VLDB 2026 Research / reviewers in the wild / expert
Jingwei Li 0001
dblp:92/7728-1
· DBLP profile ↗
54ranked-venue papers
18as first author
25since 2021 · last 2026
0000-0001-8457-0454ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 25 · 10 first-author · 11 since 2021Security and privacy · 21 · 8 first-author · 6 since 2021Computer networks · 7 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SACK: Shielding Dynamic Attribute-based Access Control in Persistent Key-Value Stores
Yanjing Ren, Jingwei Li 0001, Patrick Lee |
Proc. VLDB Endow. | 2 |
| 2026 | A Byzantine-Robust Secure Federated Learning Scheme in Heterogeneous Data
Ruijin Wang, Zengpeng Li 0001, Fengli Zhang, Jingwei Li 0001, Xiong Li 0002 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | TrustSearch: Toward Secure and Efficient Reverse Image Search via SGXabstractOutsourcing image management to a cloud should not only protect the confidentiality of image data, but also maintain the capability of reverse image search, which requires identifying the existing stored images that are similar to an input image. Previous studies build on cryptographic approaches to realize reverse image search on encrypted images, yet failing to achieve either security or performance. This paper explores trusted image search, which uses Intel SGX to realize reverse image search in an enclave, in order to provide security guarantees via SGX while performing search on plain data (inside the enclave) for performance. However, due to the resource limits of SGX, directly realizing the search process in the enclave incurs high performance overhead. We present TRUSTSEARCH, which implements various design approaches to mitigate the resource overhead of SGX. We evaluate TRUSTSEARCH using real-world image datasets, and show that it outperforms state-of-the-art approaches for search performance while preserving space efficiency for the enclave. Fang Zou, Jingwei Li 0001, Dayan Wu, Xiong Li 0002, Hongwei Li 0001, Ting Chen 0002, Xiaosong Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Maat: Analyzing and Optimizing Overcharge on Blockchain Storage
Zheyuan He, Zihao Li 0001, Ao Qiao, Jingwei Li 0001, Feng Luo 0009, Gelei Deng, Shuwei Song, Xiaosong Zhang 0001, Ting Chen 0002, Xiapu Luo |
FAST | 4 |
| 2025 | SGX-Enabled Encrypted Cross-Cloud Data SynchronizationabstractThe increasing adoption of multicloud storage has necessitated the development of efficient cross-cloud data synchronization to improve performance and accessibility across regions, and reduce reliance on single cloud service. Yet, securing cross-cloud synchronization while achieving network efficiency poses challenges. First, ensuring data confidentiality and integrity is difficult due to the diverse encryption configurations and management complexities inherent to different clouds. Second, balancing security and network efficiency is non-trivial, as encryption disrupts content redundancy, complicating efforts to reduce network traffic. We present SeedSync, a system designed to provide secure and efficient cross-cloud data synchronization. SeedSync leverages shielded execution to ensure both security guarantees and network efficiency. It enables encrypted data synchronization without revealing sensitive information and ensures end-to-end data integrity with limited performance overhead using tree-structured integrity protection. It also addresses the dilemma between encryption and network reduction by allowing data to be processed unencrypted within a secure shielded region. Furthermore, inspired by workload characteristics, it speeds up data synchronization by reducing fine-grained network transmission and context switching of SGX. Evaluation on real-world datasets shows that SeedSync achieves up to 8.2 × higher throughput and 5.4 × network reduction existing traffic compared with encrypted synchronization approaches, while incurring limited overhead compared with plaintext synchronization. Yanjing Ren, Jingwei Li 0001, Patrick P. C. Lee |
ICDCS | 3 |
| 2025 | ShieldReduce: Fine-Grained Shielded Data Reduction
Jingyuan Yang 0018, Jun Wu 0001, Ruilin Wu, Jingwei Li 0001, Patrick P. C. Lee, Xiong Li 0002, Xiaosong Zhang 0001 |
USENIX ATC | 4 |
| 2025 | Auspex: Unveiling Inconsistency Bugs of Transaction Fee Mechanism in Blockchain
Zheyuan He, Zihao Li 0001, Jiahao Luo, Feng Luo 0009, Junhan Duan, Jingwei Li 0001, Shuwei Song, Xiapu Luo, Ting Chen 0002, Xiaosong Zhang 0001 |
USENIX Security Symposium | 6 |
| 2025 | Fast Generation-Based Gradient Leakage Attacks: An Approach to Generate Training Data Directly From the GradientabstractFederated learning (FL) is a distributed machine learning technique that guarantees the privacy of user data. However, FL has been shown to be vulnerable to gradient leakage attacks (GLA), which have the ability to reconstruct private training data from public gradients with high probability. These attacks are either analytic-based, requiring modification of the FL model, or optimization-based, requiring long convergence times and failing to effectively address the challenge of dealing with highly compressed gradients in practical FL systems. This paper presents a pioneering generation-based GLA method called FGLA that can reconstruct batches of user data without the need for the optimization process. We specifically design a feature separation technique that first extracts the features of each sample in a batch and then directly generates the user data. Our extensive experiments on multiple image datasets show that FGLA can reconstruct user images in seconds with a batch size of 256 from highly compressed gradients (0.8% compression ratio or higher), thereby significantly outperforming state-of-the-art methods. Haomiao Yang, Dongyun Xue, Mengyu Ge, Jingwei Li 0001, Guowen Xu, Hongwei Li 0001, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | A Practical DoS Attack on Commercial UWB Ranging SystemsabstractUltra-wideband (UWB) ranging systems are increasingly deployed in critical, security-sensitive applications due to their precise positioning and secure ranging capabilities. In this work, we introduce a practical DoS attack via reactive jamming, referred to as UWBAD+, which targets commercial UWB ranging systems by exploiting the vulnerabilities of the normalized cross-correlation process. This allows UWBAD+ to selectively and effectively disrupt ranging sessions without requiring prior knowledge of the victim devices' configurations, leading to potentially severe consequences such as property loss, unauthorized access, or vehicle theft. The enhanced effectiveness and low detectability of UWBAD+ stem from the following: (i) it can rapidly sniff the physical layer structures of unknown UWB systems, even in the presence of multiple UWB devices operating simultaneously; (ii) it blocks each ranging session efficiently by employing field-level jamming, thus exerting a significant impact on commercial UWB ranging systems; and (iii) its compact, reactive, and selective design based on COTS UWB chips, which makes it both affordable and less noticeable. We successfully executed real-world attacks on commercial UWB ranging systems produced by the three largest UWB chip vendors in the market, including Apple, NXP, and Qorvo. We disclosed our findings to Apple, relevant Original Equipment Manufacturers (OEMs), and the Automotive Security Research Group. As of the time of writing, the involved OEM has acknowledged this vulnerability in their automotive systems and has issued a${\$} 5,000$bounty as a reward. Yongzhao Zhang, Yuqiao Yang, Zhongjie Wu, Ting Chen 0002, Jie Yang 0003, Guowen Xu, Xiaosong Zhang 0001, Jingwei Li 0001, Yu Jiang 0001, Zhuo Su 0005 |
IEEE Trans. Mob. Comput. | 11 |
| 2025 | A Unified Framework for Hybrid Network Intrusion DetectionabstractLately, hybrid network intrusion detection systems (HNIDSs) have progressed significantly. Through the cascade or ensemble of multiple machine learning models, HNIDS benefits from each model and achieves better performance. A widely adopted framework for designing HNIDS consists of two models: a misuse detector and an anomaly detector. However, (1) benign traffic must be analyzed by both models, reducing inference speed; (2) the misuse detector performs dual functionalities, leading to suboptimal accuracy; (3) deploying the misuse and anomaly detectors on two devices introduces substantial latency and restricts distributed deployment. In this paper, we propose a unified framework called AUF. To solve (1), we deploy the anomaly detector in the first stage rather than the second, which improves inference speed. To solve (2), we employ two independent models to implement the misuse detector’s functionality, enhancing overall accuracy. To solve (3), we ensure that the different models operate independently, supporting distributed deployment. To demonstrate the effectiveness of the AUF framework, we implement XGBoost for detection and classification and propose an adaptive k-nearest neighborhood-based approach to achieve accurate discrimination. We also introduce zero-shot learning to showcase the framework’s customized model. Extensive experiments validate the effectiveness of the AUF framework and methods. Our code is available at https://github.com/wangyann2000/A-Unified-Framework-for-Hybrid-Network-Intrusion-Detection. Yan Wang 0103, Jingwei Li 0001, Xiaosong Zhang 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | UWBAD: Towards Effective and Imperceptible Jamming Attacks Against UWB Ranging Systems with COTS ChipsabstractUWB ranging systems have been adopted in many critical and security sensitive applications due to its precise positioning and secure ranging capabilities. We present a practical jamming attack, namely UWBAD, against commercial UWB ranging systems, which exploits the vulnerability of the adoption of the normalized cross-correlation process in UWB ranging and can selectively and quickly block ranging sessions without prior knowledge of the configurations of the victim devices, potentially leading to severe consequences such as property loss, unauthorized access, or vehicle theft. UWBAD achieves more effective and less imperceptible jamming due to: (i) it efficiently blocks every ranging session by leveraging the field-level jamming, thereby exerting a tangible impact on commercial UWB ranging systems, and (ii) the compact, reactive, and selective system design based on COTS UWB chips, making it affordable and less imperceptible. We successfully conducted real attacks against commercial UWB ranging systems from the three largest UWB chip vendors on the market, e.g., Apple, NXP, and Qorvo. We reported our findings to Apple, related Original Equipment Manufacturers (OEM), and the Automotive Security Research Group. As of the writing of this paper, the related OEM has acknowledged this vulnerability in their automotive systems and has offered a 5, 000 reward as a bounty. Yuqiao Yang, Zhongjie Wu, Yongzhao Zhang, Ting Chen 0002, Jie Yang 0003, Xiaosong Zhang 0001, Ruicong Shi, Jingwei Li 0001, Yu Jiang 0001, Zhuo Su 0005 |
CCS | 10 |
| 2024 | ELECT: Enabling Erasure Coding Tiering for LSM-tree-based Storage
Yanjing Ren, Yuanming Ren, Xiaolu Li 0002, Yuchong Hu, Jingwei Li 0001, Patrick P. C. Lee |
FAST | 5 |
| 2024 | CDCache: Space-Efficient Flash Caching via Compression-before-DeduplicationabstractLarge-scale storage systems boost I/O performance via flash caching, but the underlying storage medium of flash caching incurs significant financial costs and also exhibits low endurance. Previous studies adopt compression-after-deduplication to mitigate writing redundant contents into the flash cache, so as to address the cost and endurance issues. However, deduplication and compression have conflicting preferable cases, and compression-after-deduplication essentially compromises the space-saving benefits of either deduplication or compression. To simultaneously preserve the benefits of both approaches, we explore compression-before-deduplication, which applies compression to eliminate byte-level redundancies across data blocks, followed by deduplication to write only a single copy of duplicate compressed blocks into the flash cache. We present CDCache, a space-efficient flash caching system that realizes compression-before-deduplication. It proposes to dynamically adjust the compression range of data blocks, so as to preserve the effectiveness of deduplication on the compressed blocks. Also, it builds on various design techniques to approximately estimate duplicate data blocks and efficiently manage compressed blocks. Trace-driven experiments show that CDCache improves the read hit ratio and the write reduction ratio of a previous compression-after-deduplication approach by up to 1.3× and 1.6×, respectively, while it only has small memory overhead for index management. Hengying Xiao, Jingwei Li 0001, Yanjing Ren, Ruijin Wang, Xiaosong Zhang 0001 |
INFOCOM | 2 |
| 2024 | PhantomPatch: Easy-ignoring Attacks on Object Detectors Using Ghosting ArtifactsabstractCurrent patches used to attack object detectors are easily noticeable as abnormal. To mitigate this shortcoming, we devise an innovative technique named PhantomPatch, which leverages lens flare phenomena to attack object detectors, particularly in autonomous driving systems. Leveraging transfer-based adversarial examples, this method fools object detectors by projecting deceptive lens flares or ghost images, which are meaningless to people, while the light source looks like nearby light for people. Thus, it is easy to ignore.In this way, we enable a cost-effective approach to manipulate the perception of the vehicle remotely. This strategy harmonizes adversarial patches with projecting image integrity correcting. Firstly, we propose to train a black-box transfer-based adversarial patch to fool the object-detecting system behind the camera. Then, the patch is printed and attached in front of a flashlight, which casts the patch onto the camera, resulting in a ghost image. We maintain the integrity of the image captured by the camera while casting the patch with image loss correction and optical distortion modeling.Our experimental results validate the effectiveness of PhantomPatch in evading existing object detectors such as YOLO V3/V5 and Faster R-CNN. Notably, during nocturnal scenarios, the technique achieves a success rate of 98.2%. Furthermore, our approach addresses limitations of existing methods, like conspicuousness and positional constraints, offering a low-cost and effective technique for adversarial attacks, especially for autonomous vehicles. Code and demo are available at https://github.com/rufus0803/PhantomPatch. Qingsong Yao, Jingwei Li 0001, Xuewen Dong, Jianfeng Ma 0001 |
ISPA | 3 |
| 2024 | Encrypted Data Reduction: Removing Redundancy from Encrypted Data in Outsourced StorageabstractStorage savings and data confidentiality are two primary goals for outsourced storage. However, encryption by design destroys the content redundancy within plaintext data, so there exist design tensions when combining encryption with data reduction techniques (i.e., deduplication, delta compression, and local compression). We present EDRStore, an outsourced storage system that realizes encrypted data reduction to achieve both storage savings and data confidentiality. EDRStore’s core idea is a careful design of the encryption and data reduction workflows. It proposes new key generation and encryption schemes to preserve the content similarity of encrypted data for deduplication and delta compression. It further proposes selective local compression based on content similarity, so as to achieve storage savings of encrypted data from both delta compression and local compression. Evaluation on real-world datasets shows that EDRStore achieves higher storage savings than existing encrypted storage approaches and incurs moderate performance overhead compared with plaintext storage. Zuoru Yang, Jingwei Li 0001, Patrick P. C. Lee |
ACM Trans. Storage | 3 |
| 2023 | FeatureSpy: Detecting Learning-Content Attacks via Feature Inspection in Secure Deduplicated Storage
Jingwei Li 0001, Yanjing Ren, Patrick P. C. Lee, Ting Chen 0002, Xiaosong Zhang 0001 |
INFOCOM | 1 |
| 2023 | Fast Generation-Based Gradient Leakage Attacks against Highly Compressed GradientsabstractFederated learning (FL) is a distributed machine learning technology that preserves data privacy. However, it has been shown to be vulnerable to gradient leakage attacks (GLA), which can reconstruct private training data from public gradients with an overwhelming probability. Nevertheless, these attacks either require modification of the FL model (analytics-based) or take a long time to converge (optimization-based) and fail in dealing with highly compressed gradients in practical FL systems. In this paper, we pioneer a generation-based GLA method called FGLA that can reconstruct batches of user data, forgoing the optimization process. Specifically, we design a feature separation technique that extracts the feature of each data in a batch and then generates user data directly. Extensive experiments on multiple image datasets demonstrate that FGLA can reconstruct user images in milliseconds with a batch size of 256 from highly compressed gradients (0.8% compression ratio or higher), thus substantially outperforming state-of-the-art methods. Dongyun Xue, Haomiao Yang, Mengyu Ge, Jingwei Li 0001, Guowen Xu, Hongwei Li 0001 |
INFOCOM | 4 |
| 2023 | BlockExplorer: Exploring Blockchain Big Data Via Parallel ProcessingabstractToday's blockchain systems store detailed runtime information in the format of transactions and blocks, which are valuable not only to understand the finance of blockchain-based ecosystems but also to audit the security of on-chain applications. However, exploring this blockchain “big data” is challenging due to data heterogeneity and the huge amount. Existing blockchain exploration techniques are either incomplete or inefficient, making them inapt in time-sensitive applications. This paper presents ${\sf BlockExplorer}$ , an efficient and flexible blockchain exploration system for Ethereum. ${\sf BlockExplorer}$ builds on a master-slave architecture, where the master partitions all blocks into multiple non-overlapped sets and each slave simultaneously processes Ethereum big data based on a set of blocks. ${\sf BlockExplorer}$ implements a transaction-based partitioning approach to address load balance among slaves, and a code instrumentation approach to acquire complete Ethereum big data. The evaluation shows that ${\sf BlockExplorer}$ accelerates the data acquisition performance of the state-of-the-art by 4.1×, while the workload difference among slaves is up to 18%. To demonstrate the application of ${\sf BlockExplorer}$ , we develop three apps upon ${\sf BlockExplorer}$ to detect real-life attacks against Ethereum and show that our apps can detect attacks in a large range of blocks (e.g., ten million) within a short time (e.g., multiple hours). Jingwei Li 0001, Yuxing Tang, Xiapu Luo, Zheyuan He, Zihao Li 0001, Yang Bai 0011, Ting Chen 0002, Yuzhe Tang, Zhe Liu 0001, Xiaosong Zhang 0001 |
IEEE Trans. Computers | 2 |
| 2023 | Using Highly Compressed Gradients in Federated Learning for Data Reconstruction AttacksabstractFederated learning (FL) preserves data privacy by exchanging gradients instead of local training data. However, these private data can still be reconstructed from the exchanged gradients. Deep leakage from gradients (DLG) is a classical reconstruction attack that optimizes dummy data to real data by making the corresponding dummy and real gradients as similar as possible. Nevertheless, DLG fails with highly compressed gradients, which are crucial for communication-efficient FL. In this study, we propose an effective data reconstruction attack against highly compressed gradients, called highly compressed gradient leakage attack (HCGLA). In particular, HCGLA is characterized by the following three key techniques: 1) Owing to the unreasonable optimization objective of DLG in compression scenarios, we redesign a plausible objective function, ensuring that compressed dummy gradients are similar to the compressed real gradients. 2) Instead of simply initializing dummy data through random noise, as in DLG, we design a novel dummy data initialization method, Init-Generation, to compensate for information loss caused by gradient compression. 3) To further enhance reconstruction quality, we train an ad hoc denoising model using the methods of “first optimizing, next filtering, and then reoptimizing”. Extensive experiments on various benchmark data sets and mainstream models show that HCGLA is an effective reconstruction attack even against highly compressed gradients of 0.1%, whereas state-of-the-art attacks can only support 70% compression, thereby achieving a 700-fold improvement. Haomiao Yang, Mengyu Ge, Kunlan Xiang, Jingwei Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Revisiting Frequency Analysis against Encrypted Deduplication via Statistical DistributionabstractEncrypted deduplication addresses both security and storage efficiency in large-scale storage systems: it ensures that each plaintext is encrypted to a ciphertext by a symmetric key derived from the content of the plaintext, so as to allow deduplication on the ciphertexts derived from duplicate plaintexts. However, the deterministic nature of encrypted deduplication leaks the frequencies of plaintexts, thereby allowing adversaries to launch frequency analysis against encrypted deduplication and infer the ciphertext-plaintext pairs in storage. In this paper, we revisit the security vulnerability of encrypted deduplication due to frequency analysis, and show that encrypted deduplication can be even more vulnerable to the sophisticated frequency analysis attack that exploits the underlying storage workload characteristics. We propose the distribution-based attack, which builds on a statistical approach to model the relative frequency distributions of plaintexts and ciphertexts, and improves the inference precision (i.e., have high confidence on the correctness of inferred ciphertext-plaintext pairs) of the previous attack. We evaluate the new attack against real-world storage workloads and provide insights into its actual damage. Jingwei Li 0001, Guoli Wei, Jiacheng Liang, Yanjing Ren, Patrick P. C. Lee, Xiaosong Zhang 0001 |
INFOCOM | 1 |
| 2022 | Secure and Lightweight Deduplicated Storage via Shielded Deduplication-Before-Encryption
Zuoru Yang, Jingwei Li 0001, Patrick P. C. Lee |
USENIX ATC | 2 |
| 2022 | Dynamic incentive mechanism design for regulation-aware systemsabstractAs the gig economy continues to grow, behaviors of workers on gig service platforms have an increasing impact on service satisfaction. For example, fatigue driving behaviors of drivers in ride-hailing platforms may cause serious damages, both for individuals and society. Therefore, regulating behaviors of workers is urgent and challenging. A lot of studies are conducted to detect workers' noncompliance behaviors, such as detecting fatigue driving by computer vision or pattern recognition methods. However, few of them indicate how to efficiently exploit the detection results to regulate workers' behaviors. In this paper, we point out that workers' noncompliance behaviors and their incomes should be correlated, and propose a quantifiable computation framework that includes a price-based incentive mechanism and a method to verify the effectiveness of the mechanism. Historical behaviors of workers are summarized as credits and stored in nonfungible token called CreditToken to ensure that it cannot be tampered with. CreditToken will further affect workers' incomes. We abstract the decision-making behavior of workers as a Markov decision process and demonstrate the effectiveness of the incentive mechanism with model checking and formal methods. The analysis shows that our framework is able to provide a rational price strategy formation for gig service platforms, and can be flexibly integrated into existing pricing schemes to maximize the value of the detection results. Extensive experiments illustrate the advanced nature and practicality of our framework. Sixuan Dang, Jingwei Li 0001, Xiaosong Zhang 0001 |
Int. J. Intell. Syst. | 3 |
| 2022 | Enabling Secure and Space-Efficient Metadata Management in Encrypted DeduplicationabstractEncrypted deduplication combines encryption and deduplication in a seamless way to provide confidentiality guarantees for the physical data in deduplicated storage, yet it incurs substantial metadata storage overhead due to the additional storage of keys. We present a new encrypted deduplication storage system called${\sf Metadedup}$, which suppresses metadata storage by also applying deduplication to metadata. Its idea builds on indirection, which adds another level of metadata chunks that record metadata information. We find that metadata chunks are highly redundant in real-world workloads and hence can be effectively deduplicated. We further extend${\sf Metadedup}$to incorporate multiple servers via a distributed key management approach, so as to provide both fault-tolerant storage and security guarantees. We extensively evaluate${\sf Metadedup}$from performance and storage efficiency perspectives. We show that${\sf Metadedup}$achieves high throughput in writing and restoring files, and saves the metadata storage by up to 93.94 percent for real-world backup workloads. Jingwei Li 0001, Suyu Huang, Yanjing Ren, Zuoru Yang, Patrick P. C. Lee, Xiaosong Zhang 0001, Yao Hao |
IEEE Trans. Computers | 1 |
| 2022 | Tunable Encrypted Deduplication with Attack-resilient Key ManagementabstractConventional encrypted deduplication approaches retain the deduplication capability on duplicate chunks after encryption by always deriving the key for encryption/decryption from the chunk content, but such a deterministic nature causes information leakage due to frequency analysis. We present TED , a tunable encrypted deduplication primitive that provides a tunable mechanism for balancing the tradeoff between storage efficiency and data confidentiality. The core idea of TED is that its key derivation is based on not only the chunk content but also the number of duplicate chunk copies, such that duplicate chunks are encrypted by distinct keys in a controlled manner. In particular, TED allows users to configure a storage blowup factor, under which the information leakage quantified by an information-theoretic measure is minimized for any input workload. In addition, we extend TED with a distributed key management architecture and propose two attack-resilient key generation schemes that trade between performance and fault tolerance. We implement an encrypted deduplication prototype TEDStore to realize TED in networked environments. Evaluation on real-world file system snapshots shows that TED effectively balances the tradeoff between storage efficiency and data confidentiality, with small performance overhead. Zuoru Yang, Jingwei Li 0001, Yanjing Ren, Patrick P. C. Lee |
ACM Trans. Storage | 2 |
| 2021 | Accelerating Encrypted Deduplication via SGX
Yanjing Ren, Jingwei Li 0001, Zuoru Yang, Patrick P. C. Lee, Xiaosong Zhang 0001 |
USENIX ATC | 2 |
| 2020 | Balancing storage efficiency and data confidentiality with tunable encrypted deduplicationabstractConventional encrypted deduplication approaches retain the deduplication capability on duplicate chunks after encryption by always deriving the key for encryption/decryption from the chunk content, but such a deterministic nature causes information leakage due to frequency analysis. We present TED, a tunable encrypted deduplication primitive that provides a tunable mechanism for balancing the tradeoff between storage efficiency and data confidentiality. The core idea of TED is that its key derivation is based on not only the chunk content but also the number of duplicate chunk copies, such that duplicate chunks are encrypted by distinct keys in a controlled manner. In particular, TED allows users to configure a storage blowup factor, under which the information leakage quantified by an information-theoretic measure is minimized for any input workload. We implement an encrypted deduplication prototype TEDStore to realize TED in networked environments. Evaluation on real-world file system snapshots shows that TED effectively balances the trade-off between storage efficiency and data confidentiality, with small performance overhead. Jingwei Li 0001, Zuoru Yang, Yanjing Ren, Patrick P. C. Lee, Xiaosong Zhang 0001 |
EuroSys | 1 |
| 2020 | EVA: Efficient Versatile Auditing Scheme for IoT-Based Datamarket in JointcloudabstractCloud storage offers convenient outsourcing services to users, and it serves as a basic platform to drive Internet-of-Things (IoT) where massive devices are connected to the cloud storage and interact with each other. However, cloud storage is more than a data warehouse. In the literature, data market was proposed as a novel model to empower IoT, where data are circulated as merchandise in the digital marketplace with financial activities. When storing IoT data in cloud storage, security and efficiency rules should be applied. Meanwhile, data dynamics is counted as a critical factor to the feasibility of datamarket as data are supposed to be manipulated through circulation and exploitation for IoT. Another issue is the single-point-of-failure (SPoF) of cloud server in which the initiative of jointcloud was suggested. Since providing data security, efficiency, and dynamics simultaneously is challenging, in this article, we propose a versatile auditing scheme (EVA) as a solution to problems. Our proposal ensures that data are securely, efficiently, and dynamically stored in the jointcloud meanwhile supported by data trades via blockchain. We give a comprehensive security analysis based on our security definitions and experiments to support our claims. The evidence has shown that our EVA is efficient for processing large files when proper parameters are chosen. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Jingwei Li 0001, Qi Xia 0001, Jing Qin 0002 |
IEEE Internet Things J. | 6 |
| 2020 | Information Leakage in Encrypted Deduplication via Frequency Analysis: Attacks and DefensesabstractEncrypted deduplication combines encryption and deduplication to simultaneously achieve both data security and storage efficiency. State-of-the-art encrypted deduplication systems mainly build on deterministic encryption to preserve deduplication effectiveness. However, such deterministic encryption reveals the underlying frequency distribution of the original plaintext chunks. This allows an adversary to launch frequency analysis against the ciphertext chunks and infer the content of the original plaintext chunks. In this article, we study how frequency analysis affects information leakage in encrypted deduplication, from both attack and defense perspectives. Specifically, we target backup workloads and propose a new inference attack that exploits chunk locality to increase the coverage of inferred chunks. We further combine the new inference attack with the knowledge of chunk sizes and show its attack effectiveness against variable-size chunks. We conduct trace-driven evaluation on both real-world and synthetic datasets and show that our proposed attacks infer a significant fraction of plaintext chunks under backup workloads. To defend against frequency analysis, we present two defense approaches, namely MinHash encryption and scrambling. Our trace-driven evaluation shows that our combined MinHash encryption and scrambling scheme effectively mitigates the severity of the inference attacks, while maintaining high storage efficiency and incurring limited metadata access overhead. Jingwei Li 0001, Patrick P. C. Lee, Chufeng Tan, Chuan Qin 0009, Xiaosong Zhang 0001 |
ACM Trans. Storage | 1 |
| 2019 | Metadedup: Deduplicating Metadata in Encrypted Deduplication via IndirectionabstractEncrypted deduplication combines encryption and deduplication in a seamless way to provide confidentiality guarantees for the physical data in deduplication storage, yet it incurs substantial metadata storage overhead due to the additional storage of keys. We present a new encrypted deduplication storage system called Metadedup, which suppresses metadata storage by also applying deduplication to metadata. Its idea builds on indirection, which adds another level of metadata chunks that record metadata information. We find that metadata chunks are highly redundant in real-world workloads and hence can be effectively deduplicated. In addition, metadata chunks can be protected under the same encrypted deduplication framework, thereby providing confidentiality guarantees for metadata as well. We evaluate Metadedup through microbenchmarks, prototype experiments, and trace-driven simulation. Metadedup has limited computational overhead in metadata processing, and only adds 6.19% of performance overhead on average when storing files in a networked setting. Also, for real-world backup workloads, Metadedup saves the metadata storage by up to 97.46% at the expense of only up to 1.07% of indexing overhead for metadata chunks. Jingwei Li 0001, Patrick P. C. Lee, Yanjing Ren, Xiaosong Zhang 0001 |
MSST | 1 |
| 2019 | Discovering Vulnerabilities in COTS IoT Devices through Blackbox Fuzzing Web Management InterfaceabstractA novel approach for discovering vulnerability in commercial off-the-shelf (COTS) IoT devices is proposed in this paper, which will revolutionize the area. Unlike previous work, the web management interface in IoT was used to detect vulnerabilities by leveraging fuzzing technology. To validate and evaluate this scheme, a tool named WMIFuzzer was designed and implemented. There were also two challenges: (1) due to the diversity of web interface implementations, there were no existing seed messages for fuzzing this interface and it was inefficient while taking random messages to launch the fuzzing and (2) because of the highly structured seed message, fuzzing with byte-level mutation could conduce to be rejected by the device at an early stage. To address these challenges, a brute-force UI automation was designed to drive the web interface to generate initial seed messages automatically, as well as a weighted message parse tree (WMPT) was proposed to guide the mutation to generate mostly structure-valid messages. The extensive experimental results show that WMIFuzzer could achieve expected result while 10 vulnerabilities including 6 zero-days in 7 COTS IoT devices were discovered. Dong Wang 0018, Xiaosong Zhang 0001, Ting Chen 0002, Jingwei Li 0001 |
Secur. Commun. Networks | 4 |
| 2017 | Information Leakage in Encrypted Deduplication via Frequency AnalysisabstractEncrypted deduplication seamlessly combines encryption and deduplication to simultaneously achieve both data security and storage efficiency. State-of-the-art encrypted deduplication systems mostly adopt a deterministic encryption approach that encrypts each plaintext chunk with a key derived from the content of the chunk itself, so that identical plaintext chunks are always encrypted into identical ciphertext chunks for deduplication. However, such deterministic encryption inherently reveals the underlying frequency distribution of the original plaintext chunks. This allows an adversary to launch frequency analysis against the resulting ciphertext chunks, and ultimately infer the content of the original plaintext chunks. In this paper, we study how frequency analysis practically affects information leakage in encrypted deduplication storage, from both attack and defense perspectives. We first propose a new inference attack that exploits chunk locality to increase the coverage of inferred chunks. We conduct trace-driven evaluation on both real-world and synthetic datasets, and show that the new inference attack can infer a significant fraction of plaintext chunks under backup workloads. To protect against frequency analysis, we borrow the idea of existing performance-driven deduplication approaches and consider an encryption scheme called MinHash encryption, which disturbs the frequency rank of ciphertext chunks by encrypting some identical plaintext chunks into multiple distinct ciphertext chunks. Our trace-driven evaluation shows that MinHash encryption effectively mitigates the inference attack, while maintaining high storage efficiency. Jingwei Li 0001, Chuan Qin 0009, Patrick P. C. Lee, Xiaosong Zhang 0001 |
DSN | 1 |
| 2017 | Towards Privacy-Preserving Storage and Retrieval in Multiple CloudsabstractCloud computing is growing exponentially, whereby there are now hundreds of cloud service providers (CSPs) of various sizes. While the cloud consumers may enjoy cheaper data storage and computation offered in this multi-cloud environment, they are also in face of more complicated reliability issues and privacy preservation problems of their outsourced data. Though searchable encryption allows users to encrypt their stored data while preserving some search capabilities, few efforts have sought to consider the reliability of the searchable encrypted data outsourced to the clouds. In this paper, we propose a privacy-preserving STorage and REtrieval (STRE) mechanism that not only ensures security and privacy but also provides reliability guarantees for the outsourced searchable encrypted data. The STRE mechanism enables the cloud users to distribute and search their encrypted data across multiple independent clouds managed by different CSPs, and is robust even when a certain number of CSPs crash. Besides the reliability, STRE also offers the benefit of partially hidden search pattern. We evaluate the STRE mechanism on Amazon EC2 using a real world dataset and the results demonstrate both effectiveness and efficiency of our approach. Jingwei Li 0001, Dan Lin 0001, Anna Cinzia Squicciarini, Jin Li 0002, Chunfu Jia |
IEEE Trans. Cloud Comput. | 1 |
| 2017 | MMBcloud-Tree: Authenticated Index for Verifiable Cloud Service SelectionabstractCloud brokers have been recently introduced as an additional computational layer to facilitate cloud selection and service management tasks for cloud consumers. However, existing brokerage schemes on cloud service selection typically assume that brokers are completely trusted, and do not provide any guarantee over the correctness of the service recommendations. It is then possible for a compromised or dishonest broker to easily take advantage of the limited capabilities of the clients and provide incorrect or incomplete responses. To address this problem, we propose an innovative cloud service selection verification (CSSV) scheme and index structures (MMBcloud-tree) to enable cloud clients to detect misbehavior of the cloud brokers during the service selection process. We demonstrate correctness and efficiency of our approaches both theoretically and empirically. Jingwei Li 0001, Anna Cinzia Squicciarini, Dan Lin 0001, Smitha Sundareswaran, Chunfu Jia |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2017 | The Design and Implementation of a Rekeying-Aware Encrypted Deduplication Storage SystemabstractRekeying refers to an operation of replacing an existing key with a new key for encryption. It renews security protection to protect against key compromise and enable dynamic access control in cryptographic storage. However, it is non-trivial to realize efficient rekeying in encrypted deduplication storage systems, which use deterministic content-derived encryption keys to allow deduplication on ciphertexts. We design and implement a rekeying-aware encrypted deduplication (REED) storage system. REED builds on a deterministic version of all-or-nothing transform, such that it enables secure and lightweight rekeying, while preserving the deduplication capability. We propose two REED encryption schemes that trade between performance and security and extend REED for dynamic access control. We implement a REED prototype with various performance optimization techniques and demonstrate how we can exploit similarity to mitigate key generation overhead. Our trace-driven testbed evaluation shows that our REED prototype maintains high performance and storage efficiency. Chuan Qin 0009, Jingwei Li 0001, Patrick P. C. Lee |
ACM Trans. Storage | 2 |
| 2016 | Efficient Network Path Verification for Policy-routedQueries
Sushama Karumanchi, Jingwei Li 0001, Anna Cinzia Squicciarini |
CODASPY | 2 |
| 2016 | Rekeying for Encrypted Deduplication StorageabstractRekeying refers to an operation of replacing an existing key with a new key for encryption. It renews security protection, so as to protect against key compromise and enable dynamic access control in cryptographic storage. However, it is non-trivial to realize efficient rekeying in encrypted deduplication storage systems, which use deterministic content-derived encryption keys to allow deduplication on ciphertexts. We design and implement REED, a rekeying-aware encrypted deduplication storage system. REED builds on a deterministic version of all-or-nothing transform (AONT), such that it enables secure and lightweight rekeying, while preserving the deduplication capability. We propose two REED encryption schemes that trade between performance and security, and extend REED for dynamic access control. We implement a REED prototype with various performance optimization techniques. Our trace-driven testbed evaluation shows that our REED prototype maintains high performance and storage efficiency. Jingwei Li 0001, Chuan Qin 0009, Patrick P. C. Lee, Jin Li 0002 |
DSN | 1 |
| 2016 | Secure Auditing and Deduplicating Data in CloudabstractAs the cloud computing technology develops during the last decade, outsourcing data to cloud service for storage becomes an attractive trend, which benefits in sparing efforts on heavy data maintenance and management. Nevertheless, since the outsourced cloud storage is not fully trustworthy, it raises security concerns on how to realize data deduplication in cloud while achieving integrity auditing. In this work, we study the problem of integrity auditing and secure deduplication on cloud data. Specifically, aiming at achieving both data integrity and deduplication in cloud, we propose two secure systems, namely SecCloud and SecCloud$^+$. SecCloud introduces an auditing entity with a maintenance of a MapReduce cloud, which helps clients generate data tags before uploading as well as audit the integrity of data having been stored in cloud. Compared with previous work, the computation by user in SecCloud is greatly reduced during the file uploading and auditing phases. SecCloud$^+$is designed motivated by the fact that customers always want to encrypt their data before uploading, and enables integrity auditing and secure deduplication on encrypted data. Jingwei Li 0001, Jin Li 0002, Dongqing Xie, Zhang Cai |
IEEE Trans. Computers | 1 |
| 2015 | SecLoc: Securing Location-Sensitive Storage in the CloudabstractCloud computing offers a wide array of storage services. While enjoying the benefits of flexibility, scalability and reliability brought by the cloud storage, cloud users also face the risk of losing control of their own data, in partly because they do not know where their data is actually stored. This raises a number of security and privacy concerns regarding one's sensitive data such as health records. For example, according to Canadian laws, data related to personal identifiable information must be stored within Canada. Nevertheless, in contrast to the urgent demands, privacy requirements regarding to cloud storage locations have not been well investigated in the current cloud computing market, fostering security and privacy concerns among potential adopters. Aiming at addressing this emerging critical issue, we propose a novel secure location-sensitive storage framework, called SecLoc, which offers protection for cloud users' data following the storage location restrictions, with minimum management overhead to existing cloud storage services. We conduct security analysis, complexity analysis and experimental evaluation on the proposed SecLoc system. Our results demonstrate both effectiveness and efficiency of our mechanism. Jingwei Li 0001, Anna Cinzia Squicciarini, Dan Lin 0001, Chunfu Jia |
SACMAT | 1 |
| 2015 | New access control systems based on outsourced attribute-based encryptionabstractAs cloud computing becomes prevalent, more and more sensitive data is being centralized into the cloud for sharing, which brings forth new challenges for outsourced data security and privacy. Attribute-based encryption (ABE) is a promising cryptographic primitive, which has been widely applied to design fine-grained access control system recently. However, ABE is criticized for its high scheme overhead as the computational cost grows with the complexity of the access formula. This disadvantage becomes more serious for mobile devices with constrained computing resources. Aiming at tackling the challenge above, we present a generic and efficient solution to implement attribute-based access control system by introducing secure outsourcing techniques into ABE. More precisely, two cloud service providers (CSPs), namely key generation-cloud service provider (KG-CSP) and decryption-cloud service provider (D-CSP) are introduced to perform the outsourced key-issuing and decryption on behalf of attribute authority and users respectively. In order to outsource heavy computation to both CSPs without private information leakage, we formalize an underlying primitive called outsourced ABE (OABE) and propose several constructions with outsourced decryption and key-issuing. Finally, extensive experiment demonstrates that with the help of KG-CSP and D-CSP, efficient key-issuing and decryption are achieved in our constructions. Jin Li 0002, Xiaofeng Chen 0001, Jingwei Li 0001, Chunfu Jia, Jianfeng Ma 0001, Wenjing Lou |
J. Comput. Secur. | 3 |
| 2015 | Designing cloud-based electronic health record system with attribute-based encryption
Fatos Xhafa, Jingwei Li 0001, Gansen Zhao, Jin Li 0002, Xiaofeng Chen 0001, Duncan S. Wong |
Multim. Tools Appl. | 2 |
| 2015 | Identity-Based Encryption with Outsourced Revocation in Cloud ComputingabstractIdentity-Based Encryption (IBE) which simplifies the public key and certificate management at Public Key Infrastructure (PKI) is an important alternative to public key encryption. However, one of the main efficiency drawbacks of IBE is the overhead computation at Private Key Generator (PKG) during user revocation. Efficient revocation has been well studied in traditional PKI setting, but the cumbersome management of certificates is precisely the burden that IBE strives to alleviate. In this paper, aiming at tackling the critical issue of identity revocation, we introduce outsourcing computation into IBE for the first time and propose a revocable IBE scheme in the server-aided setting. Our scheme offloads most of the key generation related operations during key-issuing and key-update processes to a Key Update Cloud Service Provider, leaving only a constant number of simple operations for PKG and users to perform locally. This goal is achieved by utilizing a novel collusion-resistant technique: we employ a hybrid private key for each user, in which an AND gate is involved to connect and bound the identity component and the time component. Furthermore, we propose another construction which is provable secure under the recently formulized Refereed Delegation of Computation model. Finally, we provide extensive experimental results to demonstrate the efficiency of our proposed construction. Jin Li 0002, Jingwei Li 0001, Xiaofeng Chen 0001, Chunfu Jia, Wenjing Lou |
IEEE Trans. Computers | 2 |
| 2014 | Securing Resource Discovery in Content Hosting Networks
Sushama Karumanchi, Jingwei Li 0001, Anna Cinzia Squicciarini |
SecureComm (1) | 2 |
| 2014 | STRE: Privacy-Preserving Storage and Retrieval over Multiple Clouds
Jingwei Li 0001, Dan Lin 0001, Anna Cinzia Squicciarini, Chunfu Jia |
SecureComm (1) | 1 |
| 2014 | Policy Driven Node Selection in MapReduce
Anna Cinzia Squicciarini, Dan Lin 0001, Smitha Sundareswaran, Jingwei Li 0001 |
SecureComm (1) | 4 |
| 2014 | Enabling efficient and secure data sharing in cloud computingabstractSUMMARY With the rapid development of cloud computing, more and more data are being centralized into remote cloud server for sharing, which raises a challenge on how to keep them both private and accessible. Although searchable encryption provides an efficient solution to support keyword‐based search directly on encrypted data, considering its application in file sharing, existing work depends on key sharing among authorized users, which inevitably causes the risks of key exposure and abuse. In this paper, aiming at enabling efficient and secure data sharing in cloud computing, we provide a generic construction for this purpose. The proposed construction is full‐featured: (i) It enables authorized users to perform keyword‐based search directly on encrypted data without sharing the unique secret key; and (ii) it provides two‐layered access control to limit unauthorized user's access to the shared data. On the basis of the proposed generic construction, we utilize the existing techniques on identity‐based broadcast encryption and public key searchable encryption to instantiate a concrete construction. Copyright © 2013 John Wiley & Sons, Ltd. Jingwei Li 0001, Jin Li 0002, Zheli Liu, Chunfu Jia |
Concurr. Comput. Pract. Exp. | 1 |
| 2014 | Privacy-preserving data utilization in hybrid clouds
Jingwei Li 0001, Jin Li 0002, Xiaofeng Chen 0001, Zheli Liu, Chunfu Jia |
Future Gener. Comput. Syst. | 1 |
| 2014 | Secure Deduplication with Efficient and Reliable Convergent Key ManagementabstractData deduplication is a technique for eliminating duplicate copies of data, and has been widely used in cloud storage to reduce storage space and upload bandwidth. Promising as it is, an arising challenge is to perform secure deduplication in cloud storage. Although convergent encryption has been extensively adopted for secure deduplication, a critical issue of making convergent encryption practical is to efficiently and reliably manage a huge number of convergent keys. This paper makes the first attempt to formally address the problem of achieving efficient and reliable key management in secure deduplication. We first introduce a baseline approach in which each user holds an independent master key for encrypting the convergent keys and outsourcing them to the cloud. However, such a baseline key management scheme generates an enormous number of keys with the increasing number of users and requires users to dedicatedly protect the master keys. To this end, we propose Dekey , a new construction in which users do not need to manage any keys on their own but instead securely distribute the convergent key shares across multiple servers. Security analysis demonstrates that Dekey is secure in terms of the definitions specified in the proposed security model. As a proof of concept, we implement Dekey using the Ramp secret sharing scheme and demonstrate that Dekey incurs limited overhead in realistic environments. Jin Li 0002, Xiaofeng Chen 0001, Mingqiang Li, Jingwei Li 0001, Patrick P. C. Lee, Wenjing Lou |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2014 | Secure Outsourced Attribute-Based SignaturesabstractAttribute-based signature (ABS) enables users to sign messages over attributes without revealing any information other than the fact that they have attested to the messages. However, heavy computational cost is required during signing in existing work of ABS, which grows linearly with the size of the predicate formula. As a result, this presents a significant challenge for resource-constrained devices (such as mobile devices or RFID tags) to perform such heavy computations independently. Aiming at tackling the challenge above, we first propose and formalize a new paradigm called Outsourced ABS, i.e., OABS, in which the computational overhead at user side is greatly reduced through outsourcing intensive computations to an untrusted signing-cloud service provider (S-CSP). Furthermore, we apply this novel paradigm to existing ABS schemes to reduce the complexity. As a result, we present two concrete OABS schemes: i) in the first OABS scheme, the number of exponentiations involving in signing is reduced from O(d) to O(1) (nearly three), where d is the upper bound of threshold value defined in the predicate; ii) our second scheme is built on Herranz et al.'s construction with constant-size signatures. The number of exponentiations in signing is reduced from O(d2) to O(d) and the communication overhead is O(1). Security analysis demonstrates that both OABS schemes are secure in terms of the unforgeability and attribute-signer privacy definitions specified in the proposed security model. Finally, to allow for high efficiency and flexibility, we discuss extensions of OABS and show how to achieve accountability as well. Xiaofeng Chen 0001, Jin Li 0002, Xinyi Huang 0001, Jingwei Li 0001, Yang Xiang 0001, Duncan S. Wong |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2014 | Securely Outsourcing Attribute-Based Encryption with CheckabilityabstractAttribute-Based Encryption (ABE) is a promising cryptographic primitive which significantly enhances the versatility of access control mechanisms. Due to the high expressiveness of ABE policies, the computational complexities of ABE key-issuing and decryption are getting prohibitively high. Despite that the existing Outsourced ABE solutions are able to offload some intensive computing tasks to a third party, the verifiability of results returned from the third party has yet to be addressed. Aiming at tackling the challenge above, we propose a new Secure Outsourced ABE system, which supports both secure outsourced key-issuing and decryption. Our new method offloads all access policy and attribute related operations in the key-issuing process or decryption to a Key Generation Service Provider (KGSP) and a Decryption Service Provider (DSP), respectively, leaving only a constant number of simple operations for the attribute authority and eligible users to perform locally. In addition, for the first time, we propose an outsourced ABE construction which provides checkability of the outsourced computation results in an efficient way. Extensive security and performance analysis show that the proposed schemes are proven secure and practical. Jin Li 0002, Xinyi Huang 0001, Jingwei Li 0001, Xiaofeng Chen 0001, Yang Xiang 0001 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2013 | Fine-Grained Access Control System Based on Outsourced Attribute-Based Encryption
Jin Li 0002, Xiaofeng Chen 0001, Jingwei Li 0001, Chunfu Jia, Jianfeng Ma 0001, Wenjing Lou |
ESORICS | 3 |
| 2013 | Secure Storage and Fuzzy Query over Encrypted Databases
Zheli Liu, Jin Li 0002, Chunfu Jia, Jingwei Li 0001 |
NSS | 5 |
| 2013 | Cycle-walking revisited: consistency, security, and efficiencyabstractABSTRACT Cycle‐walking is a method that makes sure ciphertext falls in the acceptable range through encrypting plaintext repeatedly with some underlying cipher. This technology provides a general way to construct cryptographic schemes for various interesting applications, including enhancing existing system security without the change of original structure, encrypting multimedia data with the preservation of scalability, generating credit card numbers for Web transaction, and so on, which have a common feature that ciphertext is required to satisfy certain restrictions in order to allow some operations directly imposed on encrypted data. Nevertheless, as far as we know, there exists little work making rigorous analysis on cycle‐walking, especially its undeterministic efficiency, which may limit the application of schemes constructed by such technology or even lead it to unpracticality. In this paper, aiming at filling some gaps about cycle‐walking and helping cryptographic theory “catch up” with its application, we present the rigorous analysis on cycle‐walking's properties including consistency, security, and efficiency. On consistency, we show that cycle‐walking will necessarily arrive back with finite iteration rounds and its decryption reverses encryption. On security, we show that cycle‐walking would not degrade the security of underlying ciphers. On efficiency, instead of using “nondeterministic” to describe cycle‐walking's performance in previous work, we make precise analysis and provide the answer to “how long is the duration of cycle‐walking's encrypting process.” Copyright © 2012 John Wiley & Sons, Ltd. Jingwei Li 0001, Chunfu Jia, Zheli Liu, Zongqing Dong |
Secur. Commun. Networks | 1 |
| 2012 | Outsourcing Encryption of Attribute-Based Encryption with MapReduce
Jingwei Li 0001, Chunfu Jia, Jin Li 0002, Xiaofeng Chen 0001 |
ICICS | 1 |
| 2012 | Efficient Keyword Search over Encrypted Data with Fine-Grained Access Control in Hybrid Cloud
Jingwei Li 0001, Jin Li 0002, Xiaofeng Chen 0001, Chunfu Jia, Zheli Liu |
NSS | 1 |