VLDB 2026 Research / reviewers in the wild / expert
Zhen Liu 0008
dblp:77/35-8
· DBLP profile ↗
45ranked-venue papers
13as first author
18since 2021 · last 2025
0000-0001-9268-702XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 35 · 11 first-author · 14 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Systems, architecture and hardware · 1Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The Philosopher's Stone: Trojaning Plugins of Large Language Models
Tian Dong 0003, Minhui Xue 0001, Guoxing Chen, Rayne Holland, Yan Meng 0001, Shaofeng Li 0001, Zhen Liu 0008, Haojin Zhu |
NDSS | 7 |
| 2025 | Depth Gives a False Sense of Privacy: LLM Internal States Inversion
Tian Dong 0003, Yan Meng 0001, Shaofeng Li 0001, Guoxing Chen, Zhen Liu 0008, Haojin Zhu |
USENIX Security Symposium | 5 |
| 2025 | MVOC: A Lighter Multi-Client Verifiable Outsourced Computation for Malicious Lightweight ClientsabstractGordon et al. systematically studied the Universally Composable (UC) security of Multi-client Verifiable Computation (MVC), in which a set of computationally-weak clients delegate the computation of a general function to an untrusted server based on their private inputs, and proposed a UC-secure scheme ensuring that the protocol remains secure even when arbitrarily composed with other UC-secure instances. However, this scheme imposed a significant computational overhead on clients due to the utilization of fully homomorphic encryption, and the plaintext size scaled linearly with function input size. In this work, we present MVOC, a more efficient UC-secure MVC protocol, that significantly reduces the amortized overhead for clients in both semi-honest and malicious settings, by delegating a larger portion of the computation to the server. We enable clients to verify the garbled circuit before entering the online phase, ensuring security against malicious clients without incurring heavy overhead of compiling a semi-honest protocol into a malicious one. We present the detailed proof and analyze the theoretical complexity of MVOC. Furthermore, we implement our protocol and evaluate the performance, and the results demonstrate that the computation and communication overheads during the input phase can be decreased by at least 95.55% and 87.17%, respectively. Zhenfu Cao, Zhen Liu 0008, Kaitai Liang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | HDWSA$^{2}$2: A Secure Hierarchical Deterministic Wallet Supporting Stealth Address and Signature AggregationabstractHierarchical Deterministic Wallet (HDW) and Stealth Address (SA) are widely used in cryptocurrency communities due to their functionality and security. In the preliminary version of this work (ESORICS 2022), we formally define the syntax and security models of Hierarchical Deterministic Wallet supporting Stealth Address (HDWSA), capturing the functionality and security requirements imposed by the practice in cryptocurrency. We propose a concrete HDWSA construction and prove its security in the random oracle model. Note that when applied in blockchain, in practice, signature aggregation could reduce the cost of computation, storage, and communication dramatically. In this full version, we develop HDWSA definition to further support signature aggregation (referred to as HDWSA$^{2}$). In particular, we first formally define HDWSA$^{2}$, which, besides enjoying all the virtues of HDWSA on functionality and security, allows multiple signatures on different messages to be aggregated into one signature. We propose a concrete HDWSA$^{2}$construction and prove its security in the random oracle model. We implement the HDWSA$^{2}$construction and the experimental results show that verification of an aggregate signature is about 13$\boldsymbol{\times }$faster than sequential verification of all the individual signatures. We can reduce the size of signatures in a single block by about 60% after aggregation. Zhen Liu 0008, Guomin Yang, Guoxing Chen, Haojin Zhu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Forward-Secure Hierarchical Delegable Signature for Smart HomesabstractAiming to provide people with great convenience and comfort, smart home systems have been deployed in thousands of homes. In this paper, we focus on handling the security and privacy issues in such a promising system by customizing a new cryptographic primitive to provide the following security guarantees: 1) fine-grained, privacy-preserving authorization for smart home users and integrity protection of communication contents; 2) flexible self-sovereign permission delegation; 3) forward security of previous messages. To our knowledge, no previous system has been designed to consider these three security and privacy requirements simultaneously. To tackle these challenges, we put forward the first-ever efficient cryptographic primitive called the Forward-secure Hierarchical Delegable Signature (FS-HDS) scheme for smart homes. Specifically, we first propose a new primitive, efficient Hierarchical Delegable Signature (HDS) scheme, which is capable of supporting partial delegation capability while realizing privacy-preserving authorization and integrity guarantee. Then, we present an FS-HDS for smart homes with the efficient HDS as the underlying building block, which not only inherits all the desirable features of HDS but also ensures that the past content integrity is not affected even if the current secret key is compromised. We provide comprehensively strict security proofs to prove the security of our proposed solutions. Its performance is also validated via experimental simulations to showcase its practicability and effectiveness. Jianfei Sun, Guowen Xu, Yang Yang 0026, Xuehuan Yang, Xiaoguo Li, Cong Wu 0003, Zhen Liu 0008, Guomin Yang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | Linkable ring signature scheme with stronger security guarantees
Mingxing Hu, Zhen Liu 0008, Xiaojun Ren, Yunhong Zhou |
Inf. Sci. | 2 |
| 2024 | A secure hierarchical deterministic wallet with stealth address from lattices
Zhen Liu 0008 |
Theor. Comput. Sci. | 2 |
| 2023 | Universally Composable Key-Insulated and Privacy-Preserving Signature Scheme with Publicly Derived Public Key
Chunping Zhu, Zhen Liu 0008 |
Inscrypt (1) | 3 |
| 2023 | RAI2: Responsible Identity Audit Governing the Artificial Intelligence
Tian Dong 0003, Shaofeng Li 0001, Guoxing Chen, Minhui Xue 0001, Haojin Zhu, Zhen Liu 0008 |
NDSS | 6 |
| 2023 | An Improved Lattice-Based Ring Signature With Unclaimable Anonymity in the Standard ModelabstractAbstract Ring signatures enable a user to sign messages on behalf of an arbitrary set of users, called the ring, without revealing exactly which member of that ring actually generated the signature. The signer-anonymity property makes ring signatures have been an active research topic. Recently, Park and Sealfon (PS; CRYPTO’19) presented an important anonymity notion named signer-unclaimability and constructed a lattice-based ring signature scheme with unclaimable anonymity in the standard model; however, it did not consider the unforgeable w.r.t. adversarially chosen-key attack (the public key ring of a signature may contain keys created by an adversary) and the signature size grows quadratically in the size of ring and message. In this work, we propose a new lattice-based ring signature scheme with unclaimable anonymity in the standard model. In particular, our work improves the security and efficiency of PS work, which is unforgeable w.r.t. adversarially chosen-key attack, and the ring signature size grows linearly in the ring size. Mingxing Hu, Weijiong Zhang, Zhen Liu 0008 |
Comput. J. | 3 |
| 2022 | DeChain: A Blockchain Framework Enhancing Decentralization via Sharding
Shenwei Chen, Zhen Liu 0008, Yu Long 0001, Dawu Gu |
ACISP | 2 |
| 2022 | MixCT: Mixing Confidential Transactions from Homomorphic Commitment
Jiajun Du, Zhonghui Ge, Yu Long 0001, Zhen Liu 0008, Shifeng Sun 0001, Xian Xu 0001, Dawu Gu |
ESORICS (3) | 4 |
| 2022 | Lighter is Better: A Lighter Multi-client Verifiable Outsourced Computation with Hybrid Homomorphic Encryption
Zhenfu Cao, Zhen Liu 0008, Kaitai Liang |
ESORICS (2) | 3 |
| 2022 | Secure Hierarchical Deterministic Wallet Supporting Stealth Address
Zhen Liu 0008, Guomin Yang, Guoxing Chen, Haojin Zhu |
ESORICS (1) | 2 |
| 2022 | Secure Deterministic Wallet and Stealth Address: Key-Insulated and Privacy-Preserving Signature Scheme With Publicly Derived Public KeyabstractDeterministic Wallet (DW) and Stealth Address (SA) mechanisms have been widely adopted in the cryptocurrency community, due to their virtues on functionality and privacy protection, which come from a key derivation mechanism that allows an arbitrary number of derived keys to be generated from a master key. However, these algorithms suffer a vulnerability that, when one derived key is compromised somehow, the damage is not limited to the leaked derived key only, but to the master key and in consequence all derived keys are compromised. In this article, we introduce and formalize a new signature variant, called Key-Insulated and Privacy-Preserving Signature Scheme with Publicly Derived Public Key (PDPKS), which fully captures and improves the functionality, security, and privacy requirements of DW and SA. We propose a PDPKS construction and prove its security and privacy in the random oracle model. Furthermore, we implement the construction with parameters for 128-bit security, and the results show that it is practically efficient for the setting of cryptocurrencies. With its solid guarantee on functionality, security and privacy, as well as its practical efficiency, our PDPKS construction provides a practical cryptographic tool that refines DW and SA, without security vulnerability. Zhen Liu 0008, Guomin Yang, Duncan S. Wong, Khoa Nguyen 0002, Huaxiong Wang, Xiaorong Ke |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Fully Secure Lattice-Based ABE from Noisy Linear Functional Encryption
Zhen Liu 0008, Dawu Gu |
Inscrypt | 3 |
| 2021 | MPC-in-Multi-Heads: A Multi-Prover Zero-Knowledge Proof System - (or: How to Jointly Prove Any NP Statements in ZK)
Hongrui Cui, Kaiyi Zhang 0001, Yu Chen 0003, Zhen Liu 0008, Yu Yu 0001 |
ESORICS (2) | 4 |
| 2021 | On Enabling Attribute-Based Encryption to Be Traceable Against TraitorsabstractAbstract Attribute-based encryption (ABE) is a versatile one-to-many encryption primitive, which enables fine-grained access control over encrypted data. Due to its promising applications in practice, ABE schemes with high efficiency, security and expressivity have been continuously emerging. On the other hand, due to the nature of ABE, a malicious user may abuse its decryption privilege. Therefore, being able to identify such a malicious user is crucial towards the practicality of ABE. Although some specific ABE schemes in the literature enjoys the tracing function, they are only proceeded case by case. Most of the ABE schemes do not support traceability. It is thus meaningful and important to have a generic way of equipping any ABE scheme with traceability. In this work, we partially solve the aforementioned problem. Namely, we propose a way of transforming (non-traceable) ABE schemes satisfying certain requirements to fully collusion-resistant black-box traceable ABE schemes, which adds only $O(\sqrt{\mathcal{K}})$ elements to the ciphertext where ${\mathcal{K}}$ is the number of users in the system. And to demonstrate the practicability of our transformation, we show how to convert a couple of existing non-traceable ABE schemes to support traceability. Zhen Liu 0008, Qiong Huang 0001, Duncan S. Wong |
Comput. J. | 1 |
| 2020 | A Lattice-Based Key-Insulated and Privacy-Preserving Signature Scheme with Publicly Derived Public Key
Wenling Liu, Zhen Liu 0008, Khoa Nguyen 0002, Guomin Yang, Yu Yu 0001 |
ESORICS (2) | 2 |
| 2019 | A Lattice-Based Linkable Ring Signature Supporting Stealth Addresses
Zhen Liu 0008, Khoa Nguyen 0002, Guomin Yang, Huaxiong Wang, Duncan S. Wong |
ESORICS (1) | 1 |
| 2019 | Key-Insulated and Privacy-Preserving Signature Scheme with Publicly Derived Public KeyabstractSince the introduction of Bitcoin in 2008, cryptocurrency has been undergoing a quick and explosive development. At the same time, privacy protection, one of the key merits of cryptocurrency, has attracted much attention by the community. A deterministic wallet algorithm and a stealth address algorithm have been widely adopted in the community, due to their virtues on functionality and privacy protection, which come from a key derivation mechanism that an arbitrary number of derived keys can be generated from a master key. However, these algorithms suffer a vulnerability. In particular, when a minor fault happens (say, one derived key is compromised somehow), the damage is not limited to the leaked derived key only, instead, it spreads to the master key and all derived keys are compromised. In this paper, to provide a formal treatment for the problem, we introduce and formalize a new signature variant, called Key-Insulated and Privacy-Preserving Signature Scheme with Publicly Derived Public Key (PDPKS), which forms a convenient and robust cryptographic tool for offering the virtues of deterministic wallet and stealth address, while eliminating the security vulnerabilities. Specifically, PDPKS allows anyone to derive new signature verification keys for a user, say Alice, based on her long-term public key, while only Alice can derive the signing keys corresponding to those verification keys. In terms of privacy, given a derived verification key and valid signatures with respect to it, an adversary is not able to tell which long-term public key, out of a set of known long-term public keys, is the one from which the verification key was derived. A distinguishing security feature of PDPKS, with the above functionality and privacy features, is that the derived keys are independent/insulated from each other, namely, compromising the signing key associated with a verification key does not allow an adversary to forge a valid signature for another verification key, even if both verification keys are derived from the same long-term public key. We formalize the notion of PDPKS and propose a practical and proven secure construction, which could be a convenient and secure cryptographic tool for building privacy-preserving cryptocurrencies and supporting promising use cases in practice, as it can be used to implement secure stealth addresses, and can be used to implement deterministic wallets and the related appealing use cases, without security concerns. Zhen Liu 0008, Guomin Yang, Duncan S. Wong, Khoa Nguyen 0002, Huaxiong Wang |
EuroS&P | 1 |
| 2019 | Ciphertext Policy Attribute-Based Encryption for Circuits from LWE Assumption
Zhen Liu 0008, Dawu Gu |
ICICS | 2 |
| 2019 | Gnocchi: Multiplexed Payment Channels for Cryptocurrencies
Shuyang Tang, Zhonghui Ge, Zhiqiang Liu 0001, Yu Long 0001, Zhen Liu 0008, Dawu Gu |
NSS | 6 |
| 2019 | A Practical Dynamic Enhanced BFT Protocol
Yu Long 0001, Zhen Liu 0008, Zhiqiang Liu 0001, Dawu Gu |
NSS | 3 |
| 2019 | TumbleBit++: A Comprehensive Privacy Protocol Providing Anonymity and Amount-Invisibility
Zhen Liu 0008, Yu Long 0001, Zhiqiang Liu 0001, Dawu Gu, Fei Huan, Yanxue Jia |
ProvSec | 2 |
| 2019 | Towards a Multi-chain Future of Proof-of-Space
Shuyang Tang, Jilai Zheng, Zhiqiang Liu 0001, Dawu Gu, Zhen Liu 0008, Yu Long 0001 |
SecureComm (1) | 7 |
| 2019 | All-But-Many Lossy Trapdoor Functions under Decisional RSA Subgroup Assumption and ApplicationabstractAbstract Lossy trapdoor functions (LTDFs) were introduced by Peikert and Waters (STOC 2008) and have a number of applications in cryptography. All-but-many lossy trapdoor functions (ABM-LTDFs) are generalizations of LTDFs studied by Hofheinz (Eurocrypt 2012). Specially, using ABM-LTDFs to construct public key encryption (PKE) scheme with selective opening security has been proven feasible. Existing ABM-LTDFs were built on pairings, lattices and decisional composite residuosity (DCR) assumption. However, pairing-based ABM-LTDFs and DCR-based ABM-LTDFs rely on non-standard assumptions. In this paper, we construct an ABM-LTDF under the decisional RSA subgroup (DRSA) assumption, and we employ it to construct PKE scheme with selective opening security. We also propose a construction of DCR-based ABM-LTDF relying on standard assumption in Appendix. Nanyuan Cao, Zhenfu Cao, Zhen Liu 0008, Xiaolei Dong |
Comput. J. | 3 |
| 2019 | Z-Channel: Scalable and efficient scheme in Zerocash
Yuncong Zhang, Yu Long 0001, Zhen Liu 0008, Zhiqiang Liu 0001, Dawu Gu |
Comput. Secur. | 3 |
| 2019 | Fork-free hybrid consensus with flexible Proof-of-Activity
Zhiqiang Liu 0001, Shuyang Tang, Sherman S. M. Chow, Zhen Liu 0008, Yu Long 0001 |
Future Gener. Comput. Syst. | 4 |
| 2019 | Pri-RTB: Privacy-preserving real-time bidding for securing mobile advertisement in ubiquitous computing
Erdong Deng, Fei Guo 0003, Zhen Liu 0008, Haojin Zhu, Zhenfu Cao |
Inf. Sci. | 5 |
| 2018 | Z-Channel: Scalable and Efficient Scheme in Zerocash
Yuncong Zhang, Yu Long 0001, Zhen Liu 0008, Zhiqiang Liu 0001, Dawu Gu |
ACISP | 3 |
| 2018 | Goshawk: A Novel Efficient, Robust and Flexible Blockchain Protocol
Cencen Wan, Shuyang Tang, Yuncong Zhang, Zhiqiang Liu 0001, Yu Long 0001, Zhen Liu 0008, Yu Yu 0001 |
Inscrypt | 7 |
| 2018 | Secure Scheme Against Compromised Hash in Proof-of-Work Blockchain
Fengjun Chen, Zhiqiang Liu 0001, Yu Long 0001, Zhen Liu 0008, Ning Ding 0001 |
NSS | 4 |
| 2017 | Attribute based Encryption: Traitor Tracing, Revocation and Fully Security on Prime Order Groups
Kaitai Liang, Zhen Liu 0008, Duncan S. Wong |
CLOSER | 3 |
| 2016 | Dealerless Corporate Key Generation for Identity-Based Encryption SchemesabstractIn Identity-Based Encryption (IBE) system, the Private Key Generator (PKG) holds the master secret key and is responsible for generating private keys for the users. This incurs the key-escrow problem, i.e. the PKG can decrypt any user' any ciphertexts without any possible detection. Also, compromising the master secret key will enable an adversary to do anything to the whole system, and having the master secret key be unavailable implies that new users cannot obtain private keys from the PKG, and existing users cannot get their private keys back from the PKG when they lost them. To address the key-escrow problem and protect the master secret key as much as possible with strong security and availability, distributed PKG protocols supporting threshold policy have been adopted in some IBE schemes. In this paper, we propose a distributed PKG protocol that supports the policy to be any monotonic access structures. Also, we propose the first distributed PKG protocol that supports the dynamic changes of the PKGs and the policy, while remaining the master secret key unchanged. The two protocols do not need any third party acting as a trusted dealer to present, and the master secret key should never be generated or resided in any one single site. The protocols are applicable to a generic IBE template, which covers many existing important IBE schemes. When applied to this generic type of IBE schemes, the two distributed PKG protocols do not affect the encryption and decryption algorithms, and only each user knows his own private key. Zhen Liu 0008, Duncan S. Wong, Jack Poon |
AsiaCCS | 1 |
| 2016 | Practical Attribute-Based Encryption: Traitor Tracing, Revocation and Large UniverseabstractA blackbox traceable Attribute-Based Encryption (ABE) can identify a malicious user called traitor, which created a decryption box with respect to an attribute set (respectively, access policy), out of all the users who share the same attribute set (respectively, access policy). However, none of the existing traceable ABE schemes can also support revocation and large attribute universe, that is, being able to revoke compromised keys, and can take an exponentially large number of attributes. In this paper, we formalize the definitions and security models, and propose constructions of both Ciphertext-Policy ABE and Key-Policy ABE that support (i) public and fully collusion-resistant blackbox traceability, (ii) revocation, (iii) large universe and (iv) any monotonic access structures as policies (i.e. high expressivity). We also show that the schemes are secure and blackbox traceable in the standard model against selective adversaries. Zhen Liu 0008, Duncan S. Wong |
Comput. J. | 1 |
| 2016 | Identity-based aggregate signcryption in the standard model from multilinear maps
Hao Wang 0007, Zhen Liu 0008, Zhe Liu 0001, Duncan S. Wong |
Frontiers Comput. Sci. | 2 |
| 2015 | Practical Ciphertext-Policy Attribute-Based Encryption: Traitor Tracing, Revocation, and Large Universe
Zhen Liu 0008, Duncan S. Wong |
ACNS | 1 |
| 2015 | Traceable CP-ABE on Prime Order Groups: Fully Secure and Fully Collusion-Resistant Blackbox Traceable
Zhen Liu 0008, Duncan S. Wong |
ICICS | 1 |
| 2015 | Traceable CP-ABE: How to Trace Decryption Devices Found in the WildabstractIn Ciphertext-policy attribute-based encrypt- ion (CP-ABE), ciphertexts are associated with access policies, which do not have to contain the identities of eligible receivers, and attributes are shared by multiple users. CP-ABE is useful for providing fine-grained access control on encrypted data. However, it also has a practicality concern that a malicious user, with his attributes shared with other users, might leak his decryption privilege as a decryption blackbox, for some financial gain or other incentives, as there is little risk of getting caught. There are two types of decryption blackboxes that reflect different practical scenarios. A key-like decryption blackbox is associated with an attribute set SDand can decrypt ciphertexts with access policies satisfied by SD. A policy-specific decryption blackbox is associated with an access policy ADand can decrypt ciphertexts with AD. Policy-specific decryption blackbox has weaker decryption capacity than key-like decryption blackbox, but tracing it is deemed to be more difficult. In the preliminary version (in CCS 2013) of this paper, we proposed a new CP-ABE scheme which is adaptively traceable against key-like decryption blackbox. The scheme has sublinear overhead, which is the most efficient one to date supporting fully collusion-resistant blackbox traceability. The scheme is fully secure in the standard model, and supports any monotonic access structures. In this paper, we further show that the scheme is also selectively traceable against policy-specific decryption blackbox. Furthermore, and more importantly, we prove a general statement that if a CP-ABE scheme is (selectively) traceable against policy-specific decryption blackbox, it is also (selectively) traceable against key-like decryption blackbox, which implies that we now only need to focus on building CP-ABE schemes which are traceable against policy-specific decryption blackbox. Zhen Liu 0008, Zhenfu Cao, Duncan S. Wong |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | Fully Collusion-Resistant Traceable Key-Policy Attribute-Based Encryption with Sub-linear Size Ciphertexts
Zhen Liu 0008, Zhenfu Cao, Duncan S. Wong |
Inscrypt | 1 |
| 2014 | Securely Outsourcing Exponentiations with Single Untrusted Program for Cloud Storage
Qianhong Wu, Duncan S. Wong, Sherman S. M. Chow, Zhen Liu 0008, Xiao Tan 0003 |
ESORICS (1) | 6 |
| 2013 | Blackbox traceable CP-ABE: how to catch people leaking their keys by selling decryption devices on ebayabstractIn the context of Ciphertext-Policy Attribute-Based Encryption (CP-ABE), if a decryption device associated with an attribute set S_D appears on eBay, and is alleged to be able to decrypt any ciphertexts with policies satisfied by S_D, no one including the CP-ABE authorities can identify the malicious user(s) who build such a decryption device using their key(s). This has been known as a major practicality concern in CP-ABE applications, for example, providing fine-grained access control on encrypted data. Due to the nature of CP-ABE, users get decryption keys from authorities associated with attribute sets. If there exists two or more users with attribute sets being the supersets of S_D, existing CP-ABE schemes cannot distinguish which user is the malicious one who builds and sells such a decryption device. In this paper, we extend the notion of CP-ABE to support Blackbox Traceability and propose a concrete scheme which is able to identify a user whose key has been used in building a decryption device from multiple users whose keys associated with the attribute sets which are all the supersets of S_D. The scheme is efficient with sub-linear overhead and when compared with the very recent (non-traceable) CP-ABE scheme due to Lewko and Waters in Crypto 2012, we can consider this new scheme as an extension with the property of fully collusion-resistant blackbox traceability added, i.e. an adversary can access an arbitrary number of keys when building a decryption device while the new tracing algorithm can still identify at least one particular key which must have been used for building the underlying decryption device. We show that this new scheme is secure against adaptive adversaries in the standard model, and is highly expressive by supporting any monotonic access structures. Its additional traceability property is also proven against adaptive adversaries in the standard model. Zhen Liu 0008, Zhenfu Cao, Duncan S. Wong |
CCS | 1 |
| 2013 | White-Box Traceable Ciphertext-Policy Attribute-Based Encryption Supporting Any Monotone Access StructuresabstractIn a ciphertext-policy attribute-based encryption (CP-ABE) system, decryption keys are defined over attributes shared by multiple users. Given a decryption key, it may not be always possible to trace to the original key owner. As a decryption privilege could be possessed by multiple users who own the same set of attributes, malicious users might be tempted to leak their decryption privileges to some third parties, for financial gain as an example, without the risk of being caught. This problem severely limits the applications of CP-ABE. Several traceable CP-ABE (T-CP-ABE) systems have been proposed to address this problem, but the expressiveness of policies in those systems is limited where only and gate with wildcard is currently supported. In this paper we propose a new T-CP-ABE system that supports policies expressed in any monotone access structures. Also, the proposed system is as efficient and secure as one of the best (non-traceable) CP-ABE systems currently available, that is, this work adds traceability to an existing expressive, efficient, and secure CP-ABE scheme without weakening its security or setting any particular trade-off on its performance. Zhen Liu 0008, Zhenfu Cao, Duncan S. Wong |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2011 | Fully Secure Multi-authority Ciphertext-Policy Attribute-Based Encryption without Random Oracles
Zhen Liu 0008, Zhenfu Cao, Qiong Huang 0001, Duncan S. Wong, Tsz Hon Yuen |
ESORICS | 1 |