VLDB 2026 Research / reviewers in the wild / expert
Cheng Huang 0001
dblp:83/5898-1
· DBLP profile ↗
69ranked-venue papers
12as first author
49since 2021 · last 2026
0000-0003-3769-7211ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 37 · 7 first-author · 23 since 2021Security and privacy · 14 · 3 first-author · 10 since 2021Systems, architecture and hardware · 6 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SpecGate: Spectral Decomposition and LOF-Gated Aggregation for Defending Against Backdoor Attacks in Federated Learning
Wenxiu Wu, Haiyong Bao, Menghong Guan, Jiaan Jiang, Hongning Dai, Cheng Huang 0001 |
ACISP (3) | 6 |
| 2026 | AoI-Aware Privacy-Preserving Task Allocation in Vehicular CrowdsensingabstractIn Vehicular Crowdsensing (VCS) systems, task allocation is a critical process that connects sensing demands with distributed vehicular resources. Its effectiveness fundamentally relies on optimizing the spatio-temporal features of vehicles, where information freshness is quantified by the Age of Information (AoI). However, task allocation that aims to jointly optimize spatial coverage and AoI requires the collection of precise trajectory and region data, which raises serious privacy concerns and becomes a key barrier to practical deployment. To achieve privacy-preserving and spatio-temporally optimized task allocation, this paper proposes a novel AoI-aware privacy-preserving task allocation framework based on secret sharing. The framework encodes both task regions and vehicle trajectories into timestamp-associated arrays and splits them into lightweight random shares. Through collaborative computation between two fog servers and a cloud platform, it enables secure evaluation of vehicle-task spatio-temporal matching without exposing the original data. Furthermore, we design a budget-constrained, spatio-temporally near-optimal vehicle selection algorithm that simultaneously maximizes spatial coverage and minimizes AoI under budget constraints. Security analysis and experimental results demonstrate that our scheme effectively protects location privacy while achieving near-optimal spatio-temporal coverage. Moreover, it significantly reduces both communication and computational overhead compared with a homomorphic encryption baseline, confirming its practical effectiveness for time-sensitive VCS applications. Jialing Hong, Jingxiao Ma, Cheng Huang 0001, Rongxing Lu |
IEEE Internet Things J. | 4 |
| 2026 | CQED: Secure and efficient composite query processing over encrypted healthcare data
Haiyong Bao, Yaotian Zhang, Xinqi Tu, Sunyu Tian, Cheng Huang 0001, Hongning Dai |
Inf. Sci. | 5 |
| 2026 | KMCS: Efficient and privacy-preserving k-core multi-attribute community search
Ziyang Zhong, Haiyong Bao, Ronghai Xie, Jiani Wu, Cheng Huang 0001, Hongning Dai |
Inf. Sci. | 5 |
| 2026 | LPSQ: Achieving Efficient and Privacy-Preserving Location-Point-Set Similarity Range Query for Cloud ComputingabstractLocation point set similarity range query aims to retrieve candidate point sets that are similar to the given point set in terms of location distribution patterns and geographical features, and it is vital in GIS (Geographic Information Systems), IoT (Internet of Things), and biometrics. Due to the economic and flexible advantages of cloud services, location data is frequently outsourced to cloud servers, which simultaneously increases the risk of privacy breaches. To address this, service providers choose to encrypt data before outsourcing. However, the existing schemes for similarity range query of encrypted location point sets have some problems, such as high computational complexity of measurements, which limit the query efficiency and security of schemes. To tackle these problems, this paper achieves the efficient and privacy-preserving location-point-set similarity range query for cloud computing (LPSQ). Firstly, we propose a lightweight similarity measurement called Geo-Jaccard similarity, to reduce the time complexity to$O(n)$. Secondly, to enhance the efficiency of the scheme, we integrate the kd-tree with pivot point technology to construct a pkd-tree, and design a corresponding filtering and verification algorithm. Thirdly, to enhance the security of our scheme, we encrypt the pkd-tree using a mix of matrix encryption and SHE (Symmetric Homomorphic Encryption), and design a series of protocols under SHE, such as SHE batch minimum value calculation protocol, SHE division protocol, and the approximation algorithm for computing Jaccard similarity securely. Finally, we prove that the security of our proposed LPSQ achieves CPA (Chosen Plaintext Attack) security. Furthermore, we conduct experiments to assess the performance, and the results demonstrate that LPSQ achieves sublinear search efficiency, while Geo-Jaccard similarity proves effective for similarity range queries on location point sets. Haiyong Bao, Daqi Li, Jing Wang 0239, Qinglei Kong, Cheng Huang 0001, Hongning Dai |
IEEE Trans. Cloud Comput. | 6 |
| 2026 | KDCS: Achieving Efficient and Privacy-Preserving ($k,d$k,d)-Truss Community Search for Social NetworksabstractCommunity search is essential in social network analysis, with the ($k,d$)-truss model offering a robust framework to identify densely connected subgraphs that contain a query vertex and meet both$k$-truss and distance constraints. Despite the increasing reliance on cloud servers for processing large social network graph data, privacy concerns remain unaddressed. To fill this gap, we propose a novel privacy-preserving ($k,d$)-truss community search (KDCS) scheme based on weighted community graphs. Specifically, to enhance search efficiency, we introduce a$k$-truss-G (KTG) tree to index communities for efficient queries. Firstly, we develop a boundary vertex encoding mechanism for the social distance matrix. Then, we design a KTG tree construction algorithm and a ($k,d$)-truss community search algorithm based on the concept of segmentation and assembly. To ensure data security, we propose a secure community distance calculation (SCDC) algorithm, which utilizes mutually orthogonal matrices to preserve the privacy of the social distance matrix while accurately calculating the social distance. Furthermore, improved symmetric homomorphic encryption (iSHE) and matrix encryption are utilized to safeguard both dataset privacy and query privacy effectively. In addition, rigorous security analysis demonstrates that the proposed KDCS scheme is indeed privacy-preserving. Finally, extensive comparative experiments with real social network datasets show that KDCS exhibits outstanding performance at every stage, underscoring its practical significance. Haiyong Bao, Jiani Wu, Ziyang Zhong, Cheng Huang 0001, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Two-Server Offline/Online Private Information Retrieval With Small Client StorageabstractIn this paper, we propose PIRS, a two-server offline/online private information retrieval scheme with small client storage. In PIRS, a client first engages in an offline phase to preprocess a database replicated on two servers to generate query-independent hints. Utilizing the pre-computed hints, the client then securely retrieves any record from the database without exposing its index during an online phase, with the server-side computational complexity being sublinear for high efficiency. Compared to state-of-the-art schemes, PIRS distinguishes itself by enabling the client to outsource the hints to the servers instead of storing them, dramatically reducing the local storage requirement from GB/MB to MB/KB, given that the size of the hints is directly proportional to the database volume. Specifically, the client employs secret sharing to achieve secure hint outsourcing and only fetches the relevant hint for each online PIR query. In such an outsourcing environment, we introduce a new technique named oblivious switching to obfuscate repeated hint/record accesses, and carefully tailor online PIR queries to guarantee sublinear computational complexity. Furthermore, we propose a secure and efficient method that delegates the task of locating appropriate hints for particular PIR queries to the servers, thus avoiding costly computations or extra data storage on the client side. Finally, we conduct a comprehensive security analysis to demonstrate PIRS's security, and develop a proof-of-concept prototype to show the practicality of PIRS in terms of computational, communication, and storage overheads. Cheng Huang 0001, Anjia Yang, Rongxing Lu, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | MPKS: Efficient and Privacy-Enhanced Multi-Party Keyword-Oriented Similarity Query in ehealthcare
Zian Zhang, Haiyong Bao, Jing Wang 0239, Cheng Huang 0001, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Trigger as Entity: Backdoor Attacks to Graph-Based Retrieval-Augmented Generation of Large Language ModelsabstractGraph-based Retrieval-Augmented Generation (RAG) has achieved remarkable success in refining the outputs of Large Language Models (LLMs), enabling them to integrate relational and multi-hop knowledge into context-aware responses by constructing a knowledge graph from an external database. In this paper, we focus on the underexplored security risks arising from the external database, and propose the first backdoor attacks against the graph-based RAG of LLMs. Specifically, attackers insert the backdoor into the knowledge graph as entities by poisoning a carefully crafted corpus into the external database, thereby causing LLMs to output attacker-desired answers for trigger-containing queries while preserving correct answers for others. The attacks are formulated as a minimax problem, whose solution is a poison corpus. Powered by the chain-of-thought reasoning capabilities of LLMs, we propose a new strategy to solve the minimax problem. We craft retrieval text to insert triggers into the knowledge graph as entities, exploit hijacking text to redirect LLMs’ attention toward attacker-desired answers, and finally link the hijacking text to the triggers so that it serves as context only for trigger-containing queries. In addition, our attacks involve three types of triggers, including word-level, topic-level, and semantic-level, with progressively increasing stealthiness. Empirical results across multiple knowledge databases and language models indicate that the proposed attacks achieve the desired attack performance. Our findings highlight the substantial risks in LLM applications (e.g., chatbots and agents) built on graph-based RAG systems. Zhirun Zheng, Young-June Choi, Cheng Huang 0001, Hangcheng Cao, Shujuan Tian, Tingrui Pei |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | Region Partitioning-Based Scalable Real-Time Network Verification via Native Distributed Architecture
Bo He 0003, Lingqi Guo, Chenyang Zhao 0005, Qi Qi 0001, Zirui Zhuang, Haifeng Sun 0001, Gong Zhang 0001, Jianxin Liao, Cheng Huang 0001, Jingyu Wang 0001 |
IEEE Trans. Netw. | 11 |
| 2025 | EBS-CFL: Efficient and Byzantine-robust Secure Clustered Federated LearningabstractDespite federated learning (FL)'s potential in collaborative learning, its performance has deteriorated due to the data heterogeneity of distributed users. Recently, clustered federated learning (CFL) has emerged to address this challenge by partitioning users into clusters according to their similarity. However, CFL faces difficulties in training when users are unwilling to share their cluster identities due to privacy concerns. To address these issues, we present an innovative Efficient and Robust Secure Aggregation scheme for CFL, dubbed EBS-CFL. The proposed EBS-CFL supports effectively training CFL while maintaining users' cluster identity confidentially. Moreover, it detects potential poisonous attacks without compromising individual client gradients by discarding negatively correlated gradients and aggregating positively correlated ones using a weighted approach. The server also authenticates correct gradient encoding by clients. EBS-CFL has high efficiency with client-side overhead O(ml + m^2) for communication and O(m^2l) for computation, where m is the number of cluster identities, and l is the gradient size. When m = 1, EBS-CFL's computational efficiency of client is at least O(log(n)) times better than comparison schemes, where n is the number of clients. In addition, we validate the scheme through extensive experiments. Finally, we theoretically prove the scheme's security. Zhiqiang Li 0007, Haiyong Bao, Menghong Guan, Cheng Huang 0001, Hongning Dai |
AAAI | 5 |
| 2025 | UEFL: Universal and Efficient Privacy-Preserving Federated LearningabstractFederated Learning (FL) is a distributed machine learning framework that allows for model training across multiple clients without requiring access to their local data. However, FL poses some risks, for example, curious clients might conduct inference attacks (e.g., membership inference attacks, model-inversion attacks) to extract sensitive information from other participants. Existing solutions typically fail to strike a good balance between performance and privacy, or are only applicable to specific FL scenarios. To address these challenges, we propose a universal and efficient privacy-preserving FL framework based on matrix theory. Specifically, we design the Improved Extended Hill Cryptosystem (IEHC), which efficiently encrypts model parameters while supporting the secure ReLU function. To accommodate different training tasks, we design the Secure Loss Function Computation (SLFC) protocol, which computes derivatives of various loss functions while maintaining data privacy of both client and server. And we implement SLFC specifically for three classic loss functions, including MSE, Cross Entropy, and L1. Extensive experimental results demonstrate that our approach robustly defends against various inference attacks. Furthermore, model training experiments conducted in various FL scenarios indicate that our method shows significant advantages across most metrics. Zhiqiang Li 0007, Haiyong Bao, Menghong Guan, Cheng Huang 0001, Hongning Dai |
IEEE Internet Things J. | 5 |
| 2025 | DualGuard: Obfuscated Federated Learning With Two-Party Secure Robust AggregationabstractFederated learning (FL) is a promising privacy-preserving distributed machine learning paradigm. However, data privacy leakage and Byzantine clients are common challenges in the FL aggregation phase. While extensive research has been conducted to explore defenses for these risks independently, there is a notable lack of scholarly work on integrated defense strategies to address both challenges simultaneously. To bridge this gap, we propose a novel two-party secure robust aggregation (TPSRA) framework. The critical insight of TPSRA is to couple client-side gradient obfuscation with server-side secure two-party computation to achieve robust and private FL aggregation. Specifically, clients obfuscate and split local gradients using matrix theory, while servers utilize a novel secure multiparty computation protocol based on mutually orthogonal matrices to preserve the privacy of local gradients. Additionally, TPSRA designs and integrates state-of-the-art robust aggregation algorithms into compatible subprotocols, enabling efficient parallel computation. This establishes a highly efficient and versatile secure robust aggregation framework for FL. Experiments demonstrate that our TPSRA framework not only effectively resists gradient leakage attacks and detects malicious gradients, but also exhibits superior computational and communication efficiency. We also prove theoretically that TPSRA is secure under the semi-honest adversary model. Haiyong Bao, Menghong Guan, Zhiqiang Li 0007, Cheng Huang 0001, Hongning Dai |
IEEE Internet Things J. | 5 |
| 2025 | Mul_STK: Efficient and privacy-preserving query with spatio-temporal-keyword multiple attributes in cloud computing
Haiyong Bao, Menghong Guan, Jing Wang 0239, Qinglei Kong, Hongning Dai, Cheng Huang 0001 |
J. Syst. Archit. | 7 |
| 2025 | TAMT: Privacy-Preserving Task Assignment With Multi-Threshold Range Search for Spatial Crowdsourcing ApplicationsabstractSpatial crowdsourcing is a distributed computing paradigm that utilizes the collective intelligence of workers to perform complex tasks. How to achieve privacy-preserving task assignment in spatial crowdsourcing applications has been a popular research area. However, most of the existing task assignment schemes may reveal private and sensitive information of tasks or workers. Few schemes can support task assignment based on different attributes simultaneously, such as spatial, interest, etc. To study the above themes, in this paper, we propose one privacy-preserving task assignment scheme with multi-threshold range search for spatial crowdsourcing applications (TAMT). Specifically, we first define Euclidean distance-based location search and Hamming distance-based interest search, which map the demands of the tasks and the interests of the workers into the binary vectors. Second, we deploy PKD-tree to index the task data leveraging the pivoting techniques and the triangular inequality of Euclidean distance, and propose an efficient multi-threshold range search algorithm based on matrix encryption and decomposition technology. Furthermore, based on DT-PKC, we introduce a ciphertext-based secure comparison protocol to support multi-threshold range search for spatial crowdsourcing applications. Finally, comprehensive security analysis proves that our proposed TAMT is privacy-preserving. Meanwhile, theoretical analysis and experimental evaluation demonstrate that TAMT is practical and efficient. Haiyong Bao, Zhehong Wang, Rongxing Lu, Cheng Huang 0001, Beibei Li 0002 |
IEEE Trans. Big Data | 4 |
| 2025 | PRRQ: Privacy-Preserving Resilient RkNN Query Over Encrypted Outsourced Multiattribute DataabstractTraditional reverse k-nearest neighbor (RkNN) query schemes typically assume that users are available online in real-time for interactive key reception, overlooking scenarios where users might be offline. Moreover, existing privacy-preserving RkNN query schemes primarily focus on user features or spatial data, neglecting the significance of user reputation values. To address these limitations, we propose a privacy-preserving resilient RkNN query scheme over encrypted outsourced multi-attribute data (PRRQ). Specifically, to mitigate the challenges posed by resilient online presence (i.e., non-real-time online) of users for interactive key reception, we incorporate a non-interactive key exchange (NIKE) protocol and the Diffie-Hellman two-party key exchange algorithm to propose a multi-party NIKE algorithm (2K-NIKE), facilitating non-interactive key reception for multiple users. Considering the privacy leakage issues, PRRQ encodes original multi-attribute data (i.e., spatial, feature, and reputation values) alongside query requests based on formalized criteria. Additionally, we integrate the proposed 2K-NIKE and the improved symmetric homomorphic encryption (iSHE) algorithms to encrypt them. Furthermore, catering to the requirements of ciphertext-based RkNN queries, we propose a private RkNN query eligibility-checking (PREC) algorithm and a private reputation-verifying (PRRV) algorithm, which validate the compliance of encrypted outsourced multi-attribute data with query requests. Security analysis demonstrates that PRRQ achieves simulation-based security under anhonest-but-curiousmodel. Experimental results show that PRRQ offers superior computational efficiency compared to comparative schemes. Jing Wang 0239, Haiyong Bao, Na Ruan, Qinglei Kong, Cheng Huang 0001, Hongning Dai |
IEEE Trans. Computers | 5 |
| 2025 | MKAC: Efficient and Privacy-Preserving Multi- Keyword Ranked Query With Ciphertext Access Control in Cloud EnvironmentsabstractWith the explosion of big data in cloud environments, data owners tend to delegate the storage and computation to cloud servers. Since cloud servers are generally untrustworthy, data owners often encrypt data before outsourcing it to the cloud. Numerous privacy-preserving schemes for the multi-keyword ranked query have been proposed, but most of these schemes do not support ciphertext access control, which can easily lead to malicious access by unauthorized users, causing serious damage to personal privacy and commercial secrets. To address the above challenges, we propose an efficient and privacy-preserving multi-keyword ranked query scheme (MKAC) that supports ciphertext access control. Specifically, in order to enhance the efficiency of the multi-keyword ranked query, we employ a vantage point (VP) tree to organize the keyword index. Additionally, we develop a VP tree-based multi-keyword ranked query algorithm, which utilizes the pruning strategy to minimize the number of nodes to search. Next, we propose a privacy-preserving multi-keyword ranked query scheme that combines asymmetric scalar-product-preserving encryption with the VP tree. Furthermore, attribute-based encryption mechanism is used to generate the decryption key based on the query user's attributes, which is then employed to decrypt the query results and trace any malicious query user who may leak the secret key. Finally, a rigorous analysis of the security of MKAC is conducted. The extensive experimental evaluation shows that the proposed scheme is efficient and practical. Haiyong Bao, Menghong Guan, Na Ruan, Cheng Huang 0001, Hongning Dai |
IEEE Trans. Cloud Comput. | 6 |
| 2025 | Enabling Efficient and Privacy-Preserving Sequence Similarity Query on Encrypted GenomesabstractOver the past decades, Sequence Similarity Query (SSQ) has been widely used in genomic analysis. Several privacy-preserving SSQ schemes have been proposed to protect sensitive genomic data but struggle to balance security and efficiency. This paper proposes a Privacy-preserving Genomic SSQ (PGSSQ) scheme to address the above issue. Specifically, we first design two fundamental privacypreserving genomic matching methods, Edit-distance Threshold Match (ETM) and Dual-Threshold Match (DTM), to support approximate editdistance based threshold SSQ matches and range-constrained SSQ matches on encrypted high-dimensional genomic sequences, respectively. Then, we present a genetic index structure called Genomic Evaluation Tree (GE-Tree) based on the ETM and DTM. GE-Tree enables dynamic pruning of query paths without disclosing any genomic information from encrypted nodes, thereby supporting privacy-preserving SSQ on encrypted genomic data with sublinear computational complexity. Security analysis proves that PGSSQ is secure under selective chosenplaintext attacks. Experiments on a real-world dataset show that PGSSQ is efficient compared to state-of-the-art schemes. Xiangyu Wang 0010, Dan Zhu 0001, Cheng Huang 0001, Zhuoran Ma 0002, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Highly-Secure and Efficient Certificateless AKA for Vehicular Access NetworksabstractThis paper proposes a highly secure and efficient certificateless authenticated key agreement (CL-AKA) scheme, which is particularly apt for deployment in vehicular access networks, as it improves not only communication but also computational efficiency in real-world scenarios where multiple vehicles concurrently access the internet via a limited number of base stations. The cornerstone of our CL-AKA scheme stems from an improved certificateless signature (CLS). Specifically, we re-design the key structure of CLS, allowing signers to locally maintain a single public key (instead of two public keys in most state-of-the-art works) as well as two private keys after key generation. With such a novel key structure, the proposed CLS facilitates pairing-free signature generation and verification and realizes efficient batch verification on the verifier’s end. Moreover, a signer only needs to disseminate one public key to verifiers, thus saving communication bandwidth. In addition to the advanced CLS, we develop a CL-AKA scheme that efficiently handles network access requests from multiple vehicles at base stations. To resist physical attacks and achieve highly secure key management, we further integrate the Physical Unclonable Function (PUF) into our scheme. Formal security proofs demonstrate that the proposed CL-AKA scheme is secure against conventional attacks and preserves common security properties such as forward secrecy and session key independence. Finally, we develop a proof-of-concept prototype and conduct extensive experiments to demonstrate the efficiency and practicality of our scheme. Suhui Liu, Cheng Huang 0001, Liqun Chen 0002, Liquan Chen, Jiguo Yu |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | Defending Data Poisoning Attacks in DP-Based Crowdsensing: A Game-Theoretic ApproachabstractDifferential privacy (DP) is widely used for protecting privacy in crowdsensing by adding noises. However, malicious attackers can exploit noise to launch covert data poisoning attacks. In this paper, we propose a game-based defense approach to resist such data poisoning attacks in DP-based crowdsensing systems. In this approach, attackers are believed to be powerful as they can refine their attack strategy based on the observations of deployed defenders’ defense strategy. Specifically,the defendersformulate the defense as a functional minimization problem (which cannot be directly solved by numerical optimization algorithms because its decision variable is a set of functions), resisting data poisoning attacks by deleting data shared by identified malicious workers through the log-likelihood ratio test. To obtain a current defense strategy, the decision variable of the problem is relaxed into the coefficients of basis-based linear combinations through the variable-basis approximation, and then solved using the simulated annealing genetic algorithm. Correspondingly,the attackersformulate their attack strategy as a bi-level maximization problem (which is an NP-hard problem), biasing crowdsensing results as much as possible while remaining undetected. Since the attackers can know the defense strategy, they may bypass the defenders by constraining the expected log-likelihood ratio test. Additionally, the attackers can evade truth discovery methods deployed in crowdsensing using DP noise. To determine a current attack strategy, the bi-level problem is decomposed into upper-level and lower-level sub-problems, wherein the upper-level sub-problem is solved by the variational methods, and then these sub-problems are alternately optimized. Finally, we propose a local minimax points calculating algorithm to obtain an equilibrium point in the defenders-attackers game, thereby finding an optimal defense strategy to resist the powerful data poisoning attack. Extensive experiments on real-world and synthetic datasets show that the proposed game-based defense approach can effectively defend powerful and covert attackers. Zhirun Zheng, Zhetao Li, Cheng Huang 0001, Saiqin Long, Xuemin Shen |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | EPPQ: Efficient and Privacy-Preserving $k$NN Query Processing for Outsourced High-Dimensional DataabstractExtensive schemes have been conducted on the development of efficient and privacy-preserving$k$NN query algorithms in data outsourcing scenarios. However, existing researches primarily address low-dimensional data, posing scalability challenges in higher dimensions. To tackle this issue, we propose an efficient and privacy-preserving$k$NN query scheme for outsourced high-dimensional data (EPPQ), emphasizing the complete lifecycle from secure dimensionality reduction of high-dimensional data to secure$k$NN query on the reduced-dimensional data. Specifically,in the secure dimensionality reduction phase: on the one hand, EPPQ integrates principal component analysis (PCA) for dimensionality reduction to minimize computational overhead. On the other hand, to address privacy concerns during the process of PCA, by incorporating differential privacy (DP), we propose the Privacy-Preserving Data Dimensionality Reduction Algorithm based on PCA (PDDRP).In the secure$k$NN query phase: for one thing, EPPQ facilitates the index of the reduced-dimensional data by k-d tree. To enhance index efficiency, we innovatively propose plaintexts-based distance calculation definitions (PDC definitions) and construct an efficient variant of k-d tree (Ek-d tree), for the first time. For another, the Paillier homomorphic encryption (PHE) technique is leveraged to safeguard privacy when outsourcing Ek-d tree to untrusted cloud servers. Additionally, for ciphertexts-based distance calculations and comparisons, we design the Secure Precomputed Distance protocol (SPCD) and Secure Comparison protocol (SCOM). Finally, we creatively present the Privacy-Preserving$k$NN Query Algorithm based on Ek-d tree (PKQKT) for efficient and secure$k$NN query. Comprehensive security analysis demonstrates that the EPPQ scheme meets the required security properties under thehonest-but-curiousmodel. Extensive experiments confirms that EPPQ achieves high computational efficiency and query accuracy. Jing Wang 0239, Haiyong Bao, Rongxing Lu, Cheng Huang 0001, Menghong Guan |
IEEE Trans. Serv. Comput. | 4 |
| 2024 | Enabling Efficient Spatio-Temporal Range Query over Encrypted DatabasesabstractSpatio-temporal query services have been playing an increasingly important role in people’s daily lives. While outsourcing such services to third parties (e.g., cloud servers) offers considerable benefits, it raises data privacy issues. However, no existing work can fully support secure and efficient spatio-temporal queries in outsourcing environments. In this paper, we investigate the problem of Spatio-Temporal Range queries over Encrypted databases (STRE). Firstly, we design a new index structure, called Hilbert Hierarchical Prefix Bloom tree (H2PB-tree), which reduces the search complexity of spatio-temporal range query to sublinear. Then, we build an efficient STRE construction called E-STRE in the single-cloud model based on H2PB-tree and symmetric hidden-vector encryption. Moreover, we perform sufficient security analysis and experimental test, and the results show E-STRE outperforms prior arts in terms of performance while guaranteeing data security. Compared with the prior arts presented under the single-cloud model, our construction reduces the query delay by at least 18×. Dan Zhu 0001, Xiangyu Wang 0010, Cheng Huang 0001, Peilin Han, Wei Hu 0008, Jianfeng Ma 0001 |
GLOBECOM | 3 |
| 2024 | PMRK: Privacy-Preserving Multidimensional Range Query With Keyword Search Over Spatial DataabstractWith the intensification of mobile devices, vast amounts of spatial data have been outsourced to cloud servers to provide query services. However, existing privacy-preserving schemes for spatial data only support spatial range queries and keyword searches and do not scale well in the scenario of multidimensional range queries. To address the above challenges, we propose a privacy-preserving scheme for the multidimensional range query with keyword search over spatial data (PMRK). Specifically, based on the encoding technique, we design data comparison and text matching algorithms, which can convert range queries and keyword searches into Hadamard-product-based operations. To improve the search efficiency, we index the spatial data by R-tree and propose the range intersection algorithm to implement the multidimensional range query with keyword search on R-tree simultaneously. Furthermore, the homomorphic encryption and matrix encryption techniques are leveraged to design the intersection predicate encryption (IPE) and subset predicate encryption (SPE) schemes, which preserve the privacy of range queries and keyword searches. Then, we propose our PMRK scheme, which not only supports efficient and secure multidimensional range queries and keyword searches at the same time but also preserves the single-dimensional privacy for multidimensional queries, and the path pattern privacy of the R-tree. In addition, the security of IPE and SPE is formally proved, and the security of PMRK is analyzed. In the experimental part, the feasibility and efficiency of PMRK are demonstrated by conducting experiments on real data sets. Xinqi Tu, Haiyong Bao, Rongxing Lu, Cheng Huang 0001, Hongning Dai |
IEEE Internet Things J. | 4 |
| 2024 | KMSQ: Efficient and Privacy-Preserving Keyword-Oriented Multidimensional Similarity Query in eHealthcareabstractExtensive research has been conducted on efficient and privacy-preserving similarity queries in eHealthcare, aiming at disease diagnosis based on similar patients while protecting the outsourced sensitive healthcare data. In this article, a new secure similarity query scheme named keyword-oriented multidimensional similarity query (KMSQ) is proposed for eHealthcare. Different from the state-of-the-art similar works, our proposed scheme enables users to query historical similar patients’ records based on their multidimensional physiological characteristics and symptom keywords (two data types) at the same time. Although the query can be securely performed sequentially by formerly proposed schemes, we carefully tailor a binary-decision-PB (BD-PB) tree to index the two data types simultaneously for efficient queries. Furthermore, inspired by the Hilbert exclusion condition and the properties of the polynomial function, an efficient query algorithm based on the BD-PB tree is designed in a filtration–verification manner, which further greatly improves the computational efficiency of queries, especially on the server side. To ensure secure query on untrusted clouds, the BD-PB tree-based KMSQ is protected through multiple encryption techniques. Specifically, function-hiding inner product preserving encryption (FHIPPE) is modified and combined with a lightweight matrix encryption technique to achieve secure data filtration. In addition, a symmetric homomorphic encryption (SHE) scheme is utilized to ensure secure verification that each candidate record in the filtration result satisfies the query requirements. Security analysis demonstrates the modified FHIPPE (MFHIPPE) and our proposed scheme meet the necessary security properties under the honest-but-curious model. Finally, extensive experiments are also conducted to show that KMSQ is computationally efficient. Zian Zhang, Haiyong Bao, Rongxing Lu, Cheng Huang 0001, Beibei Li 0002 |
IEEE Internet Things J. | 4 |
| 2024 | SAMFL: Secure Aggregation Mechanism for Federated Learning with Byzantine-robustness by functional encryption
Menghong Guan, Haiyong Bao, Zhiqiang Li 0007, Cheng Huang 0001, Hongning Dai |
J. Syst. Archit. | 5 |
| 2024 | Collaborative and Verifiable VNF Management for Metaverse With Efficient Modular DesignsabstractThe metaverse is envisioned to create immersive and virtual worlds for people to experience interoperable 3D applications. However, the real-time, interactive, and multimedia characteristics of the metaverse applications require strict quality-of-service (QoS) on the underlying networking architecture, including high throughput, ultra-low delay, and human-centric service configurations. Network function virtualization (NFV)-enabled networking resource management can provide a promising solution to service-oriented QoS satisfaction for metaverse users. In this paper, we propose a blockchain-based collaborative and verifiable virtualized network function (VNF) management scheme for metaverse, named BVNF+. BVNF+ enables multiple network providers across different trust domains to abstract their services as VNFs and collaboratively manage end-to-end network slices for human-centric network services in metaverse. To address the design challenge of balancing the on-chain and off-chain overheads, we decouple the computations of VNF queries into modular components based on software and hardware verifiable computation (vc) approaches. Our modular strategy can achieve on/off-chain computation and communication efficiency while keeping low usage of the secure hardware. We conduct security analysis and extensive experiments based on a real-world blockchain testing network. The analysis and experimental results demonstrate that BVNF+ is both secure and efficient as compared with the existing works. Cheng Huang 0001, Weihua Zhuang, Xuemin Shen, Bidi Ying |
IEEE J. Sel. Areas Commun. | 2 |
| 2024 | Data Protection: Privacy-Preserving Data Collection With ValidationabstractThe ubiquitous data collection has raised potential risks of leaking physical and private attribute information associated with individuals in a collected dataset. A data collector who wants to collect data for provisioning its machine learning (ML)-based services requires establishing a privacy-preserving data collection protocol for data owners. In this work, we design, implement, and evaluate a novel privacy-preserving data collection protocol. Specifically, we validate the functionality of the data collection protocol on behalf of data owners. First, the ML-based services are not always predefined, it is challenging for a data collector to combat inference of private attributes and user identity from the collected data while maintaining the utility of data. To address the challenge, we reconstruct the data by designing a data transformation model based on the autoencoder and clustering. Second, it is necessary to ensure that the reconstructed data satisfy certain privacy-preserving properties as untrusted data collectors can provide the data transformation models. Therefore, we utilize detection models and design an efficient enclave-based mechanism to validate that the reconstructed data's private attribute estimation probability is bounded by the predefined thresholds. Extensive experiments demonstrate our protocol's effectiveness, such as significantly reducing the accuracy of private attribute detection Jiahui Hou, Cheng Huang 0001, Weihua Zhuang, Xuemin Shen, Rob Sun, Bidi Ying |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Multi-Client Secure and Efficient DPF-Based Keyword Search for Cloud StorageabstractIn this paper, we propose a multi-client secure and efficient keyword search scheme for cloud storage, which is built upon distributed point function (DPF). Specifically, outsourced keyword indexes are encoded by using garbled bloom filter and cuckoo filter, instead of bloom filter adopted by most of the state-of-the-art DPF-based schemes. In this way, clients can apply cuckoo hashing into DPF and utilize a segmentation method to interact with cloud servers for keyword search, and servers can obliviously aggregate DPF evaluation results to perform the search. Accordingly, the computational complexity at server side can be significantly reduced. Furthermore, the proposed scheme preserves constant downlink overheads, which is more communication-efficient for multi-keyword conjunctive search. To achieve privacy preservation and access control for multiple clients, we propose a double encryption method to encrypt outsourced indexes and correspondingly put forward an authorization algorithm from set-constrained pseudorandom functions by which fine-grained search-authorized keys can be generated, and collusion attacks among clients are addressed by integrating Wegman-Carter message authentication codes and cover-free systems. Since our scheme is designed under both semi-honest and malicious models (i.e., malicious servers may return incorrect query results), we use a simulation-based proof to formally demonstrate its security properties. Finally, we develop a proof-of-concept prototype and perform extensive experiments to show our scheme's practicality and efficiency in terms of computation, communication, and storage overheads. Cheng Huang 0001, Anjia Yang, Rongxing Lu, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Data Poisoning Attacks and Defenses to LDP-Based Privacy-Preserving CrowdsensingabstractIn this paper, we explore data poisoning attacks and their defenses in local differential privacy (LDP)-based crowdsensing systems. First, we construct data poisoning attacks launched by corrupted workers to subvert crowdsensing results by tampering information reported. Specifically, the attacks are formulated as a bi-level optimization problem where attackers strive to conceal their malicious behavior by delicately exploiting noise perturbation introduced by LDP protocols. In this way, the attacks can not be detected, even with the weight-based truth discovery methods. Due to the NP-hard nature of the bi-level problem, we decompose it into upper-level and lower-level sub-problems and employ the augmented Lagrangian method to iteratively solve them, ultimately identifying optimal attack strategies. Second, we propose corresponding countermeasures to defend against the attacks. The countermeasures are formulated as a minimization problem, with the objective of minimizing disruptions caused by attacks through the identification and removal of corrupted workers from crowdsensing systems. To solve the problem, we utilize a differential evolution algorithm instead of gradient-based methods since the objective function of the problem is not differentiable. Extensive experiments on real-world datasets are conducted to evaluate the performance of the proposed attacks and defenses. The evaluation results demonstrate that LDP perturbation indeed facilitates the success of data poisoning attacks, and the proposed defenses can accurately distinguish malicious behaviors disguised. Zhirun Zheng, Zhetao Li, Cheng Huang 0001, Saiqin Long, Mushu Li, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Efficient and Accurate Cloud-Assisted Medical Pre-Diagnosis With Privacy PreservationabstractThe emergence of cloud computing enables various healthcare institutions to outsource pre-diagnostic models and provide timely and convenient services for patients. However, healthcare institutions and patients have serious concerns about potential privacy leakage as cloud servers cannot be fully trusted. In this paper, a privacy-preserving cloud-assisted medical pre-diagnosis scheme, named NAIAD, is proposed, where patients can securely query the outsourced model and obtain their pre-diagnostic results. Specifically, the pre-diagnostic model is constructed on$k$-Nearest Neighbor ($k$NN), and Mahalanobis Distance (MD) is chosen as the similarity metric to achieve high accuracy. Accordingly, a secure MD-based comparison method (SMDC) is designed based on a matrix encryption technique. The method is a basic module of NAIAD that enables cloud servers to compare encrypted medical records and achieve privacy-preserving$k$NN-based pre-diagnosis with linear complexity. To further improve the computational efficiency, medical records are first clustered and encrypted to construct a hierarchical index tree, then patients can query the tree to speed up the query process. Detailed security analysis indicates NAIAD can resist closeness-same-pattern chosen-plaintext attack, and extensive experiments on real-world and synthetic databases demonstrate NAIAD has high query efficiency and pre-diagnosis accuracy. Dan Zhu 0001, Hui Zhu 0001, Cheng Huang 0001, Rongxing Lu, Dengguo Feng, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | PPRP: Preserving Location Privacy for Range-Based Positioning in Mobile NetworksabstractIn this paper, we propose a privacy-preserving range-based positioning scheme, named PPRP, which can preserve the location privacy of both user equipment (UE) and anchors (ACs) in mobile networks. Specifically, PPRP is established on a decentralized trust-based framework that divides trust between two location management function (LMF) servers. With such a framework, UE and ACs are allowed to securely upload their range/range-difference measurement data to LMF servers using lightweight additive secret sharing techniques (ASS) instead of cumbersome cryptographic operations. Then, PPRP takes secret-shared measurement data as inputs and decomposes UE's location estimation procedures into secure two-party matrix computation sub-protocols, which are elaborately crafted using somewhat homomorphic encryption and randomization techniques to ensure both efficiency and privacy preservation in positioning. Furthermore, to mitigate the negative effects arising from non-line-of-sight (NLoS) ACs, PPRP achieves privacy-preserving residual-based NLoS analysis. To this end, we additionally propose a series of secure two-party sub-protocols to support various non-linear functions, including comparison, division, square root computation, oblivious shuffle and sorting. These sub-protocols serve as fundamental modules that can be effectively combined to perform sophisticated operations of NLoS analysis in a privacy-preserving manner. A comprehensive simulation-based security analysis demonstrates that PPRP can achieve location privacy preservation. Finally, we develop a proof-of-concept prototype and conduct extensive experiments to show PPRP's high performance in terms of positioning accuracy, computational efficiency, and communication complexity. Cheng Huang 0001, Anjia Yang, Rongxing Lu, Xuemin Shen |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Enabling Efficient and Distributed Access Control for Pervasive Edge Computing ServicesabstractIn this paper, we propose an efficient and distributed service access control framework (E-DAC) in the pervasive edge computing (PEC) environment, where the resources of peer devices at the network edge are integrated to provide latencysensitive computing services to the nearby devices on behalf of edge servers. E-DAC addresses the challenge of efficient and distributed service access control, comprising edge service authorization, service access authorization, and mutual authentication between edge servers and edge devices. In dong so, E-DAC first extends a key-aggregate cryptosystem to enable batch service authorization, in which a service provider can aggregate the authorization keys of different services to produce a constant-size aggregate key for an edge server. Second, E-DAC enables users to acquire authorization from the service provider for service access on edge servers by using efficient secret sharing. Third, edge servers and users can authenticate with each other without interacting with a centralized server, while enabling secure zero-round trip communication, so that the service data is protected and the communication bandwidth cost is low. In addition, the service provider is capable of efficiently revoking the authorization of the dropout or compromised edge servers or users in response to the dynamics of the PEC environment. Finally, we prove the security of service access control in E-DAC, including unforgeability of service authorization and confidentiality of service data, and conduct extensive analysis and experiments to demonstrate that E-DAC is highly computational and communication-efficient on service authorization, authentication, and revocation. Lingshuang Liu, Cheng Huang 0001, Dan Zhu 0001, Jianbing Ni, Xuemin Shen |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Secure, Dynamic, and Efficient Keyword Search With Flexible Merging for Cloud StorageabstractIn this paper, we propose a Mergeable Searchable Symmetric Encryption (MSSE) scheme to enable secure keyword search and updates over encrypted cloud data. Particularly, MSSE allows flexible keyword merging, where users can remotely merge file identifiers associated with keywords to create new keyword-to-file identifier relationships. The function is designed for a user to manage their outsourced data conveniently. To this end, we first introduce a new encrypted index where each keyword's relevant file identifiers are grouped, encoded, and encrypted with super-increasing sequences and homomorphic encryption. With such an index, users leverage Distributed Multi-point Functions (DMPFs) to achieve secure keyword search and merge, maintaining efficiency while ensuring high privacy. To address the issue of maintaining “merging consistency” between pre-merged entries and newly updated entries, we employ the DMPF on clusters that incorporate the updated files. The approach significantly minimizes client-side computational overhead compared to re-executing the entire keyword merging process. We formally prove that MSSE can achieve parallel privacy. Extensive performance evaluation shows that MSSE is efficient in terms of computational and communication overheads. Xi Zhang 0005, Cheng Huang 0001, Ye Su 0001, Jing Qin 0002 |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | Adaptive Distributed Learning with Byzantine Robustness: A Gradient-Projection-Based MethodabstractIn this paper, we propose an adaptive distributed learning algorithm that not only resists three types of Byzantine attacks (i.e., gradient negative direction attacks, gradient partial dimension zeroing attacks, gradient scaling attacks) but also ensures high model accuracy. The proposed algorithm is built on a fully distributed model: clients share their local model updates with a group of dynamic committee clients, who cooperatively and iteratively train a global model. Specifically, to counter gradient negative direction attacks, we design a method based on gradient projection that maps clients' local gradients into small subspaces. The design allows committee clients to efficiently and precisely filter out adversarial clients by comparing angles between these subspaces. Moreover, considering that data heterogeneity among clients may cause misdetections of gradient partial dimension zeroing and scaling attacks, thereby reducing model accuracy, we introduce an adaptive multi-dimensional scoring method, which is applied after the gradient-projection-based filtering. The method assists committee clients in scoring and selecting most suitable clients for model aggregation using three hyperparameters, and thus achieves a balance between model accuracy and security. Finally, we conduct extensive experiments on real-world datasets to show the proposed algorithm's effectiveness: it can achieve Byzantine robustness and simultaneously maintain high model accuracy. Xinghan Wang 0001, Cheng Huang 0001, Jiahong Ning, Tingting Yang 0001, Xuemin Shen |
GLOBECOM | 2 |
| 2023 | Blockchain-Assisted Secure Intra/Inter-Domain Authorization and Authentication for Internet of ThingsabstractMultidomain Internet of Things (IoT) is faced with serious domain interoperability (DI) and compatibility issues since different intradomain authorization and authentication (A&A) mechanisms are deployed without the consideration of interdomain A&A. This article proposes a blockchain-assisted scheme to achieve flexible intra- and inter-domain A&A simultaneously and seamlessly. Specifically, we first design a contract-based mutual access control agreement on top of a consortium blockchain, where domain managers can manage their access permission without any trusted parties. Based on the agreement, a secure and privacy-preserving authentication protocol is further proposed by tailoring one-out-of-many proof techniques, which enables IoT devices to anonymously access authorized IoT domains. We additionally design a voting-based protocol by using a threshold-based cryptosystem. The protocol allows domain managers to transparently audit resource access with the assistance of the blockchain. Detailed security analysis demonstrates that the proposed scheme achieves the security properties, such as DI, privacy protection, and accountability. Finally, we develop two proof-of-concept prototypes in a physical testbed and virtual machine, respectively, based on an open-source blockchain platform to show our scheme’s efficiency in terms of computation and communication overhead. Fei Tong 0001, Xing Chen 0021, Cheng Huang 0001, Yujian Zhang, Xuemin Shen |
IEEE Internet Things J. | 3 |
| 2023 | A Blockchain-Based Copyright Protection Scheme With Proactive DefenseabstractCopyright protection, including copyright registration, copyright transfer and infringement penalty, plays a critical role in preventing illegal usage of original works. The mainstream traditional copyright protection schemes need an authority online all the time to handle copyright issues and face some problems such as intricate copyright transfer, single point of failure and so on. To alleviate the burden of the authority, a few blockchain-based copyright protection schemes are proposed. However, most of them do not consider copyright transfer, and their infringement penalty may only happen after copyright owners discover the infringement behavior (i.e., “ex-post penalty”). In this article, we propose a new security strategy, called “Proactive Defense” in copyright protection which can prevent infringement before it occurs. With our proposed proactive defense strategy, we design a secure copyright protection scheme which provides advantages of compact copyright transfer and prior infringement penalty. More concrete, both copyright registration and transfer are regarded as transactions and recorded to the blockchain. Based on the double-authentication-prevention signature and non-interactive zero-knowledge proof techniques, illegal copyright transfer can be detected and the infringement penalty can be done automatically with a tailored smart contract before the completion of the transfer. Our security analysis shows that the proposed scheme can achieve all desirable security properties. Moreover, we implement our scheme in Java and evaluate the performance experimentally. Experimental results show that the proposed scheme has good security and efficiency, which can be applied for the copyright protection. Anjia Yang, Jian Weng 0001, Cheng Huang 0001, Tao Li 0067 |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | Secure and Distributed Access Control for Dynamic Pervasive Edge Computing ServicesabstractPervasive edge computing (PEC) integrates the re-sources of peer devices at the network edge to serve users' latency-sensitive computation needs. Due to the high dynamics of the PEC environment, it is very challenging to achieve efficient service access control of edge servers and users without an “always-online” centralized server. In this paper, we propose a secure, efficient, and distributed service access control frame-work (SE-DAC) in the PEC environment. Specifically, SE-DAC extends the key-aggregate cryptosystem to achieve batch service authorization, where the service provider aggregates the access keys of different services to produce a constant-size aggregate key for the edge servers. Meanwhile, user authentication tasks are delegated to the edge servers by integrating secret sharing. The mutual authentication between the edge servers and the users is based on zero-round trip communication, such that the communication bandwidth cost is low. In addition, the service provider can efficiently revoke the authorization of the dropout or compromised edge servers in response to the dynamics of the PEC environment. Finally, we conduct numerical analysis and experiments to demonstrate that SE-DAC is highly computational efficient on service authorization, authentication, and revocation. Lingshuang Liu, Cheng Huang 0001, Dan Zhu 0001, Jianbing Ni, Xuemin Shen |
GLOBECOM | 2 |
| 2022 | Defending Against DDOS Attacks on IoT Network Throughput: A Trust-Stackelberg Game ModelabstractIoTs generally rely on resource-constrained devices to sense, relay, and collect data, which are highly vulnerable to Distributed-Denial-of-Services (DDOS) attacks on network throughput. In this paper, we propose a trust-based method to optimize the network throughput of IoTs under DDOS attacks. Specifically, with the assistance of a small number of dedicatedly deployed defense nodes as defenders, a network controller can first measure the behavior of other IoT nodes and categorize them into three types (i.e., innocent, selfish, and attack) through a well-designed trust evaluation model. Then, a Stackelberg game model is constructed accordingly, where defenders are leaders and other nodes are followers. We carefully define the utilities of the leaders and the followers in the game, and transform the optimization problem of the network throughput into the maximization problem of the defenders' utilities considering the utilities of the followers. We adopt the Dinkelbach Programming (DP)-based algorithm to solve the maximization problem such that a Stackelberg equilibrium can be reached with optimized network throughput. Extensive simulations are performed to demonstrate that the proposed defense method can significantly increase the IoT network throughput under different DDOS attack intensities. Chunyang Qi, Jie Huang 0016, Cheng Huang 0001, Huaqing Wu, Xuemin Shen |
GLOBECOM | 3 |
| 2022 | Divertible Searchable Symmetric Encryption for Secure Cloud StorageabstractSearchable Symmetric Encryption (SSE) is a promising method for users to store data in remote clouds securely and search them using keywords over an encrypted index. In this paper, we explore a new function named “keyword diverting” and propose a variant of SSE named Divertible Searchable Symmetric Encryption (DivSSE). Specifically, the index in DivSSE is encoded into an inverted, compressed, and encrypted format, by using the super-increasing sequence, symmetric homomorphic encryption (SHE), and a secure hash function. According to the homomorphic properties of SHE, users can construct a unique keyword diverting token, which can be utilized to update the encrypted index by obliviously merging data identifiers corresponding to different keywords without searching in advance and thus achieve keyword diverting. Moreover, based on function secret sharing, DivSSE can protect users' search patterns and reduce communication costs with the assistance of two independent clouds. Detailed security proof demonstrates that DivSSE can achieve parallel privacy, forward privacy, and backward privacy. Extensive performance evaluation also shows that DivSSE is efficient in terms of computational and communication overheads. Xi Zhang 0005, Cheng Huang 0001, Ye Su 0001, Jing Qin 0002, Xuemin Shen |
GLOBECOM | 2 |
| 2022 | Efficient Server-Aided Personalized Treatment Recommendation with Privacy PreservationabstractWith AI-derived knowledge graph (KG), medical centers can recommend appropriate treatment options to physicians as references based on their patients' personal healthcare information (PHI). However, the treatment recommendation services may also cause serious privacy concerns. In this paper, we propose an efficient and privacy-preserving personalized treatment recommendation scheme with the aid of a third-party server. Specifically, a medical center denotes the KG of each disease by a directed graph with conditional edges and vertices that describe the treatment options and costs in different states. To prevent privacy leakage while reducing computational and management cost, the graphs are encrypted and then delegated to an honest-but-curious server. With the assistance of the server, physicians can set proper illness states and cost requirements according to patients' PHI, and correspondingly generate personalized ciphertexts to retrieve appropriate treatment options. The key component of the proposed scheme is a novel designed secure and flexible path comparison protocol, by tailoring a symmetric homomorphic encryption algorithm and combining it with a secure hash function. The protocol can enable the server to compare the uploaded ciphertexts with encrypted graphs in a secure and efficient way. Comprehensive security analysis indicates that the proposed scheme can meet desirable privacy requirements, and extensive experimental results demonstrate its practicality. Dan Zhu 0001, Hui Zhu 0001, Cheng Huang 0001, Rongxing Lu, Xuemin Shen, Dengguo Feng |
GLOBECOM | 3 |
| 2022 | Secure and Flexible Data Sharing for Distributed Storage with Efficient Key ManagementabstractIn this paper, we propose a Secure and Flexible Data Sharing (SFDS) scheme for distributed storage, where data owners can outsource their data to a distributed storage network and share the data with authorized users. To preserve confidentiality, all data are encrypted by data owners’ secret keys before being outsourced, and fine-grained access policies are enforced on the encrypted data (ciphertexts) to achieve flexible data sharing. Furthermore, based on the ciphertext puncturable encryption and the hierarchical identity-based encryption, we design an efficient key and ciphertext update mechanism, which enables data owners to update their secret keys and the corresponding ciphertexts periodically to deal with side-channel attacks and system vulnerabilities. Update tokens are constructed to directly derive new keys and ciphertexts. Through detailed security analysis, it is demonstrated that SFDS can achieve all three essential security properties, i.e., forward security, post-compromise security, and collusion attack resistance. Cheng Huang 0001, Xuemin Shen, Weihua Zhuang, Rob Sun, Bidi Ying |
ICC | 3 |
| 2022 | Blockchain-Assisted Transparent Cross-Domain Authorization and Authentication for Smart CityabstractSecure cross-domain authorization and authentication (AA) enable application service providers (ASPs) to allow users for resource access from different trusted domains. In this article, we propose a unified blockchain-assisted secure cross-domain AA framework for smart city, which can guarantee transparent cross-domain resource access while preserving user privacy. In the framework, ASPs can flexibly delegate their authentication capabilities to the blockchain, and users authorized by different ASPs can be authenticated by the blockchain where the authentication events are publicly audited and traced. Since the blockchain is publicly accessible, users’ sensitive identity attributes may be exposed during the authentication process. To address privacy leakage caused by the authentication events, several privacy-preserving techniques, including threshold-based homomorphic encryption, zero-knowledge proof, and random permutation, are exploited to hide users’ sensitive information on the blockchain. Moreover, to improve user revocation efficiency, we integrate a cryptographic accumulator and secure hash functions into the framework where ASPs are allowed to revoke their users through a global revocation contract. Our security analysis shows that the proposed framework can achieve all desirable security and privacy properties, and a proof-of-concept prototype has been developed to demonstrate the correctness and efficiency of the proposed framework. Cheng Huang 0001, Xuemin Shen, Weihua Zhuang, Rob Sun, Bidi Ying |
IEEE Internet Things J. | 1 |
| 2022 | Blockchain-Based Credential Management for Anonymous Authentication in SAGVNabstractIn this paper, we propose a blockchain-based collaborative credential management scheme for anonymous authentication in space-air-ground integrated vehicular networks (SAGVN), namedSAG-BC. First, we build a consortium blockchain among service providers and design a distributed system setup (DSS) scheme to securely generate public parameters for issuing credentials. Second, we design a collaborative credential issuance (CCI) scheme to generate a succinct and easy-to-manage subscription credential. The credential can be used by users to access different access points in SAGVN efficiently without revealing true identities from the authentication messages. With co-designs of zero-knowledge proofs and succinct on-chain commitments,SAG-BCprovides efficient verifiability and incentives for credential management operations in SAGVN. By doing so, expensive on-chain storage and computational overheads are reduced in the DSS and CCI. Finally, we conduct a thorough security analysis to demonstrate thatSAG-BCachieves security and verifiability for credential management in SAGVN. We set up a real-world blockchain network and conduct extensive experiments to show the feasibility and efficiency ofSAG-BC. Huaqing Wu, Cheng Huang 0001, Jianbing Ni, Xuemin Shen |
IEEE J. Sel. Areas Commun. | 3 |
| 2022 | Blockchain-Based Data Sharing With Key Update for Future NetworksabstractFuture networks incorporate artificial intelligence to enable smart resource management and adaptive service provisioning. With a heterogeneous architecture and a large number of users in future networks, transparent and decentralized data sharing is required to promote data circulation and break data silos, for which blockchain is a potential solution to allow intelligent access permission control. However, it remains a challenging task to achieve flexible authorization management for blockchain-based data sharing and efficient key update for multi-users in case of key exposure. In this paper, we propose an intelligent blockchain-based data-sharing scheme with key update for future networks. First, we design a new encryption scheme, where keywords of data are extracted using machine learning algorithms that are published on the blockchain. Then, keywords of data and time validity are used to encrypt different types of data for flexible data authorization. Second, using hierarchical identity-based encryption, we construct an efficient key update mechanism, where update tokens are generated by invoking a smart contract deployed on the blockchain to facilitate key and ciphertext updates. We formally prove that the proposed scheme can guarantee three essential security properties: forward security, post-compromise security, and collusion attack resistance. On-chain and off-chain experiment results are provided to demonstrate that the proposed scheme can achieve computational and communication efficiency for key and ciphertext updates. Cheng Huang 0001, Xuemin Shen, Weihua Zhuang, Rob Sun, Bidi Ying |
IEEE J. Sel. Areas Commun. | 3 |
| 2022 | Blockchain-Cloud Transparent Data Marketing: Consortium Management and FairnessabstractData are generated by Internet of Things (IoT) devices and centralized at a cloud server, that can later be traded with third parties, i.e., data marketing, to enable various data-intensive applications. However, the centralized approach is recently under debate due to the lack of (1) transparent and distributed marketplace management, and (2) marketing fairness for both IoT users (data sellers) and third parties (data buyers). In this paper, we propose a Blockchain-Cloud Transparent Data Marketing (Block-DM) with consortium management and executable fairness. First, we introduce a hybrid data-marketing architecture, where the cloud acts as an efficient data management unit and a consortium blockchain serves as a transparent marketing controller. Under the architecture, consent-based secure data trading and identity privacy for data owners are achieved with the distributed credential issuance and threshold credential openings. Second, with a consortium committee, we design a fair on/off-chain data marketing protocol. By financial incentives and succinct ‘commitments’ of marketing operations, the protocol can achieve the marketing fairness and effective detection of unfair marketing operations. We demonstrate the security of Block-DM with thorough analysis. We conduct extensive experiments with a consortium blockchain network on Hyperledger Fabric to show the feasibility and practicality of Block-DM. Cheng Huang 0001, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Computers | 2 |
| 2022 | Delegating Authentication to Edge: A Decentralized Authentication Architecture for Vehicular NetworksabstractSecure and efficient access authentication is one of the most important security requirements for vehicular networks, but it is difficult to fulfill due to potential security attacks and long authentication delay caused by high vehicle mobility, etc. Most of the existing authentication protocols, either do not consider attacks like single point of failure or do not focus on reducing authentication delay. To address these issues, we introduce an edge-assisted decentralized authentication (EADA) architecture, which provides secure and more communication-efficient authentication by enabling an authentication server to delegate its authentication capability to distributed edge nodes (ENs) such as roadside units (RSUs) and base stations (BSs). Under the architecture, we propose a threshold mutual authentication protocol that supports fast handover, which involves two scenarios, Auth-I and Auth-II. Auth-I only happens once when a vehicle tries to access the network for the first time, while Auth-II happens when a vehicle seamlessly roams between two ENs, i.e., handover. Specifically, for Auth-I, each vehicle can be cooperatively authenticated by$t$out of$n$ENs with identity-based signature techniques to obtain an authentication token and the involved ENs can be efficiently authenticated in a batch by the vehicle. For Auth-II, the vehicle can utilize the token as its private credential to achieve fast handover based on identity-based signature without interacting with multiple ENs, which further reduces the authentication delay significantly. In addition, we design a flexible method to support dynamic joining and leaving of ENs without the assistance of a trusted center. We demonstrate that the proposed protocol is secure and efficient through security analysis and performance evaluation. Anjia Yang, Jian Weng 0001, Kan Yang 0001, Cheng Huang 0001, Xuemin Shen |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | Location Privacy-Preserving Task Recommendation With Geometric Range Query in Mobile CrowdsensingabstractIn mobile crowdsensing, location-based task recommendation requires each data requester to submit a task-related geometric range to crowdsensing service providers such that they can match suitable workers within this range. Generally, a trusted server (i.e., database owner) should be deployed to protect location privacy during the process, which is not desirable in practice. In this paper, we propose the location privacy-preserving task recommendation (PPTR) schemes with geometric range query in mobile crowdsensing without the trusted database owner. Specifically, we first propose a PPTR scheme with linear search complexity, named PPTR-L, based on a two-server model. By leveraging techniques of polynomial fitting and randomizable matrix multiplication, PPTR-L enables the service provider to find the workers located in the data requester’s arbitrary geometric query range without disclosing the sensitive location privacy. To further improve query efficiency, we design a novel data structure for task recommendation and propose PPTR-F to achieve faster-than-linear search complexity. Through security analysis, it is shown that our schemes can protect the confidentiality of workers’ locations and data requesters’ queries. Extensive experiments are performed to demonstrate that our schemes can achieve high computational efficiency in terms of geometric range query. Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Jianbing Ni, Cheng Huang 0001, Xuemin Shen |
IEEE Trans. Mob. Comput. | 5 |
| 2022 | Authenticated and Prunable Dictionary for Blockchain-Based VNF ManagementabstractNetwork function virtualization is a key enabling technology in future wireless networks for flexible and efficient sharing of network resources. Due to the increasing heterogeneity of network resource providers, a blockchain-based distributed architecture is a promising solution to enable reliable and transparent virtualized network function (VNF) management. However, since on-chain storage and computation are costive, it becomes a challenging task to achieve efficient VNF management with blockchain. In this paper, we first introduce a consortium blockchain for collaborative VNF management among network resource providers. Then, we propose an authenticated VNF dictionary that can be stored as a succinct authenticator on blockchain to support rich VNF query functionalities and efficient verifications of query results. Moreover, we design a dictionary pruning strategy to securely generate a compact authenticator for a given query, which reduces unnecessary memory accesses of the original dictionary when VNF queries are represented as arithmetic circuits. Finally, we conduct extensive experiments with a consortium blockchain network. The experimental results demonstrate that our pruning strategy is efficient for both on-chain and off-chain VNF management. Cheng Huang 0001, Jiahui Hou, Xuemin Shen, Weihua Zhuang, Rob Sun, Bidi Ying |
IEEE Trans. Wirel. Commun. | 2 |
| 2021 | Achieving Accountable and Efficient Data Sharing in Industrial Internet of ThingsabstractIn this article, we propose an accountable and efficient data sharing scheme for industrial IoT (IIoT), named an accountable and data sharing scheme (ADS), in which a data owner can pursue the responsibility of a data receiver if the latter leaks some sensitive shared data to the public for profits while without permission (i.e., accountability). Specifically, ADS is built upon an adaptive decentralized oblivious transfer protocol together with a zero-knowledge proof technique, which enables the data receiver's private key to be hidden from the data owner and yet correctly embedded into the shared data during the process of data sharing. Once data breaches occur, the private key can be automatically revealed to the data owner so as to achieve the accountability. In addition, with ADS, a group of sharing providers can also assist IIoT devices in handling heavy computational tasks via the secret sharing technique without sacrificing the security. Extensive performance evaluations are conducted, and the simulation results demonstrate that ADS has high computational efficiency, making it well fit for IIoT. Cheng Huang 0001, Jianbing Ni, Rongxing Lu, Xuemin Shen |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | Efficient and Privacy-Preserving Non-Interactive Truth Discovery for Mobile CrowdsensingabstractTruth discovery is one of the key technologies to extract truthful information from unreliable sensory data collected by different mobile devices in mobile crowdsensing, but the sensory data and the outputs of truth discovery (i.e., truths and mobile devices' weights) may contain sensitive information and cause serious privacy concerns. In this paper, we propose an efficient and privacy-preServing non-interActive Truth discovEry scheme (SATE) in mobile crowdsensing. Specifically, SATE is designed based on a two-cloud model. First, the sensory data is encoded into two parts (i.e., perturbed data and noises) at the mobile device, which are maintained by two clouds separately. Second, by utilizing an adapted distributed public key homomorphic cryptosystem, two clouds can co-operatively exchange the intermediate weights and truths in a privacy preserving manner and thus achieve privacy-preserving truth discovery without the participation of the mobile devices. Security analysis demonstrates that SATE can provide full privacy protection for sensory data, weights, and truths. Performance evaluation also shows that SATE can achieve high computational efficiency and low communication overhead on the mobile devices, since there is no time-consuming cryptographic operation involved. Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Jianbing Ni, Cheng Huang 0001, Xuemin Shen |
GLOBECOM | 5 |
| 2020 | Secure and Efficient Distributed Network Provenance for IoT: A Blockchain-Based ApproachabstractNetwork provenance is essential for Internet-of-Things (IoT) network administrators to conduct the network diagnostics and identify root causes of network errors. However, the distributed nature of the IoT network results in the management of the provenance data at different trust domains, which poses concerns on the security and trustworthiness of the cross-domain network diagnostics. In this article, we propose a blockchain-based architecture for secure and efficient distributed network provenance (SEDNP) in the IoT. Instead of directly storing and querying the whole provenance data on the blockchain with prohibitive implementation cost, we introduce a unified provenance query model and develop a provenance digest strategy that: 1) enables compact (constant size) on-blockchain digests of provenance data and a multilevel index regardless of provenance data volume and 2) ensures the correctness and integrity of provenance query results through the verification of the on-blockchain digests. We formally define the security requirements as Archiving Security along with thorough security analysis. Moreover, we conduct extensive experiments with the integration of a verifiable computation (VC) framework and a blockchain testing network. The experimental results are provided as performance benchmarks to demonstrate the application feasibility of SEDNP. Jianbing Ni, Cheng Huang 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Internet Things J. | 3 |
| 2019 | Exploring Anonymous User Reviews: Linkability Analysis Based on Machine LearningabstractIdentity anonymization is believed to be a common mechanism to protect users' privacy in a public review platform, as each user's unique identifier is removed to ensure pseudonymity and unlinkability. However, the usefulness of the mechanism is not explicit, i.e., whether it is possible for an adversary to link anonymous reviews from the same user has not been well studied. In this paper, we attempt to explore this issue by means of machine learning techniques. Specifically, we first extract major features from anonymous reviews and propose some adaptive metrics to measure their effectiveness. Then, we exploit these features and several machine learning methods to link the anonymous reviews created by the same user in a real- world dataset. Considering that different adversaries has different background knowledge, both supervised and unsupervised methods, such as random forest and hierarchical agglomerative clustering, are designed and utilized to perform linkability attacks. The simulation results demonstrate that the supervised methods have a good performance, i.e., almost 40% anonymous reviews can be accurately linked to users if an adversary has the background knowledge. The unsupervised methods, compared with supervised methods, has a bad performance, i.e., it is difficult for an adversary without the background knowledge to link anonymous reviews with a high probability. Cheng Huang 0001, Jianbing Ni, Rongxing Lu, Xuemin Shen |
GLOBECOM | 1 |
| 2019 | Privacy-Preserving Interest-Ability Based Task Allocation in CrowdsourcingabstractNumerous crowdsourcing applications have emerged in our daily lives, which enable customers to outsource their complicated tasks to a crowd of workers. However, the information of task tags and worker profiles is explicitly obtained by the crowdsourcing server to recommend tasks effectively, which violates the privacy of both customers and workers. Moreover, the worker's ability to do the task should also be verified in a privacy-preserving way. To address these issues, we propose a privacy-preserving interest-ability based task allocation scheme in crowdsourcing, which protects both task and worker privacy and enables the crowdsourcing server to allocate tasks in a fine-grained way. Specifically, by utilizing attribute-based encryption (ABE) and proxy re-encryption based searchable encryption (PRE-SE) on the task content and task tags respectively, customers are able to enforce fine-grained ability requirements on their tasks, and workers can specify flexible interests to choose their desired tasks. Additionally, ElGamal signature enables workers to prove their abilities to the crowdsourcing server without revealing the task content. Numerical analysis and experiment results demonstrate that our proposed scheme is efficient in terms of computation and storage overhead and is practical to be implemented in crowdsourcing. Jialu Hao, Cheng Huang 0001, Guangyu Chen, Ming Xian, Xuemin Shen |
ICC | 2 |
| 2019 | Online Advertising with Verifiable FairnessabstractOnline advertising is a popular business model where advertisers can deliver promotional marketing messages to their potential consumers via Ad brokers. However, as the proxy between advertisers and customers, a malicious Ad broker could arbitrarily fabricate the advertising rates to overcharge advertisers, which causes unnecessary financial loss. To deal with this issue, we propose a publicly verifiable and fair online advertising scheme. Specifically, a proof-of-downloading (PoD) protocol is first designed based on the zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK), to help the customer generate a unique acknowledgment for downloading the Ad; the acknowledgment will then be published to both the advertiser and the Ad broker such that anyone can verify the acknowledgment to guarantee the fairness and transparency of online advertising. Moreover, as long as the customer's private key is not leaked, our scheme can resist the collusion attack, i.e., the Ad broker and the customer collude with each other to deceive the advertiser, which has not been addressed in previous works. Finally, we evaluate the performance of the proposed scheme to demonstrate its computational efficiency. Cheng Huang 0001, Jianbing Ni, Rongxing Lu, Xuemin Shen |
ICC | 1 |
| 2019 | Forward Secure and Fine-grained Data Sharing for Mobile CrowdsensingabstractSecure task-driven data sharing can improve the sensing data usage and protect data confidentiality in mobile crowdsensing (MCS). However, the existing data sharing schemes lack efficient support of forward secrecy, i.e., if the secret key of a data requester is compromised, all the historically shared data will be leaked. In this paper, we propose a forward secure and fine-grained data sharing scheme in mobile crowdsensing to provide a strong security guarantee and flexible access control over the sensing data. Specifically, by incorporating puncturable encryption and attribute based encryption, a shared symmetric key for data sharing can be encrypted by an access structure over the attributes of data requesters and the introduced Bloom filter attributes. Moreover, the shared key establishment between the MCS server and data requesters can be done jointly with the both sides authentication. By utilizing the structure of the Bloom filter, the update of a private key which is used to achieve forward secrecy only needs several deletion operations and no communication with the key distributor is involved. The security proof shows our scheme is provably secure under the security model. Experiment results demonstrate the practicability of the scheme. Jianbing Ni, Cheng Huang 0001, Xiaodong Lin 0001, Xuemin Shen |
PST | 3 |
| 2019 | Fine-grained data access control with attribute-hiding policy for cloud-based IoT
Jialu Hao, Cheng Huang 0001, Jianbing Ni, Hong Rong, Ming Xian, Xuemin Shen |
Comput. Networks | 2 |
| 2019 | An efficient and privacy-Preserving pre-clinical guide scheme for mobile eHealthcare
Guoming Wang, Rongxing Lu, Cheng Huang 0001, Yong Liang Guan 0001 |
J. Inf. Secur. Appl. | 3 |
| 2018 | Efficient Outsourced Data Access Control with User Revocation for Cloud-Based IoTabstractData owners have benefited significantly from cloud computing for managing the numerous data produced by massive devices in various Internet of Things (IoT) applications, such as smart home and electronic healthcare. On the other hand, fine- grained access control on outsourced data is a big concern for data owners, after they lose physical control over their data. Key-policy attribute- based encryption (KP-ABE), which provides data confidentiality and fine-grained data access control simultaneously, can be naturally introduced in this cloud-based IoT paradigm. However, the primitive KP-ABE cannot achieve efficient data access control with flexible user revocation. In this paper, we propose an efficient and fine-grained data access control scheme based on the proxy re-encryption and key blinding techniques for cloud-based IoT. With the scheme, the decryption capability of misbehaving users can be efficiently revoked to prevent data disclosure. In addition, most of the costly update operations over ciphertexts and keys due to user revocation, are delegated to the cloud. Extensive experiment results demonstrate that our scheme is more efficient than existing solutions in terms of computation and communication overheads. Jialu Hao, Cheng Huang 0001, Jian Liu 0024, Ming Xian, Xuemin Shen |
GLOBECOM | 2 |
| 2018 | Reliable and Privacy-Preserving Selective Data Aggregation for Fog-Based IoTabstractInternet of Things (IoT) is reshaping our daily lives by bridging the gaps between physical and digital world. To enable ubiquitous sensing, seamless connection and real-time processing for IoT applications, fog computing is considered as a key component in a heterogeneous IoT architecture, which deploys storage and computing resources to network edges. However, the fog-based IoT architecture can lead to various security and privacy risks, such as compromised fog nodes that may impede developments of IoT by attacking the data collection and gathering period. In this paper, we propose a novel privacy-preserving and reliable scheme for the fog-based IoT to address the data privacy and reliability challenges of the selective data aggregation service. Specifically, homomorphic proxy re-encryption and proxy re-authenticator techniques are respectively utilized to deal with the data privacy and reliability issues of the service, which supports data aggregation over selective data types for any type-driven applications. We define a new threat model to formalize the non-collusive and collusive attacks of compromised fog nodes, and it is demonstrated that the proposed scheme can prevent both non-collusive and collusive attacks in our model. In addition, performance evaluations show the efficiency of the scheme in terms of computational costs and communication overheads. Cheng Huang 0001, Jianbing Ni, Rongxing Lu, Xuemin Shen |
ICC | 1 |
| 2017 | Achieve Efficient and Privacy-Preserving Proximity Detection Scheme for Social Applications
Fengwei Wang, Hui Zhu 0001, Rongxing Lu, Cheng Huang 0001, Hui Li 0006 |
SecureComm | 5 |
| 2017 | Secure and flexible cloud-assisted association rule mining over horizontally partitioned databases
Cheng Huang 0001, Rongxing Lu, Kim-Kwang Raymond Choo |
J. Comput. Syst. Sci. | 1 |
| 2017 | PTRS: A privacy-preserving trust-based relay selection scheme in VANETs
Hao Hu 0017, Rongxing Lu, Cheng Huang 0001, Zonghua Zhang |
Peer-to-Peer Netw. Appl. | 3 |
| 2016 | FSSR: Fine-Grained EHRs Sharing via Similarity-Based Recommendation in Cloud-Assisted eHealthcare SystemabstractWith the evolving of ehealthcare industry, electronic health records (EHRs), as one of the digital health records stored and managed by patients, have been regarded to provide more benefits. With the EHRs, patients can conveniently share health records with doctors and build up a complete picture of their health. However, due to the sensitivity of EHRs, how to guarantee the security and privacy of EHRs becomes one of the most important issues concerned by patients. To tackle these privacy challenges such as how to make a fine-grained access control on the shared EHRs, how to keep the confidentiality of EHRs stored in cloud, how to audit EHRs and how to find the suitable doctors for patients, in this paper, we propose a fine-grained EHRs sharing scheme via similarity-based recommendation accelerated by Locality Sensitive Hashing (LSH) in cloud-assisted ehealthcare system, called FSSR. Specifically, our proposed scheme allows patients to securely share their EHRs with some suitable doctors under fine-grained privacy access control. Detailed security analysis confirms its security prosperities. In addition, extensive simulations by developing a prototype of FSSR are also conducted, and the performance evaluations demonstrate the FSSR's effectiveness in terms of computational cost, storage and communication cost while minimizing the privacy disclosure. Cheng Huang 0001, Rongxing Lu, Hui Zhu 0001, Jun Shao 0001, Xiaodong Lin 0001 |
AsiaCCS | 1 |
| 2016 | PTVC: Achieving Privacy-Preserving Trust-Based Verifiable Vehicular Cloud ComputingabstractWith the development of intelligent transport systems (ITS) and vehicular ad hoc network (VANET), vehicular cloud computing (VCC) has been proposed to bring essential and potential benefits, such as improving traffic safety and offering computational services to road users. To make such computational services reliable and secure, the computation results from the vehicular cloud (VC) should be verifiable and the trustworthy vehicles need to be selected to form the VC with disclosure-minimizing privacy. To address these challenges, a privacy-preserving trust-based verifiable vehicular cloud computing scheme has been proposed in this paper, named PTVC. Specifically, the proposed PTVC scheme integrates the unique features of VCC and the requirements of privacy into traditional reputation system based on beta distribution, which can help differentiate the trust levels of the vehicles and preserve location privacy in the meantime. Moreover, by using the verifiable techniques, the cloud users can verify the correctness of outsourced computation while guaranteeing the privacy of their outsourced data. Detailed security analysis shows that the proposed PTVC scheme is secure and robust against several sophisticated attacks. In addition, performance evaluations via extensive simulations are also conducted, demonstrating its effectiveness. Cheng Huang 0001, Rongxing Lu, Hui Zhu 0001, Hao Hu 0017, Xiaodong Lin 0001 |
GLOBECOM | 1 |
| 2016 | EPPD: Efficient and privacy-preserving proximity testing with differential privacy techniquesabstractWith the ubiquity of mobile devices, location-based social networking applications have been widely used in people's daily life. However, due to the importance and sensitivity of location information, these applications may lead to serious security issues for user's location privacy. To handle these location privacy challenges, in this paper, we propose an efficient and privacy-preserving proximity testing scheme, called EPPD, for location-based services. With EPPD, a group of users can test whether they are within a given distance with minimal privacy disclosure. In specific, EPPD is comprised of two phases: first, users periodically upload their encrypted locations to service provider; and later, users can send requests to service provider for proximity testing and obtain the final testing results. Detailed security analysis shows that EPPD can achieve privacy-preserving proximity testing. In addition, performance evaluations via extensive simulations also demonstrate the efficiency and effectiveness of EPPD in term of low computational cost and communication overhead. Cheng Huang 0001, Rongxing Lu, Hui Zhu 0001, Jun Shao 0001, Abdulrahman Alamer, Xiaodong Lin 0001 |
ICC | 1 |
| 2016 | EPLQ: Efficient Privacy-Preserving Location-Based Query Over Outsourced Encrypted DataabstractWith the pervasiveness of smart phones, location-based services (LBS) have received considerable attention and become more popular and vital recently. However, the use of LBS also poses a potential threat to user's location privacy. In this paper, aiming at spatial range query, a popular LBS providing information about points of interest (POIs) within a given distance, we present an efficient and privacy-preserving location-based query solution, called EPLQ. Specifically, to achieve privacy-preserving spatial range query, we propose the first predicate-only encryption scheme for inner product range (IPRE), which can be used to detect whether a position is within a given circular area in a privacy-preserving way. To reduce query latency, we further design a privacy-preserving tree index structure in EPLQ. Detailed security analysis confirms the security properties of EPLQ. In addition, extensive experiments are conducted, and the results demonstrate that EPLQ is very efficient in privacy-preserving spatial range query over outsourced encrypted data. In particular, for a mobile LBS user using an Android phone, around 0.9 s is needed to generate a query, and it also only requires a commodity workstation, which plays the role of the cloud in our experiments, a few seconds to search POIs. Lichun Li, Rongxing Lu, Cheng Huang 0001 |
IEEE Internet Things J. | 3 |
| 2015 | A Novel Privacy-Preserving Set Aggregation Scheme for Smart Grid CommunicationsabstractIn this paper, we propose a novel privacy- preserving set aggregation scheme for smart grid communications. The proposed scheme is characterized by employing a group G of composite order n=pq to achieve two-subset aggregation from a single aggregated data. With the proposed set aggregation scheme, the control center in smart grid is able to obtain more fine- grained data aggregation results for better monitoring and controlling smart grid. Detailed security analysis shows that the proposed scheme can achieve privacy-preserving property with formal proof in the random oracle model. In addition, extensive experiments are conducted, and the results demonstrate the proposed scheme is also efficient in terms of low computational costs and communication overheads. Rongxing Lu, Khalid Nawaf Alharbi, Xiaodong Lin 0001, Cheng Huang 0001 |
GLOBECOM | 4 |
| 2015 | PGuide: An Efficient and Privacy-Preserving Smartphone-Based Pre-Clinical Guidance SchemeabstractWith the pervasiveness of smartphones, mobile e-Healthcare has attracted considerable attention in recent years. Disease risk prediction, as it can assist in predicting user's disease with big data analytics techniques, has become one of important topics in the field of e-Healthcare. However, if the privacy issue is not well addressed, disease risk predication cannot step into its flourish. Aiming at addressing this challenge, in this paper, we propose a new efficient and privacy- preserving pre-clinical guidance scheme, called PGuide, which offers self-diagnosis service to medical users in a privacy-preserving way. In specific, to motivate medical users to provide more detailed health profile for accurate disease risk prediction, we introduce a privacy-preserving comparison protocol PPCP in the PGuide scheme. As a result, with enough health profile information offered by the medical users, the accuracy of disease risk prediction can be improved. Detailed security analysis shows that our proposed PGuide scheme ensures the privacy-preservation for both medical users and service provider. In addition, the performance evaluation via extensive experiments also demonstrates that our proposed PPCP protocol is much efficient in terms of low computational cost and communication overhead. Guoming Wang, Rongxing Lu, Cheng Huang 0001 |
GLOBECOM | 3 |
| 2015 | Information Diffusion Model Based on Privacy Setting in Online Social Networking ServicesabstractSocial networking service (SNS) is one of the major technological applications based on Web 2.0, which can help users to express their views and share information with others. How to describe the information diffusion process in online SNS accurately has attracted considerable interest recently. However, almost all existing models focus on a single online SNS tool and face many challenges with multiple online SNS tools. In this paper, we turn to users’ privacy setting policies and propose a general stochastic model with multiple diffusion mechanisms in online SNS, called DMPS. Specifically, we first define a privacy protection mechanism based on information sharing in online SNS and classify nodes according to different privacy setting policies; then, we define the states of the nodes and information dissemination rules with dynamics of infectious disease; finally, we describe the evolution process of different nodes by dynamic evolution equations. Detailed simulations and analysis show that the DMPS can precisely describe the diffusion process with multiple diffusion mechanisms and have the same characteristics as a diffusion process in real online SNS. As a result, DMPS can be used to identify the underlying diffusion mechanism of information and forecast its trend in online SNS. Hui Zhu 0001, Cheng Huang 0001, Hui Li 0006 |
Comput. J. | 2 |