VLDB 2026 Research / reviewers in the wild / expert
Jinguang Han
dblp:77/9673
· DBLP profile ↗
70ranked-venue papers
21as first author
35since 2021 · last 2026
0000-0002-4993-9452ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 10 first-author · 11 since 2021Systems, architecture and hardware · 16 · 3 first-author · 8 since 2021Computer networks · 11 · 9 since 2021Databases, data management, data science and information retrieval · 7 · 3 first-author · 5 since 2021Software engineering, systems software and programming languages · 5 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 first-author · 1 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Generating Falcon Trapdoors via Gibbs Sampler
Thomas Espitau, Junjie Song, Jinguang Han, Mehdi Tibouchi |
PQCrypto (1) | 4 |
| 2026 | VFEFL: Privacy-preserving federated learning against malicious clients via verifiable functional encryption
Nina Cai, Jinguang Han, Weizhi Meng 0001 |
J. Inf. Secur. Appl. | 2 |
| 2026 | TPM-based adaptive access control scheme with break-glass support for healthcare systemsabstractMedical data access control faces an inherent conflict between privacy protection and emergency accessibility: Attribute-Based Encryption (ABE) can protect privacy, but cannot support timely access to critical medical data in emergency scenarios due to its expensive computation cost. Existing break-glass solutions, though supporting emergency authorization, generally overlook the trustworthiness of decryption devices, leading to potential key exposure on unverified terminals and introducing leakage risks. To address these challenges, this paper proposes an adaptive access control scheme based on the Trusted Platform Module (TPM), called TPM-AACS, which supports two modes for accessing encrypted medical files. In normal mode, the system enforces strict access control through both TPM-based device authentication and ABE-based attribute authentication. In break-glass mode (i.e., during emergencies), it enables the TPM hardware root of trust to implement a controlled and secure local key recovery mechanism, thereby temporarily bypassing the strict access control enforced in normal mode. Considering the limited computation and storage capability of TPM, we optimize the break-glass key generation and recovery procedures to ensure low-latency emergency access while protecting privacy. We reduce the security of our scheme to well-known complexity assumptions and conduct experiment to evaluate its efficiency. The experimental results demonstrate that the decryption time in break-glass mode is approximately 9ms, which is even faster than the outsourced decryption in normal mode and satisfies the timeliness requirements of emergency medical scenarios. Wenjuan Dong, Jinguang Han |
J. Inf. Secur. Appl. | 2 |
| 2026 | Privacy-preserving federated learning from partial decryption verifiable threshold multi-client functional encryption
Jinguang Han, Weizhi Meng 0001 |
J. Inf. Secur. Appl. | 2 |
| 2026 | LTRAS: A linkable threshold ring adaptor signature scheme for efficient and private cross-chain transactions
Jinguang Han |
J. Syst. Archit. | 2 |
| 2026 | Reinforcing Data Integrity for Smart Wearable Devices via Certificateless Signature With Enhanced SecurityabstractDue to the convenience of real time monitoring and feedback, eHealth system is gaining its popularity. With the wide adoption of electronic health records (EHRs), the security issues arise at the same time. Data integrity is one of the most fundamental security requirements and many techniques have been extensively studied to provide integrity guarantee, such as digital signature. Among various signature schemes, certificateless signature enjoys the advantages of there is neither complicated certificate management nor the key escrow problem. In this paper, we study the particular security threats in eHealth systems and analyze the limitations of traditional certificateless signature schemes if being directly applied to protect data integrity. We show that there is a gap between the traditional threat model and the security threats in practice. To improve the security, we define an enhanced notion for the “normal” type adversary in certificateless signature. Then, a concrete construction secure in the enhance model is presented, which can withstand more powerful but realistic attacks. In addition, we provide experimental simulations to analyze the efficiency and security of our proposed scheme. The results demonstrate its utility in eHealth systems and other similar scenarios. Ge Wu 0001, Hua Shen 0002, Zhen Zhao 0005, Liquan Chen, Jinguang Han |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Privacy-Preserving Healthcare Cloud Access Control: Registered Attribute-Based Encryption With Auditable Policy Updating
Wuwei Weng, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jinguang Han, Jian Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Forward Secure Equality Test for Secure Data Sharing in Healthcare SystemsabstractIn healthcare systems, the protection of the sensitive data of patient during sharing across multiple entities is crucial. Encrypting these data before outsourcing to the healthcare server is an effective method to protect data privacy. As a solution to protect data sharing within healthcare systems, identity-based encryption with equality test (IBEET) is an effective strategy that allows testing whether two ciphertexts encrypted from the same plaintext without certificate management. However, current IBEET schemes often lack of control over the trapdoors’ lifetime, i.e. the malicious server could use trapdoor to test whether two ciphertext generated after the trapdoor encrypted by the same plaintext all the time, potentially leaking sensitive data which the user are unwilling to see. To address this problem, we introduce a forward secure identity-based encryption with equality test (FS-IBEET) scheme. This new scheme prevents the malicious server from accessing useful information from newly encrypted files. We perform a thorough security analysis using the random oracle model under the q-BDHI assumption. Our experiments demonstrate that the performance of our scheme in comparison to other schemes. Jianchang Lai, Jinguang Han, Liquan Chen, Xinyan Yang |
IEEE Internet Things J. | 3 |
| 2025 | PH-MG-ABE: A Flexible Policy-Hidden Multigroup Attribute-Based Encryption Scheme for Secure Cloud StorageabstractCiphertext-policy attribute-based encryption (CP-ABE) has attracted significant attention due to its fine-grained access control capabilities, which are highly compatible with cloud computing. Most enterprises utilizing cloud storage technology consist of multiple user groups. However, the current multigroup CP-ABE scheme may pose a risk of sensitive information leakage due to the plaintext access policy mechanisms. To mitigate this issue, it is necessary to conceal access policies. In this article, we propose a flexible policy-hidden multigroup attribute-based encryption (PH-MG-ABE) scheme that enables unique multigroup operations, such as group merging and splitting without affecting user keys. Each attribute in the access policy is divided into attribute values and attribute names. The proposed scheme achieves partial policy hiding by concealing the attribute values. Our scheme allows to directly revoke and join arbitrary numbers of users. In order to reduce the local decryption burden for users, the heavy decryption tasks are outsourced to cloud servers and correctness of the outsourced decryption is verifiable. We prove that our scheme is indistinguishable against under chosen plaintext attacks secure (IND-CPA) based on the decisional q-bilinear Diffie-Hellman exponent assumption. In addition, the proposed scheme appears to be efficient through the performance evaluation. Jiguo Li 0001, Enfan Zhang, Jinguang Han, Yichen Zhang 0003, Jian Shen 0001 |
IEEE Internet Things J. | 3 |
| 2025 | Keyword-Field-Free Conjunctive Searchable Encryption for Multiuser in EMR SystemabstractIn EMR systems, numerous electronic medical records are usually uploaded to cloud servers for storage and data sharing. Public key authenticated encryption with keyword search (PAEKS) which can resist keyword guessing attacks (KGA) provides a feasible approach for data sharing and searching in EMR systems. Specifically, a PAEKS scheme requires the sender to use the receiver’s public key when encrypting, which restricts the generated ciphertext to be searchable by only one specified receiver. If a sender wants to share a data with multiple receivers, the sender has to repeatedly encrypt the data for multiple receivers using the public keys of different receivers. For the receiver, the same issue also exists in the trapdoor generation phase. Therefore, the traditional PAEKS is not suitable for EMR systems involving multiple senders and multiple receivers because of a large number of repeated computations. In this work, we present a practical scheme called multi-user keyword-field-free conjunctive searchable encryption (MU-KFFCSE). In order to achieve KGA-resistant searchable encryption between senders and receivers, we use receiver servers and sender servers such that the computation cost and communication cost of the ciphertext (trapdoor) generation phase are independent of the number of receivers (senders). The proposed scheme also supports flexible searchable encryption with keyword-field-free conjunctive utilizing polynomial technology, which not only increases the accuracy of search results, but also eliminates the limitation of fields. We prove that our scheme satisfies ciphertext indistinguishability (CI) and trapdoor indistinguishability (TI) security without random oracle. Theoretical analysis and experimental results show that our scheme is efficient in terms of computation cost and storage cost compared with existing schemes. Jianchang Lai, Liquan Chen, Jinguang Han, Ge Wu 0001 |
IEEE Internet Things J. | 4 |
| 2025 | Multi-client functional encryption for set intersection with non-monotonic access structures in federated learning
Ruyuan Zhang, Jinguang Han, Liqun Chen 0002, Yiheng Wei |
J. Syst. Archit. | 2 |
| 2025 | Privacy-Preserving and Traceable Functional Encryption for Inner Product in Cloud ComputingabstractCloud computing is a distributed infrastructure that centralizes server resources on a platform in order to provide services over the internet. Traditional public-key encryption protects data confidentiality in cloud computing, while functional encryption provides a more fine-grained decryption method, which only reveals a function of the encrypted data. However, functional encryption in cloud computing faces the problem of key sharing. In order to trace malicious users who share keys with others, traceable FE-IP (TFE-IP) schemes were proposed where the key generation center (KGC) knows users’ identities and binds them with different secret keys. Nevertheless, existing schemes fail to protect the privacy of users’ identities. The fundamental challenge to construct a privacy-preserving TFE-IP scheme is that KGC needs to bind a key with a user's identity without knowing the identity. To balance privacy and accountability in cloud computing, we propose the concept of privacy-preserving traceable functional encryption for inner product (PPTFE-IP) and give a concrete construction which offers the features: (1) To prevent key sharing, both a user's identity and a vector are bound together in the key; (2) The KGC and a user execute a two-party secure computing protocol to generate a key without the former knowing anything about the latter's identity; (3) Each user can ensure the integrity and correctness of his/her key through verification; (4) The inner product of the two vectors embedded in a ciphertext and in his/her key can be calculated by an authorized user; (5) Only the tracer can trace the identity embedded in a key. We formally reduce the security of the proposed PPTFE-IP to well-known complexity assumptions, and conduct an implementation to evaluate its efficiency. The novelty of our scheme is to protect the user's privacy and provide traceability if required. Muyao Qiu, Jinguang Han, Feng Hao 0001, Ge Wu 0001 |
IEEE Trans. Cloud Comput. | 2 |
| 2025 | Lightweight Conditional Privacy-Preserving Scheme for VANET CommunicationsabstractAs a crucial component of intelligent transportation systems, VANETs are essential for enhancing road safety and enabling efficient traffic management. To ensure secure communication, vehicles often use pseudonyms to protect their identity privacy. However, unconditional anonymity can hinder accountability, making it very necessary to provide conditional privacy protection for vehicles. The conditional privacy-preserving technology not only protects the identity privacy of legitimate vehicles, but also can trace the real identity of malicious vehicles. Some existing schemes lack conditional privacy protection or have large computation and communication costs, which makes them unsuitable for resource-constrained VANETs environments. Hence, we improve the current schnorr-based aggregate signature by eliminating bilinear pairing operations, optimizing the aggregation procedure for batch verification and propose a lightweight certificateless-based aggregate signature scheme (ECPP-CLAS) for VANETs. In our scheme, the aggregation enables multiple signatures to be compressed into an aggregated signature and verified simultaneously, thereby reducing communication consumption, trusted entity generates the pseudonym for the corresponding vehicle through special construction to meet the conditional privacy-preserving requirement. The security analysis and performance evaluation show that our proposed scheme can meet the expected security objectives and lightweight requirements. Jianchang Lai, Jinguang Han, Liquan Chen |
IEEE Trans. Cloud Comput. | 3 |
| 2025 | Privacy-Preserving Decentralized Signature-Based Access Control
Jinguang Han, Liqun Chen 0002, Willy Susilo |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Efficient Registered Attribute Based Access Control With Same Sub-Policies in Mobile Cloud ComputingabstractCiphertext-policy attribute-based encryption (CP-ABE) has long been considered as a promising access control technology for cloud storage. However, CP-ABE depends on a central trusted authority to generate and distribute decryption keys, resulting in the key escrow issue. Most existing solutions only mitigate this problem but fail to resolve it entirely. Registered attribute-based encryption (RABE), a new cryptographic primitive, fundamentally addresses the key escrow problem by modifying the trust model, but its high computational overhead limits its practical application. Inspired by this challenge, we present an efficient registered attribute-based access control scheme designed for data encrypted with access policies containing the same sub-policy. In our scheme, users generate their own keys, while a key manager, who does not hold keys, replaces the central authority in managing users. Additionally, for data encrypted with the same sub-policy, the user’s initial decryption stores the relevant parameters, which can be used for subsequent decryptions to reduce computational overhead. The proposed scheme is proven to achieve semantic security. Performance analysis demonstrates that our scheme enhances decryption efficiency by roughly 41.4$\%$compared to existing RABE scheme, with a minimal storage trade-off, making it more practical for cloud storage application. Wuwei Weng, Jiguo Li 0001, Yichen Zhang 0003, Yang Lu 0001, Jian Shen 0001, Jinguang Han |
IEEE Trans. Mob. Comput. | 6 |
| 2024 | Privacy-Preserving Confidential Reporting System With Designated ReportersabstractAbstract A confidential reporting system (CRS) allows reporters to report concerns or problems in confidence without the fear of blame or reprisals. Nevertheless, privacy has been the primary concern of reporters. In this paper, we propose a privacy-preserving confidential reporting system with designated reporters (PPCRS-DR) to protect the privacy of reporters and the confidentiality of reports. Our PPCRS-DR provides the following interesting features: (1) for an event, an auditor can designate a reporter to report; (2) an auditor can neither see the report nor know the reporter’s identity from an encrypted report if the reporter is not the designated one; (3) when an auditor is unavailable, he/she can temporarily designate a delegatee to collect and review reports on behalf of him/her. We formalize both the definition and security model of our PPCRS-DR, and propose a concrete construction. Furthermore, the security of the proposed PPCRS-DR is formally proven. The implementation shows that it is efficient. The novelty is to implement flexible decryption delegation of CRSs and protect reporters’ privacy. Jinguang Han, Willy Susilo, Liquan Chen, Jianchang Lai, Ge Wu 0001 |
Comput. J. | 1 |
| 2024 | Efficient Revocable Attribute-Based Encryption With Verifiable Data IntegrityabstractNowadays, cloud computing and cloud storage services that can reduce the local workload are becoming increasingly popular, allowing individual and corporate users to upload data to the cloud. Since the user’s permissions in the system are not immutable, the users should have dynamic access. Revocation of users who have been granted access to data is also a strong need for cloud computing systems. In addition, we should ensure the data integrity after the cloud server performs a revocation. To address the above issues, we propose a revocable attribute-based encryption scheme that protects the data integrity (RABE-DI). Our scheme is more efficient compared with existing RABE-DI schemes. In addition, we prove the semantic security and integrity of the scheme. Experimental result shows that the similar scheme is not as efficient as ours. Shaobo Chen, Jiguo Li 0001, Yichen Zhang 0003, Jinguang Han |
IEEE Internet Things J. | 4 |
| 2024 | IoT Privacy-Preserving Data Mining With Dynamic Incentive MechanismabstractWith the rise of the Internet of Things (IoT), IoT data analytics has gradually stepping into the spotlight of data mining. Existing research has primarily focused on enhancing the precision of IoT data mining, while the privacy protection aspects have not been fulfilled so far. The deployment of IoT data mining is contingent on the protection of data privacy and its economic worth to all parties. However, most existing IoT data mining research disregards economic benefits and lacks incentives, limiting its applicability. To address this issue, we provide a system for differential privacy-based IoT privacy-preserving data mining (IoT-PPDM) with dynamic incentive mechanism, and a formal economic model for IoT data mining is constructed. We utilized noncooperative game theory to simulate the multilateral interaction process in IoT data mining. To encourage participation from all parties, a dynamic incentive mechanism is designed to establish a balance between privacy protection and data mining requirements. In addition, we discuss the utility of all participants and theoretically validate the feasibility of IoT-PPDM. The experimental results show that IoT-PPDM with dynamic incentive mechanism can increase the benefits for all participants while avoiding irrational behavior of all parties. Yuan Gao 0034, Liquan Chen, Jinguang Han, Ge Wu 0001, Willy Susilo |
IEEE Internet Things J. | 3 |
| 2024 | OABS: Efficient Outsourced Attribute-Based Signature Scheme With Constant SizeabstractAttribute-based signature (ABS) extends the identity-based signature, in which the unique identity for the signer is expanded into an attribute set composed of multiple attributes. The current ABS schemes supporting linear secret-sharing scheme (LSSS) matrix are flexible, but the computational cost of the signing algorithm is linear with the number of required attributes. Therefore, it is inappropriate to constrained devices (mobile phone, tablet, etc.) which have limited computation power. For the sake of solving the above issue, we devise an key-policy outsourced ABS (OABS) scheme supporting LSSS access structure. The designed scheme provides the outsourced key for the cloud service provider (CSP) which computes most of module exponentiation in the signing phase. The signer only needs to perform lightweight calculations to endorse a message. The presented OABS scheme is proved secure against the q-Diffie-Hellman exponentiation (q-DHE) assumption under the standard model. In addition, the devised OABS scheme fulfills the signer privacy. Moreover, the signature length for the designed scheme is invariable and unrelated to the number of required attributes, which reduces communication cost. Performance analysis demonstrates that the designed OABS scheme is more high efficiency in the aspect of the computational cost. Zhaozhe Kang, Jiguo Li 0001, Yuting Zuo, Yichen Zhang 0003, Jinguang Han |
IEEE Internet Things J. | 5 |
| 2024 | Blockchain-based privacy-preserving public key searchable encryption with strong traceability
Jinguang Han, Weizhi Meng 0001, Jianchang Lai, Ge Wu 0001 |
J. Syst. Archit. | 2 |
| 2024 | Similarity-Based Secure Deduplication for IIoT Cloud Management SystemabstractWith the development of the Industrial Internet of Things (IIoT), the scale of IIoT data is rapidly increasing, bringing significant challenges to existing data management systems. To tackle this issue, we propose a similarity-based secure deduplication for IIoT cloud management system, which can effectively balance the security and availability of IIoT data and minimize the storage cost. Concretely, we propose a similarity-based secure deduplication algorithm for IIoT (IIoT-SBSD) by designing a similarity-preserving tag (IIoT-Simhash). This algorithm can perform similarity deduplication over ciphertexts, thus reducing storage space while ensuring data security. Besides, we construct a parallelizable edge-based deduplication framework in which similarity comparison and deduplication operations are performed directly by edge nodes, significantly alleviating the transmission pressure. Additionally, we propose similarity-based proofs of ownership, S-PoWs, to mitigate the impact of data deduplication on the user's access to the IIoT data. Experimental results show that our method significantly reduces storage space and transmission bandwidth without increasing the computation burden. Yuan Gao 0034, Liquan Chen, Jinguang Han, Shui Yu 0001, Huiyu Fang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Privacy-Preserving Decentralized Functional Encryption for Inner ProductabstractTo support secure data mining and privacy-preserving computation, partial access and selective computation on encrypted data are desirable. Functional encryption (FE) is a new paradigm of public-key encryption and allows authorized users to compute specific functions on encrypted data without knowing the data. However, in some FE schemes, a trusted central authority (CA) is required to generate secret keys for users according to the description of functions. In this paper, to reduce trust on the CA and protect users' privacy, a privacy-preserving decentralised FE for inner product (PPDFEIP) scheme is proposed where multiple authorities co-exist and work independently without any interaction. Especially, to resist collusion attacks, all secret keys of the same user are tied to his/her global identifier (GID), but authorities cannot know any information of the GID even if they collaborate. We formalize the definition and security model of our PPFEIP scheme, and propose a concrete construction. Furthermore, the proposed scheme is implemented and evaluated. Finally, the security of our PPDFEIP scheme is reduced to well-known complexity assumptions. The novelty is to reduce trust on the CA, protect users' privacy and enable authorized users to compute inner product on encrypted data without compromising confidentiality. Jinguang Han, Liqun Chen 0002, Aiqun Hu, Liquan Chen, Jiguo Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | OLBS: Oblivious Location-Based ServicesabstractWith the growing use of mobile devices, location-based services (LBS) are becoming increasingly popular. BLS deliver accurate services to individuals according to their geographical locations, but privacy issues have been the primary concerns of users. Privacy-preserving LBS (PPLBS) were proposed to protect location privacy, but there are still some problems: 1) a semi-trusted third party (STTP) is required to blur users’ locations; 2) both the computation and communication costs of generating a query are linear with the size of queried areas; 3) the schemes were not formally treated, in terms of definition, security model, security proof, etc. In this paper, to protect location privacy and improve query efficiency, an oblivious location-based services (OLBS) scheme is proposed. Our scheme captures the following features: 1) an STTP is not required; 2) users can query services without revealing their exact location information; 3) the service provider only knows the size of queried areas and nothing else; and 4) both the computation and communication costs of generating a query is constant, instead of linear with the size of queried areas. We formalise both the definition and security model of our OLBS scheme, and propose a concrete construction. Furthermore, the implementation is conducted to show its efficiency. The security of our scheme is reduced to well-known complexity assumptions. The novelty is to reduce the computation and communication costs of generating a query and enable the service provider to obliviously generate decrypt keys for queried services. This contributes to the growing work of formalising PPLBS schemes and improving query efficiency. Jinguang Han, Willy Susilo, Nan Li 0007, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | RIS-assisted physical layer key generation by exploiting randomness from channel coefficients of reflecting elements and OFDM subcarriers
Tianyu Lu, Liquan Chen, Jinguang Han, Yu Wang 0073, Kunliang Yu |
Ad Hoc Networks | 3 |
| 2023 | DFE-IP: Delegatable functional encryption for inner product
Jinguang Han, Liqun Chen 0002, Willy Susilo, Liquan Chen, Ge Wu 0001 |
Inf. Sci. | 1 |
| 2023 | Similarity-based deduplication and secure auditing in IoT decentralized storage
Yuan Gao 0034, Liquan Chen, Jinguang Han, Ge Wu 0001, Suhui Liu |
J. Syst. Archit. | 3 |
| 2023 | TFS-ABS: Traceable and Forward-Secure Attribute-Based Signature Scheme With Constant-SizeabstractAttribute-based signature (ABS) is a versatile and useful cryptogrammic technology. In an ABS scheme, every signer is distributed a signing secret key in term of her/his attributes, and endorses a message in relation to some signing policy fulfilled by the signer's attributes. The verifier checks that the signature is indeed endorsed by the signer whose attributes match with the signing policy. However, existing ABS schemes suffer from the issue of abusing signature and key exposure. To address the above issues, we provide a traceable and forward-secure attribute-based signature (TFS-ABS) scheme with constant-size supporting flexible threshold predicates. Furthermore, we prove that the presented TFS-ABS scheme is existential unforgeability against selective predicate attack under the standard model. We reduce the security for the provided scheme to$q$-Diffie-Hellman exponentiation assumption. The designed scheme can be used to alleviate the damage induced by key exposure and traces the real identity of signer by attribute authority (AA) when the signer occurs abusing behavior. Furthermore, the signature size in presented scheme keeps constant and is independent of the number of attributes. Experimental evaluations exhibit that the presented TFS-ABS scheme is efficient in term of the communication and computation overhead. Zhaozhe Kang, Jiguo Li 0001, Jian Shen 0001, Jinguang Han, Yuting Zuo, Yichen Zhang 0003 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2022 | An empirical study of supervised email classification in Internet of Things: Practical performance and key influencing factorsabstract202111 bcwh Wenjuan Li 0001, Lishan Ke, Weizhi Meng 0001, Jinguang Han |
Int. J. Intell. Syst. | 4 |
| 2022 | Decentralized Attribute-Based Server-Aid Signature in the Internet of ThingsabstractDevices of Internet of Things (IoT) play a significant role in people’s daily life. A large scale of data is generated, collected, and analyzed in these devices, which inevitably faces secure authentication and access control problem. Attribute-based signature (ABS), where a signer signs a message over a set of attributes, plays an elegant tool for privacy-preserving access control and data authentication. In multiauthority ABS scheme, multiple authorities distribute users’ private keys over their different attributes and these attribute authorities are managed by a central authority. Nevertheless, the whole ABS system can be broken if the central authority is compromised. Besides, the multiauthority ABS scheme needs a lot of pairing and exponentiation operations in the verification and signature algorithms. Therefore, it is very expensive for resource-limited devices (e.g., sensors in IoT) to utilize the ABS scheme. In order to solve above problems, we present a decentralized attribute-based server-aid signature (DABSAS) scheme. In the DABSAS scheme, a server can help users execute heavy computation in the signature and verification algorithms. The proposed scheme provides anonymity and unforgeability. In addition, our scheme mitigates the burden of the signature and verification phase. The proposed scheme is proved secure under the well-known computational co-Diffie–Hellman (co-CDH) assumption. Compared with the existing schemes, the presented DABSAS scheme is efficient. Jiguo Li 0001, Jinguang Han, Chengdong Liu, Yichen Zhang 0003, Huaqun Wang |
IEEE Internet Things J. | 3 |
| 2022 | Key escrow-free attribute based encryption with user revocation
Ruyuan Zhang, Jiguo Li 0001, Yang Lu 0001, Jinguang Han, Yichen Zhang 0003 |
Inf. Sci. | 4 |
| 2022 | Lightweight ID-based broadcast signcryption for cloud-fog-assisted IoT
Suhui Liu, Liquan Chen, Jinguang Han, Jiguo Yu |
J. Syst. Archit. | 3 |
| 2022 | Efficient Attribute Based Server-Aided Verification SignatureabstractAttribute based signature (ABS) is a novel cryptographic primitive, which permits users to sign a message over attributes without revealing other information. A signature only reveals that it is signed by a signer whose some attributes meet an access policy. However, some ABS schemes only support the threshold access policy, where the signing algorithms are limited by the threshold. The threshold access policy can not express precise access control well. In addition, the computation cost of the verification algorithm is heavy since pairing operations are required. Pairing is costly operation comparing to exponentiation. Therefore, existing ABS schemes are not suitable to resource-limited devices, such as RFID tags and smart cards. In order to solve the issues above, we present a novel ABS scheme by using the attribute tree as access policy that expresses flexible access control. We utilize server-aid technique to help the verifier to verify signatures and reduce the computation burden. Our scheme is proved secure against unforgeable and anonymous under chosen-policy selective-message attack in the standard model. Compared with existing schemes, our scheme is more efficient in terms of private key generation and verification. The proposed scheme reduces users’ calculation burden and expresses more flexible access policy. Jiguo Li 0001, Chengdong Liu, Jinguang Han, Yichen Zhang 0003 |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | Editorial for accountability and privacy issues in blockchain and cryptocurrency
Sherman S. M. Chow, Kim-Kwang Raymond Choo, Jinguang Han |
Future Gener. Comput. Syst. | 3 |
| 2021 | An efficient identity-based signature scheme with provable security
Jiguo Li 0001, Chengdong Liu, Jinguang Han, Huaqun Wang, Yichen Zhang 0003 |
Inf. Sci. | 4 |
| 2021 | Privacy-Preserving Electronic Ticket Scheme with Attribute-Based CredentialsabstractUsers accessing services are often required to provide personal information, for example, age, profession and location, in order to satisfy access polices. This personal information is evident in the application of e-ticketing where discounted access is granted to visitor attractions or transport services if users satisfy policies related to their age or disability or other defined over attributes. We propose a privacy-preserving electronic ticket scheme using attribute-based credentials to protect users' privacy. The benefit of our scheme is that the attributes of a user are certified by a trusted third party so that the scheme can provide assurances to a seller that a user's attributes are valid. The scheme makes the following contributions: (1) users can buy different tickets from ticket sellers without releasing their exact attributes; (2) two tickets of the same user cannot be linked; (3) a ticket cannot be transferred to another user; (4) a ticket cannot be double spent. The novelty of our scheme is to enable users to convince ticket sellers that their attributes satisfy the ticket policies and buy discounted tickets anonymously. This is a step towards identifying an e-ticketing scheme that captures user privacy requirements in transport services. The security of our scheme is proved and reduced to a well-known complexity assumption. The scheme is also implemented and its performance is empirically evaluated. Jinguang Han, Liqun Chen 0002, Steve A. Schneider, Helen Treharne, Stephan Wesemeyer |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Special Issue on Cryptographic Currency and Blockchain Technology
Man Ho Au, Jinguang Han, Qianhong Wu, Colin Boyd |
Future Gener. Comput. Syst. | 2 |
| 2020 | Reversible data hiding in encrypted images for coding channel based on adaptive steganographyabstractIn this study, a novel reversible data hiding (RDH) in encrypted domain scheme for coding channel based on sliding‐block segmentation and adaptive steganography is proposed. The proposed scheme enriches the residual information with as little additional encryption information as possible to improve the testing error rate of a steganalyser by sliding‐block segmentation with bit stream encryption. The specific encryption process effectively weakens the correlation between the adjacent pixels and minimises the size of key stream bits. The encryption key can be further embedded in the channel code stream before transmitted in the channel. Experimental analysis shows that the image encrypted by the proposed RDH scheme can achieve a peak‐signal‐to‐noise ratio of >50 dB, as the payload is 0.5 bits per pixel (bpp). In terms of security performance, compared with the state‐of‐the‐art methods, their method has a higher testing error rate when the steganalyser is utilised. Even if the payload is 0.5 bpp, the testing error rate is >0.25. Kunliang Yu, Liquan Chen, Yu Wang 0073, Jinguang Han, Lejun Zhang |
IET Image Process. | 4 |
| 2020 | A decentralized multi-authority ciphertext-policy attribute-based encryption with mediated obfuscation
Jiguo Li 0001, Shengzhou Hu, Yichen Zhang 0003, Jinguang Han |
Soft Comput. | 4 |
| 2020 | Anonymous Single Sign-On With Proxy Re-VerificationabstractAn anonymous single sign-on (ASSO) scheme allows users to access multiple services anonymously using one credential. We propose a new ASSO scheme, where users can access services anonymously through the use of anonymous credentials and unlinkably through the provision of designated verifiers. Notably, verifiers cannot link a user's service requests even if they collude. The novelty is that when a designated verifier is unavailable, a central authority can authorize new verifiers to authenticate the user on behalf of the original verifier. Furthermore, a central verifier can also be authorized to de-anonymize users and trace their service requests. We formalize the scheme along with a security proof and provide an empirical evaluation of its performance. This scheme can be applied to smart ticketing where minimizing the collection of personal information of users is increasingly important to transport organizations due to privacy regulations such as general data protection regulations (GDPRs). Jinguang Han, Liqun Chen 0002, Steve A. Schneider, Helen Treharne, Stephan Wesemeyer |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Full Verifiability for Outsourced Decryption in Attribute Based EncryptionabstractAttribute based encryption (ABE) is a popular cryptographic technology to protect the security of users' data. However, the decryption cost and ciphertext size restrict the application of ABE in practice. For most existing ABE schemes, the decryption cost and ciphertext size grow linearly with the complexity of access structure. This is undesirable to the devices with limited computing capability and storage space. Outsourced decryption is considered as a feasible method to reduce the user's decryption overhead, which enables a user to outsource a large number of decryption operations to the cloud service provider (CSP). However, outsourced decryption cannot guarantee the correctness of transformation done by the cloud, so it is necessary to check the correctness of outsourced decryption to ensure security for users' data. Current research mainly focuses on verifiability of outsourced decryption for the authorized users. It still remains a challenging issue that how to guarantee the correctness of outsourced decryption for unauthorized users. In this paper, we propose an ABE scheme with verifiable outsourced decryption (called full verifiability for outsourced decryption), which can simultaneously check the correctness for transformed ciphertext for the authorized users and unauthorized users. The proposed ABE scheme with verifiable outsourced decryption is proved to be selective CPA-secure in the standard model. Jiguo Li 0001, Yichen Zhang 0003, Jinguang Han |
IEEE Trans. Serv. Comput. | 4 |
| 2020 | VOD-ADAC: Anonymous Distributed Fine-Grained Access Control Protocol with Verifiable Outsourced Decryption in Public CloudabstractRemote data access control is of crucial importance in public cloud. Based on its own inclinations, the data owner predefines the access policy. When the user satisfies the data owner's access policy, it has the right to access the data owner's remote data. In order to improve flexibility and efficiency of remote data access control, attribute-based encryption (for short, ABE) is used to realize the remote data fine-grained access control. For the low-capacity terminals, verifiable outsourced decryption is a very attractive technique. In the real application scenarios, the user's attributes are usually managed by many authorities. When some authorized users access some sensitive remote data, they hope to preserve their identity privacy. From the two points, we propose an anonymous distributed fine-grained access control protocol with verifiable outsourced decryption in public cloud (for short, VOD-ADAC). VOD-ADAC is a novel concept which is proposed for the first time in the paper. By adopting the pseudonym technique, the user's high anonymity can be achieved by frequently changing the independent pseudonyms at some highly social spots. This paper formalizes the system model and security model of VOD-ADAC protocol. Then, by using hybrid encryption technique of distributed ABE and symmetric encryption, a concrete VOD-ADAC protocol is designed from the bilinear pairings. Through security analysis and performance analysis, our proposed VOD-ADAC protocol is provably secure and efficient. Huaqun Wang, Debiao He, Jinguang Han |
IEEE Trans. Serv. Comput. | 3 |
| 2020 | A Blockchain-Based Public Auditing Scheme for Cloud Storage Environment without Trusted AuditorsabstractIn the cloud storage applications, the cloud service provider (CSP) may delete or damage the user’s data. In order to avoid the responsibility, CSP will not actively inform the users after the data damage, which brings the loss to the user. Therefore, increasing research focuses on the public auditing technology recently. However, most of the current auditing schemes rely on the trusted third public auditor (TPA). Although the TPA brings the advantages of fairness and efficiency, it cannot get rid of the possibility of malicious auditors, because there is no fully trusted third party in the real world. As an emerging technology, blockchain technology can effectively solve the trust problem among multiple individuals, which is suitable to solve the security bottleneck in the TPA-based public auditing scheme. This paper proposed a public auditing scheme with the blockchain technology to resist the malicious auditors. In addition, through the experimental analysis, we demonstrate that our scheme is feasible and efficient. Jian Liu 0025, Guannan Yang, Jinguang Han |
Wirel. Commun. Mob. Comput. | 4 |
| 2019 | Attribute-Based Information Flow ControlabstractAbstract Information flow control (IFC) regulates where information is permitted to travel within information systems. To enforce IFC, access control encryption (ACE) was proposed to support both the no read-up rule and the no write-down rule. There are some problems in existing schemes. First, the communication cost is linear with the number of receivers. Second, senders are not authenticated, namely an unauthorized sender can send a message to a receiver. To reduce communication cost and implement sender authentication, we propose an attribute-based IFC (ABIFC) scheme by introducing attribute-based systems into IFC. Our ABIFC scheme captures the following features: (i) flexible IFC policies are defined over a universal set of descriptive attributes; (ii) both the no read-up rule and the no write-down rule are supported; (iii) the communication cost is linear with the number of required attributes, instead of receivers; (iv) receivers can outsource heavy computation to a server without compromising data confidentiality; (v) authorized senders can control release their attributes when sending messages to receivers. To the best of our knowledge, it is the first IFC scheme where flexible policies are defined over descriptive attributes and outsourced computation is supported. Jinguang Han, Maoxuan Bei, Liqun Chen 0002, Yang Xiang 0001, Jie Cao 0001, Fuchun Guo, Weizhi Meng 0001 |
Comput. J. | 1 |
| 2019 | Enhancing the security of FinTech applications with map-based graphical password authentication
Weizhi Meng 0001, Liqiu Zhu, Wenjuan Li 0001, Jinguang Han, Yan Li 0075 |
Future Gener. Comput. Syst. | 4 |
| 2019 | Toward Practical Privacy-Preserving Processing Over Encrypted Data in IoT: An Assistive Healthcare Use CaseabstractWith the advancement of Internet of Things (IoT), a large number of electronic devices are connected to the Internet. These connected electronic devices acquire and transmit information, and respond to any received actions. In the medical ecosystem, hospitals can implement medical diagnosis (MD) with medical sensors, especially for remote auxiliary MD. But, in this context, patients' privacy (PP) is of paramount importance, and confidentiality of medical data is crucial. Therefore, the main challenge ahead is how to realize remote auxiliary MD while protecting confidentiality of the medical data and ensuring PP. In this article, based on somewhat homomorphic encryption (SHE) scheme addressed by Junfeng Fan and Frederik Vercauteren (FV), we provide the first instance of a new efficient SHE scheme for homomorphic evaluation over single instruction multiple data (SIMD). We also implement a new set of efficient SIMD homomorphic comparison and division schemes. Based on these findings, we implement efficient privacy preserving and SIMD homomorphic surf and multiretina-image matching schemes. Offered functionalities include SIMD homomorphic feature point detection, multiretina-image matching, and lesion detection for the encrypted retinal image of diabetic retinopathy. Finally, we provide a proof-of-concept application implementation toward remote auxiliary diagnosis systems for diabetes in order to showcase the core security and privacy pillars of our solution. In the meantime, our IoT system designed with lattice-based cryptography preserves data confidentiality under quantum computation and quantum computers. Linzhi Jiang, Liqun Chen 0002, Thanassis Giannetsos, Bo Luo, Kaitai Liang, Jinguang Han |
IEEE Internet Things J. | 6 |
| 2019 | Fine-grained information flow control using attributes
Jinguang Han, Liqun Chen 0002, Willy Susilo, Xinyi Huang 0001, Aniello Castiglione, Kaitai Liang |
Inf. Sci. | 1 |
| 2018 | Anonymous Single-Sign-On for n Designated Services with Traceability
Jinguang Han, Liqun Chen 0002, Steve A. Schneider, Helen Treharne, Stephan Wesemeyer |
ESORICS (1) | 1 |
| 2018 | Towards Securing Challenge-Based Collaborative Intrusion Detection Networks via Message Verification
Wenjuan Li 0001, Weizhi Meng 0001, Yu Wang 0017, Jinguang Han, Jin Li 0002 |
ISPEC | 4 |
| 2018 | CPMap: Design of Click-Points Map-Based Graphical Password Authentication
Weizhi Meng 0001, Fei Fei, Lijun Jiang, Zhe Liu 0001, Chunhua Su, Jinguang Han |
SEC | 6 |
| 2018 | Towards leakage-resilient fine-grained access control in fog computing
Zuoxia Yu, Man Ho Au, Qiuliang Xu, Rupeng Yang, Jinguang Han |
Future Gener. Comput. Syst. | 5 |
| 2018 | Expressive attribute-based keyword search with constant-size ciphertext
Jinguang Han, Joseph K. Liu, Jiguo Li 0001, Kaitai Liang, Jian Shen 0001 |
Soft Comput. | 1 |
| 2017 | Automatic Encryption Schemes Based on the Neural Networks: Analysis and Discussions on the Various Adversarial Models (Short Paper)
Marino Anthony James, Jiageng Chen, Chunhua Su, Jinguang Han |
ISPEC | 5 |
| 2017 | An Efficient Key-Policy Attribute-Based Searchable Encryption in Prime-Order Groups
Ru Meng, Yanwei Zhou, Jianting Ning, Kaitai Liang, Jinguang Han, Willy Susilo |
ProvSec | 5 |
| 2017 | A Novel Efficient Remote Data Possession Checking Protocol in Cloud StorageabstractAs an important application in cloud computing, cloud storage offers user scalable, flexible, and high-quality data storage and computation services. A growing number of data owners choose to outsource data files to the cloud. Because cloud storage servers are not fully trustworthy, data owners need dependable means to check the possession for their files outsourced to remote cloud servers. To address this crucial problem, some remote data possession checking (RDPC) protocols have been presented. But many existing schemes have vulnerabilities in efficiency or data dynamics. In this paper, we provide a new efficient RDPC protocol based on homomorphic hash function. The new scheme is provably secure against forgery attack, replace attack, and replay attack based on a typical security model. To support data dynamics, an operation record table (ORT) is introduced to track operations on file blocks. We further give a new optimized implementation for the ORT, which makes the cost of accessing ORT nearly constant. Moreover, we make the comprehensive performance analysis, which shows that our scheme has advantages in computation and communication costs. Prototype implementation and experiments exhibit that the scheme is feasible for real applications. Jiguo Li 0001, Jinguang Han, Yichen Zhang 0003 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | KSF-OABE: Outsourced Attribute-Based Encryption with Keyword Search Function for Cloud StorageabstractCloud computing becomes increasingly popular for data owners to outsource their data to public cloud servers while allowing intended data users to retrieve these data stored in cloud. This kind of computing model brings challenges to the security and privacy of data stored in cloud. Attribute-based encryption (ABE) technology has been used to design fine-grained access control system, which provides one good method to solve the security issues in cloud setting. However, the computation cost and ciphertext size in most ABE schemes grow with the complexity of the access policy. Outsourced ABE (OABE) with fine-grained access control system can largely reduce the computation cost for users who want to access encrypted data stored in cloud by outsourcing the heavy computation to cloud service provider (CSP). However, as the amount of encrypted files stored in cloud is becoming very huge, which will hinder efficient query processing. To deal with above problem, we present a new cryptographic primitive called attribute-based encryption scheme with outsourcing key-issuing and outsourcing decryption, which can implement keyword search function (KSF-OABE). The proposed KSF-OABE scheme is proved secure against chosen-plaintext attack (CPA). CSP performs partial decryption task delegated by data user without knowing anything about the plaintext. Moreover, the CSP can perform encrypted keyword search without knowing anything about the keywords embedded in trapdoor. Jiguo Li 0001, Xiaonan Lin, Yichen Zhang 0003, Jinguang Han |
IEEE Trans. Serv. Comput. | 4 |
| 2017 | Flexible and Fine-Grained Attribute-Based Data Storage in Cloud ComputingabstractWith the development of cloud computing, outsourcing data to cloud server attracts lots of attentions. To guarantee the security and achieve flexibly fine-grained file access control, attribute based encryption (ABE) was proposed and used in cloud storage system. However, user revocation is the primary issue in ABE schemes. In this article, we provide a ciphertext-policy attribute based encryption (CP-ABE) scheme with efficient user revocation for cloud storage system. The issue of user revocation can be solved efficiently by introducing the concept of user group. When any user leaves, the group manager will update users' private keys except for those who have been revoked. Additionally, CP-ABE scheme has heavy computation cost, as it grows linearly with the complexity for the access structure. To reduce the computation cost, we outsource high computation load to cloud service providers without leaking file content and secret keys. Notably, our scheme can withstand collusion attack performed by revoked users cooperating with existing users. We prove the security of our scheme under the divisible computation Diffie-Hellman assumption. The result of our experiment shows computation cost for local devices is relatively low and can be constant. Our scheme is suitable for resource constrained devices. Jiguo Li 0001, Yichen Zhang 0003, Huiling Qian, Jinguang Han |
IEEE Trans. Serv. Comput. | 5 |
| 2016 | Leakage-Resilient Functional Encryption via Pair Encodings
Zuoxia Yu, Man Ho Au, Qiuliang Xu, Rupeng Yang, Jinguang Han |
ACISP (1) | 5 |
| 2016 | Improved handover authentication and key pre-distribution for wireless mesh networksabstractSummary Ticket‐based authentication is a critical technology to secure wireless mesh networks (WMN), which enable efficient communication among laptops, cell phones and other wireless devices. In this paper, we provide a new design of handoff authentication for WMN to reduce the delay caused by handoff. Our major improvement is on the key pre‐distribution for handoff authentication. We apply the attribute‐based encryption to encrypt key pre‐distribution messages for neighbor mesh routers. As a result, key pre‐distribution has constant computation and communication costs, which are independent of the number of neighbor mesh routers. Another advantage of our design is that it can perform immediate handoff authentication once the login authentication is complete, even before key pre‐distribution messages reach the foreign mesh router. The security of our handoff authenticator protocol is also improved by employing home mesh router's digital signature in the handoff ticket and key pre‐distribution messages. Our scheme can efficiently thwart forgery attacks. The proposed scheme provides an efficient and secure solution that meets the requirements of WMN in the era of Big Data. Copyright © 2015 John Wiley & Sons, Ltd. Xu Yang 0002, Xinyi Huang 0001, Jinguang Han, Chunhua Su |
Concurr. Comput. Pract. Exp. | 3 |
| 2016 | Accountable mobile E-commerce scheme via identity-based plaintext-checkable encryption
Jinguang Han, Xinyi Huang 0001, Tsz Hon Yuen, Jiguo Li 0001, Jie Cao 0001 |
Inf. Sci. | 1 |
| 2016 | ABKS-CSC: attribute-based keyword search with constant-size ciphertextsabstractAbstract Attribute‐based keyword search (ABKS) was proposed to enable a third party to search encrypted keywords without compromising the security of the original data. Because it can express flexible access policy, ABKS has attracted a lot of attention. Existing ABKS schemes mainly focused on the expression of access structures, while the computation cost and communication cost are linear with the number of required attributes. Therefore, existing ABKS schemes are unsuitable to the devices that have constrained space and computing power, such as smart phone and tablet. In this paper, an ABKS with constant‐size ciphertext scheme is proposed. The proposed scheme captures the following nice features: (1) The index encryption algorithm has constant computation cost; (2) the searchable ciphertexts are constant size; (3) the trapdoors for keywords are constant size; and (4) the test algorithm has constant computation cost. To the best of our knowledge, it is the first time that an ABKS with constant‐size ciphertext scheme is proposed. Copyright © 2016 John Wiley & Sons, Ltd. Jinguang Han, Willy Susilo, Tsz Hon Yuen, Jiguo Li 0001 |
Secur. Commun. Networks | 2 |
| 2016 | User Collusion Avoidance Scheme for Privacy-Preserving Decentralized Key-Policy Attribute-Based EncryptionabstractDecentralized attribute-based encryption (ABE) is a variant of multi-authority based ABE whereby any attribute authority (AA) can independently join and leave the system without collaborating with the existing AAs. In this paper, we propose a user collusion avoidance scheme which preserves the user's privacy when they interact with multiple authorities to obtain decryption credentials. The proposed scheme mitigates the well-known user collusion security vulnerability found in previous schemes. We show that our scheme relies on the standard complexity assumption (decisional bilienar Deffie-Hellman assumption). This is contrast to previous schemes which relies on non-standard assumption (q-decisional Diffie-Hellman inversion). Yo Rahul, Suresh Veluru 0001, Jinguang Han, Fei Li 0012, Muttukrishnan Rajarajan, Rongxing Lu |
IEEE Trans. Computers | 3 |
| 2015 | AAC-OT: Accountable Oblivious Transfer With Access ControlabstractTo prevent illegal users accessing the database and protect users' privacy, oblivious transfer with access control (AC-OT) was proposed. In an AC-OT scheme, the database provider can encrypt the records and publish corresponding access control lists (ACLs). Prior to accessing the records, a user needs to obtain anonymous credentials from the issuer. Subsequently, an authorized user can obtain the intended records without the database provider knowing its choices. Although AC-OT schemes have shown a lot of merits, there are some practical issues: 1) one of the inherited problems in anonymous credentials is timely revocation and 2) how to prevent malicious users overusing the records. In this paper, we propose an accountable AC-OT scheme to address these issues. In our scheme, an authorized user can access the protected records without the database provider knowing his personal information and choices if: 1) he has obtained the required credentials listed in the ACLs and 2) the number of the access times for each record is no more than the specified bound. Notably, the database provider can trace and revoke the user who overused the records even in the lifetime of his credentials. To the best of our knowledge, it is the first AC-OT scheme where timely revocation and overuse detection are considered. Jinguang Han, Willy Susilo, Yi Mu 0001, Man Ho Au, Jie Cao 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Improving Privacy and Security in Decentralized Ciphertext-Policy Attribute-Based EncryptionabstractIn previous privacy-preserving multiauthority attribute-based encryption (PPMA-ABE) schemes, a user can acquire secret keys from multiple authorities with them knowing his/her attributes and furthermore, a central authority is required. Notably, a user's identity information can be extracted from his/her some sensitive attributes. Hence, existing PPMA-ABE schemes cannot fully protect users' privacy as multiple authorities can collaborate to identify a user by collecting and analyzing his attributes. Moreover, ciphertext-policy ABE (CP-ABE) is a more efficient public-key encryption, where the encryptor can select flexible access structures to encrypt messages. Therefore, a challenging and important work is to construct a PPMA-ABE scheme where there is no necessity of having the central authority and furthermore, both the identifiers and the attributes can be protected to be known by the authorities. In this paper, a privacy-preserving decentralized CP-ABE (PPDCP-ABE) is proposed to reduce the trust on the central authority and protect users' privacy. In our PPDCP-ABE scheme, each authority can work independently without any collaboration to initial the system and issue secret keys to users. Furthermore, a user can obtain secret keys from multiple authorities without them knowing anything about his global identifier and attributes. Jinguang Han, Willy Susilo, Yi Mu 0001, Jianying Zhou 0001, Man Ho Au |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | PPDCP-ABE: Privacy-Preserving Decentralized Ciphertext-Policy Attribute-Based Encryption
Jinguang Han, Willy Susilo, Yi Mu 0001, Jianying Zhou 0001, Man Ho Au |
ESORICS (2) | 1 |
| 2014 | Attribute-Based Data Transfer with Filtering Scheme in Cloud ComputingabstractData transfer is a transmission of data over a point-to-point or point-to-multipoint communication channel. To protect the confidentiality of the transferred data, public-key cryptography has been introduced in data transfer schemes (DTSs). Data transfer is a transmission of data over a point-to-point or point-to-multipoint communication channel. To protect the confidentiality of the transferred data, public-key cryptography has been introduced in data transfer schemes (DTSs). Unfortunately, there exist some drawbacks in the current DTSs. First, the sender must know who the real receivers are. This is undesirable in a system where the number of the users is very large, such as cloud computing. In practice, the sender only knows some descriptive attributes of the receivers. Secondly, the receiver cannot be guaranteed to only receive messages from the legal senders. Therefore, it remains an elusive and challenging research problem on how to design a DTS scheme where the sender can send messages to the unknown receivers and the receiver can filter out false messages according to the described attributes. In this paper, we propose an attribute-based data transfer with filtering (ABDTF) scheme to address these problems. In our proposed scheme, the receiver can publish an access structure so that only the users whose attributes satisfy this access structure can send messages to him. Furthermore, the sender can encrypt a message under a set of attributes such that only the users who hold these attributes can obtain the message. In particular, we provide an efficient filtering algorithm for the receiver to resist the denial-of-service attacks. Notably, we propose the formal definition and security models for ABDTF schemes. To the best of our knowledge, it is the first time that a provable ABDTF scheme is proposed. Hence, this work provides a new research approach to ABDTF schemes. must know who are the real receivers. This is undesirable in a system where the number of the users is very large, such as cloud computing. In practice, the sender only knows some descriptive attributes of the receivers. Second, the receiver cannot be guaranteed to only receive messages from the legal senders. Therefore, it remains an elusive and challenging research problem on how to design a DTS scheme where the sender can send messages to the unknown receivers and the receiver can filter out false messages according to the described attributes. In this paper, we propose an attribute-based data transfer with filtering (ABDTF) scheme to address these problems. In our proposed scheme, the receiver can publish an access structure so that only the users whose attributes satisfy this access structure can send messages to him. Furthermore, the sender can encrypt a message under a set of attributes such that only the users who hold these attributes can obtain the message. In particular, we provide an efficient filtering algorithm for the receiver to resist the denial-of-service (DoS) attacks. Notably, we propose the formal definition and security models for ABDTF schemes. To the best of our knowledge, it is the first time that a provable ABDTF scheme is proposed. Hence, this work provides a new research approach to ABDTF schemes. Jinguang Han, Willy Susilo, Yi Mu 0001, Jun Yan 0005 |
Comput. J. | 1 |
| 2014 | Identity-Based Secure DistributedData Storage SchemesabstractSecure distributed data storage can shift the burden of maintaining a large number of files from the owner to proxy servers. Proxy servers can convert encrypted files for the owner to encrypted files for the receiver without the necessity of knowing the content of the original files. In practice, the original files will be removed by the owner for the sake of space efficiency. Hence, the issues on confidentiality and integrity of the outsourced data must be addressed carefully. In this paper, we propose two identity-based secure distributed data storage (IBSDDS) schemes. Our schemes can capture the following properties: (1) The file owner can decide the access permission independently without the help of the private key generator (PKG); (2) For one query, a receiver can only access one file, instead of all files of the owner; (3) Our schemes are secure against the collusion attacks, namely even if the receiver can compromise the proxy servers, he cannot obtain the owner’s secret key. Although the first scheme is only secure against the chosen plaintext attacks (CPA), the second scheme is secure against the chosen ciphertext attacks (CCA). To the best of our knowledge, it is the first IBSDDS schemes where an access permission is made by the owner for an exact file and collusion attacks can be protected in the standard model. Jinguang Han, Willy Susilo, Yi Mu 0001 |
IEEE Trans. Computers | 1 |
| 2013 | Identity-based data storage in cloud computing
Jinguang Han, Willy Susilo, Yi Mu 0001 |
Future Gener. Comput. Syst. | 1 |
| 2012 | Attribute-Based Oblivious Access ControlabstractIn an attribute-based system (ABS), users are identified by various attributes, instead of their identities. Since its seminal introduction, the attribute-based mechanism has attracted a lot of attention. However, current ABS schemes have a number of drawbacks: (i) the communication cost is linear in the number of the required attributes; (ii) the computation cost is linear in the number of the required attributes and (iii) there are no efficient verification algorithms for the secret keys. These drawbacks limit the use of ABS in practice. In this paper, we propose an attribute-based oblivious access control (ABOAC) scheme to address these problems, where only the receiver whose attributes satisfy the access policies can obtain services obliviously. As a result, the receiver does not release anything about the contents of the selected services and his attributes to the sender, and even the number and supersets of his attributes are protected. The sender only knows the number of the services selected by the authorized receiver. Notably, the costs of computation and communication are constant and independent of the number of required attributes. While, in the prior comparable schemes, both the costs of computation and communication are linear in the required attributes. Therefore, our ABOAC scheme provides a novel and elegant solution to protect user's privacy in the systems where both the bandwidth and the computing capability are limited, such as wireless sensor and actor networks, mobile ad hoc networks, etc.. Jinguang Han, Willy Susilo, Yi Mu 0001, Jun Yan 0005 |
Comput. J. | 1 |
| 2012 | Privacy-Preserving Decentralized Key-Policy Attribute-Based EncryptionabstractDecentralized attribute-based encryption (ABE) is a variant of a multiauthority ABE scheme where each authority can issue secret keys to the user independently without any cooperation and a central authority. This is in contrast to the previous constructions, where multiple authorities must be online and setup the system interactively, which is impractical. Hence, it is clear that a decentralized ABE scheme eliminates the heavy communication cost and the need for collaborative computation in the setup stage. Furthermore, every authority can join or leave the system freely without the necessity of reinitializing the system. In contemporary multiauthority ABE schemes, a user's secret keys from different authorities must be tied to his global identifier (GID) to resist the collusion attack. However, this will compromise the user's privacy. Multiple authorities can collaborate to trace the user by his GID, collect his attributes, then impersonate him. Therefore, constructing a decentralized ABE scheme with privacy-preserving remains a challenging research problem. In this paper, we propose a privacy-preserving decentralized key-policy ABE scheme where each authority can issue secret keys to a user independently without knowing anything about his GID. Therefore, even if multiple authorities are corrupted, they cannot collect the user's attributes by tracing his GID. Notably, our scheme only requires standard complexity assumptions (e.g., decisional bilinear Diffie-Hellman) and does not require any cooperation between the multiple authorities, in contrast to the previous comparable scheme that requires nonstandard complexity assumptions (e.g., q-decisional Diffie-Hellman inversion) and interactions among multiple authorities. To the best of our knowledge, it is the first decentralized ABE scheme with privacy-preserving based on standard complexity assumptions. Jinguang Han, Willy Susilo, Yi Mu 0001, Jun Yan 0005 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2010 | A Generic Construction of Dynamic Single Sign-on with Strong Security
Jinguang Han, Yi Mu 0001, Willy Susilo, Jun Yan 0005 |
SecureComm | 1 |