VLDB 2026 Research / reviewers in the wild / expert
Chengzhe Lai
dblp:74/11196
· DBLP profile ↗
48ranked-venue papers
25as first author
27since 2021 · last 2026
0000-0002-4603-3380ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 36 · 20 first-author · 18 since 2021Security and privacy · 6 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FGPAM: Fine-Grained Privacy-Preserving User Attribute Matching in Mobile Social Networks
Chengzhe Lai |
IEEE Internet Things J. | 1 |
| 2026 | A Lightweight Privacy-Preserving Scheme With Efficient Reputation Management for Vehicular Crowdsensing
Chengzhe Lai, Kaihuan Deng |
IEEE Internet Things J. | 3 |
| 2026 | WLCHAT-PDP: Provable Data Possession Based on Weighted Link-List Chameleon Hash Authentication Tree in Edge ComputingabstractIn Internet of Things (IoT) scenarios, the integrity audit of massive amounts of data uploaded from Edge Nodes (ENs) to the cloud poses significant challenge to researchers. Existing Provable Data Possession (PDP) schemes suffer from low communication and computational efficiency, as well as the issue of Third-Party Auditors (TPAs) not being completely trustworthy, especially in dynamic data update scenarios. This paper designs an efficient authentication structure, named the Weighted Link-list Chameleon Hash Authentication Tree (WLCHAT), to reduce cloud storage overhead and improve dynamic update efficiency. Based on this, the paper further proposes the WLCHAT-PDP scheme, which is built upon the WLCHAT structure. Building on the PDP model, the proposed scheme introduces the ENs to proxy user operations for tag generation and to participate in the audit process. By combining this with a user authorization signature mechanism, the proposed scheme not only alleviates terminal computational load but also guarantees that all operations are authorized. To enhance the credibility of the audit process, the proposed scheme incorporates blockchain-anchored log records to effectively prevent collusive behavior between cloud service providers and TPAs. Theoretical analyses and comparative evaluation demonstrate that the scheme achieves a balance between security and computational overhead, rendering it suitable for dynamic and trusted IoT cloud storage environments. Youjun Xu, Yiyu Yang, Dengqi Yang, Chengzhe Lai |
Peer Peer Netw. Appl. | 6 |
| 2026 | Splight: A Lightweight Block Cipher for Resource-Constrained Embedded Devices
Chengzhe Lai, Yong Yu 0002 |
IEEE Trans. Computers | 3 |
| 2026 | SRAA: A Secure and Revocable Access Authentication Scheme in Cross-Domain Vehicular Twin NetworksabstractVehicular twin networks (VTN) create virtual agents of vehicular entities through digital twin (DT) technology, replacing physical counterparts in connecting and exchanging traffic information in cyberspace, overcoming physical range constraints and extending information sources for enhanced vehicular decision support. However, the inherent openness of VTN renders communication between DTs, vulnerable to security threats, such as tampering and impersonation, especially in scenarios where DTs are distributed across multiple cloud domains. These issues result in erroneous decisions to threaten vehicular safety because DTs may receive compromised information. To address these challenges, this article proposes a secure and revocable access authentication scheme in the cross-domain VTN. In the scheme, DTs should be authorized first to obtain identity-bound symmetric functions before joining the VTN, and then perform secure access authentication and key agreement with others based on chameleon hash functions for both intradomain and cross-domain communication. Moreover, a dynamic revocation mechanism is introduced to remove malicious DTs from VTN. Formal verification using the Tamarin tool demonstrates that the proposed scheme achieves diverse security properties. Performance evaluation further shows that the proposed scheme outperforms most related schemes in terms of computational and communication overhead. Guanjie Li, Jin Cao 0001, Jinkai Zheng, Chengzhe Lai, Tom H. Luan, Zehui Xiong |
IEEE Trans. Ind. Informatics | 4 |
| 2026 | Cloud-Assisted Privacy-Preserving Safety Monitoring Scheme for Online Ride-Hailing Services
Chengzhe Lai, Jiping Ma, Zhiquan Liu 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | MOA-RHS: Maximized Order Acceptance Ride-Hailing Scheme with Collusion ResistanceabstractRide-hailing services provide convenient transportation and contribute to urban traffic efficiency, but they also introduce security and privacy challenges. A major concern is collusion between ride-hailing service providers (RHSPs) and drivers, which can compromise passengers’ location privacy through repeated matching. Additionally, existing solutions often fail to consider drivers’ profit-oriented nature, leading to low order acceptance rates and inefficient resource allocation. To address these issues, we propose a privacy-preserving ride-matching scheme utilizing Multi-Party Secure Computation (MPC) and homomorphic encryption. Our approach prevents RHSPs from accessing sensitive user data while ensuring fair ride allocation. By incorporating drivers’ expected earnings into the matching process, our solution enhances order acceptance rates and reduces resource waste. Furthermore, an efficient decentralized matching algorithm offloads computation to Roadside Units (RSUs), minimizing reliance on centralized servers. Our scheme ensures secure, efficient, and accountable ride-hailing services while protecting user privacy. Chengzhe Lai |
VTC2025-Fall | 1 |
| 2025 | Efficient and secure cross-domain data sharing scheme with traceability for Industrial Internet
Wei Luo 0003, Ziyi Lv, Chengzhe Lai |
Comput. Networks | 3 |
| 2025 | Two-phase authentication for secure vehicular digital twin communications
Xinwei Zhang 0008, Chengzhe Lai, Guanjie Li, Dong Zheng 0001 |
Comput. Networks | 2 |
| 2025 | SECR: A Secure and Efficient Charging Reservation Scheme Based on Digital Twin in Vehicular NetworkabstractDespite the rapid growth of electric vehicles (EVs), charging remains a time-consuming issue that requires effective management. An important solution uses digital twin (DT) technology, which acts as a virtual agent for EVs in the digital space. DT can analyze real-time vehicle data to develop optimal charging schedules and reserve charging providers in advance through the vehicular network, leading to more efficient charging processes. However, the vehicular network exposes the automated reservation process of the DT to security attacks. Additionally, there is a risk that the actual charging process may deviate from the scheduled requirements set by the DT, resulting in wasted charging resources. To address these issues, this article proposes a secure and efficient charging reservation scheme based on DT technology. To prevent malicious attacks, we first design a secure and privacy-preserving reservation authentication protocol using the extended Chebyshev chaotic maps, taking into account the computational resources of the EV. Furthermore, we develop a reputation mechanism to evaluate and incentivize the charging behavior of EVs. Formal verification and further discussions are conducted to show diverse security functionalities of the proposed scheme can be achieved. We evaluate that the proposed scheme outperforms existing schemes in terms of computation and communication overheads, while also assessing the impact of EV charging behavior on reputation and charging level. Guanjie Li, Tom H. Luan, Jinkai Zheng, Chengzhe Lai, Kuan Zhang 0001, Shui Yu 0001 |
IEEE Internet Things J. | 4 |
| 2025 | LAPMS: A lightweight and privacy-preserving management scheme for secure vehicle platoons
Chengzhe Lai, Guanjie Li, Lingchen Li |
Peer Peer Netw. Appl. | 2 |
| 2025 | DTHA: A Digital Twin-Assisted Handover Authentication Scheme for 5G and BeyondabstractWith the rapid development and extensive deployment of the fifth-generation wireless system (5G), it has achieved ubiquitous high-speed connectivity and improved overall communication performance. Additionally, as one of the promising technologies for integration beyond 5G, digital twin in cyberspace can interact with the core network, transmit essential information, and further enhance the wireless communication quality of the corresponding mobile device (MD). However, the utilization of millimeter-wave, terahertz band, and ultra-dense network technologies presents urgent challenges for MD in 5G and beyond, particularly in terms of frequent handover authentication with target base stations during faster mobility, which can cause connection interruption and incur malicious attacks. To address such challenges in 5G and beyond, in this paper, we propose a secure and efficient handover authentication scheme by utilizing digital twin. Acting as an intelligent intermediate, the authorized digital twin can handle computations and assist the corresponding MD in performing secure mutual authentication and key negotiation in advance before attaching the target base stations in both intra-domain and inter-domain scenarios. In addition, we provide the formal verification based on BAN logic, RoR model, and ProVerif, and informal analysis to demonstrate that the proposed scheme can offer diverse security functionality. Performance evaluation shows that the proposed scheme outperforms most related schemes in terms of signaling, computation, and communication overheads. Guanjie Li, Tom H. Luan, Chengzhe Lai, Jinkai Zheng, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Traceable Access Control Encryption With Parallel Multiple SanitizersabstractAccess control encryption (ACE) is an innovative cryptographic primitive that realizes fine-grained read/write control of data and protects data privacy and security while facilitating the effective flow of information. However, existing ACE schemes face several limitations: 1) Inability to adequately mitigate the risks of a single point of failure in the sanitizer. 2) Lack of an effective accountability mechanism for disputes arising during the sanitization process. To solve these problems, this paper proposes the notion of traceable access control encryption with parallel multiple sanitizers for the first time and designs a specific structure of traceable parallel ACE to prevent the single point of failure, effectively deter abnormal sanitizer behaviors, and optimize system performance. Additionally, computationally intensive operations in the encryption and decryption processes are outsourced to third-party servers, resulting in a significant reduction of computational overhead. Furthermore, theoretical analysis and experimental simulations validate the effectiveness of the proposed scheme. Comprehensive security analysis demonstrates its no-read security under the decisional q-parallel Bilinear Diffie-Hellman Exponent (BDHE) assumption and its no-write security under the Discrete Logarithm (DL) assumption, ensuring its reliability in practical applications. Wei Luo 0003, Qinghe Duan, Chengzhe Lai |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | GAN Augmentation-Based Continuous Authentication for Vehicular Digital TwinabstractIn this paper, to secure the communication between autonomous vehicle and its digital representative in the vehicular digital twin system, we propose a GAN augmentation-based continuous authentication scheme. Specifically, in the proposed scheme, we first introduce a data augmentation technique based Generative Adversarial Network (GAN) that provides the augmentation of raw data from vehicle sensors. We then present the efficient authentication: 1) We train a Convolutional Neural Network (CNN) using raw and augmented data; 2) Deep features are extracted through a combination of Principal Component Analysis (PCA) and CNN; 3) We train the OC-SVM classifier during the registration to ensure the legality of vehicle in the authentication phase. Performance evaluations via extensive simulations demonstrate the efficiency and effectiveness of the proposed scheme in terms of GAN loss and accuracy. Chengzhe Lai, Xinwei Zhang 0008, Guanjie Li, Yong Yu 0002, Dong Zheng 0001 |
ICC | 1 |
| 2024 | Privacy-Preserving Medical Data Sharing Scheme Based on Two-Party Cloud-Assisted PSIabstractThe conflict between data privacy and sharing among healthcare institutions creates data silos, causing wasteful duplication, incomplete information, and potential hindrances to scientific research. In this article, we present a privacy-preserving medical data sharing scheme based on cloud-assisted private set intersection (PSI) and aggregate signature technique. First, we propose a novel authenticated cloud-assisted PSI, named AC-PSI, which can achieve client authentication and randomized processing of private data by using Diffie–Hellman-based oblivious pseudorandom function (DH-OPRF) and vector oblivious linear-function evaluation-based oblivious pseudorandom function (VOLE-OPRF), respectively. Second, based on the AC-PSI and locally verifiable signature (LVS), we design a privacy-preserving and secure medical data sharing scheme, which can provide enhanced security features by enabling access control of computing resources and resist precomputation attacks from external sources. Our approach has been proven through a rigorous analysis of security. Finally, through comparative analysis with the existing schemes, it is demonstrated that the proposed AC-PSI and medical data sharing scheme has low communication and computation overhead while achieving a higher level of privacy preservation and security. Chengzhe Lai, Hanyue Zhang, Rongxing Lu, Dong Zheng 0001 |
IEEE Internet Things J. | 1 |
| 2023 | A Secure and Efficient Handover Authentication Based on Digital Twin in 5G-V2XabstractIn recent years, 5G-V2X has promoted the advancement of autonomous vehicles, enabling the latter to obtain more information via 5G networks. However, fast-moving vehicles have to perform frequent handover authentication with base stations in vulnerable wireless channels, which can cause access failures and affect smooth driving. The digital twin is the virtual agent in cyberspace to reliably provide real-time decisions and added-value services to improve the quality of communication for vehicles by analyzing raw data and interacting with the 5G core network. Based on the capabilities of digital twin, in this paper, we propose digital twin-assisted handover authentication scheme that uses the digital twin as the bridge to exchange necessary parameters in 5G-V2X, thereby intelligently assisting in completing mutual authentication and key negotiation between the vehicle and the target base station in advance and reducing the complexity of the handover process. Furthermore, the security and performance analysis demonstrates that our proposed scheme is secure and efficient. Guanjie Li, Tom H. Luan, Jinkai Zheng, Chengzhe Lai, Zhou Su 0001, Haixia Peng |
GLOBECOM | 4 |
| 2023 | A PUF-based Authentication and Key Distribution Scheme for In-Vehicle NetworkabstractWith the increasing connectivity between and within vehicles, in-vehicle network security has received considerable attention. As the most widely used protocol in in-vehicle network, Controller Area Network (CAN) bus lacks security mechanisms by design, and is vulnerable to various attacks. Although many frameworks have been proposed to solve the security issues of CAN buses, spoofing attacks by compromised Electronic Control Units (ECUs) and reducing message latency while ensuring security remains a challenge. In this paper, we propose an authentication and key distribution scheme for the CAN bus. Specifically, the scheme includes ECU identity authentication, key distribution, and authentication of data frames. By utilizing physically unclonable functions (PUF) technique, each ECU avoids the risk of long-term key leakage, simplifies the key distribute process, and reduces the communication overhead of vehicles. Compared with the state-of-the-art group-based schemes, the proposed scheme has lower computational and communication overhead. Chengzhe Lai, Dong Zheng 0001 |
ICC | 1 |
| 2023 | A Group-oriented Authentication Scheme for IoT Devices in 5G NetworksabstractOne of the 5G support for IoT is Massive Machine Type Communication (mMTC). However, it also poses a great challenge to the IoT network, which cannot cope with the massive number of devices accessing at the same time. In this paper, we propose a group-oriented authentication scheme which supports a large number of devices accessing. In particular, the proposed scheme enables lightweight intra-group authentication and leader election through collaborative filtering techniques. In addition, our solution enables secure and efficient key agreement and mutual authentication by using Round-Efficient and Sender-Unrestricted Dynamic Group Key Agreement (RESUD-GKA), aggregate signature with forward security and proxy signature. We also introduce software-defined networking (SDN) and combine mobile edge computing (MEC) and network function virtualization (NFV) to fully utilize the links and greatly reduce the time cost. Ultimately, multiple security objectives of the protocol are assessed through the utilization of security analysis and the formal verification tool Scyther. Performance evaluation shows that the proposed scheme has lower bandwidth and transmission overhead compared to existing schemes. Qili Guo, Chengzhe Lai, Haoyan Ma, Dong Zheng 0001 |
MSN | 2 |
| 2023 | A blockchain-based traceability system with efficient search and query
Chengzhe Lai, Yinzhen Wang, Dong Zheng 0001 |
Peer Peer Netw. Appl. | 1 |
| 2023 | Searchable Encryption With Autonomous Path Delegation Function and Its Application in Healthcare CloudabstractOutsourcing medical data to healthcare cloud has become a popular trend. Since medical data of patients contain sensitive personal information, they should be encrypted before outsourcing. However, information retrieval methods based on plaintext cannot be directly applied to encrypted data. In this article, we present a new cryptographic primitive named conjunctive keyword search with secure channel free and autonomous path delegation function (AP-SCF-PECKS), which can be applied in scenarios where patients want to search for and autonomous delegate their private medical information without revealing their private key. Particularly, the proposed solution allows patients to set up multi-hop delegation path with their preferences, and the delegated doctors in the path can search for and access the patient’s private medical information with priority from high to low. Patients can ensure that authorized doctors are always trustworthy, and unauthorized users cannot obtain the private medical information of patients. Moreover, the scheme supports the conjunctive keyword search, secure channel free, and is secure against chosen keyword attack, chosen ciphertext attack, and keyword guessing attack. The security of proposed scheme has been formally proved in the standard model. Finally, the performance evaluations demonstrate that the overhead of proposed scheme are modest for healthcare cloud scenarios. Qian Wang 0033, Chengzhe Lai, Rongxing Lu, Dong Zheng 0001 |
IEEE Trans. Cloud Comput. | 2 |
| 2023 | A Novel Authentication Scheme Supporting Multiple User Access for 5G and BeyondabstractThe deployment of ultra-dense networks in the fifth-generation (5 G) network architecture can significantly improve the quality of wireless links, but this will cause frequent handovers of mobile users and increase authentication delays. Furthermore, the simultaneous influx of a large number of mobile users may cause serious network congestion. Aiming at these problems, this article proposes a novel authentication scheme supporting multi-user access, which fully considers the scenarios of intra-domain handover and inter-domain handover across AMF. Using the characteristics of the network architecture integrated with mobile edge computing (MEC) and software-defined networks (SDN), the user's moving path can be predicted in advance to speed up the handover process. Most importantly, the proposed scheme can perform secure, efficient and flexible mutual authentication and key agreement between the group and the core network by using aggregated message authentication codes with detecting functionality (AMAD) and contributory broadcast encryption technique. Through the use of BAN Logic and Scyther tool verification, the proposed scheme can not only realize multiple user authentication and key agreement, but also fulfill various security goals. Performance evaluations demonstrate that the proposed scheme has moderate computational and communication overhead, and lower transmission overhead compared with existing schemes, which can effectively reduce authentication delay. Chengzhe Lai, Rongxing Lu, Yinghui Zhang 0002, Dong Zheng 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | pdRide: Privacy-Preserving Distributed Online Ride-Hailing Matching SchemeabstractPrivacy-preserving online ride-hailing (ORH) service enables riders and drivers to conveniently establish optimized ride-hailing through mobile applications without disclosing their location information. In order to alleviate the load of central server and unnecessary increased response latency caused by centralized schemes, we investigate the privacy-preserving ORH matching service in distributed deployment environment. In this paper, we first design three secure outsourced calculation protocols based on Distributed Two-Trapdoor Public-Key Cryptosystem (DT-PKC), including ciphertext packing, blinding and decryption protocol across domains (CPBD), secure Euclidean square distance calculation protocol across domains (SESDC) and secure minimum distance selection protocol (SMDS). Then, we apply the protocols to construct a privacy-preserving distributed ORH matching scheme named pdRide. Geographically distributed road-side unit (RSU) and computation service provider (CSP) collaborate to securely select the matching driver for the requesting rider within a range. Specifically, SESDC can effective calculate the Euclidean square distances between multiple drivers and requesting rider over the encrypted location information with different keys. SMDS can select the driver with the minimum distance for the requesting rider on the encrypted distances. Finally, experiment results demonstrate its effectiveness in terms of communication overhead, computation overhead and transmission latency. Qian Wang 0033, Chengzhe Lai, Dong Zheng 0001 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | Achieving Efficient and Secure Query in Blockchain-based Traceability SystemsabstractWith the rapid development of blockchain technology, it provides a new technical solution for secure storage of data and trusted computing. However, in the actual application of data traceability, blockchain technology has an obvious disadvantage: the large amount of data stored in the blockchain system will lead to a long response time for users to query data. Higher query delay severely restricts the development of block chain technology in the traceability system. In order to solve this problem, we propose an efficient, secure and low storage overhead blockchain query scheme. Specifically, we design an index structure independent of Merkle tree to support efficient intra-block query, and create new fields in the block header to optimize inter-block query. Compared with several existing schemes, our scheme ensures the security of data. Finally, we simulate and evaluate our proposed scheme. The results show that the proposed scheme has better execution efficiency while reducing additional overhead. Chengzhe Lai, Yinzhen Wang |
PST | 1 |
| 2022 | Secure medical data sharing scheme based on traceable ring signature and blockchain
Chengzhe Lai, Rui Guo 0005, Dong Zheng 0001 |
Peer-to-Peer Netw. Appl. | 1 |
| 2021 | Group-based Handover Authentication for Space-Air-Ground Integrated Vehicular NetworksabstractSpace-air-ground integrated vehicular networks (SAGIVN) integrate satellite networks, aerial networks (UAVs) and vehicular networks into a complete network system, which has been attracting a lot of attention and exploration. SAGIVN can make vehicular platoon to keep connected and accessing the network of some areas with lack of infrastructure. However, satellites, UAVs and vehicular platoon accessing the SAGIVN will bring a huge security and efficiency challenges. In this paper, we propose an efficient and secure handover authentication scheme, along with the batch verification mechanism, for vehicular platoon in SAGIVN. The proposed scheme can enhance handover efficiency when vehicular platoon switches from the current UAV to the new UAV. Finally, the security analysis shows that our scheme can satisfy a variety of security requirements. The performance evaluation shows that our scheme has a better effect on both signaling overhead and handover latency than existing schemes. Chengzhe Lai |
ICC | 1 |
| 2021 | SRSP: A Secure and Reliable Smart Parking Scheme With Dual Privacy PreservationabstractFinding an empty parking lot in a downtown or busy area is difficult and time consuming. Smart parking services enable vehicles to obtain real-time parking information, which has great potential to mitigate the parking problem. Compared with the existing parking methods, the cooperative parking information sharing based on vehicular crowdsourcing has lower cost and higher accuracy. However, vehicles face the threat of identity and trajectory privacy leakage. In order to provide secure and reliable parking service, we propose a secure and reliable smart parking scheme (SRSP) with dual privacy preservation. Specifically, a novel group signature technique can be equipped to achieve anonymous authentication among vehicles, parking server, and fog node. Meanwhile, the mix zone method combined with differential privacy can be utilized to hide the vehicles' trajectory. Moreover, message-lock encryption technique enables fog node to detect and delete duplicated reports to reduce the computational overhead of parking server. An incentive mechanism is proposed, which can not only reward contributing vehicles but also prevent the same vehicle from getting multiple rewards. In addition, the trust model is designed to evaluate the reliability of vehicles based on direct trust and recommendation trust. Finally, security analysis demonstrates that SRSP can achieve security objectives. Performance evaluation shows that SRSP has lower computational overhead compared with the existing schemes. Chengzhe Lai, Qian Li 0054, Dong Zheng 0001 |
IEEE Internet Things J. | 1 |
| 2021 | A trust-based privacy-preserving friend matching scheme in social Internet of Vehicles
Chengzhe Lai, Yangyang Du, Qili Guo, Dong Zheng 0001 |
Peer-to-Peer Netw. Appl. | 1 |
| 2020 | A Bilingual Multi-type Spam Detection Model Based on M-BERTabstractSpam has harassed Internet users for a long time, and how to detect spam accurately and efficiently is a critical problem. As yet, there are lots of research works proposed to detect spam, e.g., black and white lists, machine learning methods, and deep learning content-level measures, etc. Based on previous works, we find that most of methods' accuracy can reach 0.95 when they focus on one type and one language spam. Nevertheless, nowadays, people will receive spam messages of different types, different sources, and even different languages. Toward this, we develop a novel model, which is based on Google multilingual bidirectional encoder representations from transformers (M-BERT). Meanwhile, we design a brand new bilingual multi-type spam dataset to train our model. Particularly, we utilize optical character recognition (OCR) to extract text from image-based spam. Through the experiment, we find that the proposed model's accuracy can reach 0.9648, which outperforms the comparison models. In terms of time overhead, the proposed model only costs 0.3168 seconds per training step, which is an acceptable overhead. Therefore, these analysis results demonstrate that our approach can detect bilingual multi-type spam effectively. Jie Cao 0009, Chengzhe Lai |
GLOBECOM | 2 |
| 2020 | SPIR: A Secure and Privacy-Preserving Incentive Scheme for Reliable Real-Time Map UpdatesabstractThe high-precision maps can provide additional information on roads and conditions, which plays an important role in autonomous vehicles (AVs) navigation. Compared with the existing map update methods, the real-time map updates based on crowdsensing have lower cost and higher accuracy. However, in the process of map update, the map service platform (MSP) cannot recruit enough vehicle users to obtain the sensing data due to a lack of incentive mechanism. Therefore, how to motivate more vehicle users to provide high-quality sensing data is the key for real-time map updates. In this article, we propose a secure and privacy-preserving incentive scheme for reliable real-time map updates, named SPIR. Specifically, under the condition of limited service platform budget and limited vehicle user's ability, an effective incentive mechanism based on reverse auction is presented, which can solve two core problems: i.e., payment control for MSP and completion quality for vehicle users. Meanwhile, a credit management and payment system based on the blockchain technique are designed. In addition, the partially blind signature technique is applied to guarantee the security of the incentive mechanism and protect the privacy of vehicle users. Both theoretical analysis and simulation results indicate that the proposed SPIR achieves near-optimal benefits, which can provide the fair reward for vehicle users and reasonable budget for the MSP. In the real-time map update services, SPIR can guarantee the computational efficiency and data reliability. Chengzhe Lai, Jie Cao 0009, Dong Zheng 0001 |
IEEE Internet Things J. | 1 |
| 2020 | A provably secure aggregate authentication scheme for unmanned aerial vehicle cluster networks
Hong Wang 0017, Chengzhe Lai |
Peer-to-Peer Netw. Appl. | 3 |
| 2018 | SEIP: Secure and seamless IP communications for group-oriented machine to machine communications
Chengzhe Lai, Dong Zheng 0001 |
Peer-to-Peer Netw. Appl. | 1 |
| 2018 | The Improved Hill Encryption Algorithm towards the Unmanned Surface Vessel Video Monitoring System Based on Internet of Things TechnologyabstractDepending on the actual demand of maritime security, this paper analyzes the specific requirements of video encryption algorithm for maritime monitoring system. Based on the technology of Internet of things, the intelligent monitoring system of unmanned surface vessels (USV) is designed and realized, and the security technology and network technology of the Internet of things are adopted. The USV are utilized to monitor and collect information on the sea, which is critical to maritime security. Once the video data were captured by pirates and criminals during the transmission, the security of the sea will be affected awfully. The shortcomings of traditional algorithms are as follows: the encryption degree is not high, computing cost is expensive, and video data is intercepted and captured easily during the transmission process. In order to overcome the disadvantages, a novel encryption algorithm, i.e., the improved Hill encryption algorithm, is proposed to deal with the security problems of the unmanned video monitoring system in this paper. Specifically, the Hill algorithm of classical cryptography is transplanted into image encryption, using an invertible matrix as the key to realize the encryption of image matrix. The improved Hill encryption algorithm combines with the process of video compression and regulates the parameters of the encryption process according to the content of the video image and overcomes the disadvantages that exist in the traditional encryption algorithm and decreases the computation time of the inverse matrix so that the comprehensive performance of the algorithm is optimal with different image information. Experiments results validate the favorable performance of the proposed improved encryption algorithm. Tingting Yang 0001, Chengzhe Lai, Minghua Xia |
Wirel. Commun. Mob. Comput. | 3 |
| 2017 | Achieving Secure and Seamless IP Communications for Group-Oriented Software Defined Vehicular Networks
Chengzhe Lai, Rongxing Lu, Dong Zheng 0001 |
WASA | 1 |
| 2017 | SIRC: A Secure Incentive Scheme for Reliable Cooperative Downloading in Highway VANETsabstractIn this paper, we propose a secure incentive scheme to achieve fair and reliable cooperative (SIRC) downloading in highway vehicular ad hoc networks (VANETs). SIRC can stimulate vehicle users to help download-and-forward packets for each other and consists of cooperative downloading and forwarding phase. During the cooperative downloading phase, SIRC utilizes “virtual checks” associated with the designated verifier signature to ensure fair and secure cooperation. Meanwhile, to minimize the payment risk of the client vehicle, partial prepayment strategy is adopted, i.e., the vehicles involved in downloading packets can only obtain part of the check before the client vehicle confirms the packet reception. During the cooperative forwarding phase, a profit-sharing model associated with an aggregating Camenisch-Lysyanskaya (CL) signature can stimulate cooperation and reduce the authentication overhead. In addition, we develop a reputation system to encourage cooperation and punish malicious vehicles. The aggregating CL signature and the symmetric cryptosystem are applied to resist various attacks, including injection/removing attack, free riding attack, submission refusal attack, and denial of service attacks. Extensive simulation results are given to show that the proposed SIRC can achieve a high download success rate and low average download delay with moderate cryptographic computation and communication overhead. Chengzhe Lai, Kuan Zhang 0001, Nan Cheng 0001, Hui Li 0006, Xuemin Shen |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2016 | GLARM: Group-based lightweight authentication scheme for resource-constrained machine to machine communications
Chengzhe Lai, Rongxing Lu, Dong Zheng 0001, Hui Li 0006, Xuemin Shen |
Comput. Networks | 1 |
| 2016 | Optimal Workload Allocation in Fog-Cloud Computing Toward Balanced Delay and Power ConsumptionabstractMobile users typically have high demand on localized and location-based information services. To always retrieve the localized data from the remote cloud, however, tends to be inefficient, which motivates fog computing. The fog computing, also known as edge computing, extends cloud computing by deploying localized computing facilities at the premise of users, which prestores cloud data and distributes to mobile users with fast-rate local connections. As such, fog computing introduces an intermediate fog layer between mobile users and cloud, and complements cloud computing toward low-latency high-rate services to mobile users. In this fundamental framework, it is important to study the interplay and cooperation between the edge (fog) and the core (cloud). In this paper, the tradeoff between power consumption and transmission delay in the fog-cloud computing system is investigated. We formulate a workload allocation problem which suggests the optimal workload allocations between fog and cloud toward the minimal power consumption with the constrained service delay. The problem is then tackled using an approximate approach by decomposing the primal problem into three subproblems of corresponding subsystems, which can be, respectively, solved. Finally, based on simulations and numerical results, we show that by sacrificing modest computation resources to save communication bandwidth and reduce transmission latency, fog computing can significantly improve the performance of cloud computing. Ruilong Deng, Rongxing Lu, Chengzhe Lai, Tom H. Luan, Hao Liang 0002 |
IEEE Internet Things J. | 3 |
| 2016 | SPGS: a secure and privacy-preserving group setup framework for platoon-based vehicular cyber-physical systemsabstractRecently, the platoon-based vehicular cyber-physical system (VCPS) has attracted significant attention because the platoon based driving pattern can bring many benefits. In the platoon-based VCPS, the platoon members may change quite dynamically because vehicles can join or leave the platoon at any time. Therefore, how to securely and efficiently set up and maintain a platoon is a challenge. To address this issue, in this paper, we propose a secure and privacy-preserving group setup framework, called SPGS, for platoon-based VCPS. The key components of SPGS are two group setup policies that can be developed based on two kinds of techniques: attribute-based encryption and contributory key agreement. Based on these group setup policies, we propose two authentication protocols, respectively. The first one can authenticate all vehicles in the platoon simultaneously. The second one can guarantee anonymous authentication with traceability. With SPGS, a temporary platoon can be securely set up and maintained, and platoon merging/splitting can also be flexibly supported. Finally, we carry out extensive analysis to show the security and efficiency of our proposed SPGS. Copyright © 2016 John Wiley & Sons, Ltd. Chengzhe Lai, Rongxing Lu, Dong Zheng 0001 |
Secur. Commun. Networks | 1 |
| 2016 | Secure machine-type communications in LTE networksabstractAbstract With a great variety of potential applications, machine‐type communications (MTC) is gaining a tremendous interest from mobile network operators and research groups. MTC is standardized by the 3rd Generation Partnership Project (3GPP), which has been regarded as the promising solution facilitating machine‐to‐machine communications. In the latest standard, 3GPP proposes a novel architecture for MTC, in which the MTC server is located outside the operator domain. However, the connection between the 3GPP core network and MTC server in this scenario is insecure; consequently, there are distrustful relationships among MTC device, core network, and MTC server. If the security issue is not well addressed, all applications involved in MTC cannot be put into the market. To address this problem, we propose an end‐to‐end security scheme for MTC based on the proxy‐signature technique, called E2SEC. Specifically, both the MTC device and MTC server can establish strong trustful relationships with each other by using the proxy signatures issued by the 3GPP core network. Moreover, we present some implementation considerations of E2SEC and analyze the performance during authentication by comparing the operational cost of three cases that apply three different signature algorithms, that is, ElGamal, Schnorr, and DSA. Through security analysis by using Automatic Cryptographic Protocol Verifier (ProVerif), we conclude that the proposed E2SEC scheme can achieve the security goals and prevent various security threats. Copyright © 2015 John Wiley & Sons, Ltd. Chengzhe Lai, Rongxing Lu, Hui Li 0006, Dong Zheng 0001, Xuemin Shen |
Wirel. Commun. Mob. Comput. | 1 |
| 2015 | Towards power consumption-delay tradeoff by workload allocation in cloud-fog computingabstractFog computing, characterized by extending cloud computing to the edge of the network, has recently received considerable attention. The fog is not a substitute but a powerful complement to the cloud. It is worthy of studying the interplay and cooperation between the edge (fog) and the core (cloud). To address this issue, we study the tradeoff between power consumption and delay in a cloud-fog computing system. Specifically, we first mathematically formulate the workload allocation problem. After that, we develop an approximate solution to decompose the primal problem into three subproblems of corresponding subsystems, which can be independently solved. Finally, based on extensive simulations and numerical results, we show that by sacrificing modest computation resources to save communication bandwidth and reduce transmission latency, fog computing can significantly improve the performance of cloud computing. Ruilong Deng, Rongxing Lu, Chengzhe Lai, Tom H. Luan |
ICC | 3 |
| 2015 | SGSA: Secure Group Setup and Anonymous Authentication in Platoon-Based Vehicular Cyber-Physical Systems
Chengzhe Lai, Rongxing Lu, Dong Zheng 0001 |
WASA | 1 |
| 2015 | EAPSG: Efficient authentication protocol for secure group communications in maritime wideband communication networks
Tingting Yang 0001, Chengzhe Lai, Rongxing Lu, Rong Jiang 0001 |
Peer-to-Peer Netw. Appl. | 2 |
| 2015 | Efficient self-healing group key management with dynamic revocation and collusion resistance for SCADA in smart gridabstractAbstract In this paper, in order to simultaneously resolve the transmission security and availability in Supervisory Control And Data Acquisition (SCADA) group communications, we propose a robust and efficient group key management scheme, called LiSH+, which is characterized by developing a secure self‐healing mechanism witht‐revocation and collusion resistance capability. A dual direction hash chain is utilized to guarantee the backward secrecy and forward secrecy of group key. A novel self‐healing mechanism is constructed to ensure availability of the group member in case of devices failure and prevent the collusive users from exploiting the group key in the proposed scheme. In addition, the compromised users can be revoked from the group dynamically by broadcasting message. Detailed security analysis shows that the proposed LiSH+ scheme meets the requirements of group communication and is secure in terms oftuser collusion‐free. Performance evaluation also demonstrates its efficiency in terms of low storage requirement and communication overheads. Copyright © 2014 John Wiley & Sons, Ltd. Rong Jiang 0001, Rongxing Lu, Jun Luo 0011, Chengzhe Lai, Xuemin Shen |
Secur. Commun. Networks | 4 |
| 2014 | SEGR: A secure and efficient group roaming scheme for machine to machine communications between 3GPP and WiMAX networksabstractWith extensive promising applications, machine to machine (M2M) communications or machine-type communication (MTC) have attached a tremendous interest among mobile network operators and research groups. Supporting multiple MTC devices has been considered as an essential requirement in M2M communications. How to achieve a secure and efficient access authentication for a group of MTC devices during roaming is a challenging issue. In this paper, in order to simultaneously resolve the access security and efficiency in MTC, we propose a secure and efficient group roaming scheme for MTC between 3GPP and WiMAX networks, named SEGR, which is characterized by authenticating all MTC devices in a group simultaneously and speeding up the process of authentication through adopting a novel certificateless aggregate signature technique. Through security analysis, the proposed SEGR can provide robust security, especially overcome the drawback of key escrow in identity-based (ID-based) aggregate signature schemes. In addition, performance evaluations in terms of communication overhead and computation complexity demonstrate that SEGR is more efficient than those traditional schemes. Chengzhe Lai, Hui Li 0006, Rongxing Lu, Rong Jiang 0001, Xuemin Shen |
ICC | 1 |
| 2014 | CPAL: A Conditional Privacy-Preserving Authentication With Access Linkability for Roaming ServiceabstractThe roaming service enables mobile subscribers to access the internet service anytime and anywhere, which can fulfill the requirement of ubiquitous access for the emerging paradigm of networking, e.g., the Internet of Things (IoT). In this paper, we propose a conditional privacy-preserving authentication with access linkability (CPAL) for roaming service, to provide universal secure roaming service and multilevel privacy preservation. CPAL provides an anonymous user linking function by utilizing a novel group signature technique, which can not only efficiently hide users’ identities but also enables the authorized entities to link all the access information of the same user without knowing the user’s real identity. Specifically, by using the master linking key possessed by the trust linking server, the authorized foreign network operators or service providers can link the access information from the user to improve its service, while preserving user anonymity, e.g., using individual access information to analyze user preferences without revealing user’s identity. Furthermore, the subscribers can also use this functionality to anonymously query their usage of service. In addition, CPAL has an efficient revocation function, which revokes a group of users at the same time. Through extensive analysis, we demonstrate that CPAL resists various security threats and provides more flexible privacy preservation compared to the existing schemes. Meanwhile, performance evaluations demonstrate its efficiency in terms of communication and computation overhead. Chengzhe Lai, Hui Li 0006, Xiaohui Liang 0002, Rongxing Lu, Kuan Zhang 0001, Xuemin Shen |
IEEE Internet Things J. | 1 |
| 2013 | Robust group key management with revocation and collusion resistance for SCADA in smart gridabstractSupevisory Control And Data Acquisition (SCADA) systems are vital for operation and control of critical infrastructures in smart grid. Availability is one of the most important security objectives in SCADA communications, unavailability of which may further undermine the power delivery, and a reliable key management is essential to address this problem. In this paper, in order to simultaneously resolve the transmission security and availability in SCADA group communications, we propose a robust and efficient group key management scheme, called LiSH, which is characterized by developing a secure self-healing mechanism with t-revocation capability using one-way function to protect current session keys from being attacked by intruders. Detailed security analysis shows that the proposed LiSH scheme is secure in terms of collusion-free, and t-wise forward and backward security. In addition, performance evaluation also demonstrates its efficiency in terms of low storage and communication overheads. Rong Jiang 0001, Rongxing Lu, Chengzhe Lai, Jun Luo 0011, Xuemin Shen |
GLOBECOM | 3 |
| 2013 | LGTH: A lightweight group authentication protocol for machine-type communication in LTE networksabstractSupporting a massive number of machine-type communication (MTC) devices has been considered as an essential requirement in machine to machine (M2M) communications. Meanwhile, cyber security is of paramount importance in MTC; if MTC devices cannot securely access the networks through efficient authentication, all applications involving MTC cannot be widely accepted. One of research challenges in MTC is group authentication. A large number of MTC devices accessing the network simultaneously will cause a severe authentication signaling congestion. To solve this problem and reduce authentication overhead of the previous schemes based on public key cryptosystems, we propose a novel lightweight group authentication protocol for MTC in the long term evolution (LTE) networks based on aggregate message authentication codes (MACs), called LGTH, which can not only authenticate all MTC devices simultaneously, but also minimize the authentication overhead. Through security analysis, we conclude that the proposed LGTH can provide robust security, and avoid the authentication signaling congestion in the LTE networks. In addition, performance evaluations in terms of communication and computation overhead demonstrate that LGTH is more efficient than previous schemes. Chengzhe Lai, Hui Li 0006, Rongxing Lu, Rong Jiang 0001, Xuemin Shen |
GLOBECOM | 1 |
| 2013 | SE-AKA: A secure and efficient group authentication and key agreement protocol for LTE networks
Chengzhe Lai, Hui Li 0006, Rongxing Lu, Xuemin Shen |
Comput. Networks | 1 |
| 2012 | A simple and robust handover authentication between HeNB and eNB in LTE networks
Jin Cao 0001, Hui Li 0006, Maode Ma, Yueyu Zhang, Chengzhe Lai |
Comput. Networks | 5 |