VLDB 2026 Research / reviewers in the wild / expert
Peng Xu 0003
dblp:84/586-3
· DBLP profile ↗
55ranked-venue papers
13as first author
35since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 7 first-author · 23 since 2021Systems, architecture and hardware · 13 · 3 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 first-author · 2 since 2021Computer networks · 3 · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dynamic searchable public-key encryption and its application
Peng Xu 0003, Willy Susilo, Wei Wang 0088 |
Frontiers Comput. Sci. | 2 |
| 2026 | Enabling Scalable Resizing in Tree-Based ORAM: A Dynamic Transformation Framework
Wei Wang 0088, Xianglong Zhang, Xingyu Guo, Peng Xu 0003, Laurence T. Yang |
IEEE Trans. Computers | 4 |
| 2026 | FDXT: Forward and Backward Private Conjunctive Searchable Encryption to Suppress Volume Leakages Caused by Cross-TagsabstractDynamic Searchable Symmetric Encryption (DSSE) allows clients to update data and search keywords securely over symmetrically encrypted data on an honest but curious server. Conjunctive DSSE, an attractive type of DSSE with expressive search, enables clients to find data containing multiple keywords simultaneously. However, recently proposed efficient conjunctive DSSE schemes, such as ODXT (in NDSS’21) and SDSSE-CQ (in PETS’25), all rely on cross-tag techniques and suffer from either forward privacy or volume-privacy leakages arising from conjunctive keywords, making them vulnerable to injection or leakage-abuse attacks. In this work, we analyze the aforementioned works in depth and design a new conjunctive DSSE scheme named FDXT. For any search query with multiple keywords, FDXT guarantees the forward privacy of all queried keywords. In contrast, ODXT only maintains the forward privacy of the single and first queried keyword. FDXT also avoids volume leakage compared with SDSSE-CQ. Finally, we compared FDXT with ODXT and SDSSE-CQ in terms of performance on the Crime, Wikipedia, and Enron datasets. The experimental results show that FDXT exhibits good performance, which is comparable to ODXT and significantly better than SDSSE-CQ. Yuanhong Li, Peng Xu 0003, Bochuan Zhang, Wei Wang 0088, Yubo Zheng, Kaitai Liang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Peekaboo, I See Your Queries: Passive Attacks Against DSSE Via Intermittent ObservationsabstractDynamic Searchable Symmetric Encryption (DSSE) allows secure searches over a dynamic encrypted database but suffers from inherent information leakage. Existing passive attacks against DSSE rely on persistent leakage monitoring to infer leakage patterns, whereas this work targets intermittent observation - a more practical threat model. We propose Peekaboo - a new universal attack framework - and the core design relies on inferring the search pattern and further combining it with auxiliary knowledge and other leakage. We instantiate Peekaboo over the SOTA attacks, Sap (USENIX' 21) and Jigsaw (USENIX' 24), to derive their ''+'' variants (Sap+ and Jigsaw+). Extensive experiments demonstrate that our design achieves >0.9 adjusted rand index for search pattern recovery and ∼90% query accuracy vs. FMA's ∼30% (CCS' 23). Peekaboo's accuracy scales with observation rounds and the number of observed queries but also it resists SOTA countermeasures, with >40% accuracy against file size padding and >80% against obfuscation. Hao Nie, Wei Wang 0088, Peng Xu 0003, Wei Chen 0187, Laurence T. Yang, Mauro Conti, Kaitai Liang |
CCS | 3 |
| 2025 | Athena: Accelerating KeySwitch and Bootstrapping for Fully Homomorphic Encryption on CUDA GPU
Peng Xu 0003, Zhaojun Lu, Wei Wang 0088, Kaitai Liang |
ESORICS (2) | 3 |
| 2025 | Power of union: Federated honey password vaults against differential attack
Peng Xu 0003, Tingting Rao, Wei Wang 0088, Zhaojun Lu, Kaitai Liang |
Comput. Secur. | 1 |
| 2025 | Efficient and verifiable keyword search over public-key ciphertexts based on blockchain
Peng Xu 0003 |
J. Inf. Secur. Appl. | 2 |
| 2025 | Attribute-Based Access Control EncryptionabstractThe burgeoning complexity of communication necessitates a high demand for security. Access control encryption is a promising primitive to meet the security demand but the bulk of its constructions rely on formulating the access control policy with identities. Attribute-based access control policy in attribute-based encryption (ABE) is known to be more expressive without relying on enumerating identities. We propose a generic framework to build attribute-based access control encryption from ciphertext-policy ABE. Our instantiations prioritize different emphases on expressiveness and efficiency. The first instantiation supports multi-valued AND-gate access control structures, while the second supports the linear-secret-sharing access structure. Both are prototyped with efficiency validated empirically. Xiuhua Wang 0009, Mengyang Yu, Yinjia Pi, Peng Xu 0003, Shuai Wang 0033, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | SpaHet: A Software/Hardware Co-design for Accelerating Heterogeneous-Sparsity based Sparse Matrix MultiplicationabstractSparse general matrix-matrix multiplication is widely used in data mining applications. Its irregular memory access patterns limit the performance of general-purpose processors, thus motivating many FPGA-based hardware innovations in recent years. Nevertheless, existing accelerators fail to efficiently support heterogeneous input matrix sparsity, which is universal in various real-world applications. With in-depth experimental analysis, we observe that their performance is bottlenecked by their fixed tiling mechanisms, which only alleviate the irregularity of one input matrix. Based on the observation, we propose SpaHet, a software/hardware co-design to accelerate heterogeneous-sparsity based sparse matrix multiplication. SpaHet adopts a dual-adaptive sliding window mechanism to cover the reuse characteristics of both input matrices simultaneously. With a specialized exploration algorithm, the window-based mechanism can automatically find the optimal tiling strategy instead of applying a fixed one based on empirical experience. A sparsity-aware merge tree is also proposed to maximize the output matrix reuse via accumulating intermediate results thoroughly. Our results on a Xilinx Alveo U280 accelerator card show that SpaHet outperforms state-of-the-art CPU-, GPU- and FPGA-based solutions by 7.71×, 1.1×, and 2.74× in performance, respectively. Haoqin Huang, Pengcheng Yao, Zhaozeng An, Ao Hu, Peng Xu 0003, Long Zheng 0003, Xiaofei Liao, Hai Jin 0001 |
DAC | 6 |
| 2024 | An NTT/INTT Accelerator with Ultra-High Throughput and Area Efficiency for FHEabstractAs a core arithmetic operation and security guarantee of Fully Homomorphic Encryption (FHE), Number Theoretic Transform (NTT) of a large degree is the primary source of computational and time overhead. In this paper, we propose a scalable and conflict-free memory mapping algorithm that breaks the memory bound and releases a large amount of on-chip resources. A flexible and no-stall hardware/software pipeline architecture is designed to boost the throughput of NTT/INTT of N = 216 to over 48,543 operations per second with area efficiency, which 4× and 10× speed up the FPGA-based (HPCA'23) and GPU-based (HPCA'23) schemes. Zhaojun Lu, Weizong Yu, Peng Xu 0003, Wei Wang 0088, Jiliang Zhang 0002, Dengguo Feng |
DAC | 3 |
| 2024 | ECLIPSE: Expunging Clean-Label Indiscriminate Poisons via Sparse Diffusion Purification
Xianlong Wang 0001, Shengshan Hu, Yechao Zhang, Ziqi Zhou 0001, Leo Yu Zhang, Peng Xu 0003, Hai Jin 0001 |
ESORICS (1) | 6 |
| 2024 | PointAPA: Towards Availability Poisoning Attacks in 3D Point Clouds
Xianlong Wang 0001, Peng Xu 0003, Wei Liu 0304, Leo Yu Zhang, Shengshan Hu, Yanjun Zhang 0002 |
ESORICS (1) | 3 |
| 2024 | A Cryptographic Hardware Engineering Course based on FPGA and Security Analysis EquipmentabstractCryptographic Hardware Engineering (CHE) is an emerging field that amalgamates cryptography principles with hardware design and implementation. It plays an increasingly important role as secure and trustworthy computing and communication is needed in all applications. In order to introduce CHE into undergraduate curriculum to prepare the next generation workforce, students must have a solid theoretical foundation in cryptography, be proficient in digital circuit design, and have access to commercial design tools and equipment. In this paper, we report our experience in developing and teaching a CHE course for junior students. The course consists of three components that are complementary to each other: digital circuits and FPGA design fundamentals, hardware implementation of cryptographic algorithms, and security analysis of cryptographic hardware. Through this course, students get a good comprehension of CHE principles and gain hands-on experience in secure cryptographic hardware design and analysis. Zhaojun Lu, Qidong Chen, Peng Xu 0003, Jiliang Zhang 0002, Gang Qu 0001 |
ACM Great Lakes Symposium on VLSI | 3 |
| 2024 | An FPGA-based Key-Switching Accelerator with Ultra-High Throughput for FHEabstractFully Homomorphic Encryption (FHE) enables computations directly on encrypted numbers, thereby preserving the privacy of sensitive information even in untrusted environments. However, the substantial computational overhead associated with homomorphic evaluations restricts the practical application of FHE schemes. To deal with the performance challenges, this paper proposes a hardware/software pipeline framework with a three-level cache architecture to accelerate the costly Key-Switching operation in FHE. This framework supports the dynamically reconfigurable processing mode, two parallelism strategies, and flexible control flow, effectively breaking the compute-bound and the memory-bound limitations. A no-stall and conflict-free memory mapping algorithm is implemented on the Xilinx U55C FPGA platform that boosts the throughput of ciphertext-ciphertext multiplication to 395 operations per second, which 1.4× and 2.5× speeds up the FPGA-based (HPCA'23) and GPU-based (HPCA'23) schemes with the same parameter set and precision. Zhaojun Lu, Peng Xu 0003, Qidong Chen, Weizong Yu, Gang Qu 0001 |
ICCAD | 2 |
| 2024 | Multi-Hop D2D Cluster Formation and Resource Allocation for Scalable Video MulticastabstractScalable video coding (SVC) associated with adaptive modulation and coding (AMC) has provided an excellent solution for transmitting real-time videos. However, some users have bad channel conditions with the base station (BS) and need help getting a good quality of service (QoS). With the fifth generation (5G) of the cellular network, these users can also receive most of the data by device-to-device (D2D) transmissions. In this paper, we focus on live video delivery scenarios. We adopt the multicast Multi-Hop D2D and reuse spectrum spatially to help broadcast the scalable videos. We aim to maximize all users’ average quality of service (QoS) by jointly optimizing D2D cluster heads (CHs) selection and channel reuse. The problem is an integer non-linear programming problem, and we decompose the problem into two subproblems: the D2D cluster formation problem and the resource allocation problem. To solve the first subproblem, we propose a greedy algorithm to form D2D clusters that can broadcast more efficiently. We convert the second subproblem to a combination of two partial graph coloring problems in two conflict graphs. An algorithm similar to the recursive largest first (RLF) algorithm but considering the conflicts in both graphs is provided for the second subproblem. We execute numerical simulations to validate the performance of our proposal. Hao Nie, Wei Wang 0088, Rui Dai 0002, Chenyan Liu, Peng Xu 0003 |
ISPA | 6 |
| 2024 | d-DSE: Distinct Dynamic Searchable Encryption Resisting Volume Leakage in Encrypted Databases
Dongli Liu, Wei Wang 0088, Peng Xu 0003, Laurence T. Yang, Bo Luo, Kaitai Liang |
USENIX Security Symposium | 3 |
| 2024 | Query Recovery from Easy to Hard: Jigsaw Attack against SSE
Hao Nie, Wei Wang 0088, Peng Xu 0003, Xianglong Zhang, Laurence T. Yang, Kaitai Liang |
USENIX Security Symposium | 3 |
| 2024 | Dynamic Searchable Symmetric Encryption With Strong Security and RobustnessabstractDynamic Searchable Symmetric Encryption (DSSE) is a prospective technique in the field of cloud storage for secure search over encrypted data. A DSSE client can issue update queries to an honest-but-curious server for adding or deleting his ciphertexts to or from the server and delegate keyword search over those ciphertexts to the server. Numerous investigations focus on achieving strong security, likeforward-and-Type-I--backwardsecurity, to reduce the information leakage of DSSE to the server as much as possible. However, the existing DSSE with such strong security cannot keep search correctness and stable security (orrobustness, in short) if irrational queries are issued by the client, like duplicate add or delete queries and the delete queries for removing non-existed entries, to the server unintentionally. Hence, this work proposes two new DSSE schemes, named SR-DSSEaand SR-DSSEb, respectively. Both two schemes achieveforward-and-Type-I--backwardsecurity while keepingrobustnesswhen irrational queries are issued. In terms of performance, SR-DSSEahas more efficient communication costs and roundtrips than SR-DSSEb. In contrast, SR-DSSEbhas a more efficient search performance than SR-DSSEa. Its search performance is close to the existing DSSE scheme with the same security but fails to achieverobustness. Haochen Dou, Zhenwu Dan, Peng Xu 0003, Wei Wang 0088, Shuning Xu, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Identity-Based Group Encryption With Keyword Search Against Keyword Guessing AttackabstractPublic key Encryption with Keyword Search (PEKS) has emerged as a solution for the receiver to securely search the sender’s encrypted data on the cloud. However, the PEKS scheme is threatened by the Keyword Guessing Attack (KGA), which leaks the receiver’s keyword privacy. To resist KGA, researchers have inherited the authentication mechanism into the PEKS system (PAEKS) but also forbid using one trapdoor to search all sender’s encrypted data. In this paper, we explore the KGA problem from grouping senders and propose the notion of Identity-based Group Encryption with Keyword Search (IBGEKS), which leverages Identity-based cryptography to securely search encrypted data. Compared with the PAEKS scheme, the IBGEKS scheme can search the sender’s ciphertexts within the same group established by the receiver via one receiver’s trapdoor. For security, we analyze the KGA problem and propose ciphertexts, identities, and trapdoors indistinguishability for IBGEKS. The evaluation depicts that the IBGEKS has competitive algorithm performance with other SA-PEKS and PAEKS schemes and has superior search performance on the Enron email dataset. Wei Wang 0088, Dongli Liu, Zilin Zheng, Peng Xu 0003, Laurence T. Yang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Themis: Robust and Light-Client Dynamic Searchable Symmetric EncryptionabstractDynamic searchable symmetric encryption (DSSE), as one of the promising cryptographic tools in cloud-based services, faces two crying needs at the age of multi-device. One is a lightweight client, and the other is robustness. A lightweight client facilitates seamless synchronization among multiple devices allowing users to feel as if they are operating on a single device, even on resource-constrained devices. Robustness ensures a reliable system that can tolerate misoperations. DSSE requires both of them to achieve a leap in practicability. However, to our best knowledge, lightweight client and robustness have not been effectively combined thus far. Most existing DSSE schemes maintain a substantial amount of state information on the client for sub-linear search efficiency, but they fail to guarantee security even correctness, after executing the client’s misoperations (e.g., duplicate addition or deletion operation and deleting non-existent targets). The seminal work on robustness, ROSE (TIFS’22), leverages a heavy primitive to preserve security and correctness during post-processing and requires a heavy client storage burden. To guarantee robustness and constant client storage simultaneously, we devise a novel method to preserve robustness timely in the process of misoperations. Specifically, we introduce an alarm mechanism to promptly eliminate the effects of misoperations. Based on the misoperation alarm mechanism and thevORAM+HIRBoblivious map (S&P’16), we propose a new DSSE schemeThemis. In addition to satisfying robustness and constant client storage, it has competitive search and update performance compared to prior representative DSSE schemes. Moreover, it is superior to existing robust schemes in search. Yubo Zheng, Peng Xu 0003, Wanying Xu, Wei Wang 0088, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | You Reset I Attack! A Master Password Guessing Attack Against Honey Password Vaults
Tingting Rao, Peng Xu 0003, Yubo Zheng, Wei Wang 0088, Hai Jin 0001 |
ESORICS (3) | 3 |
| 2023 | The Power of Bamboo: On the Post-Compromise Security for Searchable Symmetric Encryption
Peng Xu 0003, Stjepan Picek, Bo Luo, Willy Susilo, Hai Jin 0001, Kaitai Liang |
NDSS | 2 |
| 2023 | Focusing on Pinocchio's Nose: A Gradients Scrutinizer to Thwart Split-Learning Hijacking Attacks Using Intrinsic Attributes
Jiayun Fu, Xiaojing Ma 0002, Bin B. Zhu, Pingyi Hu, Ruixin Zhao, Yaru Jia, Peng Xu 0003, Hai Jin 0001, Dongmei Zhang 0001 |
NDSS | 7 |
| 2023 | High Recovery with Fewer Injections: Practical Binary Volumetric Injection Attacks against Dynamic Searchable Encryption
Xianglong Zhang, Wei Wang 0088, Peng Xu 0003, Laurence T. Yang, Kaitai Liang |
USENIX Security Symposium | 3 |
| 2023 | Keyword Search Shareable Encryption for Fast and Secure Data ReplicationabstractIt has become a trend for clients to outsource their encrypted databases to remote servers and then leverage the Searchable Encryption technique to perform secure data retrieval. However, the method has yet to be considered a crucial need for replication on searchable encrypted data. It calls for challenging works on Dynamic Searchable Symmetric Encryption (DSSE) since clients must share the search capability of the encrypted data replicas and guarantee forward and backward privacy. We define a new notion called “Keyword Search Shareable Encryption” (KS2E) and the corresponding security model capturing forward and backward privacy. In our notion, data owners are allowed to share search indexes of the encrypted data with users. A search index will be updated with a new search key before sharing to guarantee the data privacy of the source database. The target database also inherits data search efficiency along with the shared data. We further construct an instance of KS2E calledBranch, prove its security, and use real-world datasets to evaluate Branch. The evaluation results show that Branch’s performance is comparable to classical DSSE schemes on search efficiency and demonstrate the effectiveness on searching encrypted data replicas from multiple owners. Wei Wang 0088, Dongli Liu, Peng Xu 0003, Laurence T. Yang, Kaitai Liang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | DEKS: A Secure Cloud-Based Searchable Service Can Make Attackers Pay
Yubo Zheng, Peng Xu 0003, Wei Wang 0088, Willy Susilo, Kaitai Liang, Hai Jin 0001 |
ESORICS (2) | 2 |
| 2022 | A Real-Time Scalable Video Distribution Strategy Based on Dynamic Coalition and D2D BroadcastabstractEven with the assistance of scalable video coding (SVC) and adaptive modulation and coding (AMC), the Internet service providers (ISP) are still challenged by videos' surging traffic, compromising the quality of service (QoS) of end-users. To further promote the efficiency of real-time video distribution, we seek aids from the device-to-device (D2D) content distribution technique, where the user equipment (UEs) helps relay content to its nearby neighbours, reducing the transmission time of less popular video layers. To accomplish this, We introduce a new Dynamic Coalition Algorithm (DCA) which allocates spectral resources among coalitions based on their demands. The DCA consists of warm-up and update modules to handle the mobility of UEs during the transmission of real-time video. Multiple experiments show that our algorithm achieves good performance with lowered computational complexity, accelerated convergence, enhanced experience of services and robustness when broadcasting long videos. Chenyan Liu, Wei Wang 0088, Rui Dai 0002, Hao Nie, Peng Xu 0003 |
GLOBECOM | 5 |
| 2022 | LaF: Lattice-Based and Communication-Efficient Federated LearningabstractFederated learning is an emerging technology which allows a server to train a global model with the cooperation of participants without exposing the participants’ data. In recent years, there have been many studies focusing on maintaining participant privacy against honest-but-curious servers. In 2017, Google proposed a promising solution that applies double masking and secret sharing tools to protect participants’ gradients for each round of federated learning (CCS’17). However, this solution fails to achieve post-quantum security and costs high communication overhead to distribute secret shares. To address this problem, this work designs a lattice-based multi-use secret sharing scheme to avoid distributing new secret shares to all participants in each round of federated learning while achieving post-quantum security. In other words, this new tool allows each participant to update his secret shares locally while maintaining the privacy of participants’ gradients against quantum attacks. Finally, this work applies this new secret sharing technique to construct a lattice-based federated learning protoclLaF. The theoretic analysis demonstrates thatLaFsaves a lot of communication costs compared with Google’s solution, and the experimental results show thatLaFachieves higher runtime efficiency. Peng Xu 0003, Manqing Hu, Wei Wang 0088, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | ROSE: Robust Searchable Encryption With Forward and Backward SecurityabstractDynamic searchable symmetric encryption (DSSE) has been widely recognized as a promising technique to delegateupdateandsearchqueries over an outsourced database to an untrusted server while guaranteeing the privacy of data. Many efforts on DSSE have been devoted to obtaining a good tradeoff between security and performance. However, it appears that all existing DSSE works miss studying on what will happen if the DSSE client issues irrationalupdatequeries carelessly, such as duplicateupdatequeries anddeletequeries to remove non-existent entries (that have been considered by many popular database system in the setting of plaintext). In this scenario, we find that (1) most prior works lose their claimed correctness or security, and (2) no single approach can achieve correctness, forward and backward security, and practical performance at the same time. To address this problem, we study for the first time the notion of robustness of DSSE. Generally, we say that a DSSE scheme is robust if it can keep the same correctness and security even in the case of misoperations. Then, we introduce a new cryptographic primitive named key-updatable pseudo-random function and apply this primitive to constructing ROSE, a robust DSSE scheme with forward and backward security. Finally, we demonstrate the efficiency of ROSE and give the experimental comparisons. Peng Xu 0003, Willy Susilo, Wei Wang 0088, Qianhong Wu, Kaitai Liang, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Bestie: Very Practical Searchable Encryption with Forward and Backward Security
Peng Xu 0003, Wei Wang 0088, Yubo Zheng, Willy Susilo, Hai Jin 0001 |
ESORICS (2) | 2 |
| 2021 | Milvus: A Purpose-Built Vector Data Management SystemabstractRecently, there has been a pressing need to manage high-dimensional vector data in data science and AI applications. This trend is fueled by the proliferation of unstructured data and machine learning (ML), where ML models usually transform unstructured data into feature vectors for data analytics, e.g., product recommendation. Existing systems and algorithms for managing vector data have two limitations: (1) They incur serious performance issue when handling large-scale and dynamic vector data; and (2) They provide limited functionalities that cannot meet the requirements of versatile applications. Jianguo Wang 0001, Xiaomeng Yi, Rentong Guo, Hai Jin 0001, Peng Xu 0003, Shengjun Li, Xiangzhou Guo, Xiaohai Xu, Yuxing Yuan, Yinghao Zou, Jiquan Long, Yudong Cai 0002, Zhenxiang Li, Yihua Mo, Ruiyi Jiang, Charles Xie |
SIGMOD Conference | 5 |
| 2021 | SDD: A trusted display of FIDO2 transaction confirmation without trusted execution environment
Peng Xu 0003, Ruijie Sun, Wei Wang 0088, Yubo Zheng, Hai Jin 0001 |
Future Gener. Comput. Syst. | 1 |
| 2021 | Efficient Server-Aided Secure Two-Party Computation in Heterogeneous Mobile Cloud ComputingabstractWith the ubiquity of mobile devices and rapid development of cloud computing, mobile cloud computing (MCC) has been considered as an essential computation setting to support complicated, scalable and flexible mobile applications by overcoming the physical limitations of mobile devices with the aid of cloud. In the MCC setting, since many mobile applications (e.g., map apps) interacting with cloud server and application server need to perform computation with the private data of users, it is important to realize secure computation for MCC. In this article, we propose an efficient server-aided secure two-party computation (2PC) protocol for MCC. This is the first work that considers collusion between a malicious garbled circuit evaluator and a semi-honest server while ensuring privacy and correctness. Also, it can guarantee fairness when collusion does not exist. The security analysis shows that our protocol can securely compute any function f(x, y) against different types of adversaries in the malicious model. Also, the experimental performance analysis shows that this work outperforms the previous works for at least 10 times with the same security level. Yulin Wu 0001, Xuan Wang 0002, Willy Susilo, Guomin Yang, Zoe Lin Jiang, Qian Chen 0028, Peng Xu 0003 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2021 | A Fairness-Based Collaborative Communication Ecosystem Over Sustainable D2D Fogs in a 5G Industrial IoTabstractIn a 5G industrial IoT, using fog devices (FD) to release the burden of transmission data between a base station (BS) and a register user, is currently a promising method for device-to-device (D2D) communications. In this article, we propose a collaborative communication ecosystem to deploy RF-powered FDs as intermediaries to improve the utility as well as the fairness. We examine three contributing works that activate a relay-labor exchanging market. First, we build Stackelberg games to attract D2D collaborations; second, we employ an energy harvest technology and a time-switching power scheme to make exchange benefits to support the games; third, to reduce the relay redundancy and guarantee effective transmission rates, we employ network-coded flows. To solve the double-objects optimization model of our collaborative games, a genetic algorithm NSGA-II is applied to find an optimal solution to the market. We also mathematically prove the existence of an equilibrium state in the proposed games, and afterwards simulate the whole scenario using Mininet for a performance analysis. The simulation results in Mininet show that the BS and FDs in the market games all achieve desirable utilities as well as fairness among FDs. Wei Wang 0088, Laurence T. Yang, Hongrui Duan, Peng Xu 0003 |
IEEE Trans. Ind. Informatics | 5 |
| 2021 | Practical Multi-Keyword and Boolean Search Over Encrypted E-mail in Cloud ServerabstractWith the outbreak of e-mail message leakage events, such as the Hillary Clinton’s Email Controversy, privacy and security of sensitive e-mail information have become users’ primary concern. Encrypted email seems to be a viable solution for providing security, but it will greatly limit their operations. Public encryption with keyword search (PEKS) scheme is a popular technology to incorporate security protection and favorable operability functions together, which can play an important role in searching over encrypted email in a cloud server. In this paper, we propose a practical PEKS scheme named as public-key multi-keyword searchable encryption with hidden structures (PMSEHS). It could enable e-mail receivers to do the multi-keyword and boolean search in the large encrypted email database as fast as possible, without revealing more information to the cloud server. We also give comparative experiments, which demonstrate that our scheme has a higher efficiency in multi-keyword search for encrypted emails. Peiming Xu, Shaohua Tang, Peng Xu 0003, Qianhong Wu, Honggang Hu, Willy Susilo |
IEEE Trans. Serv. Comput. | 3 |
| 2020 | Lightweighted Secure Searching Over Public-Key Ciphertexts for Edge-Cloud-Assisted Industrial IoT DevicesabstractFor the industrial Internet of Things (IIoT), public-key encryption with keyword search (PEKS) is a type of applicable and promising encryption technique to maintain the data stored in clouds secure and searchable. To further improve the efficiency of searching, it is popular to introduce edge computing near the IIoT as the substitute for a cloud. However, the straightforward collaboration of the two techniques performs negatively in latency-sensitive applications since the sluggish encryption of PEKS by IIoT devices negates the instant reaction of edges. To meet this challenge, in this article, we exploit the capability of the edge-cloud architecture and propose a lightweight-designed scheme called edge-aided searchable public-key encryption (ESPE). It allows IIoT devices to delegate their costly cryptographic operations to the nearby edge for fast computing and guarantees that all outsourced ciphertexts are semantically secure. Consequently, ESPE accelerates the corresponding ciphertext procedures on edges and saves over 70% encryption cost of an IIoT device. Wei Wang 0088, Peng Xu 0003, Dongli Liu, Laurence T. Yang, Zheng Yan 0002 |
IEEE Trans. Ind. Informatics | 2 |
| 2019 | Differential Privacy Preservation for Smart Meter Systems
Junfang Wu, Weizhong Qiang, Tianqing Zhu, Hai Jin 0001, Peng Xu 0003, Sheng Shen 0005 |
ICA3PP (1) | 5 |
| 2018 | Lightweight Searchable Public-Key Encryption for Cloud-Assisted Wireless Sensor NetworksabstractThe industrial Internet of Things is flourishing, which is unprecedentedly driven by the rapid development of wireless sensor networks (WSNs) with the assistance of cloud computing. The new wave of technology will give rise to new risks to cyber security, particularly the data confidentiality in cloud-assisted WSNs (CWSNs). Searchable public-key encryption (SPE) is a promising method to address this problem. In theory, it allows sensors to upload public-key ciphertexts to the cloud, and the owner of these sensors can securely delegate a keyword search to the cloud and retrieve the intended data while maintaining data confidentiality. However, all existing and semantically secure SPE schemes have expensive costs in terms of generating ciphertexts and searching keywords. Hence, this paper proposes a lightweight SPE (LSPE) scheme with semantic security for CWSNs. LSPE reduces a large number of the computation-intensive operations that are adopted in previous works; thus, LSPE has search performance close to that of some practical searchable symmetric encryption schemes. In addition, LSPE saves considerable time and energy costs of sensors for generating ciphertexts. Finally, we experimentally test LSPE and compare the results with some previous works to quantitatively demonstrate the above advantages. Peng Xu 0003, Shuanghong He, Wei Wang 0088, Willy Susilo, Hai Jin 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2018 | Cloud-Assisted Key Distribution in Batch for Secure Real-Time Mobile ServicesabstractEstablishing promising and efficient key distribution is the cornerstone of security when applying cryptographic methods to guard the privacy of smart devices in the Internet of Things (IoT). However, when using conventional key distribution methods in real-time mobile services, it is usually deficient to build multiple channels with strong security simultaneously on a single data server. Therefore, we focus our research on collecting or monitoring real-time and remote data, which is commonly observed in the health care field of the IoT. In this research, there are difficulties to apply the conventional key distribution approaches during interactions when considering both security and efficiency. Moreover, when preserving personal privacy, anonymity is also important in key distribution processes. We design a system of real-time mobile services and the related security requirements in this paper, and apply a novel and interesting Identity-Based Key Encapsulation Mechanism (IBKEM) to instantiate our system and achieve anonymous key distribution with only one-pass communication for mobile clients in batch. Our instantiated system demonstrates both strong security and practice. Wei Wang 0088, Peng Xu 0003, Laurence T. Yang, Jinjun Chen |
IEEE Trans. Serv. Comput. | 2 |
| 2017 | Dynamic Searchable Symmetric Encryption with Physical Deletion and Small Leakage
Peng Xu 0003, Wei Wang 0088, Willy Susilo, Qianhong Wu, Hai Jin 0001 |
ACISP (1) | 1 |
| 2017 | Scalable influence maximization under independent cascade model
Feng Lu 0003, Liwen Shao, Xunfei Jiang, Peng Xu 0003, Hai Jin 0001 |
J. Netw. Comput. Appl. | 5 |
| 2017 | Securely Reinforcing Synchronization for Embedded Online ContestsabstractWhen competing in eBay bidding, online games, or e-exams in embedded computing environments, people naturally face asynchronous starts from different computing devices, which is treated as a security risk of online contests. The security risks of online contests also include eavesdropping during data transmission without intended rights, and false starts by malicious competitors, which also means asynchrony in contests. Accordingly, online contests need security guarantees, especially on synchronization. In this article, for synchronic and secure starts in a contest, we update security requirements of confidentiality, anonymity, and synchrony, comparing the current work to our previous work. Based on the updated requirements, we propose a general framework for the Advanced Secure Synchronized Reading (ASSR) system, which can hold multiple contests simultaneously in the cloud. It is important to note that the system can ignore the impacts of heterogeneity among competitors. Considering the heterogeneity both on transmission and computing, we construct a novel Randomness-reused Identity Based Key Encapsulation Mechanism (RIBKEM) to support separable decapsulation, which can shorten both decryption delay and transmission delay with the best efforts. Finally, ASSR enhances synchronization achievement for contest starts with heterogeneous delays of competitors while satisfying other security requirements. As a complement, the analysis on the provable security of ASSR is given, as well as a further analysis on the achievement of synchronization. Wei Wang 0088, Peng Xu 0003, Laurence T. Yang, Willy Susilo, Jinjun Chen |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2016 | Anonymous Identity-Based Broadcast Encryption with Constant Decryption Complexity and Strong SecurityabstractAnonymous Identity-Based Broadcast Encryption (AIBBE) allows a sender to broadcast a ciphertext to multi-receivers, and keeps receivers' anonymity. The existing AIBBE schemes fail to achieve efficient decryption or strong security, like the constant decryption complexity, the security under the adaptive attack, or the security in the standard model. Hence, we propose two new AIBBE schemes to overcome the drawbacks of previous schemes in the state-of-art. The biggest contribution in our work is the proposed AIBBE scheme with constant decryption complexity and the provable security under the adaptive attack in the standard model. This scheme should be the first one to obtain advantages in all above mentioned aspects, and has sufficient contribution in theory due to its strong security. We also propose another AIBBE scheme in the Random Oracle (RO) model, which is of sufficient interest in practice due to our experiment. Peng Xu 0003, Jingnan Li, Wei Wang 0088, Hai Jin 0001 |
AsiaCCS | 1 |
| 2016 | Generally Hybrid Proxy Re-Encryption: A Secure Data Sharing among Cryptographic CloudsabstractProxy Re-Encryption (PRE) is a favorable primitive to realize a cryptographic cloud with secure and flexible data sharing mechanism. A number of PRE schemes with versatile capabilities have been proposed for different applications. The secure data sharing can be internally achieved in each PRE scheme. But no previous work can guarantee the secure data sharing among different PRE schemes in a general manner. Moreover, it is challenging to solve this problem due to huge differences among the existing PRE schemes in their algebraic systems and public-key types. To solve this problem more generally, this paper uniforms the definitions of the existing PRE and Public Key Encryption (PKE) schemes, and further uniforms their security definitions. Then taking any uniformly defined PRE scheme and any uniformly defined PKE scheme as two building blocks, this paper constructs a Generally Hybrid Proxy Re-Encryption (GHPRE) scheme with the idea of temporary public and private keys to achieve secure data sharing between these two underlying schemes. Since PKE is a more general definition than PRE, the proposed GHPRE scheme also is workable between any two PRE schemes. Moreover, the proposed GHPRE scheme can be transparently deployed even if the underlying PRE schemes are implementing. Peng Xu 0003, Wei Wang 0088, Hai Jin 0001, Willy Susilo, Deqing Zou |
AsiaCCS | 1 |
| 2016 | Secure hybrid-indexed search for high efficiency over keyword searchable ciphertexts
Wei Wang 0088, Peng Xu 0003, Hui Li 0005, Laurence T. Yang |
Future Gener. Comput. Syst. | 2 |
| 2016 | Taming transitive permission attack via bytecode rewriting on Android applicationabstractAbstract Google Android is popular for mobile devices in recent years. The openness and popularity of Android make it a primary target for malware. Even though Android's security mechanisms could defend most malware, its permission model is vulnerable to transitive permission attack, a type of privilege escalation attacks. Many approaches have been proposed to detect this attack by modifying the Android OS. However, the Android's fragmentation problem and requiring rooting Android device hinder those approaches large‐scale adoption. In this paper, we present an instrumentation framework, called SEAPP, for Android applications (or “apps”) to detect the transitive permission attack on unmodified Android. SEAPP automatically rewrites an app without requiring its source codes and produces a security‐harden app. At runtime, call‐chains are built among these apps and detection process is executed before a privileged API is invoked. Our experimental results show that SEAPP could work on a large number of benign apps from the official Android market and malicious apps, with a repackaged success rate of over 99.8%. We also show that our framework effectively tracks call‐chains among apps and detects known transitive permission attack with low overhead. Copyright © 2016 John Wiley & Sons, Ltd. Daibin Wang, Hai Jin 0001, Deqing Zou, Peng Xu 0003, Tianqing Zhu |
Secur. Commun. Networks | 4 |
| 2016 | Conditional Identity-Based Broadcast Proxy Re-Encryption and Its Application to Cloud EmailabstractRecently, a number of extended Proxy Re-Encryptions (PRE), e.g. Conditional (CPRE), identity-based PRE (IPRE) and broadcast PRE (BPRE), have been proposed for flexible applications. By incorporating CPRE, IPRE and BPRE, this paper proposes a versatile primitive referred to as conditional identity-based broadcast PRE (CIBPRE) and formalizes its semantic security. CIBPRE allows a sender to encrypt a message to multiple receivers by specifying these receivers' identities, and the sender can delegate a re-encryption key to a proxy so that he can convert the initial ciphertext into a new one to a new set of intended receivers. Moreover, the re-encryption key can be associated with a condition such that only the matching ciphertexts can be re-encrypted, which allows the original sender to enforce access control over his remote ciphertexts in a fine-grained manner. We propose an efficient CIBPRE scheme with provable security. In the instantiated scheme, the initial ciphertext, the re-encrypted ciphertext and the re-encryption key are all in constant size, and the parameters to generate a re-encryption key are independent of the original receivers of any initial ciphertext. Finally, we show an application of our CIBPRE to secure cloud email system advantageous over existing secure email systems based on Pretty Good Privacy protocol or identity-based encryption. Peng Xu 0003, Tengfei Jiao, Qianhong Wu, Wei Wang 0088, Hai Jin 0001 |
IEEE Trans. Computers | 1 |
| 2015 | A design for cloud-assisted Fair-Play Management System of online contests with provable security
Wei Wang 0088, Peng Xu 0003, Laurence T. Yang, Hui Li 0005 |
Future Gener. Comput. Syst. | 2 |
| 2015 | Generating Searchable Public-Key Ciphertexts With Hidden Structures for Fast Keyword SearchabstractExisting semantically secure public-key searchable encryption schemes take search time linear with the total number of the ciphertexts. This makes retrieval from large-scale databases prohibitive. To alleviate this problem, this paper proposes searchable public-key ciphertexts with hidden structures (SPCHS) for keyword search as fast as possible without sacrificing semantic security of the encrypted keywords. In SPCHS, all keyword-searchable ciphertexts are structured by hidden relations, and with the search trapdoor corresponding to a keyword, the minimum information of the relations is disclosed to a search algorithm as the guidance to find all matching ciphertexts efficiently. We construct an SPCHS scheme from scratch in which the ciphertexts have a hidden star-like structure. We prove our scheme to be semantically secure in the random oracle (RO) model. The search complexity of our scheme is dependent on the actual number of the ciphertexts containing the queried keyword, rather than the number of all ciphertexts. Finally, we present a generic SPCHS construction from anonymous identity-based encryption and collision-free full-identity malleable identity-based key encapsulation mechanism (IBKEM) with anonymity. We illustrate two collision-free full-identity malleable IBKEM instances, which are semantically secure and anonymous, respectively, in the RO and standard models. The latter instance enables us to construct an SPCHS scheme with semantic security in the standard model. Peng Xu 0003, Qianhong Wu, Wei Wang 0088, Willy Susilo, Josep Domingo-Ferrer, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | A Secure Synchronized Reading system over time-critical online contestsabstractThe time-critical online contest environment calls for an elegant and precise management system to start a contest online. The management system should simultaneously follow three rules of security that are confidentiality, anonymity and fairness. We present in this paper a novel system named Secure Synchronized Reading (SSR) system as well as its corresponding security model according to the three rules. SSR can evoke a synchronized start for all competitors in a contest at the intended time by employing a Randomness-reused Identity-Based Encryption (RIBE) scheme. It can avoid huge differences among delivery delays of heterogeneous competitors and any false start by an adverse competitor. Consequently when an online contest begins, the SSR system performs quasi real-time with ignorable communication delays in the security model. As a complement, the analysis on the provable security of SSR is given finally, as well as a further analysis on the achievement of synchronization. Wei Wang 0088, Peng Xu 0003, Hui Li 0005, Laurence T. Yang |
ICC | 2 |
| 2014 | Towards Efficient Yet Privacy-Preserving Approximate Search in Cloud ComputingabstractOwing to the great advances in cloud computing and Internet technologies, data owners (DOs) have been motivated to outsource the storage of their data to remote cloud servers (CSs) in order to enjoy great data management service with an efficient cost. For security purposes, DOs usually have to encrypt their data prior to outsourcing it to the untrusted CSs. But encryption makes searching the encrypted data a challenging task. Recently, several approaches have been provided to enable searching over encrypted data. However, the majority of these systems are limited to handling an exact search, not a similarity search; but the latter is an important need for real-world applications. In this paper, we propose an efficient yet secure scheme to search encrypted cloud data, while recovering the misspellings and typographical errors that exist frequently both in the search request and in the source data. To do so, we use a metric space to construct a tree-based index, which allows retrieving only the relevant entries with a minimum number of distance evaluations. String embedding techniques are used to refine the relevant entries efficiently and securely. Our index construction maintains the privacy of the keyword trapdoors as well as the stored data. Comparing our scheme with other similarity searchable encryption systems via experiments shows that our scheme is efficient in terms of search time and storage overhead. Ayad Ibrahim, Hai Jin 0001, Ali A. Yassin, Deqing Zou, Peng Xu 0003 |
Comput. J. | 5 |
| 2013 | Public-Key Encryption with Fuzzy Keyword Search: A Provably Secure Scheme under Keyword Guessing AttackabstractPublic-key encryption with keyword search (PEKS) is a versatile tool. It allows a third party knowing the search trapdoor of a keyword to search encrypted documents containing that keyword without decrypting the documents or knowing the keyword. However, it is shown that the keyword will be compromised by a malicious third party under a keyword guess attack (KGA) if the keyword space is in a polynomial size. We address this problem with a keyword privacy enhanced variant of PEKS referred to as public-key encryption with fuzzy keyword search (PEFKS). In PEFKS, each keyword corresponds to an exact keyword search trapdoor and a fuzzy keyword search trapdoor. Two or more keywords share the same fuzzy keyword trapdoor. To search encrypted documents containing a specific keyword, only the fuzzy keyword search trapdoor is provided to the third party, i.e., the searcher. Thus, in PEFKS, a malicious searcher can no longer learn the exact keyword to be searched even if the keyword space is small. We propose a universal transformation which converts any anonymous identity-based encryption (IBE) scheme into a secure PEFKS scheme. Following the generic construction, we instantiate the first PEFKS scheme proven to be secure under KGA in the case that the keyword space is in a polynomial size. Peng Xu 0003, Hai Jin 0001, Qianhong Wu, Wei Wang 0088 |
IEEE Trans. Computers | 1 |
| 2012 | A Practical Framework for $t$-Out-of- $n$ Oblivious Transfer With Security Against Covert AdversariesabstractOblivious transfer plays a fundamental role in the area of secure distributed computation. In particular, this primitive is used to search items in decentralized databases. Using a variant of smooth projective hash previously presented by Zeng , we construct a practical framework fort-out-of-noblivious transfer in the plain model without any set-up assumption. It can be implemented under a variety of standard intractability assumptions, including the decisional Diffie-Hellman assumption, the decisionalN-th residuosity assumption, the decisional quadratic residuosity assumption, and the learning with error problem. It is computationally secure in the presence of covert adversaries and only requires four rounds of communication. Compared to existing practical protocols with fully-simulatable security against covert adversaries or malicious adversaries, our framework is generally more efficient. Christophe Tartary, Peng Xu 0003, Jiandu Jing, Xueming Tang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2010 | A more efficient accountable authority IBE scheme under the DL assumption
Peng Xu 0003, Guohua Cui, Cai Fu, Xueming Tang |
Sci. China Inf. Sci. | 1 |
| 2010 | One-time encryption-key technique for the traditional DL-based encryption scheme with anonymity
Peng Xu 0003, Guohua Cui, Feng-Yu Lei, Jing-Fang Xu |
Inf. Sci. | 1 |