABSTRACT By integrating the traditional grid with the advanced communication and information technologies, smart grid can provide a reliable and efficient energy service for our modern society. Data aggregation plays an important role in evaluating the current energy usage information of consumer domains, based on which the operation center can accommodate distributed power sources to maximize the utilization efficiency. However, it also incurs a potential risk to the consumer privacy. In this paper, we propose an anonymous multi‐dimensional data aggregation for smart grid systems. With the proposed scheme, the operation center can compute both additive and non‐additive aggregation functions over the collected reports from consumers. The computation cost of each consumer is independent of the number of collected data types. In addition, by using the batch verification technique, the operation center's computation cost can be significantly reduced. The security analysis demonstrates that the proposed scheme can achieve identity privacy preserving, data authentication, and confidentiality. Copyright © 2013 John Wiley & Sons, Ltd. Xuefeng Liu 0002, Yuqing Zhang 0001, Boyang Wang 0001, Huaqun Wang |
Secur. Commun. Networks | 4 |
| 2014 | Signer-admissible strong designated verifier signature from bilinear pairingsabstractABSTRACT In the designated verifier signature, the validity of signature can be proved by the specific verifier although the verifier has no ability to prove this to others. On the other hand, strong designated verifier signature (SDVS) can only be verified by the designated verifier. It will not be verified without the designated verifier's private key. The third party cannot tell who generates the signature. Even if the true signer signs a message by using SDVS, he has no ability to show any evidence. In some cases, the true signer wants to admit the signature if the admission can bring about reward. On the basis of the idea, this paper proposes the new concept of signer‐admissible SDVS. By utilizing bilinear pairings and the modified ElGamal signature, we design an efficient identity‐based SDVS scheme with signer‐admission property. Compared with the existing identity‐based SDVS schemes, our scheme supports the signer‐admission property, and it is efficient. Copyright © 2013 John Wiley & Sons, Ltd. Huaqun Wang |
Secur. Commun. Networks | 1 |
| 2014 | On the Knowledge Soundness of a Cooperative Provable Data Possession Scheme in Multicloud StorageabstractProvable data possession (PDP) is a probabilistic proof technique for cloud service providers (CSPs) to prove the clients' data integrity without downloading the whole data. In 2012, Zhu et al. proposed the construction of an efficient PDP scheme for multicloud storage. They studied the existence of multiple CSPs to cooperatively store and maintain the clients' data. Then, based on homomorphic verifiable response and hash index hierarchy, they presented a cooperative PDP (CPDP) scheme from the bilinear pairings. They claimed that their scheme satisfied the security property of knowledge soundness. It is regretful that this comment shows that any malicious CSP or the malicious organizer (O) can generate the valid response which can pass the verification even if they have deleted all the stored data, i.e., Zhu et al.'s CPDP scheme cannot satisfy the property of knowledge soundness. Then, we discuss the origin and severity of the security flaws. It implies that the attacker can get the pay without storing the clients' data. It is important to clarify the scientific fact to design more secure and practical CPDP scheme in Zhu et al.'s system architecture and security model. Huaqun Wang, Yuqing Zhang 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2013 | Proxy Provable Data Possession in Public CloudsabstractRecently, cloud computing rapidly expands as an alternative to conventional computing due to it can provide a flexible, dynamic and resilient infrastructure for both academic and business environments. In public cloud environment, the client moves its data to public cloud server (PCS) and cannot control its remote data. Thus, information security is an important problem in public cloud storage, such as data confidentiality, integrity, and availability. In some cases, the client has no ability to check its remote data possession, such as the client is in prison because of committing crime, on the ocean-going vessel, in the battlefield because of the war, and so on. It has to delegate the remote data possession checking task to some proxy. In this paper, we study proxy provable data possession (PPDP). In public clouds, PPDP is a matter of crucial importance when the client cannot perform the remote data possession checking. We study the PPDP system model, the security model, and the design method. Based on the bilinear pairing technique, we design an efficient PPDP protocol. Through security analysis and performance analysis, our protocol is provable secure and efficient. Huaqun Wang |
IEEE Trans. Serv. Comput. | 1 |
| 2012 | Analysis and Improvements of Two Identity Based Anonymous Signcryption Schemes for Multiple ReceiversabstractAnonymous signcryption provides anonymity of the sender with the advantages of signcryption. When a sender wants to send a message to multiple receivers in the confidential and authenticated way, multi receiver signcryption is needed. In 2010, Zhang et al. proposed an identity based anonymous signcryption scheme for multiple receivers which is proved secure in the standard model. At the same time, Lal et al. designed another identity based anonymous signcryption scheme for multiple receivers in the random oracle model. Unfortunately, we show that the two schemes do not satisfy the semantic security. Then we improve their corresponding anonymous signcryption schemes that remedy the weaknesses of the above two schemes. Our proposed schemes satisfy the semantic security, unforgeability, signcrypter identity's ambiguity, and public authenticity. Huaqun Wang, Yuqing Zhang 0001 |
TrustCom | 1 |
| 2012 | Improved one-to-many authentication scheme for access control in pay-TV systemsabstractMutual authentication is important in a mobile pay-TV system. Traditional authentication schemes make use of one-to-one delivery, that is, one authentication message per request is delivered from a head-end system to subscriber. This delivery occupies too much bandwidth and therefore is inefficient and costly. One-to-many authentication scheme for access control in mobile pay-TV systems was proposed by Sun et al. in 2009. In one-to-many authentication scheme, only one authentication message for multiple requests is broadcasted from the head-end system (HES) to subscribers. Sun et al. claimed that their scheme is secure and provides anonymous authentication for protecting user privacy. However, the authors demonstrate that their scheme has a critical weakness. An attacker without any secret information can not only successfully impersonate mobile set (MS) to cheat the HES but also impersonate HES to cheat MS. The authors result is important for security engineers who design and develop user authentication systems. Afterwards, the authors design a novel one-to-many authentication scheme from bilinear pairings. They give the formal security proof in the random oracle model. In addition, they present the performance analysis of our scheme. The analysis results showed that their novel authentication scheme has shorter transmission message and can be applied in the environment which has limited bandwidth. At the same time, their scheme is also the first secure one-to-many authentication scheme for access control in pay-TV systems. Huaqun Wang |
IET Inf. Secur. | 1 |
| 2012 | Cryptanalysis and improvements of an anonymous multi-receiver identity-based encryption schemeabstractIn 2010, Fan et al. presented an anonymous multi-receiver identity-based encryption scheme where they adopt Lagrange interpolating polynomial mechanism. They showed that their scheme makes it impossible for an attacker or any other message receiver to derive the identity of a message receiver such that the privacy of every receiver can be guaranteed. They also formally showed that every receiver in the proposed scheme is anonymous to any other receiver. In this work, the authors study the security of Fan et al.'s anonymous multi-receiver identity-based encryption scheme. It is regretful that they found their scheme is insecure. Every receiver in Fan et al.'s scheme is not anonymous to any other receiver. The authors showed that simple protocol changes can fix these weaknesses and render Fan et al.'s scheme. The improved scheme is proved to satisfy the confidentiality and receiver anonymity in the random oracle. Huaqun Wang, Yi-Chun Zhang, Hu Xiong |
IET Inf. Secur. | 1 |
| 2012 | On the Security of a Ticket-Based Anonymity System with Traceability Property in Wireless Mesh NetworksabstractIn 2011, Sun et al. proposed a security architecture to ensure unconditional anonymity for honest users and traceability of misbehaving users for network authorities in wireless mesh networks (WMNs). It strives to resolve the conflicts between the anonymity and traceability objectives. In this paper, we attacked Sun et al. scheme's traceability. Our analysis showed that trusted authority (TA) cannot trace the misbehavior client (CL) even if it double-time deposits the same ticket. Huaqun Wang, Yuqing Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2011 | Identity-Based Strong Key-Insulated Ring Signature Scheme in the Standard ModelabstractIn order to improve the security of ring signature, we combine standard ring signature and key-insulated cryptography. We give the definition and security model for ID-based key-insulated ring signature, and at the same time we proposed an ID-based strong key-insulated ring signature scheme. This scheme can deal with key-exposure problem. The proposed ring signature scheme enjoys several attractive features: (1)it is provably secure in standard model, (2)it is unconditional anonymous, (3)it is strong key-insulated, (4)it allows frequent key-updates without increasing the risk of helper key-exposure, and thus enhances the security of the system. Huaqun Wang, Yuqing Zhang 0001 |
MSN | 1 |
| 2011 | Cryptanalysis of an Efficient Threshold Self-Healing Key Distribution SchemeabstractIn 2009, Han et al. proposed an efficient threshold self-healing key distribution scheme with sponsorization for infrastructureless wireless networks. They claimed that the key distribution scheme satisfies the forward security, i.e., any internal user who has been revoked can not generate a new session key. In this paper,an attack method against this key distribution scheme's forward security was presented. Furthermore, this attack method can also be applied to this scheme's backward security.Thus,the original threshold self-healing key distribution scheme is insecure. Huaqun Wang, Yuqing Zhang 0001 |
IEEE Trans. Wirel. Commun. | 1 |
| 2009 | Cryptanalysis of a Generalized Ring Signature SchemeabstractThe concept of ring signature was first introduced by Rivest et al. in 2001. In a ring signature, instead of revealing the actual identity of the message signer, it specifies a set of possible signers. The verifier can be convinced that the signature was indeed generated by one of the ring members; however, the verifier is unable to tell which member actually produced the signature. A convertible ring signature scheme allows the real signer to convert a ring signature into an ordinary signature by revealing secret information about the ring signature. Thus, the real signer can prove the ownership of a ring signature if necessary, and the the other members in the ring cannot prove the ownership of a ring signature. Based on the original ElGamal signature scheme, a generalized ring signature scheme was proposed for the first time in 2008. The proposed ring signature can achieve unconditional signer ambiguity and is secure against adaptive chosen-message attack in the random oracle model. By comparing to ring signatures based on RSA algorithm, the authors claimed that the proposed generalized ring signature scheme is convertible. It enables the actual message signer to prove to a verifier that only she is capable of generating the ring signature. Through cryptanalysis, we show that the convertibility of the generalized ring signature scheme cannot be satisfied. Everyone in the ring signature has the ability to claim that she generates the generalized ring signature. Huaqun Wang, Futai Zhang, Yanfei Sun |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2008 | Cryptanalysis of Two Ring Signcryption Schemes
Huaqun Wang |
Inscrypt | 1 |