VLDB 2026 Research / reviewers in the wild / expert
Zhao Zhang 0026
dblp:87/6853-26
· DBLP profile ↗
11ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0002-0178-2169ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 6 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy-preserving electricity trading matching based on blockchain in smart grid
Zhao Zhang 0026, Chunxiang Xu, Changsong Jiang |
Expert Syst. Appl. | 1 |
| 2026 | Efficient Multi-Designated Receiver Authenticated Broadcast Encryption for Group MessagingabstractCommunication protocol is a fundamental component of modern networking. With proliferation of networking and communication, users have become more concerned about privacy. This leads to development of end-to-end encrypted messaging systems which provides confidential communication. Besides confidentiality, there is an increasing demand for additional security properties such as unforgeability, anonymity, off-the-record (OTR), and consistency. However, efficiently achieving these properties simultaneously, especially on resource-constrained mobile devices, remains a significant challenge. In this paper, we propose MERIT, a novel multi-designated receiver authenticated broadcast encryption scheme that satisfies all the above security guarantees in a highly efficient manner. MERIT ensures the following key properties: (i) unforgeability prevents unauthorized parties from generating valid messages; (ii) privacy safeguards the messages and identities of the sender and receivers from non-designated parties; (iii) OTR ensures that receivers cannot later prove the origin of the messages even with their secret keys; and (iv) consistency ensures that all designated receivers obtain identical decrypted messages and identities. The core building block of MERIT is a practical multi-designated verifier signature (PMDVS), which might be of independent interest. We employed a novel batched cut-and-choose technology to prove that the ciphertext is well-formed. This results in an order-of-magnitude efficiency improvement in our scheme compared to its counterparts that rely on general-purpose zero-knowledge proofs. We then show how MERIT leverages PMDVS to provide unforgeability, privacy, OTR, and consistency in the scenario of group messaging. We provide security analysis to demonstrate that MERIT satisfies these security guarantees. We also conduct a thorough performance implementation, and the experimental results demonstrate that MERIT is highly efficient for deployment on mobile devices. Zhao Zhang 0026, Chunxiang Xu, Chuhan Ma |
IEEE Trans. Netw. | 1 |
| 2025 | LPbT-SSO: Password-Based Threshold Single-Sign-On Authentication From LWEabstractIn networks, clients access various servers. Servers need to authenticate clients' identities and provide services to clients who pass the authentication. Password-based threshold single-sign-on authentication (PbT-SSO) delegates multiple identity servers to authenticate a client with the client's password, and issue a token for subsequent access. However, existing PbT-SSO schemes are based on conventional hardness problems, which are vulnerable to adversaries equipped with quantum computers in the near future. Once quantum computers are accessible, adversaries can retrieve passwords by off-line dictionary guessing attacks (DGA) from the credentials of clients' passwords. Moreover, quantum adversaries can derive identity servers' secret from public information and further forge tokens with the secret. Motivated by these issues, we propose a password-based threshold single-sign-on authentication from learning with errors problem (LWE), dubbed LPbT-SSO, which is resistant to quantum attacks. LPbT-SSO evaluates a one-way function of passwords, and takes the function outputs as credentials. Since the function is grounded on LWE problem intractable for quantum computation, quantum adversaries cannot recover passwords by off-line DGA. Additionally, LPbT-SSO leverages a lattice-based threshold signature scheme to issue tokens, and guarantees that no adversary can forge a valid token. The comprehensive performance evaluation demonstrates that LPbT-SSO is efficient in terms of computation, storage, and communication costs. Chenchen Cao, Chunxiang Xu, Changsong Jiang, Zhao Zhang 0026, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Device-Enhanced Password-Based Threshold Single-Sign-On AuthenticationabstractPassword-based threshold single-sign-on authentication (PbTA) allows multiple identity servers to in a threshold manner authenticate a user and issue a token, with which the user accesses relevant services. We analyze existing PbTA schemes and reveal a potential threat: vulnerability against perpetual credential leakage, in which “perpetual” adversaries could perpetually attempt to compromise long-lived credential databases maintained by identity servers. Compromising a threshold number of credential databases enables the adversaries to launch offline dictionary guessing attacks (DGA) or illegally obtain users’ tokens. To address these issues, we first propose a basic device-enhanced PbTA scheme (DE-PbTA), where an auxiliary device collaborates with identity servers in hardening a user’s password during authentication, such that perpetual adversaries cannot learn the password from compromised credentials via offline DGA. Using the hardened password, a private key can be derived to decrypt ciphertexts from identity servers for token construction, which protects the user’s tokens against perpetual adversaries. Then, we extend basic DE-PbTA to support dynamic usage of multiple devices, where a user can actively choose$t^{\prime } $devices out of$n^{\prime } $for authentication. Provable security and high efficiency of the basic/enhanced DE-PbTA scheme are demonstrated by comprehensive analysis and experimental evaluations. Changsong Jiang, Chunxiang Xu, Guomin Yang, Zhao Zhang 0026, Jie Chen 0093 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Privacy-Preserving Single-Sign-on With Fine-Grained Access Control for IoT DevicesabstractIoT-based sharing economy is a win-win business model, where a transferor owns idle IoT devices and transfers the right to use a device to a user for a fee. Considering usage of multiple devices and privacy preservation, anonymous single-sign-on (ASSO) is a feasible solution for authentication. ASSO allows a user to access multiple devices with one token issued by the transferor and prevents the transferor from identifying the user. We also observe that in the scenario of IoT-based sharing economy, the token should (i) support attributes since a device should be available only to users with specific attributes (e.g., age) and (ii) avoid incurring significant communication/computation overhead as IoT devices are resource-constrained. In this paper, we proposed PILOT, a privacy-preserving single-sign-on with fine-grained access control for IoT devices. When a user attempts to access a device, he/she requests a token from the transferor. The token is actually a blind signature that cannot be tracked, and contains the user’s attributes which facilitate fine-grained access control on the device. Besides, the token consists of only four group elements and verification of the token involves only several exponentiation operations. This renders PILOT superior in terms of communication/computation overhead and suitable for IoT devices. Zhao Zhang 0026, Chunxiang Xu, Man Ho Au, Changsong Jiang |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Single-sign-on Authentication with Anonymous Token and Restricted Covert ChannelabstractSingle-sign-on authentication (SSO) enables a user to obtain a token from an identity server, and access multiple service providers with the token. In conventional SSO, the identity server can identify the user through the token, which compromises the user’s privacy. Anonymous SSO is proposed to solve this problem. However, the unconditional anonymity precludes identification of fraudulent users and leads to increase in illegitimate activities. In this paper, we propose SONAR, an anonymous single-sign-on authentication protocol that supports fraud detection. The identity server first accesses a user’s trustworthiness using fraud detection. We observe that directly refusing to issue tokens to an untrustworthy user allows the user to immediately realize that he have been detected, which poses security problems. Instead, we postpone the moment the user realizes he has been detected until he attempts to access a service provider. We also illustrate the benefits of this postponement using denial of service attacks as an example. In the proposed SONAR, the identity server issues the user (regardless of his trustworthiness) with a token that contains a covert channel, which is restricted to conveying only a 0/1 bit that is hidden from the user. The restriction of the channel prevents the identity server from tracking the user by embedding specific information in the channel, and meanwhile the 0/1 bit indicates whether the user is trustworthy or not. The token is actually a randomizable signature and can be randomized by the user, while the embedded bit remains unchanged. The user accesses a service provider with a randomized token, which protects the user from being identified as well as informs the service provider whether the user’s access should be permitted. We provide a formal security proof to demonstrate that SONAR is secure, and conduct a performance evaluation to show efficiency of SONAR. Zhao Zhang 0026, Chunxiang Xu, Man Ho Au |
TrustCom | 1 |
| 2024 | TSAPP: Threshold Single-Sign-On Authentication Preserving PrivacyabstractSingle-sign-on (SSO) authentication enables a user to gain a token from the identity server, with which the user accesses multiple services. To address single-point-of-failure of SSO, threshold SSO, where a group of identity servers issue a user with a token in the threshold manner, is introduced. SSO including threshold schemes suffers from privacy disclosure. One can learn a user's identity and access pattern from her/his token. Recent works focus on privacy preservation of SSO. However, these works merely consider scenarios of one single identity server SSO. No works that address privacy preservation of threshold SSO have emerged. In this work, we propose TSAPP, a threshold SSO authentication scheme preserving privacy. Each identity server issues a user with a partial token which is a signature on the user's pseudonym. With a threshold number of partial tokens, the user constructs a token, blinds the token with random numbers and accesses services with blinded tokens. Such mechanism preserves the user's identity, simultaneously protects the user's access pattern since adversaries cannot link the user's accesses, even if identity servers are corrupted. Security analysis demonstrates that TSAPP satisfies properties of anonymity, unlinkability, unforgeability and password-safety. The performance evaluation demonstrates that TSAPP is efficient in practice. Zhao Zhang 0026, Chunxiang Xu, Changsong Jiang, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Two-Factor Authenticated Key Exchange From Biometrics With Low Entropy RatesabstractMulti-factor authenticated key exchange (AKE) enables a user to be authenticated by a server using multiple factors and negotiate a shared session key to protect subsequent communications. Most existing multi-factor AKE schemes utilize biometrics as one factor due to their uniqueness and invariance properties. To support matching for noisy biometrics and protect them, fuzzy extractors are employed to extract a constant random string from varying biometric measurements without disclosing biometric data. However, the fuzzy extractors used in these schemes merely work on biometrics with an entropy rate greater than the error rate. Hence these schemes are unsuitable for biometrics with low entropy rates. In this paper, we propose a secure two-factor AKE scheme dubbed AHEAD from passwords and biometrics, which eliminates the limitation of biometric entropy rates. In AHEAD, we conceive a matching mechanism to simultaneously check whether an input biometric measurement with low entropy rates is close enough to the registered one, and whether an input password exactly matches the registered password. The mechanism allows a valid user to generate a secret element shared with the server in an oblivious way. By adopting a randomization technique, the secret element can be randomized for derivation of session keys. The security and efficiency of AHEAD are demonstrated by formal security proofs and experimental evaluations. Changsong Jiang, Chunxiang Xu, Yunxia Han, Zhao Zhang 0026, Kefei Chen |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Privacy-Preserving Cryptocurrency With Threshold Authentication and RegulationabstractCryptocurrency allows for immutable and transparent payments in the decentralized manner. The transparency nature inevitably leads to leakage of users’ private information. Although existing schemes provided privacy preservation in cryptocurrencies, they fail to consider regulation and facilitates conducting illegal activities. To solve this problem, several works aimed at striking a balance between preservation of users’ privacy and identification of malicious users. However, they introduced a central authority (which runs counter to the decentralization design of cryptocurrencies), and reveals only the pseudonym of a malicious user other than her/his real identity due to lack of authentication. In this work, we propose PICTURE, a privacy-preserving cryptocurrency with threshold authentication and regulation. In PICTURE, a user registers to a group of authorities (instead of a centralized one) who cooperatively issue the user with a master account which is actually a randomizable signature. The user randomizes the master account to be authenticated and transact anonymously. Besides, the transaction contains a record, with which the authorities can reveal the user’s identity (that is used in registration) in the threshold way. Our construction enables the user to prove that the record is well-formed with only a standard Schnorr’s protocol, leading to lower overheads compared with existing works. We provide a formal security proof to demonstrate that PICTURE is secure, and conduct a comprehensive performance evaluation to show that PICTURE is ready to be deployed in real world. Zhao Zhang 0026, Chunxiang Xu, Yunxia Han |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Practical Blockchain-Based Options ContractabstractDecentralized finance (DeFi) relies on crypto assets in blockchains to provide financial services. High volatility of crypto assets puts users at risk of financial loss. Options contracts address this issue by empowering a buyer to exchange his asset with that of a seller, which mitigates risks for both parties. Existing options contract protocols have the following two weaknesses: (i) The buyer have to lock his asset during the contract's lifespan, incurring heavy opportunity costs; (ii) Turing-completed smart contract (TCSC)/hash time lock contract (HTLC) is required to exchange assets, which restricts applicability as TCSC/HTLC is supported by a limited number of blockchains. In this paper, we propose UP-BLOC, a universal and practical blockchain-based options contract. We construct UP-BLOC using a buyer-pay-first design, and propose a blockchain-based secret storage mechanism to ensure the security of the assets involved. This allows the buyer to engage in an options contract without locking any asset and resulting opportunity costs, and thus is more practical than existing works. Besides, UP-BLOC achieves the exchange of assets using standard digital signatures instead of TCSC/HTLC. Hence, UP-BLOC is compatible with all blockchains and is universal. Security analysis and performance evaluation demonstrate that UP-BLOC is secure and efficient. Zhao Zhang 0026, Chunxiang Xu, Changsong Jiang |
IEEE Trans. Serv. Comput. | 1 |
| 2023 | SR-PEKS: Subversion-Resistant Public Key Encryption With Keyword SearchabstractPublic key encryption with keyword search (PEKS) provides secure searchable data encryption in cloud storage. Users can outsource encrypted data and keywords to a cloud server, and search target one without disclosing sensitive information. To achieve resistance against off-line keyword guessing attacks, existing practical PEKS schemes employ independent key server(s) to assist users in producing keywords to be encrypted (called server-derived keywords) in an online manner. In this article, we analyze server-aided PEKS schemes and reveal a potential threat: vulnerability against subversion attacks, where algorithms in server-aided PEKS might be maliciously implemented to undermine security. In a subverted encryption implementation, a subliminal channel is established to control randomness generation such that biased ciphertexts covertly leak plaintext information. We further present a specific subversion attack against generation of server-derived keywords to violate keywords’ confidentiality. To address these issues, we propose SR-PEKS, a subversion-resistant PEKS scheme based on cryptographic reverse firewalls (CRF). In SR-PEKS, CRF sanitizes messages transmitted in server-derived keyword generation to resist the presented subversion attack. CRF also participates in a collaborative randomness generation protocol to yield unbiased randomness for encryption, thereby eliminating the subliminal channel. Provable security and high efficiency of SR-PEKS are demonstrated by comprehensive analyses and performance evaluations. Changsong Jiang, Chunxiang Xu, Zhao Zhang 0026, Kefei Chen |
IEEE Trans. Cloud Comput. | 3 |