Chi Zhang 0001

dblp:91/195-1 · DBLP profile ↗
← Back
123ranked-venue papers
11as first author
33since 2021 · last 2025
0000-0002-6528-1427ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 95 · 9 first-author · 24 since 2021Security and privacy · 9 · 5 since 2021Systems, architecture and hardware · 6 · 1 first-authorArtificial intelligence and machine learning · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3Software engineering, systems software and programming languages · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021
YearPublicationVenuePosition
2025 A Blockchain-Based Covert Communication Scheme Resilient to Internal Attacks
Chi Zhang 0001, Lingbo Wei, Yani Sun
ICC2
2025 Rethink the Role of Deep Learning towards Large-scale Quantum Systems
abstract
Characterizing the ground state properties of quantum systems is fundamental to capturing their behavior but computationally challenging. Recent advances in AI have introduced novel approaches, with diverse machine learning (ML) and deep learning (DL) models proposed for this purpose. However, the necessity and specific role of DL models in these tasks remain unclear, as prior studies often employ varied or impractical quantum resources to construct datasets, resulting in unfair comparisons. To address this, we systematically benchmark DL models against traditional ML approaches across three families of Hamiltonian, scaling up to $127$ qubits in three crucial ground-state learning tasks while enforcing equivalent quantum resource usage. Our results reveal that ML models often achieve performance comparable to or even exceeding that of DL approaches across all tasks. Furthermore, a randomization test demonstrates that measurement input features have minimal impact on DL models' prediction performance. These findings challenge the necessity of current DL models in many quantum system learning scenarios and provide valuable insights into their effective utilization.
Yusheng Zhao, Chi Zhang 0001
ICML2
2025 Privacy-Preserving Credential Management for Blockchain-Based Self-sovereign Identity
Haixing Li, Chi Zhang 0001, Lingbo Wei
WASA (1)3
2025 Public data-enhanced multi-stage differentially private graph neural networks
Heyuan Huang, Lingbo Wei, Chi Zhang 0001
J. Inf. Secur. Appl.4
2024 AdvNets: Adversarial Attacks and Countermeasures for Model-level Neural Trojan Defenses
abstract
Neural trojans constitute a serious threat to systems that employ neural networks. In response to this threat, a multitude of trojan defense strategies have surfaced, with model-level measures, particularly those applied post-training, showcasing broader applicability. However, many such model-level defenses could be vulnerable because their robustness against adaptive attacks launched by sophisticated adversaries is unvalidated. In this paper, we introduce AdvNets, a general framework developed from the perspective of adversarial attacks, to demonstrate the vulnerability and enhance the robustness of model-level trojan defenses against adaptive attacks. Specifically, we implement feature-based and score-based attack modules that thoroughly circumvent multiple state-of-the-art defenses without modifying the so-called defendable backdoor patterns. To counteract these vulnerabilities, we craft an independent random decision envelopment mechanism where detections made by our detectors are mutually independent. The implementation of this mechanism markedly improves the AUC score for detecting adversarial models to over 80%. This presents a strong argument for designing a robust and dependable trojan defense system.
Chi Zhang 0001, Lingbo Wei, Qibin Sun
GLOBECOM2
2024 ParaEthereum: Private and Parallel Smart Contracts with Trusted Hardware
abstract
The last decade has witnessed unprecedented de-velopment in blockchain smart contracts. While smart contracts inherit the decentralization and other security properties of blockchain, they are hampered by the lack of privacy protection and poor performance of blockchain. In this paper, we propose a parallel contract execution framework, ParaEthereum, that combines blockchain and trusted execution environments (TEEs) to construct private, efficient, and scalable smart contracts. By introducing TEEs, ParaEthereum performs contract execution off the chain through enclave-enabled computing nodes and confirms the correctness of the execution results on the chain, achieving the decoupling of contract execution and consensus. To meet system availability requirements and enable concurrent exe-cution of transactions, each transaction is executed independently by a set of computing nodes determined by its execution set, and different computing nodes process transactions within the block concurrently based on the constructed transaction dependency graph. We also conducted extensive tests on our proposed scheme with respect to its efficiency and effectiveness.
Lingbo Wei, Chi Zhang 0001, Jianqing Liu
ICC3
2024 CVALLM: A Cloud Platform Security Assessment Framework Based on Large Language Models
abstract
Cloud computing has revolutionized computing and data storage by providing flexible resource management and on-demand services. However, the centralized nature of cloud computing results in significant security issues that pose significant threats to cloud services. The security threat can be alleviated to a certain extent through the cloud platform security assessment. However, the existing cloud platform security assessment framework mainly measures security from the enterprise perspective and lacks methods from the user perspective. For users, much information is internal to the enterprise and cannot be obtained. To address these challenges, we propose a framework called CVALLM to measure cloud platform security from the user’s perspective, which uses a large language model to automatically complete a cloud platform security assessment. First, we utilize a large language model to complete cloud platform information extraction and vulnerability collection from SLA agreements and product description documents that the user can access. Second, to solve the vulnerability assessment problem, we propose a vulnerability severity prediction method based on deep learning. This method considers both the textual description characteristics and the source code characteristics of the vulnerability. Finally, we propose an overall security assessment method for the cloud platform based on a large language model, design quantitative indicators to measure the security of the cloud platform, and automatically generate security reports to facilitate users’ ability to quickly compare and choose the right cloud service.
Wangyuan Jing, Chi Zhang 0001, Lingbo Wei
TrustCom2
2024 Privacy Leak Detection in LLM Interactions with a User-Centric Approach
abstract
In recent years, services based on Large Language Models (LLMs) have garnered increasing attention leading to more frequent interactions between users and LLMs. However, owing to the inherent characteristics of LLMs, user inputs are at risk of privacy leaks. While previous research has proposed methods for protecting user input privacy, many of these approaches face limitations, particularly in adapting to the dynamic and diverse nature of user interactions with LLMs. To address this challenge, our study approaches privacy protection from a user-centric perspective, employing detection methods to safeguard user inputs. Specifically, we compiled a comprehensive privacy list based on General Data Protection Regulation (GDPR) requirements, defined the detection scope, and developed the PA-BERT model for automatically detecting privacy leaks in LLMs. By utilizing the PA-BERT-BiLSTM-CRF architecture, our method effectively monitors private information in user inputs. In our experiments, we not only utilized real-world datasets but also constructed a user input privacy dataset containing 15,036 privacy entities. Experimental results on the constructed dataset show that our method significantly outperforms commonly used general detection models in privacy detection, with marked improvements in precision, recall, and F1 score, making it more effective for identifying privacy in user inputs.
Tan Su, Chi Zhang 0001, Lingbo Wei
TrustCom3
2024 Enhanced Privacy Policy Comprehension via Pre-trained and Retrieval-Augmented Models
abstract
Privacy policies are crucial for informing users about how their personal information is collected, stored, and used by organizations. However, privacy policies are lengthy, information-dense, and filled with legalese, making them difficult for users to comprehend. Although previous studies have attempted to improve the readability of privacy policies via traditional machine learning techniques, these methods overlook or oversimplify critical information or rely on predefined question-answers that cannot adapt to user personalized queries. Inspired by the fact that large language models perform well in terms of text comprehension and text question-answering, we propose a novel large language model-based privacy policy question-answering framework, which aims to help users understand privacy policies more intuitively and effectively. Specifically, our framework consists of two modules: the personal data practice disclosure module, which performs a pre-training and fine-tuning approach to extract structured information about data categories and corresponding data operations from privacy policies. The retrieval-augmented question-answering module integrates sparse and dense retrievers to find the most relevant evidence from the privacy policy and generate responses corresponding to user queries. The experimental results across two representative datasets demonstrate the superiority of our method over other prior methods.
Chi Zhang 0001, Lingbo Wei
TrustCom3
2024 Secure Motion Verification for High Altitude Platforms with a Hybrid AOA-TDOA-FDOA Scheme
Chi Zhang 0001, Miao Pan
WASA (3)2
2024 A Monitoring-Free Bitcoin Payment Channel Scheme With Support for Real-Time Settlement
abstract
The Bitcoin blockchain enables users to conduct transactions securely, but its performance is restricted by the need for global consensus. Payment channels, as a promising solution to this issue, overcome this limitation through off-chain transactions. Instead of conducting each transaction on-chain, they only settle the final payment balances with the underlying blockchain. However, the most prominent scheme, the Lightning Network payment channel, requires participants to regularly monitor blockchain; otherwise, there is a potential risk of fund loss. Moreover, this scheme also fails to support participants in settling the final payment balances in real time, compromising the efficiency of fund utilization. Existing payment channel enhancing technologies are unable to overcome the above issues without compromising payment privacy. To solve the above issues, we apply the Intel Software Guard Extensions (SGX), which provides trusted execution environments with confidentiality and integrity guarantees, to design a novel Bitcoin payment channel scheme. The scheme can support real-time settlement yet guarantee the participants' fund security without monitoring the blockchain. Through a combination of the additive homomorphic property of keys, the secret sharing scheme, and customized punishments, our scheme can still guarantee fund security and off-chain transaction privacy, even if the confidentiality of SGX is compromised by side-channel attacks. Finally, security and performance analysis demonstrate that our scheme allows participants to construct a secure yet efficient payment channel to transfer value.
Yankai Xie, Ruian Li, Chi Zhang 0001, Lingbo Wei, Yani Sun
IEEE Trans. Serv. Comput.4
2023 A PATE-based Approach for Training Graph Neural Networks under Label Differential Privacy
abstract
As a standard solution to the problem of private deep learning, differential privacy (DP) is widely used in graph neural networks (GNNs) to protect sensitive information about the input graph data. However, most existing DP algorithms for GNNs protect the privacy of every attribute for each node. This results in the need for injecting a large amount of noise, making these methods significantly underperform their non-private counterparts. We argue that in some practical scenarios, node labels serve as the only or the most sensitive attribute, where label differential privacy, a more fine-grained notion of differential privacy that only protects the labels is more appropriate. To better capture these scenarios and improve the trade-off between data privacy and model accuracy, we propose a novel method of training GNNs under label differential privacy. Instead of naively adding noise to the node labels before training the GNN, our method follows the strategy of Private Aggregation of Teacher Ensembles (PATE) to generate differentially private node labels with both high accuracy and strong privacy guarantee. We also propose a label denoising module that takes advantage of the graph structure to further improve the accuracy of the trained model. Additionally, our method is model-agnostic, making it applicable to any GNN architecture. We evaluate its performance on two commonly used benchmark datasets and demonstrate its capability to learn high-performance models while ensuring privacy.
Heyuan Huang, Liwei Luo, Yankai Xie, Chi Zhang 0001, Jianqing Liu
GLOBECOM5
2023 Synthesizing High-Utility Tabular Data with Enhanced Privacy Via Split-and-Discard Pre-Training
abstract
Data sharing has led to the emergence of the deep generative model (DGM) with differential privacy for synthesizing tabular data. However, existing methods struggle to synthesize high-utility tabular data with enhanced privacy. One challenge is degraded data utility due to the limited number of training iterations available under strong privacy guarantees. The other challenge is that widely-used encoding schemes may leak the sensitive distribution of continuous features. To this end, we propose a novel pipeline incorporating split-and-discard pre-training and an embedding module to synthesize data. To reduce the impact of limited iterations, we employ the split-and-discard pre-training method. This method leverages the intrinsic structure of DGM, which can be split into discriminative and generative sub-models. By conducting pre-training and discarding specific sub-models of DGM on private data, we address these challenges while training models with differential privacy. To preserve the privacy of continuous features, we propose a piecewise linear one-hot encoding scheme followed by an embedding layer. We instantiate this pipeline using variational autoencoders and generative adversarial networks respectively and compare them against popular models and variants. Results show that our pipeline on private data effectively balances privacy and utility.
Liwei Luo, Heyuan Huang, Yankai Xie, Chi Zhang 0001, Lingbo Wei
GLOBECOM5
2023 Solving Multi-Task Offloading Problem in V2X with a Machine Learning-Based Online Algorithm
abstract
In Vehicle-to-Everything scenarios, the efficient and real-time offloading of multi-task from vehicles to roadside units with higher computing power presents a challenging endeavor. This challenge is amplified by the dynamic nature of computing power in roadside units, which fluctuates in real time due to resource sharing among multiple vehicles. Consequently, accurately determining the computing power of roadside units prior to offloading becomes a significant hurdle for vehicles. To overcome this challenge and enhance the performance of online algorithms used for task offloading, we propose a novel approach that leverages machine learning techniques. This approach utilizes historical data to predict the real-time computing power of roadside units. By incorporating machine learning predictions, our proposed approach aims to mitigate the uncertainty associated with the decision-making process of the online algorithm. This, in turn, enables vehicles to make more informed decisions regarding task offloading. Moreover, to enhance the robustness of the algorithm against potential prediction errors, our approach adopts a partial trust mechanism towards the predicted outcomes. By considering this partial trust, we aim to maintain the algorithm's reliability in real-world scenarios. Furthermore, we conduct theoretical analysis and comprehensive experiments to demonstrate the superiority of our proposed algorithm in terms of task offloading performance and robustness.
Yongwang Zhou, Dongbiao Li, Chi Zhang 0001, Lingbo Wei, Miao Pan
GLOBECOM4
2023 Private Status Retrieval for Blockchain-Based Certificate Revocation System
abstract
Blockchain is the most promising technology to tackle the security challenges of certificate revocation schemes, such as vulnerability to the single point of failure and lack of accountability systems. However, current blockchain-based certificate revocation systems suffer from privacy problems as the blockchain nodes can learn which website the client is going to connect with and infer the end-user's private information, such as identity, location, and health condition. In this paper, we propose a decentralized certificate revocation scheme that allows clients to securely and privately verify revocation information. We not only take advantage of blockchain to provide security guarantees but also further craft a novel multi-server offline/online private information retrieval (PIR) protocol named MOO-PIR to preserve query privacy for clients even if a subset of servers collude. Finally, we provide security analysis and performance evaluation, demonstrating that our scheme can protect client privacy without compromising efficiency.
Zhichao Ruan, Yankai Xie, Haixing Li, Chi Zhang 0001, Lingbo Wei
ICC5
2023 Energy Efficient Federated Learning Over Heterogeneous Mobile Devices via Joint Design of Weight Quantization and Wireless Transmission
abstract
Federated learning (FL) is a popular collaborative distributed machine learning paradigm across mobile devices. However, practical FL over resource constrained mobile devices confronts multiple challenges, e.g., the local on-device training and model updates in FL are power hungry and radio resource intensive for mobile devices. To address these challenges, in this paper, we attempt to take FL into the design of future wireless networks and develop a novel joint design of wireless transmission and weight quantization for energy efficient FL over mobile devices. Specifically, we develop flexible weight quantization schemes to facilitate on-device local training over heterogeneous mobile devices. Based on the observation that the energy consumption of local computing is comparable to that of model updates, we formulate the energy efficient FL problem into a mixed-integer programming problem where the quantization and spectrum resource allocation strategies are jointly determined for heterogeneous mobile devices to minimize the overall FL energy consumption (computation + transmissions) while guaranteeing model performance and training latency. Since the optimization variables of the problem are strongly coupled, an efficient iterative algorithm is proposed, where the bandwidth allocation and weight quantization levels are derived. Extensive simulations are conducted to verify the effectiveness of the proposed scheme.
Rui Chen 0026, Liang Li 0021, Kaiping Xue, Chi Zhang 0001, Miao Pan, Yuguang Fang
IEEE Trans. Mob. Comput.4
2023 Privacy Preservation in Multi-Cloud Secure Data Fusion for Infectious-Disease Analysis
abstract
It is often observed that people's data are scattered across various organizations and these data can be used to generate usable insights when integrated. However, data fusion from multiple data hosting sites could put user privacy at risk albeit with some security mechanisms. This paper studies a data-analytic platform that adopts the Kulldorff scan statistic to determine infectious-disease spatial hotspots by integrating and analyzing users’ health and location data that are respectively stored in two clouds. We examine the privacy threats to this platform which has a key-oblivious inner product encryption (KOIPE) mechanism in place to ensure that only coarse-grained statistical data is revealed to the honest-but-curious (HbC) entity. To protect user privacy from the designed inference attack, we exploit a game-theoretic approach to incentivize users to form anonymous clusters with a quantitative privacy guarantee. We conduct extensive simulations based on real-life datasets to demonstrate the performance of our scheme in terms of design overhead and privacy level.
Jianqing Liu, Chi Zhang 0001, Kaiping Xue, Yuguang Fang
IEEE Trans. Mob. Comput.2
2023 Private Transaction Retrieval for Lightweight Bitcoin Clients
abstract
Running a typical Bitcoin client (also called full node) needs more than 444 GB of disk space, considerable time, and computational resources to synchronize the entire blockchain, which is infeasible for resource-constrained devices. To address such concerns, the lightweight Bitcoin client proposed by Satoshi outsources most of computational and storage burdens to full nodes. Unfortunately, interacting with full nodes to query transactions leaks considerable information like addresses and transactions of lightweight client users. Thus, Bitcoin users that rely on lightweight clients are subject to de-anonymization, which defeats users privacy. Traditional schemes cannot support lightweight clients to query transactions from full nodes in an efficient yet privacy-preserving way. In this article, we propose a new efficient yet privacy-preserving transaction query scheme that specially targets the missing support for lightweight clients. We identify unique characteristics of the Bitcoin blockchain and craft a highly customized private information retrieval scheme called BIT-PIR to match the Bitcoin transaction query scenario and boost performances. Moreover, we customize a storage structure of the Bitcoin blockchain so that it further improves the query efficiency of our scheme. Finally, we develop a prototype implementation to demonstrate the feasibility of our proposed scheme.
Yankai Xie, Qingtao Wang, Ruoyue Li, Chi Zhang 0001, Lingbo Wei
IEEE Trans. Serv. Comput.4
2022 An Efficient Blockchain-Based Time-Stamping Scheme Using Commitment Signatures
abstract
Blockchain-based time-stamping services are widely used in file archiving systems, which can prove a file existed at a given time point by inserting the file hash into the blockchain. However, existing data insertion methods are not satisfactory in terms of efficiency, concealment, and scalability. Besides, to save the on-chain cost of inserting data, existing time-stamping services generate a Merkle tree to aggregate files and then utilize Merkle paths to verify the existence of files. However, as the number of files increases, the Merkle path grows in size, leading to a significant communication overhead for the file existence proof. To solve the above problems, we design a novel blockchain-based time-stamping scheme. First, we design a commitment signature scheme to embed data in the addresses and signatures of blockchain transactions, which can insert our data into public blockchains in an efficient, concealed, and scalable fashion without modifying the data structures and signature verifying schemes of the current public blockchains. Second, instead of using a Merkle tree to aggregate files, we utilize a bilinear pairing accumulator to achieve a constant communication overhead for the file existence proof. Finally, we implement a prototype on the Bitcoin blockchain to show that our scheme is more efficient without any security compromise compared with existing blockchain-based time-stamping schemes.
Sichao Zhang, Chi Zhang 0001, Lingbo Wei
GLOBECOM5
2022 Multi-Party Secure Computation with Intel SGX for Graph Neural Networks
abstract
The current privacy-preserving Graph Neural Networks (GNNs) cannot provide security and privacy guarantees against malicious adversaries without sacrificing accuracy and efficiency. For example, the Secure Multi-party Computation (MPC) can resist malicious adversaries while adding severe overhead. Trusted Execution Environment (TEE), such as Intel Software Guard Extension (SGX), can guarantee privacy and faithful execution without compromising efficiency. However, existing attacks can compromise the confidentiality of SGXs. Besides, the CPU-based structure of SGX restricts its extensibility that cannot perform collaborative computation with GPUs. To address the above issues, we propose a novel GNN training and inference framework to support data holders outsourcing their computation tasks to servers. First, we combine the advantage of MPC and the code integrity protection provided by SGXs to resist malicious adversaries without sacrificing efficiency. Second, we adopt a strategy that allows the servers to transfer the parallelizable computation task to the untrusted yet high-performance GPUs, further improving efficiency without hindering privacy. To the best of our knowledge, our proposal is the first privacy-preserving GNN framework against malicious adversaries without sacrificing accuracy and efficiency. Experiments on real-world citation datasets have demonstrated the performance of our framework regarding security, privacy, accuracy, and efficiency.
Yixin Jie, Yixuan Ren, Qingtao Wang, Yankai Xie, Chi Zhang 0001, Lingbo Wei, Jianqing Liu
ICC5
2022 Secure and Efficient Decentralized Bitcoin Mixing Scheme using Trusted Execution Environment
abstract
Mixing schemes have been applied by Bitcoin users to break their payment links in the blockchain to enhance privacy. However, most mixing schemes cannot provide secure mixing service without compromising efficiency since they are relying on complex cryptographic techniques or interactive protocols. To provide secure yet efficient mixing service, researchers introduce Intel SGX enclave, which provides Trusted Execution Environment (TEE) with confidentiality and integrity guarantees to execute mixing operations. Unfortunately, users will lose their mixing funds if a malicious service provider compromises the confidentiality guarantee of his/her enclave. Moreover, the scheme cannot scale to a large number of users in a single mixing round, that is, limited scalability. In this paper, we present a novel decentralized mixing scheme with multiple enclaves run by different service providers, which uses Shamir secret sharing scheme and additive homomorphic property of keys in Elliptic Curve Cryptography to tolerate a subset of enclaves to be compromised. Moreover, our scheme also provides stronger scalability so it achieves anonymity sets by orders of magnitude higher than the existing TEE-based mixing scheme. The experiment shows our scheme can provide stronger security and anonymity guarantees without compromising efficiency which outperforms existing mixing schemes.
Yankai Xie, Qingtao Wang, Ruiyang Xiao, Chi Zhang 0001, Lingbo Wei
ICC5
2022 A blockchain-based privacy-preserving authentication system for ensuring multimedia content integrity
abstract
With the prevalence of digital cameras, multimedia data have been used to record facts and provide evidence of events. However, the integrity of multimedia data is vulnerable to attacks with the proliferation of data tampering tools. In fact, an effective multimedia content authentication system should support compliant editing (cropping, rotation, compression, and so forth) and have the ability to detect malicious data tampering. Data traceability is a feasible strategy to verify the integrity and provenance of multimedia data. Besides, the privacy of multimedia data needs to be protected to prevent unauthorized access. In this paper, we trace transformations of multimedia data privately by integrating a transparent and immutable blockchain with trusted hardware that provides the capability of private computation. Our system exploits a hybrid storage pattern that separately stores multimedia data off the blockchain and their hashes on the blockchain. With this, our system ensures data integrity and addresses the issue of blockchain's storage capability. Experimental results and analysis show that our solution is efficient and verifiable. A lightweight verifier merely needs to store block headers and is able to validate query results returned by full nodes.
Lingbo Wei, Chi Zhang 0001
Int. J. Intell. Syst.5
2022 Probabilistic Data Prefetching for Data Transportation in Smart Cities
abstract
To deal with the ever increasing wireless traffic, we have recently designed a vehicular cognitive capability harvesting network (V-CCHN) architecture to leverage vehicles as an alternative “transmission medium” (i.e., an opportunistic data carrier), besides the wireless spectrum, to effectively transport data from the location where it is collected to the place where it is consumed or utilized in a smart city environment. In the V-CCHN, cognitive radio technologies are utilized so that a large amount of data can be exchanged between vehicles and roadside infrastructure through short-range high-speed transmissions. Considering the limited contact duration and the uncertain activities of primary users, how to facilitate efficient data exchange between vehicles and roadside infrastructure is very challenging. This problem is further complicated by the fact that the mobility of vehicles might not be accurately predicted. In this paper, we propose a probabilistic data prefetching (PDP) scheme for the V-CCHN to address these challenges. By considering the conditional value at risk, we formulate the PDP schematic design as an optimization problem which allows us to obtain the corresponding PDP scheme. Finally, we have conducted extensive study to evaluate the performance of the obtained PDP scheme under various parameter settings.
Haichuan Ding, Chi Zhang 0001, Xuanheng Li, Bin Lin 0001, Yuguang Fang, Shigang Chen
IEEE Internet Things J.3
2022 Guest Editorial Special Issue on Information-Centric Wireless Sensor Networking (ICWSN) for IoT
abstract
In recent decade, the applications of the Internet of Things (IoT) have been widely spread out and the market of IoT has been rapidly growing. One of the essential elements in IoT structure is wireless sensor network (WSN) because it provides useful information anywhere and it makes IoT be more necessary technology in people’s daily life. The types of sensors in IoT are becoming more diverse beyond the conventional sensors, such as mobile phones, wearable devices, surveillance cameras, and even vehicles. Typically, in WSNs, the end users are more interested in fetching the updated sensed data no matter which node is producing that data.
Byung-Seo Kim, Chi Zhang 0001, Spyridon Mastorakis, Muhammad Khalil Afzal, János Tapolcai
IEEE Internet Things J.2
2021 Prediction-based UTXO Cache Optimization for Bitcoin Lightweight Full Nodes
abstract
Since version 0.11 of Bitcoin Core, a user can run a full node in pruning mode, i.e. a pruned node, in resource-limited devices. The pruned node is a lightweight full node as it can independently verify new transactions and blocks received from other peers in the Bitcoin network by only maintaining some recently verified blocks (not the complete blockchain) and the complete Unspent Transaction Output (UTXO) set. However, the rapid increase in the size of the UTXO set has caused the main part of the UTXO set to be stored in the low-speed disk, and thus slows down the verification speed of new blocks in lightweight full nodes. Existing verification schemes for pruned nodes do not take advantage of the fact that different UTXO-related transactions are included in a new block with different probabilities, resulting in poor verification performance. In this paper, we propose a prediction-based UTXO cache optimization mechanism to increase the verification speed of new blocks. In order to achieve higher prediction accuracy and reduce the memory requirements of UTXO set, we first design a method to synchronize unconfirmed transactions for lightweight full nodes to ensure that the local and miners' unconfirmed transaction sets are highly consistent. Then, a lightweight full node predicts which unconfirmed transactions will have a greater probability of appearing in the new block by utilizing the fact that most miners will prioritize unconfirmed transactions to maximize the total transaction fee when mining a new block. Based on this mechanism, we can pre-load the UTXOs required for new block verification into the memory, thereby greatly improving the verification performance. Experimental results show that the proposed mechanism can accelerate the block verification of lightweight full nodes with small memory requirements.
Yukun Niu, Haixing Li, Chi Zhang 0001, Lingbo Wei
GLOBECOM3
2021 Reconfiguration in Maritime Networks Integrated with Dynamic High Altitude Balloons
abstract
Nowadays, maritime communication has attracted more and more attention. To provide high-speed and low- cost communication in maritime networks, an efficient architecture and flexible routing are expected. In this paper, we propose a novel high altitude balloon-enabled maritime network (HABMN) architecture. In the proposed architecture, considering that high altitude platforms (HAPs) are difficult to maintain station-keeping in practice, we integrate dynamic balloon networks to guarantee maritime communication coverage. Then, we formulate an integer programming to maximize the total traffic accepted by whole networks over time. Considering the unpredictable link disruption caused by sea surface movement and wave occlusions, we update the network configurations to get optimal performance. However, frequent flow update will increase the burden on control channels and lower down system stability. Then, we propose a lazy policy (LP) to wisely determine whether to apply the optimal network configurations immediately or not. At last, extensive simulation experiments demonstrate the effectiveness of the proposed policy.
Taiheng Ge, Chi Zhang 0001, Yuguang Fang
ICC3
2021 Optimizing Data Transmission in High Altitude Balloon Networks with Multi-beam Directional Antennas
abstract
High altitude balloons (HABs) can be deployed in the stratosphere to provide high capacity connectivity to users in rural and remote areas with their advantages of low cost and easy deployment. In this paper, we propose a software defined HAB-based network (SD-HABN) architecture to efficiently exploit the resource of inter-HAB links. The multi-beam directional antenna equipped on the HAB realizes concurrent transmission. However, this may result in interference because of the over-lapping beams at the receiving side. To mitigate interference and improve network performance, the beam angle adjustment, link scheduling, routing, and data rate controlling are jointly optimized, aiming to maximize the network utility. On account of the coupled relationship between the optimization variables, a novel optimization approach is proposed to solve this problem. The original problem is divided into two problems. The first one is that of optimizing the beam angle adjustment with fixed link scheduling, which is solved by a genetic algorithm. The second one is that of optimizing the routing and data rate controlling with fixed beam angle adjustment, which is solved by generalized bender decomposition. By solving the two problems orderly, the original problem will attain an approximately optimal solution. Simulation results show that the SD-HABN can achieve a high network performance via the joint optimization of beam angle adjustment, link scheduling, routing, and data rate controlling.
Chi Zhang 0001, Miao Pan
ICC2
2021 HyperChannel: A Secure Layer-2 Payment Network for Large-Scale IoT Ecosystem
abstract
For the future large-scale IoT ecosystem, the number and frequency of micro-payments will increase dramatically. However, the mainstream of cryptocurrencies such as Bitcoin and Ethereum fail to meet the need for a large-scale IoT ecosystem due to limit transaction throughput and high transaction fee. Although Layer-2 solutions such as Lightning Network (LN) increases the throughput of cryptocurrencies by allowing participants to conduct off-chain transactions, LN still suffers from two main limitations: participants need to access the Blockchain within a short bounded time, and a payment channel can only accommodate two participants. To overcome these limitations, we propose HyperChannel, a novel distributed layer-2 payment network designed specifically for the IoT ecosystem which outsources the transaction processing task safely to a group of Intel Software Guard Extensions (SGXs) run by for-profit selfish third parties. Clients such as IoT devices and IoT service providers who often trade with each other will be assigned to a channel to conduct high-frequency in-channel transactions while being allowed to conduct crosschannel transactions in a fee-saving fashion. Compared with existing SGX-based layer-2 payment framework, HyperChannel achieves maximum throughput, addresses both limitations of LN, and further lightens the burden of participants so that IoT devices can conduct layer-2 transactions without running an SGX by themselves.
Qingtao Wang, Chi Zhang 0001, Lingbo Wei, Yankai Xie
ICC2
2021 A Secure and Efficient Bitcoin Payment Channel Using Intel SGX
abstract
Hardware trusted execution environment (TEE) provided by Intel SGX enclave has been introduced in existing payment channel schemes as a root-of-trust to enforce faithful protocol execution so that participants do not need to monitor Bitcoin blockchain anymore. However, the security of these schemes relies totally on enclaves. Since private keys of all channel funds are kept by both payment channel participants’ enclaves, a malicious participant can steal funds from the counterparty by defeating her own enclave. To solve the above problem, we present a novel TEE-based payment channel scheme that transfers the responsibility of running enclaves from participants to a third party committee, while relieving both participants from monitoring the blockchain at the same time. Furthermore, since committee members can try to steal funds by defeating their own enclaves, we exploit the additive homomorphic property of signature keys in Elliptic Curve Cryptography to design a novel secret sharing scheme to tolerate a subset of committee members to be malicious. By using the above secret sharing scheme, private keys of the channel funds are never constructed in any committee member’s enclave, so that a malicious committee member cannot steal funds by defeating his own enclave. Finally, experiment shows our scheme can ensure payment channel funds security without efficient compromises compared with existing TEE-based payment channel schemes.
Yankai Xie, Chi Zhang 0001, Lingbo Wei, Qingtao Wang
ICC2
2021 A Hybrid Secure Computation Framework for Graph Neural Networks
abstract
The Multi-party Secure Computation (MPC)-based methods for privacy-preserving Graph Neural Networks (GNNs) are still challenged by high communication overhead. Moreover, the security guarantee of most MPC-based methods can only defend against the semi-honest adversary, while a few methods which can defend against the malicious adversary will cause a further increase in communication overhead. Moreover, Software Guard Extensions (SGX), which can provide the data confidentiality and code integrity, has been considered as a novel solution to privacy-preserving GNN. Unfortunately, previous work has shown that SGX is vulnerable to side-channel attacks that deprive its confidentiality and preserve only its integrity. To solve the above problems, we propose an n-party secure computation framework for GNNs using SGX. This framework can reduce the communication overhead and improve the security guarantee without relying on the confidentiality of SGX. Specifically, both data holders and the server hold SGX. Data holders enrich the data and train the model by MPC efficiently with the assistance of the server. SGX ensures integrity, where data holders and the server must execute according to protocols, so malicious adversaries cannot deviate from the protocol to breach privacy and security. Even if the confidentiality of SGX was breached, the adversary could only access the ciphertext in MPC instead of the plaintext. We conduct experiments on public datasets to demonstrate that our framework has achieved comparable performance with traditional GNNs and perform security analysis to validate that our framework satisfies security and privacy requirements.
Yixuan Ren, Yixin Jie, Qingtao Wang, Chi Zhang 0001, Lingbo Wei
PST5
2021 A Privacy-Preserving Peer-to-Peer Accommodation System Based on a Credit Network
Zhen Wang 0053, Chi Zhang 0001, Lingbo Wei, Jianqing Liu, Yuguang Fang
WASA (2)3
2021 Adaptive Data Transmission and Task Scheduling for High-Definition Map Update
Zhen Wang 0053, Chi Zhang 0001, Chengjie Gu, Miao Pan
WASA (3)3
2021 Collective Memory for Detecting Nonconcurrent Clones: A Localized Approach for Global Topology and Identity Tracing in IoT Networks
abstract
Clone attack is considered as a severely destructive threat in Internet of Things (IoT), because: 1) the attack may be easily launched due to the deficiency of hardware architecture and the limited resources against physical capture and compromise and 2) it may trigger a large variety of insider and outsider attacks. Different from traditional clone attack detection approaches that ground on a large amount of data traversing the network (e.g., locations and identities), this article tackles this problem by answering the following fundamental questions: do we really need so much raw information? whether there is an alternative for local event detection by a node far away from that event? when acquiring/tracing global knowledge of a system/network, do we really need a global collection effort? These questions are of much importance in a large variety of networks. Specifically, this article provides a collective memory design for global topology and identity tracing (GTI Tracing), via a localized computing paradigm within neighborhood. This localized paradigm computationally builds a connection of identity and topology from time and space domain to a new computation domain. Such a computation domain retains four properties: 1) transitivity; 2) global convergence; 3) determinacy; and 4) causality. With byte-size information at an arbitrary device, it can recover and keep tracing global topology and identity information, and thus providing deterministic detection of clones. Both theoretical analysis and experimental study have shown the advantages of the proposed design in both detection accuracy and privacy protection, at a cost of light communication, storage, and computation overhead at each device.
Jing Xu 0007, Chi Zhang 0001, Shuo Zhang 0011, Zhonghu Xu, Chunlin Zhong, Haojin Zhu, Zheng Yang 0002, Yunhao Liu 0001
IEEE Internet Things J.3
2020 Protecting Access Privacy in Ethereum Using Differentially Private Information Retrieval
abstract
The last decade has witnessed fast development of blockchain techniques. However, the high cost of storage space and network bandwidth caused by data synchronization prevents many nodes from joining the network, and becomes a bottleneck impeding the development of blockchain. Traditional schemes typically attempt to transfer most of the storage and computation tasks from a light client to a full node. Nevertheless, they remain susceptible to privacy attacks because light clients need to query and retrieve blockchain data. In this paper, we first describe the privacy issues and challenges for Ethereum data retrieval and then propose a privacy-preserving scheme based on private information retrieval (PIR) to secure retrieval of blockchain data. The main idea is to achieve pointer based PIR search by keywords and introduce differential privacy to mitigate PIR's performance barrier. Hence we achieve a tradeoff between privacy and performance. The evaluations on the Ethereum dataset and analysis show that our scheme is both effective and practical in protecting blockchain access privacy.
Farooq Ahmed, Lingbo Wei, Chi Zhang 0001, Yuguang Fang
GLOBECOM4
2020 Towards Anti-interference WiFi-based Activity Recognition System Using Interference-Independent Phase Component
abstract
Human activity recognition (HAR) has become increasingly essential due to its potential to support a broad array of applications, e.g., elder care, and VR games. Recently, some pioneer WiFi-based HAR systems have been proposed due to its privacy-friendly and device-free characteristics. However, their crucial limitation lies in ignoring the inevitable impact of co-channel interference (CCI), which degrades the performance of these HAR systems significantly. To address this challenge, we propose PhaseAnti, a novel HAR system to exploit the CCI- independent phase component, NLPEV (Nonlinear Phase Error Variation), of Channel State Information (CSI) to cope with the impact of CCI. We provide a rigorous analysis of NLPEV data with respect to its stability and otherness. Validated by our experiments, this phase component across subcarriers is invariant to various CCI scenarios, while different for distinct motions. Based on the analysis, we use NLPEV data to perform HAR in CCI scenarios. Extensive experiments demonstrate that PhaseAnti can reliably recognize activity in various CCI scenarios. Specifically, PhaseAnti achieves a 95% recognition accuracy rate (RAR) on average, which improves up to 16% RAR in the presence of CCI. Moreover, the recognition speed is 9× faster than the state-of-the-art solution.
Jinyang Huang, Bin Liu 0016, Yu Wu 0020, Chi Zhang 0001, Nenghai Yu
INFOCOM7
2020 Turning Waste into Wealth: Free Control Message Transmissions in Indoor WiFi Networks
abstract
A practical WiFi system only achieves a discrete data rate adjustment due to hardware constraints while channel signal-to-noise ratio (SNR) is continuous. This mismatch leads to the SNR gaps. In this paper, we introduce a novel communication mechanism, CoS (Communication through Silent subcarriers), which turns the wasted SNR gaps into new opportunities for transmitting control messages for free. Compared with traditional piggybacking schemes, CoS is more reliable to transmit control messages from one node to many nodes. In CoS, silent subcarriers are inserted into data packets and the intervals between adjacent silent subcarriers are utilized to encode information. Since the wasted SNR gap results in under-utilization of the channel code, the data bit errors induced by silent subcarriers are corrected by the correcting capability of the existing channel code as long as we carefully design the total number of inserted silent subcarriers. Based on CoS, we design CoS-MAC to validate the effectiveness of CoS. We measure the throughput of free control messages achieved by CoS under various channel conditions and conduct simulations to show the throughput gain achieved by CoS-MAC over the existing schemes.
Bing Feng, Chi Zhang 0001, Jianqing Liu, Yuguang Fang
IEEE Trans. Mob. Comput.2
2020 DPavatar: A Real-Time Location Protection Framework for Incumbent Users in Cognitive Radio Networks
abstract
Dynamic spectrum sharing between licensed incumbent users (IUs) and unlicensed wireless industries has been well recognized as an efficient approach to solving spectrum scarcity as well as creating spectrum markets. Recently, both US and European governments called a ruling on opening up spectrum that was initially licensed to sensitive military/federal systems. However, this introduces serious concerns on operational privacy (e.g., location, time, and frequency of use) of IUs for national security concerns. Although several works have proposed obfuscation methods to address this problem, these techniques only rely on syntactic privacy models, lacking rigorous privacy guarantee. In this paper, we propose a comprehensive framework to provide real-time differential location privacy for sensitive IUs. We design a utility-optimal differentially private mechanism to reduce the loss in spectrum efficiency while protecting IUs from harmful interference. Furthermore, we strategically combine differential privacy with another privacy notion, expected inference error, to provide double shield protection for IU's location privacy. Extensive simulations are conducted to validate our design and demonstrate significant improvements in utility and location privacy compared with other existing mechanisms.
Jianqing Liu, Chi Zhang 0001, Beatriz Lorenzo, Yuguang Fang
IEEE Trans. Mob. Comput.2
2019 Differentially Private Robust ADMM for Distributed Machine Learning
abstract
To embrace the era of big data, there has been growing interest in designing distributed machine learning to exploit the collective computing power of the local computing nodes. Alternating Direction Method of Multipliers (ADMM) is one of the most popular methods. This method applies iterative local computations over local datasets at each agent and computation results exchange between the neighbors. During this iterative process, data privacy leakage arises when performing local computation over sensitive data. Although many differentially private ADMM algorithms have been proposed to deal with such privacy leakage, they still have to face many challenging issues such as low model accuracy over strict privacy constraints and requiring strong assumptions of convexity of the objective function. To address those issues, in this paper, we propose a differentially private robust ADMM algorithm (PR-ADMM) with Gaussian mechanism. We employ two kinds of noise variance decay schemes to carefully adjust the noise addition in the iterative process and utilize a threshold to eliminate the too noisy results from neighbors. We also prove that PR-ADMM satisfies dynamic zero-concentrated differential privacy (dynamic zCDP) and a total privacy loss is given by (∈, δ)-differential privacy. From a theoretical point of view, we analyze the convergence rate of PR-ADMM for general convex objectives, which is O(1/K) with K being the number of iterations. The performance of the proposed algorithm is evaluated on real-world datasets. The experimental results show that the proposed algorithm outperforms other differentially private ADMM based algorithms under the same total privacy loss.
Jiahao Ding, Xinyue Zhang 0001, Mingsong Chen 0001, Kaiping Xue, Chi Zhang 0001, Miao Pan
IEEE BigData5
2019 An Efficient Query Scheme for Privacy-Preserving Lightweight Bitcoin Client with Intel SGX
abstract
In Bitcoin, lightweight clients outsource most of storage and computation tasks to full nodes in order to run on resource-limited devices. In the interaction with the full node, the lightweight client leaks considerable information about which address or transaction is relevant to it. The existing schemes to solve this problem do not support efficient yet privacy-preserving transaction search due to the fact that the blockchain is inherently inefficient for transaction query and proposed schemes perform transaction search in a block-by-block manner. Therefore, we propose an efficient transaction query scheme for the privacy-preserving lightweight client with the Intel SGX enclave running on the full node. Our main idea is to leverage the secure enclave to serve transaction-query requests from lightweight clients. However, the usage of secure enclave alone does not achieve our goals. Our scheme reorganizes the blockchain and leverages prefix tree to increase transaction-search efficiency. Due to limited capacity, the secure enclave stores reorganized blockchain data in the untrusted full node. Thus, our scheme integrates prefix tree and oblivious searching technologies to simultaneously support efficient transaction search and protect access pattern of externally stored blockchain data for the secure enclave. Security analysis and performance evaluation show that our scheme provides efficient transaction search and verification functionalities for lightweight Bitcoin clients in a privacy-preserving way.
Yukun Niu, Chi Zhang 0001, Lingbo Wei, Yankai Xie, Yuguang Fang
GLOBECOM2
2019 Optimized Real-Time Flight Data Streaming via Air-to-Air Links for Civil Aviation
abstract
Flight recorders (FRs) are required to be installed in commercial aircrafts to record operating data of planes while in flight for the purpose of facilitating the investigation of aviation accidents. Although being carefully protected, FRs may still become damaged or lost under the extreme conditions. We therefore propose a software-defined wireless networking framework to fully exploit the inter-aircraft air-to-air radio links to stream flight data in real time from the aircraft to a ground control center. With the knowledge of the physical position and predictable trajectory of each commercial aircraft, we formulate a time-expanded connectivity graph for the network controller to maintain a holistic view of the time-varying network status and propose a branch and price algorithm to optimize the flight data flows transmitted through air-to-air links. We also consider the optimality gap introduced by unpredictable network changes and delayed flow reconfigurations, and propose a traffic reroute policy to keep the gap small while minimizing the flow reconfiguration cost. We conduct extensive experiments with real commercial aircraft trajectories in North Atlantic oceanic airspace and demonstrate the feasibility and efficiency of our scheme to support flight data streaming.
Chi Zhang 0001, Miao Pan
ICC3
2019 DPSR: A Differentially Private Social Recommender System for Mobile Users
Xueling Zhou, Lingbo Wei, Yukun Niu, Chi Zhang 0001, Yuguang Fang
WASA4
2019 D2D Communications-Assisted Traffic Offloading in Integrated Cellular-WiFi Networks
abstract
Offloading cellular traffic to WiFi networks plays an important role in alleviating the increasing burden on cellular networks. However, excessive traffic offloading brings severe packet collisions into a WiFi network due to its contention-based medium access scheme, which significantly reduces the WiFi network's throughput. In this paper, we propose DAO, a device-to-device (D2D) communications-assisted traffic offloading scheme to improve the amount of traffic offloaded from cellular to WiFi in integrated cellular and WiFi networks. Specifically, in an integrated cellular-WiFi network, the cellular network exploits D2D communications in licensed cellular bands to aggregate traffic from cellular users before offloading it to the WiFi network to reduce the number of contending users in WiFi access. The traffic offloading process in DAO is formulated as an optimization problem that jointly takes into account the activations of aggregation nodes (ANs) and the connections between ANs and offloading users to maximize the offloaded traffic while guaranteeing the long-term data rates required by the offloading users. Extensive simulation results reveal the significant performance gain achieved by DAO over the existing schemes.
Bing Feng, Chi Zhang 0001, Jianqing Liu, Yuguang Fang
IEEE Internet Things J.2
2018 PhyCast: Towards Energy Efficient Packet Overhearing in WiFi Networks
abstract
WiFi's energy efficiency is a critical issue for battery-powered mobile devices. Since wireless channel has inherent broadcast nature, a non-negligible amount of a device's energy is spent on overhearing useless packets that are not addressed to itself. To resolve packet overhearing problem, most existing schemes are limited to decode data packet or exchange control packet to obtain extra information. In this paper, we propose PhyCast (Physical layer broadCast), a novel communication scheme to embed lightweight information into the front part of data transmission at the physical layer. With PhyCast, the transmitter's neighboring nodes extract information by symbol level energy detection, which does not require receiving and decoding the whole data packet. Therefore, unintended receivers can quickly drop useless packet and switch to a low-power state. The design of PhyCast does not affect the correct decoding of a data packet or sacrifice the normal data throughput. In addition, the communication scheme PhyCast is transparent to the existing WiFi devices, so PhyCast is backward compatible with the 802.11 standard. Our simulation results show that PhyCast achieves significant energy efficiency improvement under various network settings. When a WiFi network includes 15 nodes, PhyCast saves 36.85% energy compared with the 802.11 standard.
Bing Feng, Chi Zhang 0001, Haichuan Ding, Yuguang Fang
ICC2
2018 Exploiting Aerial Heterogeneous Network for Implementing Wireless Flight Recorder
Zhen Wang 0053, Chi Zhang 0001, Yuguang Fang
WASA3
2018 A Privacy-Preserving Networked Hospitality Service with the Bitcoin Blockchain
Hengyu Zhou, Yukun Niu, Jianqing Liu, Chi Zhang 0001, Lingbo Wei, Yuguang Fang
WASA4
2018 EPIC: A Differential Privacy Framework to Defend Smart Homes Against Internet Traffic Analysis
abstract
The Internet of Things (IoT) becomes a novel paradigm as more and more devices are connected to the Internet, enabling several innovative applications such as smart home, industrial automation, and connected health. However, the cyber-attack to these applications is a big issue and countermeasures are in dire need to provide system security and user privacy. In this paper, we address the traffic analysis attack to smart homes, where adversaries intercept the Internet traffic from/to the smart home gateway and profile residents' behaviors through digital traces. Traditional cryptographic tools may not work well due to the effectiveness of adversaries' machine learning algorithms in classifying encrypted traffic, so here we propose a privacy-preserving traffic obfuscation framework to achieve the goal. To be specific, we leverage the smart community network of wirelessly connected smart homes and intentionally direct each smart home's traffic to another home gateway before entering the Internet. The design jointly considers the network energy consumption and the resource constraints in IoT devices, while achieving strong differential privacy guarantee so that adversaries cannot link any traffic flow to a specific smart home. Besides, we consider a hostile smart community network and develop secure multihop routing protocols to guarantee the source/destination unlinkability and satisfy each user's personalized privacy requirement. To evaluate the effectiveness of our framework in protecting privacy and reducing network energy consumption, extensive simulations are conducted and the results demonstrate that our design outperforms other differential privacy mechanism in preserving privacy and minimizing network utility cost.
Jianqing Liu, Chi Zhang 0001, Yuguang Fang
IEEE Internet Things J.2
2018 SpecGuard: Spectrum Misuse Detection in Dynamic Spectrum Access Systems
abstract
Dynamic spectrum access (DSA) is the key to solving worldwide spectrum shortage. The open wireless medium subjects DSA systems to unauthorized spectrum use by illegitimate users. Secondary-user authentication is thus critical to ensure the proper operations of DSA systems. This paper presents SpecGuard, the first crowdsourced spectrum misuse detection framework for DSA systems. In SpecGuard, a transmitter is required to embed a spectrum permit into its physical-layer signals, which can be decoded and verified by ubiquitous mobile users. We propose three novel schemes for embedding and detecting a spectrum permit at the physical layer. The first scheme relies on a higher transmission power to embed the spectrum permit. To alleviate the assumptions on the additional transmission power, the second scheme is proposed with a limited negative impact on the normal data transmission. The third scheme takes a different approach by adopting a novel constellation design and exploiting the trust between the transmitter and the receiver. Crowdsourced spectrum misuse detection eliminates the need for the deployment of dedicated sensors and thus greatly reduces the deployment and maintenance cost. Detailed theoretical analyses, MATLAB simulations, and USRP experiments confirm that our schemes can achieve correct, low-intrusive, and fast spectrum misuse detection.
Xiaocong Jin, Jingchao Sun, Rui Zhang 0007, Chi Zhang 0001
IEEE Trans. Mob. Comput.5
2018 Session-Based Cooperation in Cognitive Radio Networks: A Network-Level Approach
Haichuan Ding, Chi Zhang 0001, Xuanheng Li, Jianqing Liu, Miao Pan, Yuguang Fang, Shigang Chen
IEEE/ACM Trans. Netw.2
2017 Communication through Symbol Silence: Towards Free Control Messages in Indoor WLANs
abstract
Efficient design of wireless networks benefits from the exchange of control messages. However, control message itself consumes scarce channel resources. In this paper, we propose CoS (Communication through symbol Silence), a novel communication strategy that conveys control messages for free without consuming extra channel resources. CoS inserts silence symbols in data packets and leverages the intervals between inserted silence symbols to encode information. The silence symbols can be located by energy detection at the granularity of symbols and the intervals are interpreted into transmitted control messages. Based on our key insights that the channel code is under-utilized in current wireless networks and the distribution of symbol errors within a data packet is predictable in indoor wireless transmissions, the symbols erased by silence symbols are recovered by the coding redundancy that is originally used to correct symbol errors. A rate adaptation scheme is designed to dynamically adjust the rate of free control messages according to channel conditions so that the transmission of free control messages does not harm the original data throughput. We implement CoS on our software defined radio platform to validate the feasibility of CoS. The extensive results show that the control messages are delivered with close to 100% accuracy in a large SNR range. In addition, we measure the achievable capacity of free control messages in various channel conditions.
Bing Feng, Jianqing Liu, Chi Zhang 0001, Yuguang Fang
ICDCS3
2016 DSN: Enabling Lightweight Coordination between Partially Overlapped Channels in Wireless LANs
abstract
Partially overlapped channels (POCs) have been studied recently to improve network performance. However, the current OFDM-based 802.11 system is designed for co-channel communication, and does not support communication over POCs. Thus the coordination between POCs imposes a new challenge to WLANs. In this paper, we present DSN (Data Symbol Nulling), a novel communication strategy that leverages the pattern of data symbols (null or non-null), rather than the actual data symbol value, to convey lightweight control information (or sequences of binary bits). The receiver whose channel is partially overlapped with the sender, interprets thus-transmitted messages by detecting the energy of received data symbols, the minimum resource units in OFDM. A key principle of DSN is that the newly designed communication strategy does not sacrifice original data throughput. Our extensive results validate communication over POCs, and show that lightweight control information can be delivered with close to 100% accuracy. Further, based on this communication paradigm, we propose DSN-MAC, an efficient coordination scheme between POCs in WLANs. The detailed simulation results show that DSN-MAC can substantially improve overall network throughput.
Bing Feng, Chi Zhang 0001, Yuguang Fang
GLOBECOM2
2016 Privacy-Preserving Genome-Aware Remote Health Monitoring
abstract
Using genetic profiles of individuals for tailored diagnosis and treatment has great promise in the healthcare industry. Despite of the rapid growth in genome-aware medicine, genome-aware health monitoring has not been studied as well. A major stumbling block is the privacy issues of such applications. In addition to privacy concerns in a traditional health monitoring system, i.e., the privacy of users' biomedical sensing data and the protection of the proprietary health monitoring program, severe privacy concerns arise when users' genomic data are integrated into the health monitoring program due to the re-identification and phenotype attacks based on the DNA profile and the relevance of DNA information in a family. In this paper, we investigate these privacy risks and propose a privacy- preserving approach for genome-aware health monitoring. In our approach, users can only learn the diagnostic results based on their genomic and biomedical sensing data, while the the healthcare service provider learns nothing. Security analysis and performance evaluations are conducted to illustrate the effectiveness and efficiency of the proposed approach.
Yanmin Gong 0001, Chi Zhang 0001, Yaodan Hu, Yuguang Fang
GLOBECOM2
2016 Policy-Based Privacy-Preserving Scheme for Primary Users in Database-Driven Cognitive Radio Networks
abstract
In cognitive radio networks (CRNs), spectrum database has been well recognized as an effective means to dynamically sharing licensed spectrum among primary users (PUs) and secondary users (SUs). In spectrum database, the protected incumbents (a.k.a. PUs) and the CRs (a.k.a. SUs) are required to register in database their operational specifications such as transmitting power, antenna height, time of operation and etc. so as to provide an up-to-date radio map for public queries and avoid possible interference. However, it poses potentially serious privacy problems especially when governmental and military systems participate in spectrum sharing through spectrum database. Most recent research works in database-driven CRNs, however, only focused on protecting user's location privacy but merely studied preserving PUs' operational specifications. In this paper, we propose a secure and privacy-preserving scheme using hidden policy-assisted attribute-based encryption technique to protect sensitive PUs' operational privacy without affecting database's accessibility and spectrum utilization efficiency. The security and performance analysis demonstrates that our scheme is secure and computationally efficient. Additionally, our policy-assisted scheme is practical and promising because of its consistency with FCC/NTIA's rule in spectrum regulation in database-driven CRNs.
Jianqing Liu, Chi Zhang 0001, Haichuan Ding, Hao Yue 0001, Yuguang Fang
GLOBECOM2
2016 Dynamic Matching Based Distributed Spectrum Trading in Multi-Radio Multi-Channel CRNs
abstract
Spectrum trading not only improves spectrum utilization but also benefits both secondary users (SUs) with more accessing opportunities and primary users (PUs) with monetary gains. Although existing centralized designs consider the special features of spectrum trading (e.g., frequency reuse, interference mitigation, multi-radio multi- channel transmissions, etc.), they have to deploy new infrastructure, deal with extra control overhead, have scalability issues, and may miss many instantaneous opportunities. To address those issues, in this paper, we propose a novel dynamic matching based distributed spectrum trading (DMDST) scheme in multi-radio multi- channel cognitive radio (CR) networks. We employ conflict graph to characterize interference relationship among SUs with multiple CR radios, and formulate the centralized PUs' revenue maximization problem under multiple constrains. In view of the NP- hardness of solving the problem and no existence of centralized entity, we develop the DMDST algorithms based on conflict graph observed by PUs, solve the problem via dynamic matching with evolving preferences, and prove its stability. Through extensive simulations, we show that the results of proposed DMDST algorithm is close to the optimal one and outperforms other distributed algorithms without considering spectrum reuse.
Jingyi Wang 0002, Wenbo Ding 0001, Yuanxiong Guo, Chi Zhang 0001, Miao Pan, Jian Song 0004
GLOBECOM4
2016 A Firewall of Two Clouds: Preserving Outsourced Firewall Policy Confidentiality with Heterogeneity
abstract
It is increasingly common for enterprises and other organizations to outsource firewalls to public clouds in order to reduce the cost and complexity in deploying and maintaining dedicated hardware middleboxes. However, this poses a serious threat to the enterprise network security because sensitive network policies, such as firewall rules, are revealed to cloud providers, which may be leaked and exploited by attackers. In this paper, we design and implement a SE- FWaaS, a secured system that enables cloud providers to support middlebox (e.g., firewall) outsourcing while preserving the network policy confidentiality. The key ingredients in our SE-FWaaS are the distribution of the firewall primitives, namely policy checking and verdict enforcing, to two independent public clouds, and the enabling techniques of efficient firewall rule obfuscation and oblivious rule-matching. Our SE-FWaaS provides the maximum achievable level of protection of network policies by enforcing the principle of the least privilege and removing the threat of offline probing attacks. We evaluate the proposed system over real-world firewall rules and demonstrate its effectiveness and feasibility.
Lingbo Wei, Chi Zhang 0001, Yanmin Gong 0001, Yuguang Fang, Kefei Chen
GLOBECOM2
2016 Attribute-based encryption scheme based on SIFF
abstract
Attribute-Based Encryption (ABE) is a public key encryption scheme that allows users to encrypt and decrypt messages based on user attributes. In this paper, we consider the problem of constructing a ciphertext-policy attribute-based encryption (CP-ABE) scheme in a setting where the attributes distributor is also the owner of messages that are to be encrypted and shared. The CP-ABE scheme we propose bases on the Sibling Intractable Function Family (SIFF) scheme. Compared to the existing ABE schemes, the decryption of our scheme in this setting is quite fast and the ciphertext size is rather small. Our ABE system also provides a high degree of compatibility with the messages that are already encrypted when our system is set up, namely, encrypted messages can be used directly in our scheme without being re-encrypted. We compare the efficiency of our scheme with Bethencourt's work in this paper.
Lingbo Wei, Chi Zhang 0001
ICC3
2016 TrInc-Based Secure and Privacy-Preserving Protocols for Vehicular Ad Hoc Networks
abstract
In vehicular ad hoc networks (VANETs), vehicles communicate with each other and with roadside units (RSUs) in order to enhance road safety, improve traffic management and provide infotainment services. Along with the growth of VANETs, some challenges are emerging. Although there are many research work on VANETs, cheating attacks are still not well resolved such as selective message relaying attack, faked information reporting attack and resource-consuming attack launched by selfish or malicious participants. To deal with this kind of attacks, we present two novel lightweight security mechanisms by equipped each vehicle's On-Board Unit (OBU) with a small elegant module called TrInc, which is a trusted hardware and composed of only a non-decreasing counter and a key. We observe that TrInc-based method not only can effectively resist against cheating attacks in safety- oriented, convenience-oriented, and commercial-oriented VANET applications, but also significantly defend various aspects of security and privacy in VANETs. Compared with previous works, our proposal features low communication and computation overhead, less memory requirements, and good network scalability.
Lingbo Wei, Chi Zhang 0001
VTC Spring2
2016 A Secure and Privacy-Preserving Billing Scheme for Online Electric Vehicles
abstract
The Online Electric Vehicle (OLEV) concept is introduced by Korea Advanced Institute of Science and Technology (KAIST) in South Korea. In OLEV system, an electric vehicle (EV) picks up electric energy remotely from power transmitters (PTs) which are buried under a certain route using its pick-up device while the EV is running. The OLEV uses wireless power transfer (WPT) technology which has been widely adopted to charge the batteries of EVs. However, there is not any billing systems for OLEV up to now. In this paper, we propose a secure and privacy-preserving billing scheme for OLEV. Users can buy electric energy from power supply company and charge their EVs anonymously and unlinkably. We assume that each PT transmits a fixed amount of energy to the EV and the energy supply company bills the EV a same amount of money for the electric energy from every PT. EVs can buy the energy according to the levels of their batteries.
Lingbo Wei, Chi Zhang 0001
VTC Spring3
2016 Piggybacking Lightweight Control Messages on Physical Layer for Multicarrier Wireless LANs
Bing Feng, Chi Zhang 0001, Lingbo Wei, Yuguang Fang
WASA2
2016 Optimal Task Recommendation for Mobile Crowdsourcing With Privacy Control
abstract
Mobile crowdsourcing (MC) is a transformative paradigm that engages a crowd of mobile users (i.e., workers) in the act of collecting, analyzing, and disseminating information or sharing their resources. To ensure quality of service, MC platforms tend to recommend MC tasks to workers based on their context information extracted from their interactions and smartphone sensors. This raises privacy concerns hard to address due to the constrained resources on mobile devices. In this paper, we identify fundamental tradeoffs among three metrics-utility, privacy, and efficiency-in an MC system and propose a flexible optimization framework that can be adjusted to any desired tradeoff point with joint efforts of MC platform and workers. Since the underlying optimization problems are NP-hard, we present efficient approximation algorithms to solve them. Since worker statistics are needed when tuning the optimization models, we use an efficient aggregation approach to collecting worker feedbacks while providing differential privacy guarantees. Both numerical evaluations and performance analysis are conducted to demonstrate the effectiveness and efficiency of the proposed framework.
Yanmin Gong 0001, Lingbo Wei, Yuanxiong Guo, Chi Zhang 0001, Yuguang Fang
IEEE Internet Things J.4
2016 M3-STEP: Matching-Based Multi-Radio Multi-Channel Spectrum Trading With Evolving Preferences
abstract
Spectrum trading not only improves spectrum utilization but also benefits both secondary users (SUs) with more accessing opportunities and primary users (PUs) with monetary gains. Although the existing centralized designs consider the special features of spectrum trading (e.g., frequency reuse, interference mitigation, multi-radio multi-channel transmissions, and so on), they still have to face many practical but challenging issues, such as the new infrastructure deployment, the extra control overhead, and the scalability issues. To address those issues, in this paper, we propose a novel matching-based multi-radio multi-channel spectrum trading (M3-STEP) scheme in cognitive radio (CR) networks. We employ conflict graph to characterize the interference relationship among SUs with multiple CR radios, and formulate the centralized PUs' revenue maximization problem under multiple constrains. In view of the NP-hardness of solving the problem and no existence of centralized entity, we develop the M3-STEP algorithms based on conflict graph observed by PUs, solve the problem via dynamic matching with evolving preferences, and prove its pairwise stability. Simulation results show that the proposed M3-STEP algorithm achieves close to optimal performance and outperforms other distributed algorithms without considering spectrum reuse.
Jingyi Wang 0002, Wenbo Ding 0001, Yuanxiong Guo, Chi Zhang 0001, Miao Pan, Jian Song 0004
IEEE J. Sel. Areas Commun.4
2016 TrueTop: A Sybil-Resilient System for User Influence Measurement on Twitter
abstract
Influential users have great potential for accelerating information dissemination and acquisition on Twitter. How to measure the influence of Twitter users has attracted significant academic and industrial attention. Existing influence measurement techniques are vulnerable to sybil users that are thriving on Twitter. Although sybil defenses for online social networks have been extensively investigated, they commonly assume unique mappings from human-established trust relationships to online social associations and thus do not apply to Twitter where users can freely follow each other. This paper presents TrueTop, the first sybil-resilient system to measure the influence of Twitter users. TrueTop is rooted in two observations from real Twitter datasets. First, although non-sybil users may incautiously follow strangers, they tend to be more careful and selective in retweeting, replying to, and mentioning other users. Second, influential users usually get much more retweets, replies, and mentions than non-influential users. Detailed theoretical studies and synthetic simulations show that TrueTop can generate very accurate influence measurement results with strong resilience to sybil attacks.
Jinxue Zhang, Rui Zhang 0007, Jingchao Sun, Chi Zhang 0001
IEEE/ACM Trans. Netw.5
2015 Design and Analysis of a Prioritized Adaptive Multiple Access Scheme for VoIP over WLANs
abstract
Voice capacity over wireless local area networks (WLANs) can be increased by the statistical multiplexing among on/off voice calls. However, in previously proposed schemes, the admitted voice calls that transit from silence state to talkspurt state are mixed up with the new voice calls to contend for the channel. The increase in the traffic load of new voice users could degrade the performance of ongoing voice calls. In this paper, we propose a novel MAC scheme for VoIP over WLANs, referred to as PAMA (Prioritized Adaptive Multiple Access). The key features of the proposed scheme are that 1) the admitted voice calls have higher priority access to the channel than the new voice calls, based on the fact that maintaining the required QoS of ongoing calls is more important than admitting new calls; 2) the dedicated contention window for admitted voice calls is dynamically adjusted according to the current estimation of the number of active ongoing voice calls to guarantee the QoS requirements; 3) a two-state Markov model is established to evaluate the system performance. Analytical and simulation results demonstrate that PAMA can increase the voice capacity while still satisfying the QoS of admitted voice calls.
Bing Feng, Zhen Wang 0053, Chi Zhang 0001, Yuguang Fang
GLOBECOM3
2015 Sequentially ordered backoff: Towards implicit resource reservation for wireless LANs
abstract
In this paper, we present SOBO, a novel hybrid MAC protocol using sequentially ordered backoff in wireless LANs. SOBO eliminates packet collisions and wasted idle backoff slots by introducing implicit resource reservation into 802.11 DCF. In SOBO, the AP divides time into repeating cycles by beacon frames. Exploiting the implicit information of successful transmission order in every cycle, sequentially ordered backoff in a distributed manner during reservation period is achieved without extra control packets. In addition, we propose a novel scheme to estimate the number of contention stations, and design an adaptive contention window algorithm. We also analyze the robustness of SOBO against message losses in realistic networks with channel errors. The performance of SOBO is verified via extensive simulations with different scenarios. Our simulation results show that SOBO achieves a significant increase in network throughput compared to the legacy 802.11 DCF.
Bing Feng, Chi Zhang 0001, Bin Liu 0016, Yuguang Fang
ICC2
2015 A secure and privacy-preserving payment system for Electric vehicles
abstract
The Electric vehicle (EV) will become futuristic and promising for its advantages such as pro-environment, high energy efficiency and so forth. However, Due to the boundedness of batteries, EVs must be recharged very frequently. In this paper, we propose a secure and privacy-preserving payment system for EVs to charge their batteries with reservation service. A user can only reserve a limited number of charging stations simultaneously using our system so that he can not misuse it before charging their EVs. More importantly, our system can not only protect the privacy of users in order that the charging stations cannot know the identities of users, but also provide a lost-protection service to users so that users can find their stolen vehicles with the help of a trusted authorities. The price of charging and reservation is dynamic according to the charging time, the location of the charging station and some attributes of the users.
Chi Zhang 0001, Lingbo Wei
ICC2
2015 SpecGuard: Spectrum misuse detection in dynamic spectrum access systems
abstract
Dynamic spectrum access is the key to solving worldwide spectrum shortage. The open wireless medium subjects DSA systems to unauthorized spectrum use by illegitimate users. This paper presents SpecGuard, the first crowdsourced spectrum misuse detection framework for DSA systems. In SpecGuard, a transmitter is required to embed a spectrum permit into its physical-layer signals, which can be decoded and verified by ubiquitous mobile users. We propose three novel schemes for embedding and detecting a spectrum permit at the physical layer. Detailed theoretical analyses, MATLAB simulations, and USRP experiments confirm that our schemes can achieve correct, low-intrusive, and fast spectrum misuse detection.
Xiaocong Jin, Jingchao Sun, Rui Zhang 0007, Chi Zhang 0001
INFOCOM5
2015 Retraining and Dynamic Privilege for Implicit Authentication Systems
abstract
With the rapid growth of the smart device market, associated security issues become more threatening and diverse than ever before. Due to the limitations of the traditional explicit authentication mechanisms (e.g., Password-based, biometrics), researchers and the industry have been promoting implicit authentication (IA) that does not require explicit user action and potentially enhances user experience to further protect devices from misuse. IA typically leverages various types of behavioral data to deduce a user behavior model for authentication purpose. However, IA systems are still at their infancy and exhibit many limitations, one of which is how to determine the best retraining frequency when updating the user behavior model. Another limitation is how to gracefully degrade user privilege, when authentication fails to identify legitimate users (i.e., False negatives) for a practical IA system. To address the first problem, we propose an algorithm that utilizes Jensen-Shannon (JS)-dis(tance) to determine the optimal retraining frequency. For the second problem, we introduce a dynamic privilege mechanism, again based on JS-dis(tance), to achieve multi-level fine-grained access control. Our simulation results show that the proposed techniques can successfully detect the degradation of accuracy of the user behavior model, as well as automatically determine and adjust to the best retraining frequency. It is also shown that the dynamic privilege-based access control reduces the impact of false negatives on legitimate users and enhances system reliability and user experience compared with the traditional lock-only method in case of authentication failure.
Yingyuan Yang, Jinyuan Sun, Chi Zhang 0001, Pan Li 0001
MASS3
2015 Soft Reservation Based Prioritized Access: Towards Performance Enhancement for VoIP over WLANs
Bing Feng, Zhen Wang 0053, Chi Zhang 0001, Nenghai Yu, Yuguang Fang
WASA3
2015 A Privacy-Preserving Attribute-Based Reputation System in Online Social Networks
Linke Guo, Chi Zhang 0001, Yuguang Fang, Phone Lin
J. Comput. Sci. Technol.2
2015 Secure Spatial Top-k Query Processing via Untrusted Location-Based Service Providers
abstract
This paper considers a novel distributed system for collaborative location-based information generation and sharing which become increasingly popular due to the explosive growth of Internet-capable and location-aware mobile devices. The system consists of a data collector, data contributors, location-based service providers (LBSPs), and system users. The data collector gathers reviews about points-of-interest (POIs) from data contributors, while LBSPs purchase POI data sets from the data collector and allow users to perform spatial top-k queries which ask for the POIs in a certain region and with the highest k ratings for an interested POI attribute. In practice, LBSPs are untrusted and may return fake query results for various bad motives, e.g., in favor of POIs willing to pay. This paper presents three novel schemes for users to detect fake spatial snapshot and moving top-k query results as an effort to foster the practical deployment and use of the proposed system. The efficacy and efficiency of our schemes are thoroughly analyzed and evaluated.
Rui Zhang 0007, Jingchao Sun, Chi Zhang 0001
IEEE Trans. Dependable Secur. Comput.4
2015 A Trust-Based Privacy-Preserving Friend Recommendation Scheme for Online Social Networks
abstract
Online social networks (OSNs), which attract thousands of million people to use everyday, greatly extend OSN users' social circles by friend recommendations. OSN users' existing social relationship can be characterized as 1-hop trust relationship, and further establish a multi-hop trust chain during the recommendation process. As the same as what people usually experience in the daily life, the social relationship in cyberspaces are potentially formed by OSN users' shared attributes, e.g., colleagues, family members, or classmates, which indicates the attribute-based recommendation process would lead to more fine-grained social relationships between strangers. Unfortunately, privacy concerns raised in the recommendation process impede the expansion of OSN users' friend circle. Some OSN users refuse to disclose their identities and their friends' information to the public domain. In this paper, we propose a trust-based privacy-preserving friend recommendation scheme for OSNs, where OSN users apply their attributes to find matched friends, and establish social relationships with strangers via a multi-hop trust chain. Based on trace-driven experimental results and security analysis, we have shown the feasibility and privacy preservation of our proposed scheme.
Linke Guo, Chi Zhang 0001, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.2
2014 Quadtree-based optimal path routing with the smallest routing table size
abstract
Routing schemes play an important role in the network. In terms of the information utilized by routing, the existing schemes can be classified into two main groups: topology-based routing and geographical routing. The former can always guarantee the optimal path, but its routing tables often contain massive entries which seriously impact the algorithm's efficiency. The latter can not guarantee the optimal path, but its routing table size is fairly small. Based on the characteristics of above routing mechanisms, we present a novel geographical routing mechanism which can guarantee the optimal path with the minimum overhead. By utilizing the geographical location information and the quadtree data structure, the routing table size can be reduced to its information-theoretic lower bound. Our theoretical analysis suggests that the performance of the routing table size of our proposed scheme is better than the best IP-based routing table compression result in the literature.
Tingting Wu 0007, Chi Zhang 0001, Nenghai Yu, Miao Pan
GLOBECOM2
2014 A Privacy-Preserving Attribute-Based Authentication System for Mobile Health Networks
abstract
Electronic healthcare (eHealth) systems have replaced paper-based medical systems due to the attractive features such as universal accessibility, high accuracy, and low cost. As a major component of eHealth systems, mobile healthcare (mHealth) applies mobile devices, such as smartphones and tablets, to enable patient-to-physician and patient-to-patient communications for better healthcare and quality of life (QoL). Unfortunately, patients' concerns on potential leakage of personal health records (PHRs) is the biggest stumbling block. In current eHealth/mHealth networks, patients' medical records are usually associated with a set of attributes like existing symptoms and undergoing treatments based on the information collected from portable devices. To guarantee the authenticity of those attributes, PHRs should be verifiable. However, due to the linkability between identities and PHRs, existing mHealth systems fail to preserve patient identity privacy while providing medical services. To solve this problem, we propose a decentralized system that leverages users' verifiable attributes to authenticate each other while preserving attribute and identity privacy. Moreover, we design authentication strategies with progressive privacy requirements in different interactions among participating entities. Finally, we have thoroughly evaluated the security and computational overheads for our proposed schemes via extensive simulations and experiments.
Linke Guo, Chi Zhang 0001, Jinyuan Sun, Yuguang Fang
IEEE Trans. Mob. Comput.2
2014 PSaD: A Privacy-Preserving Social-Assisted Content Dissemination Scheme in DTNs
abstract
Content dissemination is very useful for many mobile applications, like instant messaging, file sharing, and advertisement broadcast, etc. In real life, for various kinds of time-insensitive contents, such as family photos and video clips, the process of content dissemination forms a delay tolerant networks (DTNs). To improve the data forwarding performance in DTNs, several social-based approaches have been proposed, most of which leverage mobile users' social information, including contact history, moving trajectory, and personal profiles as metrics to design routing schemes. However, although the social-based approaches provide better performance, the revealing of mobile users' information apparently compromises their privacy. Moreover, users' contents may only be shared with a particular group of users rather everyone in the system. In this paper, we propose the PSaD: a Privacy-preserving Social-assisted content Dissemination scheme in DTNs. We apply users' verifiable attributes to establish their social relationships in terms of identical attributes in a privacy-preserving way. Besides, to provide the confidentiality of contents, our approach enables users to encrypt contents before the dissemination process, and only allows users who have particular attributes to decrypt them. By trace-driven simulations and experiments, we show the performance, privacy preservation, and efficiency of our proposed scheme.
Linke Guo, Chi Zhang 0001, Hao Yue 0001, Yuguang Fang
IEEE Trans. Mob. Comput.2
2014 Unknown-Target Information Collection in Sensor-Enabled RFID Systems
abstract
Sensor-enabled radio frequency identification (RFID) technology has generated a lot of interest from industries lately. Integrated with miniaturized sensors, RFID tags can provide not only the IDs, but also valuable real-time information about the state of the objects or their surrounding environment, which can benefit many practical applications, such as warehouse management and inventory control. In this paper, we study the problem of designing efficient protocols for a reader to collect sensor-produced information from unknown target tags in an RFID system with minimum execution time. Different from information collection with all target tags known a priori, in the scenarios we consider, the reader has to first find out the target tags in order to read information from them, which makes traditional information collection protocols not efficient any more. We design a Bloom-filter-based information collection protocol (BIC) to address this challenging problem. A Bloom filter is constructed for the reader to efficiently determine the target tags, which significantly reduces the communication and time overhead. We also introduce the allocation vectors to coordinate the transmissions from different tags and minimize collision during information collection. Extensive simulation results demonstrate that our protocol is highly efficient in terms of execution time, and it performs much better than other solutions.
Hao Yue 0001, Chi Zhang 0001, Miao Pan, Yuguang Fang, Shigang Chen
IEEE/ACM Trans. Netw.2
2013 Privacy-preserving attribute-based friend search in geosocial networks with untrusted servers
abstract
Location-based Services (LBSs) enable mobile users to request and obtain certain services based on their current locations, such as finding nearby gas station, looking for coffee shops, and using online GPS navigation, etc. As a major branch of LBSs, geosocial networking services, such as Foursquare, become popular due to the explosive growth of smartphone users. Geosocial networking services allow people to use their location information to find potential friends who have similar interests within close proximity and initiate communications with each other. However, most existing geosocial networking services ask for mobile users' current location information and store it on an untrusted server with less privacy concerns. To some extent, mobile users need to reveal their interests and physical location information to a service provider in order to realize the functionality of geosocial networking, which apparently deteriorates users' privacy on the aspects of their profiles and locations. In this paper, we propose a privacy-preserving friend search scheme in geosocial networks without relying on a trusted centralized server. Our scheme lets localization infrastructures, such as base stations, create encrypted searchable tables on an untrusted server and allow mobile users to search for their possible friends using their profiles without exposing their location information. Extensive trace-driven simulation results and analysis show both the efficiency and privacy preservation of our proposed scheme.
Linke Guo, Xiaoyan Zhu 0005, Chi Zhang 0001, Yuguang Fang
GLOBECOM3
2013 JSM-2 based ECG compression with statistical support prediction
abstract
This paper addresses the problem of developing an efficient compression scheme with high quality and low computational complexity for ECG signal compression. Taking into account the joint sparsity existing in ECG data and the temporal dependencies in ECG signal sequence, a novel scheme for JSM-2 based ECG compression is developed to exploit these characteristics. We first predict support information in sparse domain from the previous ECG data for the current recovery process. Then a modified Simultaneous Orthogonal Matching Pursuit Algorithm (SOMP) algorithm is proposed to incorporate the idea of support information establishment for JSM-2 based ECG compression. Simulation results show that the proposed JSM-2 based ECG compression scheme with statistical support prediction outperforms existing schemes with enhanced performance and low computational complexity.
Sucheng Yu, Bin Liu 0016, Chi Zhang 0001, Chang Wen Chen
Healthcom4
2013 Secure crowdsourcing-based cooperative pectrum sensing
abstract
Cooperative (spectrum) sensing is a key function for dynamic spectrum access and is essential for avoiding interference with licensed primary users and identifying spectrum holes. A promising approach for effective cooperative sensing over a large geographic region is to rely on special spectrum-sensing providers (SSPs), which outsource spectrum-sensing tasks to distributed mobile users. Its feasibility is deeply rooted in the ubiquitous penetration of mobile devices into everyday life. Crowdsourcing-based cooperative spectrum sensing is, however, vulnerable to malicious sensing data injection attack, in which a malicious CR users submit false sensing reports containing power measurements much larger (or smaller) than the true value to inflate (or deflate) the final average, in which case the SSP may falsely determine that the channel is busy (or vacant). In this paper, we propose a novel scheme to enable secure crowdsourcing-based cooperative spectrum sensing by jointly considering the instantaneous trustworthiness of mobile detectors in combination with their reputation scores during data fusion. Our scheme can enable robust cooperative sensing even if the malicious CR users are the majority. The efficacy and efficiency of our scheme have been confirmed by extensive simulation studies.
Rui Zhang 0007, Jinxue Zhang, Chi Zhang 0001
INFOCOM4
2013 A privacy-preserving social-assisted mobile content dissemination scheme in DTNs
abstract
Mobile content dissemination is very useful for many mobile applications in delay tolerant networks (DTNs), like instant messaging, file sharing, and advertisement dissemination, etc. Recently, social-based approaches, which attempt to exploit social behaviors of DTN users to forward time-insensitive data, such as family photos and friends' sightseeing video clips, have attracted intensive attentions in designing routing schemes in DTNs. Most social-based schemes leverage users' contact history and social information (e.g., community and friendship) as metrics to improve the dissemination performance. In these schemes, users need to obtain others' social information to determine their dissemination strategy, which apparently compromises others users' privacy. Moreover, the owner of mobile contents may only want to disclose his/her data to a particular group of users rather than revealing it to the public. In this paper, we propose a privacy-preserving social-assisted mobile content dissemination scheme in DTNs. We apply users' verifiable attributes to establish their potential social relationships in terms of identical attributes in a privacy-preserving way. Besides, to provide the confidentiality of mobile contents, our approach enables users to encrypt contents before the dissemination process, and only allows users who have particular attributes to decrypt them. By trace-driven simulations and experiments, we show the security and efficiency of our proposed scheme.
Linke Guo, Chi Zhang 0001, Hao Yue 0001, Yuguang Fang
INFOCOM2
2013 Prediction-based dynamic relay transmission scheme for Wireless Body Area Networks
abstract
To support long-term pervasive healthcare services, communications in Wireless Body Area Networks (WBANs) need to be both reliable and energy-efficient. As a cooperative transmission method, relay transmission scheme works effectively in resisting shadowing effect and improving reliability in WBANs. However, the extra energy consumption introduced by relay transmission is very high, which can shorten the lifetime of the whole network. In this paper, temporal and spatial correlation models for on-body channels are first presented to better characterize the slow fading effect of on-body channels. Then a prediction-based dynamic relay transmission (PDRT) scheme that makes full use of the correlation characteristics of on-body channels is proposed. In the PDRT scheme, “when to relay” and “who to relay” are decided in an optimal way based on the last known channel states. Moreover, neither extra signaling procedure nor dedicated channel sensing period is needed. Simulation results show that the PDRT scheme achieves significant performance improvement in energy efficiency, as well as ensuring the transmission reliability.
Bin Liu 0016, Zhisheng Yan, Chi Zhang 0001, Chang Wen Chen
PIMRC4
2013 Verifiable Privacy-Preserving Aggregation in People-Centric Urban Sensing Systems
abstract
People-centric urban sensing systems (PC-USSs) refer to using human-carried mobile devices such as smartphones and tablets for urban-scale distributed data collection, analysis, and sharing to facilitate interaction between humans and their surrounding environments. A main obstacle to the widespread deployment and adoption of PC-USSs are the privacy concerns of participating individuals as well as the concerns about data integrity. To tackle this open challenge, this paper presents the design and evaluation of VPA, a novel peer-to-peer based solution to verifiable privacy-preserving data aggregation in PC-USSs. VPA achieves strong user privacy by letting each user exchange random shares of its datum with other peers, while at the same time ensures data integrity through a combination of Trusted Platform Module and homomorphic message authentication code. VPA can support a wide range of statistical additive and non-additive aggregation functions such as Sum, Average, Variance, Count, Max/Min, Median, Histogram, and Percentile with accurate aggregation results. The efficacy and efficiency of VPA are confirmed by thorough analytical and simulation results.
Rui Zhang 0007, Jing Shi 0002, Chi Zhang 0001
IEEE J. Sel. Areas Commun.4
2013 CAM: Cloud-Assisted Privacy Preserving Mobile Health Monitoring
abstract
Cloud-assisted mobile health (mHealth) monitoring, which applies the prevailing mobile communications and cloud computing technologies to provide feedback decision support, has been considered as a revolutionary approach to improving the quality of healthcare service while lowering the healthcare cost. Unfortunately, it also poses a serious risk on both clients' privacy and intellectual property of monitoring service providers, which could deter the wide adoption of mHealth technology. This paper is to address this important problem and design a cloud-assisted privacy preserving mobile health monitoring system to protect the privacy of the involved parties and their data. Moreover, the outsourcing decryption technique and a newly proposed key private proxy reencryption are adapted to shift the computational complexity of the involved parties to the cloud without compromising clients' privacy and service providers' intellectual property. Finally, our security and performance analysis demonstrates the effectiveness of our proposed design.
Huang Lin, Jun Shao 0001, Chi Zhang 0001, Yuguang Fang
IEEE Trans. Inf. Forensics Secur.3
2013 Path Selection under Budget Constraints in Multihop Cognitive Radio Networks
abstract
Cognitive radio (CR) technology opens the licensed spectrum bands for opportunistic usage and initiates spectrum trading to improve the spectrum utilization. In this paper, we investigate the path selection problem in multihop cognitive radio networks (CRNs) under constraints on flow routing, link scheduling and CR source's budget. We extend the per-user-based spectrum trading in prior work to CR session-based spectrum trading, and effectively develop the spectrum trading mechanisms based on the cross-layer optimization in multihop CRNs. We introduce a new service provider, called secondary service provider (SSP), to help CR sessions to select the paths for packet delivery. Considering the price of bands and the potential returning of primary services at different CR links, the SSP purchases the licensed spectrum and jointly conducts flow routing and link scheduling under the budget constraints. We also propose a 4D conflict graph to characterize the conflict relationship among CR links and mathematically formulate the path selection problem under multiple constraints into an optimization problem with the objective of maximizing the end-to-end throughput. Due to the NP-hardness of the problem, we have also developed a heuristic algorithm to find the approximate solution.
Miao Pan, Hao Yue 0001, Chi Zhang 0001, Yuguang Fang
IEEE Trans. Mob. Comput.3
2012 CPTT: A high-throughput coding-aware routing metric for multi-hop wireless networks
abstract
Network coding is widely recognized as a promising approach to increase the throughput of wireless networks. In order to maximize the benefit of network coding, the consideration of potential coding opportunities is incorporated into the route selection, which is referred to as coding-aware routing. Most of existing coding-aware routing metrics are designed based on traditional routing metrics like expected transmission count (ETX) and fail to take many critical factors into account, such as traffic load, link transmission rate and interference. Therefore, the routes discovered with them are always sub-optimal. In this paper, we present a novel routing metric called Coding-aware Path Transmission Time (CPTT). CPTT considers the effect of traffic load, multirate, intra-flow and inter-flow interference as well as network coding and quantifies them in a unified manner, which can be used to accurately evaluate path performance and discover the path with high throughput. Through extensive simulations, we compare CPTT with different coding-aware routing metrics proposed in the literature and show that the paths selected with CPTT have maximum end-to-end throughput under network coding.
Hao Yue 0001, Xiaoyan Zhu 0005, Chi Zhang 0001, Yuguang Fang
GLOBECOM3
2012 PAAS: A Privacy-Preserving Attribute-Based Authentication System for eHealth Networks
abstract
Recently, eHealth systems have replaced paper based medical system due to its prominent features of convenience and accuracy. Also, since the medical data can be stored on any kind of digital devices, people can easily obtain medical services at any time and any place. However, privacy concern over patient medical data draws an increasing attention. In the current eHealth networks, patients are assigned multiple attributes which directly reflect their symptoms, undergoing treatments, etc. Those life-threatened attributes need to be verified by an authorized medical facilities, such as hospitals and clinics. When there is a need for medical services, patients have to be authenticated by showing their identities and the corresponding attributes in order to take appropriate healthcare actions. However, directly disclosing those attributes for verification may expose real identities. Therefore, existing eHealth systems fail to preserve patients' private attribute information while maintaining original functionalities of medical services. To solve this dilemma, we propose a framework called PAAS which leverages users' verifiable attributes to authenticate users in eHealth systems while preserving their privacy issues. In our system, instead of letting centralized infrastructures take care of authentication, our scheme only involves two end users. We also offer authentication strategies with progressive privacy requirements among patients or between patients and physicians. Based on the security and efficiency analysis, we show our framework is better than existing eHealth systems in terms of privacy preservation and practicality.
Linke Guo, Chi Zhang 0001, Jinyuan Sun, Yuguang Fang
ICDCS2
2012 A time-efficient information collection protocol for large-scale RFID systems
abstract
Sensor-enabled RFID technology has generated a lot of interest from industries lately. Integrated with miniaturized sensors, RFID tags could provide not only the IDs but also valuable real-time information about the state of the corresponding objects or the surrounding environment, which is beneficial to many practical applications, such as warehouse management and inventory control. In this paper, we study the problem on how to design efficient protocols to collect such sensor information from numerous tags in a large-scale RFID system with a number of readers deployed. Different from information collection in the small RFID system covered by only one reader, in the multi-reader scenario, each reader has to first find out which tags located in its interrogation region in order to read information from them. We start with two categories of warm-up solutions that are directly extended from the existing information collection protocols for single-reader RFID systems, and show that all of them do not work well for the multi-reader information collection problem due to their inefficiency of identifying the interrogated tags. Then, we propose a novel solution, called the Bloom filter based Information Collection protocol (BIC). In BIC, the interrogated tag identification can be efficiently achieved with a distributively constructed Bloom filter, which significantly reduces the communication overhead and thus the protocol execution time. Extensive simulations show that BIC performs better than all the warm-up solutions and its execution time is within 3 times of the lower bound.
Hao Yue 0001, Chi Zhang 0001, Miao Pan, Yuguang Fang, Shigang Chen
INFOCOM2
2012 Secure top-k query processing via untrusted location-based service providers
abstract
This paper considers a novel distributed system for collaborative location-based information generation and sharing which become increasingly popular due to the explosive growth of Internet-capable and location-aware mobile devices. The system consists of a data collector, data contributors, location-based service providers (LBSPs), and system users. The data collector gathers reviews about points-of-interest (POIs) from data contributors, while LBSPs purchase POI data sets from the data collector and allow users to perform location-based top-k queries which ask for the POIs in a certain region and with the highest k ratings for an interested POI attribute. In practice, LBSPs are untrusted and may return fake query results for various bad motives, e.g., in favor of POIs willing to pay. This paper presents two novel schemes for users to detect fake top-k query results as an effort to foster the practical deployment and use of the proposed system. The efficacy and efficiency of our schemes are thoroughly analyzed and evaluated.
Rui Zhang 0007, Chi Zhang 0001
INFOCOM3
2012 Spectrum Harvesting and Sharing in Multi-Hop CRNs Under Uncertain Spectrum Supply
abstract
The essential impediment to apply cognitive radio (CR) technology for efficient spectrum utilization lies in the uncertainty of licensed spectrum supply. In this paper, we propose a novel architecture for spectrum harvesting and sharing, and investigate the joint routing and frequency scheduling problem in multi-hop cognitive radio networks (CRNs) under uncertain spectrum supply. We introduce a new service provider, Secondary Service Provider (SSP), to facilitate the accessing for secondary users (SUs). We model the vacancy of available bands with a series of random variables, and mathematically describe the corresponding frequency scheduling and flow routing constraints. From the SSP's point of view, we characterize the CRN performance with a pair of parameters (α, β), and present an optimization problem to minimize the required network-wide spectrum resource at the (α,β) level. Given that (α, β) level is specified, we obtain a lower bound for the optimization problem and develop a threshold based coarse-grained fixing algorithm for a feasible solution. Simulation results show that (i) for any (α,β) level, the proposed algorithm provides a near-optimal solution to the formulated NP-hard problem, and (ii) the (α,β) based solution is better than the expected bandwidth based one in terms of blocking ratio and spectrum utilization in multi-hop CRNs.
Miao Pan, Chi Zhang 0001, Pan Li 0001, Yuguang Fang
IEEE J. Sel. Areas Commun.2
2012 Revenue Maximization in Time-Varying Multi-Hop Wireless Networks: A Dynamic Pricing Approach
abstract
In this paper, we study a wireless multi-hop network where multiple flows co-exist and share the network resource collectively. Each flow is associated with a user which has specific requirements on its tradeoff between cost and quality of service. To support heterogeneous transmissions efficiently, we propose a quality-aware dynamic pricing algorithm, namely, QADP, which provably maximizes the overall network revenue while maintaining the stability of the network. Our proposed scheme enjoys the merit of self-adaptability due to its online nature.
Yang Song 0005, Chi Zhang 0001, Yuguang Fang, Phone Lin
IEEE J. Sel. Areas Commun.2
2011 A Multi-Hop Privacy-Preserving Reputation Scheme in Online Social Networks
abstract
Online Social Networks (OSNs) are becoming immensely popular nowadays, and they change the ways people think and live. In this paper, we propose a novel reputation system which allows users to find potential connections between unfamiliar people based on the most updated friend list of each user in OSNs. To some extent, our scheme provides a way to judge people in OSNs without real interactions, but based on the existing overall attitudes on particular people. Moreover, our scheme can protect the confidentially of the potential relationships in which no one is able to acquire the detailed connections between two end nodes. Contrary to those which publish each individual's reputation online, we treat the reputation value in our system as a private issue that has been carefully guaranteed.
Linke Guo, Xiaoyan Zhu 0005, Chi Zhang 0001, Yuguang Fang
GLOBECOM3
2011 HCPP: Cryptography Based Secure EHR System for Patient Privacy and Emergency Healthcare
abstract
Privacy concern is arguably the major barrier that hinders the deployment of electronic health record (EHR) systems which are considered more efficient, less error-prone, and of higher availability compared to traditional paper record systems. Patients are unwilling to accept the EHR system unless their protected health information (PHI) containing highly confidential data is guaranteed proper use and disclosure, which cannot be easily achieved without patients' control over their own PHI. However, cautions must be taken to handle emergencies in which the patient may be physically incompetent to retrieve the controlled PHI for emergency treatment. In this paper, we propose a secure EHR system, HCPP (Healthcaresystem for Patient Privacy), based on cryptographic constructions and existing wireless network infrastructures, to provide privacy protection to patients under any circumstances while enabling timelyPHI retrieval for life-saving treatment in emergency situations. Furthermore, our HCPP system restricts PHI access to authorized (not arbitrary) physicians, who can be traced and held accountable if the accessed PHI is found improperly disclosed. Last but not least, HCPP leverages wireless network access to support efficient and private storage/retrieval of PHI, which underlies a secure and feasible EHR system.
Jinyuan Sun, Xiaoyan Zhu 0005, Chi Zhang 0001, Yuguang Fang
ICDCS3
2011 Joint routing and link scheduling for cognitive radio networks under uncertain spectrum supply
abstract
The essential impediment to apply cognitive radio (CR) technology for spectrum utilization improvement lies in the uncertainty of licensed spectrum supply. In this paper, we investigate the joint routing and link scheduling problem of multi-hop CR networks under uncertain spectrum supply. We model the vacancy of licensed bands with a series of random variables, and introduce corresponding scheduling constraints and flow routing constraints for such a network. From a CR network planner/operator's point of view, we characterize the network with a pair of (α, β) parameters, and present a mathematical formulation with the goal of minimizing the required network-wide spectrum resource at the (α, β) level. Given that (α, β) is specified, we derive a lower bound for the optimization problem and develop a threshold based coarse-grained fixing algorithm for a feasible solution. Simulation results show that i) for any (α, β) level, the proposed algorithm provides a near-optimal solution to the formulated NP-hard problem; ii) the (α, β) based solution is better than expected bandwidth based one in terms of blocking ratio as well as spectrum utilization in CR networks..
Miao Pan, Chi Zhang 0001, Pan Li 0001, Yuguang Fang
INFOCOM2
2011 C4: A new paradigm for providing incentives in multi-hop wireless networks
abstract
For a multi-hop wireless network (MWN) consisting of mobile nodes controlled by independent self-interested users, incentive mechanism is essential for motivating mobile nodes to cooperate and forward packets for each other. Existing solutions such as barter based, virtual-currency based and reputation based schemes are either less effective or incur high implementation costs, and therefore do not fit well with the unique requirements of MWNs. In this paper, we propose a novel and promising incentive paradigm, Controlled Coded packets as virtual Commodity Currency (C4), to induce cooperative behaviors in MWNs. In our C4, through introducing several techniques from network coding, coded information packets are utilized as a new kind of virtual currency to facilitate packet/service exchanges among self-interested nodes in a MWN. Since the virtual currency implemented in this way also carries useful data information, it is the counterpart of the so-called commodity currency in the physical world, and the overhead brought by C4 is extremely small compared to traditional schemes. We theoretically show that C4 is perfectly efficient to support MWNs with broadcast and multicast traffics. For pure unicast communications, by adjusting the grouping parameter, our C4 provides a systematic way to smoothly trade incentive effectiveness for implementation cost, and traditional barter based and virtual-currency based schemes are just two extreme cases of C4. We also show that when our C4 is combined with the social network formed by mobile users in the MWN, the implementation costs can be further reduced without sacrificing incentive effectiveness.
Chi Zhang 0001, Xiaoyan Zhu 0005, Yang Song 0005, Yuguang Fang
INFOCOM1
2011 DELAR: A Device-Energy-Load Aware Relaying Framework for Heterogeneous Mobile Ad Hoc Networks
abstract
This paper addresses energy conservation, a fundamental issue of paramount importance in heterogeneous mobile ad hoc networks (MANETs) consisting of powerful nodes (i.e., P-nodes) as well as normal nodes (i.e., B-nodes). By utilizing the inherent device heterogeneity, we propose a cross-layer designed Device-Energy-Load Aware Relaying framework, named DELAR, to achieve energy conservation from multiple facets, including power-aware routing, transmission scheduling and power control. In particular, we design a novel power-aware routing protocol that nicely incorporates device heterogeneity, nodal residual energy information and nodal load status to save energy. In addition, we develop a hybrid transmission scheduling scheme, which is a combination of reservation-based and contention-based medium access control schemes, to coordinate the transmissions. Moreover, the novel notion of "mini-routing" is introduced into the data link layer and an Asymmetric MAC (A-MAC) scheme is proposed to support the MAC-layer acknowledgements over unidirectional links caused by asymmetric transmission power levels between powerful nodes and normal nodes. Furthermore, we present a multi-packet transmission scheme to improve the end-to-end delay performance. Extensive simulations show that DELAR can indeed achieve energy saving while striking a good balance between energy efficiency and other network performance metrics.
Wei Liu 0008, Chi Zhang 0001, Guoliang Yao, Yuguang Fang
IEEE J. Sel. Areas Commun.2
2011 RescueMe: Location-Based Secure and Dependable VANETs for Disaster Rescue
abstract
Natural disasters and terrorism threaten our nation's safety and security, rendering post-disaster rescue mission critical. It is of paramount importance to carry out rescue work relying on secure and dependable networking. In this paper, we propose RescueMe, location-based vehicular ad hoc networks (VANETs), to aid in secure and dependable rescue planning for the efficient allocation of rescue resources. RescueMe leverages the location information stored during normal network operations to facilitate post-disaster rescue planning, while guaranteeing that the sensitive user location information is not exploited to trace a user's whereabouts when disasters are absent, even if the most powerful collusion attack is allowed. We provide a novel construction for the location update message, and propose several enhancements, to achieve the functional and security goals of RescueMe.
Jinyuan Sun, Xiaoyan Zhu 0005, Chi Zhang 0001, Yuguang Fang
IEEE J. Sel. Areas Commun.3
2011 SAT: A Security Architecture Achieving Anonymity and Traceability in Wireless Mesh Networks
abstract
Anonymity has received increasing attention in the literature due to the users' awareness of their privacy nowadays. Anonymity provides protection for users to enjoy network services without being traced. While anonymity-related issues have been extensively studied in payment-based systems such as e-cash and peer-to-peer (P2P) systems, little effort has been devoted to wireless mesh networks (WMNs). On the other hand, the network authority requires conditional anonymity such that misbehaving entities in the network remain traceable. In this paper, we propose a security architecture to ensure unconditional anonymity for honest users and traceability of misbehaving users for network authorities in WMNs. The proposed architecture strives to resolve the conflicts between the anonymity and traceability objectives, in addition to guaranteeing fundamental security requirements including authentication, confidentiality, data integrity, and nonrepudiation. Thorough analysis on security and efficiency is incorporated, demonstrating the feasibility and effectiveness of the proposed architecture.
Jinyuan Sun, Chi Zhang 0001, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.2
2011 The Capacity of Wireless Ad Hoc Networks Using Directional Antennas
abstract
Considering a disk of unit area with n nodes, we investigate the capacity of wireless networks using directional antennas. First, we study the throughput capacity of random directional networks with multihop relay schemes, and find that the capacity gain compared to random omnidirectional networks is O(log n), which is tighter than previous results. We also show that using directional antennas can significantly reduce power consumption in the networks. Second, for the first time, we explore the throughput capacity of random directional networks with one-hop relay schemes. Interestingly and against our intuition, we find that one-hop instead of multihop delivery schemes can make random directional networks scale. Third, we investigate the trade-offs between transmission range and throughput in random directional networks and show that using larger transmission range can result in higher throughput. Finally, we present a lower bound on the transport capacity of arbitrary directional networks, and find that without side lobe directional antenna gain, arbitrary directional networks can also scale.
Pan Li 0001, Chi Zhang 0001, Yuguang Fang
IEEE Trans. Mob. Comput.2
2011 On the price of security in large-scale wireless ad hoc networks
abstract
Security always comes with a price in terms of performance degradation, which should be carefully quantified. This is especially the case for wireless ad hoc networks (WANETs), which offer communications over a shared wireless channel without any preexisting infrastructure. Forming end-to-end secure paths in such WANETs is more challenging than in conventional networks due to the lack of central authorities, and its impact on network performance is largely untouched in the literature. In this paper, based on a general random network model, the asymptotic behaviors of secure throughput and delay with the common transmission range rnand the probability pfof neighboring nodes having a primary security association are quantified when the network size n is sufficiently large. The costs and benefits of secure-link-augmentation operations on the secure throughput and delay are also analyzed. In general, security has a cost: Since we require all the communications operate on secure links, there is a degradation in the network performance when pffis Ω(1/logn), the secure throughput remains at the Gupta and Kumar bound of Θ(1/√{n log n}) packets/time slot, wherein no security requirements are enforced on WANETs. This implies that even when the pfgoes to zero as the network size becomes arbitrarily large, it is still possible to build throughput-order-optimal secure WANETs, which is of practical interest since pfis very small in many practical large-scale WANETs.
Chi Zhang 0001, Yang Song 0005, Yuguang Fang
IEEE/ACM Trans. Netw.1
2011 Improving handoff performance by utilizing ad hoc links in multi-hop cellular systems
Rongsheng Huang, Chi Zhang 0001, Hongxia Zhao, Yuguang Fang
Wirel. Networks2
2010 Enhancing Handoff Performance by Introducing Ad Hoc Mode into Cellular Networks
abstract
As all-IP feature becomes dominant in the next generation networks (NGNs), ad hoc mode is gaining more attention as an appealing addition to cellular networks. Consequently, multi-hop handoffs become inevitable, which bring challenging issues to network designers. Handoff dropping (HOD) rate and the bandwidth reservation for the required HOD rate are two important metrics to evaluate the handoff performance of a cellular system. By introducing ad hoc mode into cellular systems, we can either achieve lower HOD rate or reserve less bandwidth for the same required HOD rate. In this paper, we incorporate traffic information from neighboring BSs and propose an algorithm to find the minimum bandwidth reservation for each BS. Since its performance greatly depends on the access probability to the adjacent cells, we further propose to utilize the embedded ad hoc networks to gather the traffic load information of neighboring cells. With such information, handoff calls can effectively select the best paths to the proper BSs. It has been demonstrated that our scheme can significantly improve the system performance.
Rongsheng Huang, Chi Zhang 0001, Hongxia Zhao, Yuguang Fang
GLOBECOM2
2010 Energy-Conserving Scheduling in Multi-hop Wireless Networks with Time-Varying Channels
abstract
MaxWeight algorithm, a.k.a., back-pressure algorithm, has received much attention as a viable solution for dynamic link scheduling in multi-hop wireless networks. The basic principle of the MaxWeight algorithm is to select a set of interference-free links with the maximum overall link weights in the network, where the link weight is determined by the queue difference between the transmitter and the receiver. While the throughput-optimality of the MaxWeight algorithm is well understood in the literature, the energy consumption induced by the MaxWeight algorithm is less studied, which is of great interest in energy-constrained wireless networks such as wireless sensor networks. In this paper, we propose an energy-conserving scheduling scheme, a.k.a., minimum energy scheduling (MES) algorithm for multi-hop wireless networks with stochastic traffic arrivals and time-varying channel conditions. We show that our algorithm is energy optimal in the sense that the proposed MES algorithm can achieve an energy consumption which is arbitrarily close to the global minimum solution. Moreover, the energy efficiency of the MES algorithm is achieved without losing the throughput- optimality. In other words, the proposed MES algorithm is still throughput optimal whereas the average consumed energy in the network is significantly reduced, as compared to the traditional MaxWeight algorithm. The theoretical results are substantiated via simulations.
Yang Song 0005, Chi Zhang 0001, Yuguang Fang, Zhisheng Niu
INFOCOM2
2010 A Formal Study of Trust-Based Routing in Wireless Ad Hoc Networks
abstract
Recently, trust-based routing has received much attention as an effective way to improve security of wireless ad hoc networks (WANETs). Although various trust metrics have been designed and incorporated into the routing metrics, as far as we know, none of the existing works have used mathematical tools such as routing algebra to analyze the compatibility of trust related routing metrics and routing protocols in WANETs. In this paper, we first identify unique features of trust metrics compared with QoS-based routing metrics. Then, we provide a systematic analysis of the relationship between trust metrics and trust-based routing protocols by identifying the basic algebraic properties that a trust metric must have in order to work correctly and optimally with different generalized distance-vector or link-state routing protocols in WANETs. Moreover, we extend our framework to model the interactions between different trust-based routing protocols. Finally, our results are applied to check the compatibility of the trust metrics proposed in previous literature and the popular routing protocols used in WANETs.
Chi Zhang 0001, Xiaoyan Zhu 0005, Yang Song 0005, Yuguang Fang
INFOCOM1
2010 Stochastic Traffic Engineering in Multihop Cognitive Wireless Mesh Networks
abstract
In this work, the stochastic traffic engineering problem in multihop cognitive wireless mesh networks is addressed. The challenges induced by the random behaviors of the primary users are investigated in a stochastic network utility maximization framework. For the convex stochastic traffic engineering problem, we propose a fully distributed algorithmic solution which provably converges to the global optimum with probability one. We next extend our framework to the cognitive wireless mesh networks with nonconvex utility functions, where a decentralized algorithmic solution, based on learning automata techniques, is proposed. We show that the decentralized solution converges to the global optimum solution asymptotically.
Yang Song 0005, Chi Zhang 0001, Yuguang Fang
IEEE Trans. Mob. Comput.2
2010 A Coverage Inference Protocol for Wireless Sensor Networks
abstract
After a wireless sensor network (WSN) is deployed, sensor nodes are usually left unattended for a long period of time. There is an inevitable devolution of the connected coverage of the WSN due to battery exhaustion of sensor nodes, intended physical destruction attacks on sensor nodes, unpredictable node movement by physical means like wind, and so on. It is, therefore, critical that the base station (BS) learns in real time how well the WSN performs the given sensing task (i.e., what is the current connected coverage) under a dynamically changing network topology. In this paper, we propose a coverage inference protocol (CIP), which can provide the BS an accurate and in-time measurement of the current connected coverage in an energy-efficient way. Especially, we show that the scheme called BOND, which our CIP requires to be implemented on each sensor node, enables each node to locally self-detect whether it is a boundary node with the minimal communication and computational overhead. The BOND can also be exploited to seamlessly integrate multiple functionalities with low overhead. Moreover, we devise extensions to CIP that can tolerate location errors and actively predict the change of the connected coverage based on residual energy of sensor nodes.
Chi Zhang 0001, Yuguang Fang
IEEE Trans. Mob. Comput.1
2010 An Identity-Based Security System for User Privacy in Vehicular Ad Hoc Networks
abstract
Vehicular ad hoc network (VANET) can offer various services and benefits to users and thus deserves deployment effort. Attacking and misusing such network could cause destructive consequences. It is therefore necessary to integrate security requirements into the design of VANETs and defend VANET systems against misbehavior, in order to ensure correct and smooth operations of the network. In this paper, we propose a security system for VANETs to achieve privacy desired by vehicles and traceability required by law enforcement authorities, in addition to satisfying fundamental security requirements including authentication, nonrepudiation, message integrity, and confidentiality. Moreover, we propose a privacy-preserving defense technique for network authorities to handle misbehavior in VANET access, considering the challenge that privacy provides avenue for misbehavior. The proposed system employs an identity-based cryptosystem where certificates are not needed for authentication. We show the fulfillment and feasibility of our system with respect to the security goals and efficiency.
Jinyuan Sun, Chi Zhang 0001, Yuguang Fang
IEEE Trans. Parallel Distributed Syst.2
2010 Minimum energy scheduling in multi-hop wireless networks with retransmissions
abstract
MaxWeight algorithm, a.k.a., back-pressure algorithm [1]-[4], has received much attention as a viable solution for dynamic link scheduling in multi-hop wireless networks. The basic principle of the MaxWeight algorithm is to select a set of interference-free links with the maximum overall link weights in the network, where the link weight is determined by the queue difference between the transmitter and the receiver. While the throughput-optimality of the MaxWeight algorithm is well understood in the literature, the energy consumption induced by the MaxWeight algorithm is less studied, which is of great interest in energy-constrained wireless networks such as wireless sensor networks. In this paper, we propose a minimum energy scheduling (MES) algorithm for multi-hop wireless networks with stochastic traffic arrivals and time-varying channel conditions. We show that our algorithm is energy optimal in the sense that the proposed MES algorithm can achieve an energy consumption which is arbitrarily close to the global minimum solution. Moreover, the energy efficiency of the MES algorithm is achieved without losing the throughput-optimality. In other words, the proposed MES algorithm is still throughput optimal whereas the average consumed energy in the network is significantly reduced, as compared to the traditional MaxWeight algorithm. The theoretical results are substantiated via simulations.
Yang Song 0005, Chi Zhang 0001, Yuguang Fang
IEEE Trans. Wirel. Commun.2
2009 Throughput-Delay Tradeoffs in Large-Scale MANETs with Network Coding
abstract
This paper characterizes the throughput-delay tradeoffs in mobile ad hoc networks (MANETs) with network coding, and compares results in the situation where only replication and forwarding are allowed in each node. The schemes/protocols achieving those tradeoffs in an effective and decentralized way are proposed and the optimality of those tradeoffs is established. The scenarios in which network coding can provide significant improvement on network performance are identified under different node mobility patterns (fast and slow mobility). The insights on when and how information mixing is beneficial for MANETs with multiple unicast and multicast sessions are provided. As far as we know, this is the first work characterizing scaling laws of throughput and delay of MANETs with network coding.
Chi Zhang 0001, Yuguang Fang, Xiaoyan Zhu 0005
INFOCOM1
2009 Capacity and delay of hybrid wireless broadband access networks
abstract
An optical network is too costly to act as a broadband access network. On the other hand, a pure wireless ad hoc network with n nodes and total bandwidth of W bits per second cannot provide satisfactory broadband services since the pernode throughput diminishes as the number of users goes large. In this paper, we propose a hybrid wireless network, which is an integrated wireless and optical network, as the broadband access network. Specifically, we assume a hybrid wireless network consisting of n randomly distributed normal nodes, and m regularly placed base stations connected via an optical network. A source node transmits to its destination only with the help of normal nodes, i.e., in the ad hoc mode, if the destination can be reached within L (L /spl geq/ 1) hops from the source. Otherwise, the transmission will be carried out in the infrastructure mode, i.e., with the help of base stations. Two transmission modes share the same bandwidth of W bits/sec. We first study the throughput capacity of such a hybrid wireless network, and observe that the throughput capacity greatly depends on the maximum hop count L and the number of base stations m. We show that the throughput capacity of a hybrid wireless network can scale linearly with n only if m = Omega(n), and when we assign all the bandwidth to the infrastructure mode traffics. We then investigate the delay in hybrid wireless networks. We find that the average packet delay can be maintained as low as Theta(1) even when the per-node throughput capacity is Theta(W).
Pan Li 0001, Chi Zhang 0001, Yuguang Fang
IEEE J. Sel. Areas Commun.2
2009 On the improvement of scaling laws for large-scale MANETs with network coding
abstract
This paper investigates the problem of how much benefit network coding can contribute to the network performance in terms of throughput, delay, and storage requirements for mobile ad hoc networks (MANETs), compared to when only replication, storage and forwarding are allowed in relay nodes. We characterize the throughput-delay-storage tradeoffs under different node mobility patterns, i.e., i.i.d. and random walk mobility, with and without network coding. Our results show that when random linear coding instead of replication is used in MANETs, an order improvement on the scaling laws of MANETs can be achieved. Note that previous work showed that network coding could only provide constant improvement on the throughput of static wireless networks. Our work thus differentiates MANETs from static wireless networks by the role network coding plays.
Chi Zhang 0001, Xiaoyan Zhu 0005, Yuguang Fang
IEEE J. Sel. Areas Commun.1
2009 Harnessing Traffic Uncertainties in Wireless Mesh Networks - A Stochastic Optimization Approach
Yang Song 0005, Chi Zhang 0001, Yuguang Fang
Mob. Networks Appl.2
2009 Asymptotic connectivity in wireless ad hoc networks using directional antennas
Pan Li 0001, Chi Zhang 0001, Yuguang Fang
IEEE/ACM Trans. Netw.2
2009 Localized algorithms for coverage boundary detection in wireless sensor networks
Chi Zhang 0001, Yuguang Fang
Wirel. Networks1
2008 Decentralized Routing in Nonhomogeneous Poisson Networks
abstract
In his seminal work, Jon Kleinberg considers a small-world network model consisting of a k-dimensional lattice augmented with shortcuts. Under the assumption that the probability of a shortcut being present between two nodes u and v decays as a power, d(u,v) -\alpha, of the distance d(u,v) between them, Kleinberg shows that decentralized routing scheme such as greedy geographic routing is efficient if alpha=k and that there is no efficient decentralized routing algorithm if alpha\neq k. The results are extended to a continuum model recently, wherein the nodes are distributed as a homogeneous Poisson point process by Franceschetti and Meester, Draief and Ganesh. In our work, we extend the result further to a more realistic model constructed from a nonhomogeneous Poisson point process, wherein each node is connected to all its neighbors within some fixed radius, as well as possessing random shortcuts to more distant nodes. More importantly, we show that in nonhomogeneous cases, the necessary and sufficient condition for greedy geographic routing to be efficient is that the probability of a shortcut being present from node u to v should be inversely proportional to the number of nodes which are closer to u than v is. We also demonstrate some applications of our results to wireless networks.
Chi Zhang 0001, Pan Li 0001, Yuguang Fang, Pramod P. Khargonekar
ICDCS1
2008 A Security Architecture Achieving Anonymity and Traceability in Wireless Mesh Networks
abstract
Anonymity has received increasing attention in the literature due to the users' awareness of their privacy nowadays. Anonymity provides protection for users to enjoy network services without being traced. While anonymity related issues have been extensively studied in payment-based systems such as e-cash [1] and peer-to-peer (P2P) [2] systems, little effort has been devoted to wireless mesh networks (WMNs). On the other hand, the network authority requires conditional anonymity such that misbehaving entities in the network remain traceable. In this paper, we propose a security architecture to ensure unconditional anonymity for honest users and traceability of misbehaving users for network authorities in WMNs. The proposed architecture strives to resolve the conflicts between the anonymity and traceability objectives, in addition to guaranteeing fundamental security requirements including authentication, confidentiality, data integrity, and non-repudiation [3]. Further security enhancements can be incorporated, rendering the proposed architecture conditionally anonymous in terms of network access activities, location information, and communication paths.
Jinyuan Sun, Chi Zhang 0001, Yuguang Fang
INFOCOM2
2008 Modeling Secure Connectivity of Self-Organized Wireless Ad Hoc Networks
abstract
Wireless ad hoc networks (WANETs) offer communications over a shared wireless channel without any pre-existing infrastructure. Forming peer-to-peer security associations in self-organized WANETs is more challenging than in conventional networks due to the lack of central authorities. In this paper, we propose a generic model to evaluate the relationship of connectivity, memory size, communication overhead and security in fully self-organized WANETs. Based on some reasonable assumptions on node deployment and mobility, we show that when the average number of authenticated neighbors of each node is Theta(1), with respect to the network size n, most of the nodes can be securely connected, forming a connected secure backbone, i.e., the secure network percolates. This connected secure backbone can be utilized to break routing-security dependency loop, and provide enough derived secure links connecting isolated nodes with the secure backbone in a multi-hop fashion, which leads to the secure connectivity of the whole network.
Chi Zhang 0001, Yang Song 0005, Yuguang Fang
INFOCOM1
2008 Routing optimization in wireless mesh networks under uncertain traffic demands
abstract
In this paper, we investigate the routing optimization problem in wireless mesh networks. While existing works usually assume static and known traffic demand, we emphasize that the actual traffic is time-varying and difficult to measure. In light of this, we alternatively pursue a stochastic optimiz
Yang Song 0005, Chi Zhang 0001, Yuguang Fang
QSHINE2
2008 SAM-MAC: An efficient channel assignment scheme for multi-channel ad hoc networks
Rongsheng Huang, Hongqiang Zhai, Chi Zhang 0001, Yuguang Fang
Comput. Networks3
2008 Joint Channel and Power Allocationin Wireless Mesh Networks: A Game Theoretical Perspective
abstract
This paper addresses the throughput maximization problem in wireless mesh networks. For the case of cooperative access points, we present a negotiation-based throughput maximization algorithm which adjusts the operating channel and power level among access points automatically, from a game-theoretical perspective. We show that this algorithm converges to the optimal channel and power assignment which yields the maximum overall throughput with arbitrarily high probability. Moreover, we analyze the scenario where access points belong to different regulation entities and hence non-cooperative. The long- term behavior and corresponding performance are investigated and the analytical results are verified by simulations.
Yang Song 0005, Chi Zhang 0001, Yuguang Fang
IEEE J. Sel. Areas Commun.2
2007 A Mobility Management Scheme for Wireless Mesh Networks
abstract
Current deployment of the wireless mesh networks (WMN) necessitates mobility management to support mobile clients roaming around the network without service interruption. Though Mobile IP and other previous protocols can be applied to WMNs to gain the micro-mobility as well as macro-mobility support, high signaling cost and long handoff latency problems still degrade the system performance significantly. In this paper we present a new mobility management scheme for WMNs, mesh mobility management (M3). It utilizes some WMN's features and combines the per-host routing and tunneling techniques to reduce the signaling cost as well as to shorten the handoff latency. Our analysis shows that significant benefits can be achieved from this scheme.
Rongsheng Huang, Chi Zhang 0001, Yuguang Fang
GLOBECOM2
2007 Asymptotic Connectivity in Wireless Networks Using Directional Antennas
abstract
Connectivity is a crucial issue in wireless networks. Gupta and Kumar show that with omnidirectional antennas, the critical transmission range for a wireless network to achieve asymptotic connectivity is O(radiclog n/n) if n nodes are uniformly and independently distributed in a disk of unit area. In this paper, we investigate the connectivity problem when directional antennas are used. We find that there also exists a critical transmission range, which corresponds to a critical transmission power. We show that in the same propagation environment, when directional antennas use the optimal antenna pattern, the critical transmission power could be much smaller than that in networks using omnidirectional antennas. Moreover, to achieve asymptotic connectivity, it is known that each node has to have O(log n) neighbors when using omnidirectional antennas. We show that even using the transmission power level at which each node has only O(1) neighbors when using omnidirectional antennas, we can still achieve the asymptotic connectivity with directional antennas.
Pan Li 0001, Chi Zhang 0001, Yuguang Fang
ICDCS2
2007 Throughput Maximization in Multi-channel Wireless Mesh Access Networks
abstract
The throughput maximization problem of wireless mesh access networks is addressed. For the case of cooperative access points, we present a negotiation-based throughput maximization algorithm which adjusts the operating frequency and power level among access points autonomously, from a game-theoretical perspective. We show that this algorithm converges to the optimal frequency and power assignment which yields the maximum overall throughput with arbitrarily high probability. Moreover, we analyze the scenario where access points belong to different regulation entities and hence non-cooperative. The long-term behavior and corresponding performance are investigated and the analytical results are verified by simulations.
Yang Song 0005, Chi Zhang 0001, Yuguang Fang
ICNP2
2007 SAM-MAC: an efficient channel assignment scheme for multi-channel ad hoc networks
abstract
Using multi-channel MAC protocols in mobile ad hoc networks (MANETs) is a promising way to improve the through-put performance. Channel assignment, which directly determines the efficiency of the frequency utilization, is the critical part of multi-channel schemes. Current 802.11-like schemes of multi-channel MAC do not efficiently use the multiple channels due to the overhead caused by channel assignment. Moreover, the control channel saturation problem limits the number of channels of these previous schemes. In this paper, we propose a new scheme called SAM-MAC (Self-Adjustable Multi-channel MAC), which features with one common channel and two half-duplex transceivers for each node. A method called self-adjustment is used to reassign the channels and balance the traffic on different channels. Due to less contention in common channel and smaller channel assignment overhead, this scheme increases the throughput compared with previous approaches. Control channels are free from saturation problem and can furthermore be used for data transmission.
Rongsheng Huang, Hongqiang Zhai, Chi Zhang 0001, Yuguang Fang
QSHINE3
2006 Energy-Efficient Coverage Measurement for Wireless Sensor Networks
abstract
In this paper, we propose a coverage measurement protocol (CMP) which can provide the base station an accurate and in-time measurement of the current connected coverage in an energy-efficient way, and our CMP is location-error tolerant. Moreover, the major component of our CMP, i.e., BOundary Node Detection (BOND) scheme, can be reused to provide many other functionalities for WSNs.
Chi Zhang 0001, Yuguang Fang
GLOBECOM1
2006 Localized coverage boundary detection for wireless sensor networks
abstract
Connected coverage, which reflects how well a target field is monitored under the base station, is the most important performance metrics used to measure the quality of surveillance that wireless sensor networks (WSNs) can provide. To facilitate the measurement of this metrics, we propose two novel algorithms for individual sensor nodes to identify whether they are on the coverage boundary, i.e., the boundary of a coverage hole or network partition. Our algorithms are based on two novel computational geometric techniques called localized Voronoi and neighbor embracing polygons. As compared to previous work, our algorithms can be applied to WSNs of arbitrary topologies. They are also truly distributed and localized by merely needing the minimal position information of one-hop neighbors and a limited number of simple local computations, and thus are of high scalability and energy efficiency. We show the correctness and efficiency of our algorithms by theoretical proofs and extensive simulations.
Chi Zhang 0001, Yuguang Fang
QSHINE1