VLDB 2026 Research / reviewers in the wild / expert
Ruei-Hau Hsu
dblp:89/936
· DBLP profile ↗
14ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0003-0856-9229ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 2 first-author · 3 since 2021Computer networks · 4 · 1 since 2021Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Secure Data Sharing Framework With Fine-Grained Access Control and Privacy Protection for IoT Data MarketplaceabstractThe proliferation of IoT devices has led to an exponential increase in data generation, creating new opportunities for data marketplaces. However, due to the security and privacy issues arising from the sensitive nature of IoT data, as well as the need for efficient management of vast amounts of IoT data, a robust solution is necessary. Therefore, this paper proposes a secure data sharing framework with fine-grained access control and privacy protection for the internet of things (IoT) data marketplace. For fine-grained access control of the data in the proposed protocol, we develop the hidden attributes and encryption outsourced key-policy attribute-based encryption (HAEO-KP-ABE) that outsources high-complex operations to peripheral devices with high capability to reduce the computation burden of IoT device. It achieves data privacy by hiding attributes in the ciphertext and by preventing entities that do not hold the data consumer’s secret key material (including SA/CS) from running the match test on stored ciphertexts before decryption. It also has an efficient match test algorithm which can verify that the hidden attributes of the ciphertext match the access policy of the data consumer’s private key without revealing those attributes. We demonstrate the proposed protocol satisfies the security features required for the data sharing process in an IoT data marketplace environment. Furthermore, we evaluate the execution time of the proposed protocol according to the number of attributes and show the practicality and efficiency of the proposed protocol compared to the related works. Woojin Jeon, Donghyun Yu, Ruei-Hau Hsu, Jemin Lee 0002 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Ensuring End-to-End Security With Fine-Grained Access Control for Connected and Autonomous VehiclesabstractAs advanced V2X applications emerge in the connected and autonomous vehicle (CAV), the data communications between in-vehicle end-devices and outside nodes increase, which make the end-to-end (E2E) security to in-vehicle end-devices as the urgent issue to be handled. However, the E2E security with fine-grained access control still remains as a challenging issue for resource-constrained end-devices since the existing security solutions require complicated key management and high resource consumption. Therefore, this paper proposes a practical and secure vehicular communication protocol for the E2E security based on a new attribute-based encryption (ABE) scheme. In the ABE scheme, the outsourced computation is provided for encryption, and the computation cost for decryption constantly remains small, regardless of the number of attributes. The policy privacy can be ensured by the proposed ABE to support privacy-sensitive V2X applications, and the existing identity-based signature for outsourced signing is newly reconstructed. The protocol achieves the confidentiality, message authentication, identity anonymity, unlinkability, traceability, and reconfigurable outsourced computation, and this paper also shows the practical feasibility of the protocol via the performance evaluation. Donghyun Yu, Ruei-Hau Hsu, Jemin Lee 0002 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Poster: Verifiable Data Valuation with Strong Fairness in Horizontal Federated LearningabstractFederated learning (FL) represents an innovative decentralized paradigm in the field of machine learning, which differs from traditional centralized approaches. It facilitates collaborative model training among multiple participants and transfers only model parameters without directly exchanging raw data to maintain confidentiality. Data valuation for each data provider becomes a critical issue to guarantee the fairness of federated learning by estimating the dataset quality of each data provider based on the contribution to the global model prediction performance. To value datasets in FL, the concept of Shapley value is introduced to estimate the contribution of each dataset to a trained global model by measuring the effects of including and excluding a local model parameter in various combinations of global model parameters. However, the contribution measurement to each dataset performed by an aggregator or certain central component as a verifier becomes irrational as the verifier is under the control of an organization. Thus, this work presents a contribution measurement framework or data valuation with strong fairness, where forged results from the contribution measurement procedure are impossible. The new framework allows every participant (data provider) to verify the results of contribution measurement. Ruei-Hau Hsu, Hsuan-Cheng Su, Yi-An Yu |
CCS | 1 |
| 2022 | EC-SVC: Secure CAN Bus In-Vehicle Communications With Fine-Grained Access Control Based on Edge ComputingabstractIn-vehicle communications are not designed for message exchange between the vehicles and outside systems originally. Thus, the security design of message protection is insufficient. Moreover, the internal devices do not have enough resources to process the additional security operations. Nonetheless, due to the characteristic of the in-vehicle network in which messages are broadcast, secure message transmission to specific receivers must be ensured. With consideration of the facts aforementioned, this work addresses resource problems by offloading secure operations to high-performance devices, and uses attribute-based access control to ensure the confidentiality of messages from attackers and unauthorized users. In addition, we reconfigure existing access control based cryptography to address new vulnerabilities arising from the use of edge computing and attribute-based access control. Thus, this paper proposes an edge computing-based security protocol with fine-grained attribute-based encryption using a hash function, symmetric-based cryptography, and reconfigured cryptographic scheme. In addition, this work formally proves the reconfigured cryptographic scheme and security protocol, and evaluates the feasibility of the proposed security protocol in various aspects using the CANoe software. Donghyun Yu, Ruei-Hau Hsu, Jemin Lee 0002, Sungjin Lee 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | ReHand: Secure Region-Based Fast Handover With User Anonymity for Small Cell Networks in Mobile CommunicationsabstractDue to the fact that the higher density of mobile devices is expected, the fifth generation (5G) mobile networks introduce small cell networks (SCNs) to prevent exhausting radio resources. SCNs improve radio spectrum utilization by deploying more base stations (BSs) in the networks. Even though authenticated key exchange (AKE) is still essential to ensure entity authentication and confidentiality in mobile communications. Besides, user anonymity is required to guarantee the footprints of mobile communications being concealed. However, AKE with user anonymity may increase the latency of communications dramatically in total due to several times more frequency in SCNs. The increase of latency will be more serious when an AKE protocol supports user anonymity, where traceability and revocability to users are necessary. Thus, this paper presents a secure region-based handover scheme (ReHand) with user anonymity and fast revocation for SCNs. ReHand greatly reduces the communication latency when user equipments (UEs) roam between small cells within the region of a macro BS, i.e., eNB, and the computation costs due to the employment of symmetry-based cryptographic operations. Compared to the three related prior arts, ReHand dramatically reduces the latency from 82.92% to 99.99% by region-based secure handover. Nevertheless, this paper demonstrates the security of ReHand by theoretically formal proofs. Chun-I Fan, Jheng-Jia Huang, Min-Zhe Zhong, Ruei-Hau Hsu, Wen-Tsuen Chen, Jemin Lee 0002 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2019 | Provably Secure and Generalized Signcryption With Public Verifiability for Secure Data Transmission Between Resource-Constrained IoT DevicesabstractThe Internet of Things (IoT) is revolutionizing our modern lives by introducing active connection between smart devices. However, IoT devices are repeatedly exhibiting many security flaws, which will inevitably lead to eavesdropping and impersonation attacks. Thus, providing a proper security in IoT becomes a prime focus for the researchers. In cryptography, certificateless signcryption (CLSC) is one of the recent public key techniques for the security requirements of the authenticity and confidentiality of any message between the parties. In this article, a new generalized CLSC (gCLSC) is introduced to provide the functions of digital signature and encryption to fulfill the authenticity and confidentiality for the resource-constrained IoT devices. Besides, the gCLSC supports the property of public verifiability and security of an ideal signcryption under the strong Diffie-Hellman and bilinear Diffie-Hellman inversion problems without random oracle model. Performance assessment of the gCLSC gives satisfactory results after comparing with other competitive CLSC schemes in terms of its functionality. Therefore, the gCLSC can be adopted in the IoT networks where authenticity, confidentiality, and lightweight are the essential factors. Arijit Karati, Chun-I Fan, Ruei-Hau Hsu |
IEEE Internet Things J. | 3 |
| 2018 | GRAAD: Group Anonymous and Accountable D2D Communication in Mobile NetworksabstractDevice-to-device (D2D) communication is mainly launched by the transmission requirements between devices for specific applications such as proximity services in long-term evolution advanced networks, and each application will form a group of registered devices for the network-covered and network-absent D2D communications. During the applications of D2D communication, each device needs to identify the other devices of the same group in proximity by their group identity. This leads to the exposure of group information, by which the usage of applications can be analyzed by eavesdroppers. Hence, this paper introduces network-covered and network-absent authenticated key exchange protocols for D2D communications to guarantee accountable group anonymity, end-to-end security to network operators, as well as traceability and revocability for accounting and management requirements. We formally prove the security of those protocols, and also develop an analytic model to evaluate the quality of authentication protocols by authentication success rate in D2D communications. Besides, we implement the proposed protocols on android mobile devices to evaluate the computation costs of the protocols. We also evaluate the authentication success rate by the proposed analytic model and prove the correctness of the analytic model via simulation. Those evaluations show that the proposed protocols are feasible to the performance requirements of D2D communications. Ruei-Hau Hsu, Jemin Lee 0002, Tony Q. S. Quek, Jyh-Cheng Chen |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Energy Efficient Mutual Authentication and Key Agreement Scheme with Strong Anonymity Support for Secure Ubiquitious Roaming ServicesabstractThis article proposes a secure and energy efficient user authentication protocol, which can preserve the user anonymity for roaming service in the mobile network. Compared to other state of the art solutions, the proposed scheme has several considerable advantages. Firstly, no encryption/ decryption, modular and exponential operations have been introduced in our design. Instead, it uses the low cost function such as HMAC and exclusive-OR operations to accomplish the goals of authentication and key agreement. This makes the protocol more suitable for battery-powered mobile devices. Secondly, the proposed scheme can resolve several existing security issues like forgery attack, known session key attack, etc., with the limited computation and communication overheads which are indeed essential for offering a secure and expeditious roaming services in mobile communication environment. Prosanta Gope, Ruei-Hau Hsu, Jemin Lee 0002, Tony Q. S. Quek |
ARES | 2 |
| 2013 | Complete EAP Method: User Efficient and Forward Secure Authentication Protocol for IEEE 802.11 Wireless LANsabstractIt is necessary to authenticate users who attempt to access resources in Wireless Local Area Networks (WLANs). Extensible Authentication Protocol (EAP) is an authentication framework widely used in WLANs. Authentication mechanisms built on EAP are called EAP methods. The requirements for EAP methods in WLAN authentication have been defined in RFC 4017. To achieve user efficiency and robust security, lightweight computation and forward secrecy, excluded in RFC 4017, are desired in WLAN authentication. However, all EAP methods and authentication protocols designed for WLANs so far do not satisfy all of the above properties. This manuscript will present a complete EAP method that utilizes stored secrets and passwords to verify users so that it can 1) fully meet the requirements of RFC 4017, 2) provide for lightweight computation, and 3) allow for forward secrecy. In addition, we also demonstrate the security of our proposed EAP method with formal proofs. Chun-I Fan, Yi-Hui Lin, Ruei-Hau Hsu |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2012 | Privacy protection for vehicular ad hoc networks by using an efficient revocable message authentication schemeabstractABSTRACT Correctness of exchanged information and guaranteeing the privacy of vehicle owners are the two most significant security concerns for VANETs. Pseudonymous public key infrastructure (PPKI) is a practical solution to these two issues. Almost all PPKI technologies are comprehensive schemes, such as the group signature‐based and identity‐based cryptosystems. An applicable PPKI scheme for secure vehicular communication (VC) should support revocability because it is a significant functionality in VANETs to revoke certificates of vehicles for surrendering or transferring the registrations. However, the computation or space complexity in most of the revocable PPKI‐based protocols is linear when the number of vehicles or revoked vehicles increases over time. This drawback markedly degrades the efficiency and stability of secure VC. This work therefore reduces the computation complexities of authentication message verification, certificate tracing, membership revocation, and space complexity of system parameters (e.g., revocation information and public keys), such that they are independent of the number of vehicles or revoked vehicles using a novel and efficient PPKI mechanism based on bilinear mapping. The proposed scheme uses the concept of accumulator schemes and transfers the computation of accumulators from vehicles to certificate authority (CA) for achieving constant computation and storage complexities on vehicles. The computation of accumulators on CA is also low in the proposed scheme. Finally, we formally prove that the proposed scheme, which is based on q‐strong Diffie–Hellman, n‐Diffie–Hellman exponent (DHE), variant n‐DHE, and decision linear Diffie–Hellman assumptions, is secure under the definitions of traceability and anonymity. Copyright © 2011 John Wiley & Sons, Ltd. Chun-I Fan, Ruei-Hau Hsu, Wei-Kuei Chen |
Secur. Commun. Networks | 2 |
| 2011 | Group Signature with Constant Revocation Costs for Signers and Verifiers
Chun-I Fan, Ruei-Hau Hsu, Mark Manulis |
CANS | 2 |
| 2010 | Provably Secure Nested One-Time Secret Mechanisms for Fast Mutual Authentication and Key Exchange in Mobile CommunicationsabstractMany security mechanisms for mobile communications have been introduced in the literature. Among these mechanisms, authentication plays a quite important role in the entire mobile network system and acts as the first defense against attackers since it ensures the correctness of the identities of distributed communication entities before they engage in any other communication activity. Therefore, in order to guarantee the quality of this advanced service, an efficient (especially user-efficient) and secure authentication scheme is urgently desired. In this paper, we come up with a novel authentication mechanism, called thenested one-time secretmechanism, tailored for mobile communication environments. Through maintaining inner and outer synchronously changeable common secrets, respectively, every mobile user can be rapidly authenticated by visited location register (VLR) and home location register (HLR), respectively, in the proposed scheme. Not only does the proposed solution achieve mutual authentication, but it also greatly reduces the computation and communication cost of the mobile users as compared to the existing authentication schemes. Finally, the security of the proposed scheme will be demonstrated by formal proofs. Chun-I Fan, Pei-Hsiu Ho, Ruei-Hau Hsu |
IEEE/ACM Trans. Netw. | 3 |
| 2006 | Remote Password Authentication Scheme with Smart Cards and BiometricsabstractMore and more researchers combine biometrics with passwords and smart cards to design remote authentication schemes for the purpose of high-degree security. However, in most of these authentication schemes proposed in the literature so far, biometric characteristics are verified in the smart cards only, not in the remote servers, during the authentication processes. Although this kind of design can prevent the biometric data of the users from being known to the servers, it will result in that they are not real three-factor authentication schemes and therefore some security flaws may occur since the remote servers do not indeed verify the security factor of biometrics. In this paper we propose a truly three-factor remote authentication scheme where all of the three security factors, passwords, smart cards, and biometric data, are examined in the remote servers. Especially, the proposed scheme fully preserves the privacy of the biometric data of every user, that is, the scheme does not reveal the biometric data to anyone else, including the remote servers. Furthermore, we also demonstrate that the proposed scheme is immune to both the replay attacks and the offline-dictionary attacks and it satisfies the requirement of low-computation cost for smart-card users. Chun-I Fan, Yi-Hui Lin, Ruei-Hau Hsu |
GLOBECOM | 3 |
| 2003 | Infinite generating keys based on publish systemabstractIn this paper, we combined the public secrete key cryptograph system proposed by Diffie and Hellman, with the infinite generation keys based on grey theory. And we got another related code for cryptograph system. This is a kind of infinite generation keys based on the public key system. This system is much more secret than traditional systems, and it can also be applied in then. According to past researches, Diffe and Hellman had presented the basic concepts of cryptography, based on the discrete logarithm model. Another search in grey field, only a few papers has touch this field. It is the first time that AGO method applied in grey theory in this kind of research. Also, based on the GM(1,1) model, we used finite original code to create an infinite variables code sequence, and we got the code from the known secrete key. In this paper, we define two parameters: cryptography sequence /spl psi/ and 3rd order symmetric group S/sub 3/ and presented six cryptography models to contribute our system. Based on discrete logarithm model, the secrete value is high to O(e/sup C/spl radic/(ln(p)ln(ln(p)))/) for public system, and it is hard to calculate the sequence by the present computing ability. Therefore, to break into this system by mathematical formula is not possible nowadays. To promote the efficiency, we also develop a toolbox not only to decrease the calculation time, but also to examine the reliability of our system. Yi-Fung Huang, Kun-Li Wen, Ruei-Hau Hsu, Chu-Hsing Lin |
SMC | 3 |