VLDB 2026 Research / reviewers in the wild / expert
Wensheng Zhang 0001
dblp:94/6627-1
· DBLP profile ↗
84ranked-venue papers
19as first author
9since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 50 · 14 first-authorSecurity and privacy · 13 · 3 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 7 · 2 first-authorSoftware engineering, systems software and programming languages · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Systems, architecture and hardware · 3Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Verifiable Personalized Mutual-Learning based on Blockchain and zk-SNARK
Hongyi Bian, Wensheng Zhang 0001, Carl K. Chang |
ICBC | 2 |
| 2024 | Clustering-based Mutual-Learning for Personalized Situation-Aware Services in Smart HomesabstractThe Internet of Things (IoT) has been extensively applied to human-centric smart environments. Services provisioned within these IoT-enabled smart settings can substantially enhance the quality of life, mitigate potential hazards, and thereby offer personalized services for their users. However, there is a notable deficiency in the consideration of human factors necessary for realizing more refined and personalized situation-aware services. Moreover, as learning-based approaches are widely used in providing situation analysis in the current era, the challenge of training a robust learning model is aggravated by the scarcity of locally collected user data. Federated Learning (FL) was proposed to address the issue in a centralized, cloud-edge-based setting. Nonetheless, it falls short of facilitating personalized learning, which is crucial for the provisioning of local situation-aware services. In this paper, we propose a decen-tralized, clustering-based mutual learning approach that enables each edge server to learn a personalized model by iteratively sharing knowledge within clusters formed based on situational similarities. We used connected smart homes as an example to demonstrate the learning approach, and show the effectiveness of achieving personalized situation analysis, which ultimately leads to robust and accurate service in smart environments. Hongyi Bian, Wensheng Zhang 0001, Carl K. Chang |
SSE | 2 |
| 2023 | Integrating Homomorphic Encryption and Trusted Execution Technology for Autonomous and Confidential Model Refining in CloudabstractWith the popularity of cloud computing and machine learning, it has been a trend to outsource machine learning processes (including model training and model-based inference) to cloud. By the outsourcing, other than utilizing the extensive and scalable resource offered by the cloud service provider, it will also be attractive to users if the cloud servers can manage the machine learning processes autonomously on behalf of the users. Such a feature will be especially salient when the machine learning is expected to be a long-term continuous process and the users are not always available to participate. Due to security and privacy concerns, it is also desired that the autonomous learning preserves the confidentiality of users' data and models involved. Hence, in this paper, we aim to design a scheme that enables autonomous and confidential model refining in cloud. Homomor-phic encryption and trusted execution environment technology can protect confidentiality for autonomous computation, but each of them has their limitations respectively and they are complementary to each other. Therefore, we further propose to integrate these two techniques in the design of the model refining scheme. Through implementation and experiments, we evaluate the feasibility of our proposed scheme. The results indicate that, with our proposed scheme the cloud server can autonomously re-fine an encrypted model with newly provided encrypted training data to continuously improve its accuracy. Though the efficiency is still significantly lower than the baseline scheme that refines plaintext-model with plaintext-data, we expect that it can be improved by fully utilizing the higher level of parallelism and the computational power of GPU at the cloud server. Pinglan Liu, Wensheng Zhang 0001 |
CLOUD | 2 |
| 2023 | Distributed and Intelligent API Mediation Service for Enterprise-Grade Hybrid-Multicloud ComputingabstractIn an enterprise-grade hybrid-multicloud computing environment, capability-providing as-a-service endpoints (or aaS-endpoints) can be deployed across diverse computing platforms, e.g., public clouds and on-prem enterprise private clouds. To ensure a seamless, unified, and enterprise-compliant acquisition of the capabilities by client applications, the presence of a cross-cloud API mediation service is crucial. However, as the number and heterogeneity of aaS-endpoints increase, delivering the API mediation service at scale becomes increasingly costly. This paper presents a robust approach to API service mediation in enterprise-grade hybrid-multicloud computing environments. It tackles the challenges, offering a distributed architecture comprising dynamically composed managed microservices, microservice zones, intelligent endpoint selection, and adaptive statistical learning (aiming to exploit localities in performance history of aaS-endpoint invocations and to facilitate adding or removing active aaS-endpoints). The successful reference implementation and$24\mathrm{x}7\mathrm{x}365$delivery in real-world settings of the approach validate its efficacy as a practical solution for API service mediation. Hongyi Bian, Rong Chang 0001, Kumar Bhaskaran, Wensheng Zhang 0001, Carl K. Chang |
SSE | 4 |
| 2023 | Situ-Oracle: A Learning-Based Situation Analysis Servicing Framework for BIoT SystemsabstractThe emergence of blockchain technologies and the rapid growth of the Internet of Things (IoT) have brought blockchain-premised IoT (BIoT) systems into the focus of recent studies. The decentralized nature of blockchain enables data traceability, transparency, and immutability as complementary security features to the existing IoT systems. It has been applied to prevent malicious control or data leakages in traditional cloud-based, vendor-specific IoT use case scenarios. Nevertheless, as we gradually step towards the situation-aware IoT era, the lack of means to incorporate situation awareness with BIoT systems has limited the full potential of such integration. In this work, we propose a framework, Situ-Oracle, as an attempt to provide situation analysis as a service to BIoT systems. The framework utilizes a Recurrent Neural Network (RNN) based learning model to perform sensory-based situation analysis. We used smart home as an example to demonstrate the feasibility of the integration in bringing situation awareness to smart-contract-enabled IoT systems. Following that, system-wide performance evaluations were conducted over a physically constructed BIoT system, the results show that the proposed system achieves better situation analysis accuracy and network performance compared to a baseline system. Overall, the paper presents a promising approach for improving situation analysis in BIoT systems, with potential applications in various domains such as smart homes, healthcare, and industrial automation. Hongyi Bian, Wensheng Zhang 0001, Carl K. Chang |
SSE | 2 |
| 2022 | Towards Practical Privacy-Preserving Solution for Outsourced Neural Network InferenceabstractWhen neural network model and data are outsourced to a cloud server for inference, it is desired to preserve the privacy of the model/data as the involved parties (i.e., cloud server, and model/data providing clients) may not trust mutually. Solutions have been proposed based on multi-party computation, trusted execution environment (TEE) and leveled or fully homomorphic encryption (LHE or FHE), but they all have limitations that hamper practical application. We propose a new framework based on integration of LHE and TEE, which enables collaboration among mutually-untrusted three parties, while minimizing the involvement of resource-constrained TEE but fully utilizing the untrusted but resource-rich part of server. We also propose a generic and efficient LHE-based inference scheme, along with optimizations, as an important performance-determining component of the framework. We implemented and evaluated the proposed scheme on a moderate platform, and the evaluations show that, our proposed system is applicable and scalable to various settings, and it has better or comparable performance when compared with the state-of-the-art solutions which are more restrictive in applicability and scalability. Pinglan Liu, Wensheng Zhang 0001 |
CLOUD | 2 |
| 2022 | Privacy-Preserving Detection of Poisoning Attacks in Federated LearningabstractWith federated learning, local learners train a shared global model using their own data, and report model updates to a server to aggregate and then update the global model. Such a learning paradigm may suffer from two attacks: privacy attacks by the untrusted server; adversarial attacks (e.g., poisoning attacks) by malicious learners. There is extensive research on addressing each of the attacks separately, but there is no scheme that can address both of them. In this paper, we pro-pose a scheme that enables both privacy-preserving aggregation and poisoning attack detection at the server, by utilizing additive homomorphic encryption and a trusted execution environment (TEE). Our evaluation based on an implemented prototype system demonstrates that our scheme can attain a similar level of detection accuracy as the state-of-the-art poisoning detection scheme, and that the increased computational workload can be parallelized and mostly executed outside of the TEE. A privacy analysis shows that the proposed scheme can protect individual learners’ model updates from being exposed. Trent Muhr, Wensheng Zhang 0001 |
PST | 2 |
| 2021 | A Practical Oblivious Cloud Storage System based on TEE and Client GatewayabstractIn this paper, we propose a new oblivious cloud storage system, which is more efficient and scalable than existing schemes due to the combined leverage of SGX-based trusted execution environment (TEE) at the cloud server side and the moderate storage space at the client side. The TEE is employed to securely implement functionalities of ORAM model in the server without tightly involving the clients. Meanwhile, the storage at the client side is utilized to store metadata and recently/frequently accessed data, which facilitates the client to remotely determine the strategies for data query/eviction and to reduce the frequency of directly accessing data from the server. The evaluation results show that, when the size of outsourced data is 1-20 GB and the block size is 1-8KB, the data access throughput between 320 KB/s and 640 KB/s can be attained, and the average query latency for each block is only 2.26–12.80 ms. Wensheng Zhang 0001 |
PST | 1 |
| 2021 | TEE-based Selective Testing of Local Workers in Federated Learning SystemsabstractThis paper considers a federated learning system consisting of a central aggregation server and multiple distributed local workers, all having access to trusted execution environments (TEEs). For the local workers, which are untrusted but economically-rational, to conduct local learning honestly, we propose a TEE-based selective testing scheme that also combines techniques from applied cryptography, game theory and smart contract. Theoretical analysis of the scheme indicates that only a small number of tests are needed to enforce honest execution by the local workers. Implementation-based experiments compare the cost of the proposed scheme against two reference schemes (i.e., the original scheme without security measure and the all-SGX scheme which conducts training completely in an SGX enclave). The results show that, our proposed scheme incurs much lower cost at the SGX enclave though introducing a higher cost at the untrusted execution environment. We argue that this tradeoff is appropriate given that computing in the untrusted environment can access more resources and is cheaper than in the trusted environment. The experiment results also show that, the increase of the cost in the untrusted execution environment get smaller as the size of the training model increases, which demonstrates the scalability of the scheme. Wensheng Zhang 0001, Trent Muhr |
PST | 1 |
| 2020 | A Situation Enabled Framework for Energy-Efficient Workload Offloading in 5G Vehicular Edge ComputingabstractCloud based vehicular edge computing is a promising technology to deliver quality of services for accessing public cloud from vehicles. As in-vehicle computers (e.g. onboard Android devices) are typically energy and resource constrained, they need to operate energy-efficiently. Due to the high cost in building sustainable infrastructure to support vehicular edge computing systems, edge services must also operate with high energy-efficiency for better acceptability and applicability in the market place. In this paper, we present a novel situation-enabled framework to enhance energy-efficiency of both in-vehicle computer applications and Mobile Edge Computing (MEC) services. The framework consists of three components. First, we collect a user's in-vehicle driving situation data and use the data to train Long Short Term Memory (LSTM) deep learning model. The model is used to predict the user's future situation, determine whether the requested application is allowable, and manage the allowable application pertaining to the predicted situation. Second, from vehicles to MEC servers, we optimize the energy consumption in request routing. Third, a Breadth First Search (BFS) based offloading algorithm to coordinate the placement of servers in the MEC servers to save the energy consumption in the server pool. Implementation of LSTM on top of a situation model and simulation of the vehicular edge offloading have been conducted to validate the energy efficiency of the proposed framework. The results show that the performance of our proposed offloading algorithm can be at par with the most aggressive energy saving variant. Chen-Yeou Yu, Carl K. Chang, Wensheng Zhang 0001 |
SERVICES | 3 |
| 2018 | A New Game Theoretic Scheme for Verifiable Cloud ComputingabstractOutsourcing computation to cloud service providers (CSPs) has been convenient as the cloud computing paradigm becomes popular. One problem with computation outsourcing is how to efficiently verify if the returned computation result is correct. This paper studies the game theoretic approach to this problem. Specifically, we re-visit a state-of-the-art game theoretic scheme for this problem, and point out that one component of the scheme is too restrictive, which if replaced by another one, the scheme will become ineffective. To further address this flaw, we propose a new game theoretic scheme, which is probabilistic, and show that, a client can use this scheme to hire two CSPs who could collude based on any collusion contract, and the computation result can be verifiable as long as the CSPs are rational. Pinglan Liu, Wensheng Zhang 0001 |
IPCCC | 2 |
| 2018 | LA ^3 : A Lightweight Accountable and Anonymous Authentication Scheme for Resource-Constrained Devices
Wensheng Zhang 0001 |
NSS | 1 |
| 2016 | SE-ORAM: A Storage-Efficient Oblivious RAM for Privacy-Preserving Access to Cloud StorageabstractOblivious RAM (ORAM) is a security-provable approach for protecting clients' access patterns to remote cloud storage. Recently, numerous ORAM constructions have been proposed to improve the communication efficiency of the ORAM model, but little attention has been paid to the storage efficiency. The state-of-the-art ORAM constructions have the storage overhead of O(N) or O(N log N) blocks at the server, when N data blocks are hosted. To fill the blank, this paper proposes a storage-efficient ORAM (SE-ORAM) construction with configurable security parameter λ and zero storage overhead at the server. Extensive analysis has also been conducted and the results show that, SE-ORAM achieves the configured level of security, introduces zero storage overhead to the storage server (i.e., the storage server only storages N data blocks), and incurs O(log N) blocks storage overhead at the client, as long as λ ≥ 2 and each node on the storage tree stores 4 log N or more data blocks. Qiumao Ma, Jinsheng Zhang, Wensheng Zhang 0001, Daji Qiao |
CSCloud | 4 |
| 2016 | Dynamic sensing scheduling to prolong network lifetime under practical requirementsabstractWe propose a unique Dynamic Sensing Scheduling (DSS) scheme to prolong the lifetime of a sensor network. Different from most existing works, we study the sensor network lifetime under two practical requirements: sensing coverage and network connectivity. A sensor node is considered critical if its depletion of energy would cause either a violation of the sensing coverage requirement (specified by the application) or a disconnection of the routing tree. The key idea of DSS is to adjust the sensing duties of sensor nodes according to their nodal lifetime as well as their criticality. Under this design principle, DSS schedules more sensing duties to non-critical nodes (even at the cost of losing them more quickly) so that critical nodes may stay alive for a longer period of time, thus extending the network lifetime. DSS adjusts the sensing duties between neighboring nodes only, and is a distributed and lightweight solution. Simulation results show that DSS performs well under various network setups, close to a theoretical upper bound. Wensheng Zhang 0001, Daji Qiao |
ICC | 3 |
| 2016 | DF-ORAM: A Practical Dummy Free Oblivious RAM to Protect Outsourced Data Access Pattern
Qiumao Ma, Wensheng Zhang 0001, Jinsheng Zhang |
NSS | 2 |
| 2015 | GP-ORAM: A Generalized Partition ORAM
Jinsheng Zhang, Wensheng Zhang 0001, Daji Qiao |
NSS | 2 |
| 2014 | S-ORAM: a segmentation-based oblivious RAMabstractAs outsourcing data to remote storage servers gets popular, protecting user's pattern in accessing these data has become a big concern. ORAM constructions are promising solutions to this issue, but their application in practice has been impeded by the high communication and storage overheads incurred. Towards addressing this challenge, this paper proposes a segmentation-based ORAM (S-ORAM). It adopts two segment-based techniques, namely, piece-wise shuffling and segment-based query, to improve the performance of shuffling and query by factoring block size into design. Extensive security analysis proves that S-ORAM is a highly secure solution with a negligible failure probability of O(N-log N). In terms of communication and storage overheads, S-ORAM outperforms the Balanced ORAM (B-ORAM) and the Path ORAM (P-ORAM), which are the state-of-the-art hash and index based ORAMs respectively, in both practical and theoretical evaluations. Particularly under practical settings, the communication overhead of S-ORAM is 12 to 23 times less than B-ORAM when they have the same constant-size user-side storage, and S-ORAM consumes 80% less server-side storage and around 60% to 72% less bandwidth than P-ORAM when they have the similar logarithmic-size user-side storage. Jinsheng Zhang, Wensheng Zhang 0001, Daji Qiao |
AsiaCCS | 2 |
| 2014 | Efficient verification of data encryption on cloud serversabstractLeak of clients' sensitive information from cloud system remains to be a problem despite of rapid development of cloud technology. One of the major reasons for such leaks to occur is the lack of efficient encryption verification schemes. For a cloud computing system, computational strength of server should not be sacrificed while encryption and verification is applied, which adds certain level of difficulty in developing an efficient verification scheme. We present in this paper an efficient incentive-triggered method to verify the data encryption on server side. Compared with previous solutions, our method is considerably faster. Besides the efficiency, our method can be applied to both archive data and frequently-modified data. The above are major features that make our scheme to be more practical and applicable than previous solutions. Keji Hu, Wensheng Zhang 0001 |
PST | 2 |
| 2014 | Joint charging and rate allocation for utility maximization in sustainable sensor networksabstractA sensor network deployed for long-term monitoring shall sustain meanwhile provide as much useful sensory information (i.e., as high network utility) as possible. We propose a JCRA (Joint Charging and Rate Allocation) scheme to maximize the network utility while satisfying the network sustainability requirement. JCRA is designed based on the observation that the energy repository of a sensor node is co-affected by three factors: uncontrollable ambient energy harvesting, controllable wireless charging, and controllable sensory data generation. It jointly controls the charging, communication, and sensing activities while guaranteeing non-empty energy repositories at all sensor nodes. JCRA is a low-cost solution, as neighbor sensor nodes collaborate with each other to adjust their data generation rates in a distributed manner, based on the status of ambient energy supply and the wireless charging schedule planned by the base station. Extensive simulations have verified the effectiveness of JCRA in achieving the stated goals: JCRA can always guarantee network sustainability, while the achieved network utility is close to that by a centralized (1 - ϵ) approximate solution to the same optimization problem, in most simulation settings. Daji Qiao, Wensheng Zhang 0001 |
SECON | 4 |
| 2014 | Detect smart intruders in sensor networks by creating network dynamics
Jie Tian 0002, Grace Guiling Wang, Tan Yan, Wensheng Zhang 0001 |
Comput. Networks | 4 |
| 2014 | 2D k-barrier duty-cycle scheduling for intruder detection in Wireless Sensor Networks
Jie Tian 0002, Wensheng Zhang 0001, Grace Guiling Wang |
Comput. Commun. | 2 |
| 2014 | ZigBee-Assisted Power Saving Management for Mobile DevicesabstractWiFi transmission can consume much energy on energy-constrained mobile devices. To improve energy efficiency, the Power Saving Management (PSM) has been standardized and applied. The standard PSM, however, may not deliver satisfactory energy efficiency in many cases as the wakeup strategy adopted by it cannot dynamically adapt to traffic pattern changes. Motivated by the fact that it has been more and more popular for a mobile device to have both WiFi and other low-power wireless interfaces such as Bluetooth and ZigBee, we propose a ZigBee-assisted Power Saving Management (ZPSM) scheme, leveraging the ZigBee interface to wake up WiFi interface on demand to improve energy efficiency without violating delay requirements. The simulation and prototype-based experiment results have shown that ZPSM can save energy significantly without violating delay requirements in various scenarios. Hua Qin, Wensheng Zhang 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2014 | A Grid-Based On-Road Localization System in VANET with Linear Error PropagationabstractGPS navigators have been widely adopted by drivers. However, due to the sensibility of GPS signals to terrain, vehicles cannot get their locations when they are inside a tunnel or on a road surrounded by high-rises where satellite signal is blocked. This incurs safety and convenience problems. To address the issue, we propose a novel Grid-based On-road localizaTion system (GOT), where vehicles with and without accurate GPS signals self-organize into a Vehicular Ad Hoc Network (VANET), exchange location and distance information and help each other to calculate an accurate position for all the vehicles inside the network. The location information can be exchanged among vehicles one or multiple hops away in this paper. We explore fuzzy geometric relationship among vehicles, and apply a novel grid-based mechanism to evaluate the geometric relationships and calculate vehicle locations. Simulation shows our GOT system is effective and efficient in calculating vehicular positions. Tan Yan, Wensheng Zhang 0001, Grace Guiling Wang |
IEEE Trans. Wirel. Commun. | 2 |
| 2013 | Joint Aggregation and MAC design to prolong sensor network lifetimeabstractThis paper proposes JAM, a Joint Aggregation and MAC design, to improve the sensor network lifetime under the end-to-end delay constraint. The key idea is to adjust both network traffic (via data aggregation) and communication overhead (via duty-cycled MAC) in a holistic manner at each individual node as well as between neighbors. As a result, JAM extends the sensor network lifetime more efficiently and effectively than the state-of-the-art solutions while guaranteeing the desired delay bound and achieving a lower level of average nodal power consumption. JAM is a lightweight and distributed solution with limited control information exchanged between neighbors only, which makes it deployable in practical sensor networks. Extensive ns-2 simulation and TinyOS experiment results are used to demonstrate the effectiveness of JAM in prolonging the network lifetime. Daji Qiao, Wensheng Zhang 0001 |
ICNP | 4 |
| 2013 | I2C: A holistic approach to prolong the sensor network lifetimeabstractWe present a novel holistic approach (called I2C - Intra-route and Inter-route Coordination) to prolong the sensor network lifetime under the end-to-end delivery delay constraint. I2C is composed of two lifetime balancing modules: (i) the IntraRoute Coordination module that allows the nodes on the same route to balance their nodal lifetimes through adjusting the MAC behaviors collaboratively; (ii) the Inter-Route Coordination module that balances the nodal lifetimes across different routes via adjusting the communication routes. Different from existing works which conduct either intra-route or inter-route lifetime balancing, or a simple combination of the two, I2C leverages the advantages of both techniques with a sophisticated design that emphasizes the awareness and collaboration between two modules. Thus, I2C is able to prolong the network lifetime much more effectively than the state-of-the-art solutions, while guaranteeing the desired delay bound and maintaining a similar level of network power consumption. This has been demonstrated with extensive ns-2 simulation and TinyOS experiment results. Daji Qiao, Wensheng Zhang 0001 |
INFOCOM | 4 |
| 2013 | ZigBee-Assisted Power Saving for More Efficient and Sustainable Ad Hoc NetworksabstractIn emergency situations, infrastructure-based wireless access networks (e.g., WLANs, cellular networks) may collapse due to power outage or infrastructure damages. To enable responsive communication for rescue operations, wireless ad hoc networks may be set up. However, due to limited battery capacity, the networks may not sustain long enough, especially when stringent communication delay is demanded. Aimed at energy efficiency, the Power Saving Management (PSM) for IEEE 802.11 DCF has been standardized and can be applied in multi-hop ad hoc networks. With PSM, however, it is difficult to achieve high energy efficiency and low delay simultaneously when data traffic is unpredictable. Motivated by the trend that low-power ZigBee interface will be more and more commonly embedded in mobile devices together with WiFi interface in the near future, we propose a ZigBee-assisted PSM (called ZPSM) for DCF, which leverages ZigBee interfaces to wake up WiFi interfaces on demand to reduce WiFi interfaces' energy consumption and thus prolong network lifetime, while satisfying delay requirements. The results of extensive simulation and prototype-based experiments have verified the performance advantages of ZPSM. Hua Qin, Wensheng Zhang 0001 |
IEEE Trans. Wirel. Commun. | 2 |
| 2012 | LBA: Lifetime balanced data aggregation in low duty cycle sensor networksabstractThis paper proposes LBA, a lifetime balanced data aggregation scheme for asynchronous and duty cycle sensor networks under an application-specific requirement of end-to-end data delivery delay bound. In contrast to existing aggregation schemes that focus on reducing the energy consumption and extending the operational lifetime of each individual node, LBA has a unique design goal to balance the nodal lifetime and thus prolong the network lifetime more effectively. To achieve this goal in a distributed manner, LBA adaptively adjusts the aggregation holding time between neighboring nodes to balance their nodal lifetime; as such balancing take place in all neighborhoods, nodes in the entire network can gradually adjust their nodal lifetime towards the globally balanced status. Experimental studies on a sensor network testbed shows that LBA can achieve the design goal, yield longer network lifetime than other non-adaptive and nodal lifetime-unaware data aggregation schemes, and approach the theoretical upperbound performance, especially when nodes have highly different nodal lifetime. Daji Qiao, Wensheng Zhang 0001 |
INFOCOM | 4 |
| 2012 | ZigBee-assisted Power Saving Management for mobile devicesabstractWiFi transmission can consume much energy on energy-constrained mobile devices. To improve energy efficiency, the Power Saving Management (PSM) has been standardized and applied. The standard PSM, however, may not deliver satisfactory energy efficiency in many cases as the wakeup strategy adopted by it cannot adapt dynamically to traffic pattern changes. Motivated by the fact that it has been more and more popular for a mobile device to have both WiFi and other low-power wireless interfaces such as Bluetooth and ZigBee, we propose a ZigBee-assisted Power Saving Management (ZPSM) scheme, leveraging the ZigBee interface to wake up WiFi interface on demand to improve energy efficiency without violating delay requirements. The simulation results have shown that ZPSM can save energy significantly without violating delay requirements in various scenarios. Hua Qin, Wensheng Zhang 0001 |
MASS | 2 |
| 2012 | DOVE: Data dissemination to a fixed number of receivers in VANETabstractEfficient data dissemination to a fixed number of receivers in VANET is a new issue and is challenging considering the dynamic nature of VANET. We aim to accurately control the number of receivers, achieve low dissemination delay and incur only small communication overhead. To achieve the goal, we design DOVE (Data Dissemination to A Fixed Number of Receivers in VANET) inspired by processor scheduling, which treats roads as processors to optimize the workload assignment and improves the efficiency of on-road dissemination. DOVE reaches the desired number of receivers with little inaccuracy and minimizes the dissemination delay with low communication overhead. We enhance our protocol with workload backup to deal with vehicles' quitting the network. We utilize the unique characteristics of VANET and propose heuristics accordingly to significantly reduce the dissemination delay and overhead. Simulation results show that our scheme disseminates data to all the pre-given number of receivers in a very light overhead and low delay. Tan Yan, Wensheng Zhang 0001, Grace Guiling Wang |
SECON | 2 |
| 2012 | LB-MAC: A Lifetime-Balanced MAC Protocol for Sensor Networks
Wensheng Zhang 0001, Daji Qiao |
WASA | 3 |
| 2012 | Catching Packet Droppers and Modifiers in Wireless Sensor NetworksabstractPacket dropping and modification are common attacks that can be launched by an adversary to disrupt communication in wireless multihop sensor networks. Many schemes have been proposed to mitigate or tolerate such attacks, but very few can effectively and efficiently identify the intruders. To address this problem, we propose a simple yet effective scheme, which can identify misbehaving forwarders that drop or modify packets. Extensive analysis and simulations have been conducted to verify the effectiveness and efficiency of the scheme. Chuang Wang 0002, Taiming Feng, Grace Guiling Wang, Wensheng Zhang 0001 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2011 | A Light-Weight Solution to Preservation of Access Pattern Privacy in Un-trusted Clouds
Ka Yang, Jinsheng Zhang, Wensheng Zhang 0001, Daji Qiao |
ESORICS | 3 |
| 2011 | J-RoC: A Joint Routing and Charging scheme to prolong sensor network lifetimeabstractThe emerging wireless charging technology creates a controllable and perpetual energy source to provide wireless power over distance. Schemes have been proposed to make use of wireless charging to prolong the sensor network lifetime. Unfortunately, existing schemes only passively replenish sensors that are deficient in energy supply, and cannot fully leverage the strengths of this technology. To address the limitation, we propose J-RoC - a practical and efficient Joint Routing and Charging scheme. Through proactively guiding the routing activities in the network and delivering energy to where it is needed, J-RoC not only replenishes energy into the network but also effectively improves the network energy utilization, thus prolonging the network lifetime. To evaluate the performance of the J-RoC scheme, we conduct experiments in a small-scale testbed and simulations in large-scale networks. Evaluation results demonstrate that J-RoC significantly elongates the network lifetime compared to existing wireless charging based schemes. Wensheng Zhang 0001, Daji Qiao |
ICNP | 3 |
| 2011 | Delay-bounded MAC with minimal idle listening for sensor networksabstractThis paper presents a new receiver-initiated sensor network MAC protocol, called CyMAC, which has the following unique features. It reduces the idle listening time of sensor nodes via establishing rendezvous times between neighbors, provides the desired relative delay bound guarantee for data delivery services via planning the rendezvous schedules carefully, and adjusts the sensor nodes' duty cycles dynamically to the varying traffic condition. More importantly, CyMAC achieves the above goals without requiring time synchrony between sensor nodes. We have implemented and evaluated CyMAC in both TinyOS and the ns-2 simulator. Experimental and simulation results show that, comparing with RI-MAC - a state-of-the-art sensor network MAC protocol, CyMAC can always guarantee the desired delay bound for data delivery services and yields a lower duty cycle under reasonable delay requirements. Daji Qiao, Wensheng Zhang 0001 |
INFOCOM | 4 |
| 2011 | Reconciling privacy preservation and intrusion detection in sensory data aggregationabstractWhen wireless sensors are deployed to monitor the working or life conditions of people, the data collected and processed by these sensors may reveal privacy of people. The actual content of sensory data should be concealed to preserve the privacy, but the data concealment feature may be abused by compromised sensors to modify or ill-process data without being caught. Hence, reconciling privacy preservation and intrusion detection, which apparently conflict with each other, is important. This paper studies this problem in the context of sensory data aggregation, a fundamental primitive for efficient operation of sensor networks. A scheme is proposed that can detect ill-performed aggregation without knowing the actual content of sensory data, and therefore allow sensory data to be kept concealed. The results show that, the actual content of raw and aggregated sensory data can be well concealed. Meanwhile, most of ill-performed aggregations can be detected; the ill-performed aggregations that can escape from being detected have only negligible impact on the final aggregation results. Chuang Wang 0002, Grace Guiling Wang, Wensheng Zhang 0001, Taiming Feng |
INFOCOM | 3 |
| 2011 | Heterogeneity-Aware Design for Automatic Detection of Problematic Road ConditionsabstractImproving driving safety is one major objective of forming vehicular ad hoc networks (VANETs). Existing VANETs usually assume drivers detect and report safety-related road conditions. However, drivers may not be willing to perform these duties; even they are, these duties may distract them from driving and thus make driving unsafe. To address the problem, this paper proposes an automatic detection system. By taking advantage of the communication capability of roadside sensors, the proposed system can automatically detect and locate problematic road conditions without any human intervention under varying traffic densities. Extensive simulations have been conducted to verify the efficiency of the proposed system. Hua Qin, Xuejia Lu, Grace Guiling Wang, Wensheng Zhang 0001, Yaying Zhang |
MASS | 5 |
| 2011 | GOT: Grid-Based On-Road Localization through Inter-Vehicle CollaborationabstractGPS navigators have been widely adopted by drivers. However, due to the sensibility of GPS signals to terrain, vehicles cannot get their locations when they are inside a tunnel or on a road surrounded by high-rises where the satellite signal is blocked. This incurs the safety and convenience problems. To address the issue, we propose a novel Grid-based On-road localizaTion system (GOT), where vehicles with or without accurate GPS signals self-organize into a vehicular ad hoc network (VANET), exchange location and distance information and help each other to calculate an accurate position for all the vehicles inside the network. GOT uniquely evaluates some fuzzy geometric relationship among vehicles and employs a grid-based approach to calculate vehicle's locations, by which GOT solves the issues of lack of beacon nodes and error propagation that are the two major challenges in on-road localization. Simulation shows our GOT system is very effective and efficient in calculating the vehicular positions. Tan Yan, Wensheng Zhang 0001, Grace Guiling Wang, Yujun Zhang 0001 |
MASS | 2 |
| 2011 | ZigBee-Assisted WiFi Transmission for Multi-interface Mobile Devices
Hua Qin, Wensheng Zhang 0001 |
MobiQuitous | 3 |
| 2011 | Optimizing sensor movement planning for energy efficiencyabstractConserving the energy for motion is an important yet not-well-addressed problem in mobile sensor networks. In this article, we study the problem of optimizing sensor movement for energy efficiency. We adopt a complete energy model to characterize the entire energy consumption in movement. Based on the model, we propose an optimal trapezoidal velocity schedule for minimizing energy consumption when the road condition is uniform; and a corresponding velocity schedule for the variable road condition by using continuous-state dynamic programming. Considering the variety in motion hardware, we also design one velocity schedule for simple microcontrollers, and one velocity schedule for relatively complex microcontrollers, respectively. Simulation results show that our velocity planning may have significant impact on energy conservation. Grace Guiling Wang, Mary Jane Irwin, Haoying Fu, Piotr Berman, Wensheng Zhang 0001, Thomas La Porta |
ACM Trans. Sens. Networks | 5 |
| 2011 | Node Reclamation and Replacement for Long-Lived Sensor NetworksabstractWhen deployed for long-term tasks, the energy required to support sensor nodes' activities is far more than the energy that can be preloaded in their batteries. No matter how the battery energy is conserved, once the energy is used up, the network life terminates. Therefore, guaranteeing long-term energy supply has persisted as a big challenge. To address this problem, we propose a node reclamation and replacement (NRR) strategy, with which a mobile robot or human labor called mobile repairman (MR) periodically traverses the sensor network, reclaims nodes with low or no power supply, replaces them with fully charged ones, and brings the reclaimed nodes back to an energy station for recharging. To effectively and efficiently realize the strategy, we develop an adaptive rendezvous-based two-tier scheduling scheme (ARTS) to schedule the replacement/reclamation activities of the MR and the duty cycles of nodes. Extensive simulations have been conducted to verify the effectiveness and efficiency of the ARTS scheme. Bin Tong, Grace Guiling Wang, Wensheng Zhang 0001, Chuang Wang 0002 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2010 | How Wireless Power Charging Technology Affects Sensor Network Deployment and RoutingabstractAs wireless power charging technology emerges, some basic principles in sensor network design are changed accordingly. Existing sensor node deployment and data routing strategies cannot exploit wireless charging technology to minimize overall energy consumption. Hence, in this paper, we (a) investigate the impact of wireless charging technology on sensor network deployment and routing arrangement, (b) formalize the deployment and routing problem, (c) prove it as NP-complete, (d) develop heuristic algorithms to solve the problem, and (e) evaluate the performance of the solutions through extensive simulations. To the best of our knowledge, this is the first effort on adapting sensor network design to leverage wireless charging technology. Bin Tong, Grace Guiling Wang, Wensheng Zhang 0001 |
ICDCS | 4 |
| 2010 | Towards Reliable Scheduling Schemes for Long-lived Replaceable Sensor NetworksabstractTo address energy constraint problem in sensor networks, node reclamation and replacement strategy has been proposed for networks accessible to human beings and robots. The major challenge in realizing the strategy is how to minimize the system maintenance cost, especially the frequency in replacing sensor nodes with limited number of backup nodes. New duty cycle scheduling schemes are required in order to address the challenge. Tong et al. have proposed a staircase-based scheme to address the problem based on ideal assumptions of sensor nodes that are free of failure and have regular energy consumption rate. Since sensor nodes are often deployed in outdoor unattended environment, node failures are inevitable. Energy consumption rates of sensor nodes are irregular due to manufacture or environmental reasons. Hence, this paper proposes several new schemes to achieve reliable scheduling for node reclamation and replacement. Extensive simulations have been conducted to verify that the proposed scheme is effective and efficient. Bin Tong, Grace Guiling Wang, Wensheng Zhang 0001 |
INFOCOM | 4 |
| 2010 | An integrated network of roadside sensors and vehicles for driving safety: Concept, design and experimentsabstractOne major goal of the vehicular ad hoc network (VANET) is to improve driving safety. However, the VANET may not guarantee timely detection of dangerous road conditions or maintain communication connectivity when the network density is low (e.g., in rural highways), which may pose as a big threat to driving safety. Towards addressing the problem, we propose to integrate the VANET with the inexpensive wireless sensor network (WSN). That is, sensor nodes are deployed along the roadside to sense road conditions, and to buffer and deliver information about dangerous conditions to vehicles regardless of the density or connectivity of the VANET. Along with the concept of VANET-WSN integration, new challenges arise and should be addressed. In this paper, we investigate these challenges and propose schemes for effective and efficient vehicle-sensor and sensor-sensor interactions. Prototype of the designed system has been implemented and tested in the field. Extensive simulations have also been conducted to evaluate the designed schemes. The results demonstrate various design tradeoffs, and indicate that satisfactory safety and energy efficiency can be achieved simultaneously when system parameters are appropriately chosen. Hua Qin, Xuejia Lu, Wensheng Zhang 0001, Grace Guiling Wang |
PerCom | 5 |
| 2010 | Prolonging Sensor Network Lifetime Through Wireless ChargingabstractThe emerging wireless charging technology is a promising alternative to address the power constraint problem in sensor networks. Comparing to existing approaches, this technology can replenish energy in a more controllable manner and does not require accurate location of or physical alignment to sensor nodes. However, little work has been reported on designing and implementing a wireless charging system for sensor networks. In this paper, we design such a system, build a proof-of-concept prototype, conduct experiments on the prototype to evaluate its feasibility and performance in small-scale networks, and conduct extensive simulations to study its performance in large-scale networks. Experimental and simulation results demonstrate that the proposed system can utilize the wireless charging technology effectively to prolong the network lifetime through delivering energy by a robot to where it is needed. The effects of various configuration and design parameters have also been studied, which may serve as useful guidelines in actual deployment of the proposed system in practice. Wensheng Zhang 0001, Daji Qiao |
RTSS | 3 |
| 2010 | Study of Joint Routing and Wireless Charging Strategies in Sensor Networks
Wensheng Zhang 0001, Daji Qiao |
WASA | 3 |
| 2010 | A three-tier framework for intruder information sharing in sensor networks
Bin Tong, Santosh Panchapakesan, Wensheng Zhang 0001 |
Ad Hoc Networks | 3 |
| 2010 | Coverage properties of clustered wireless sensor networksabstractThis article studies clustered wireless sensor networks (WSNs), a realistic topology resulting from common deployment methods. We study coverage in naturally clustered networks of wireless sensor nodes, as opposed to WSNs where clustering is facilitated by selection. We show that along with increasing the vacancy in random placement of nodes in a WSN, it also alters the connectivity properties in the network. We analyze varying levels of redundancy to determine the probability of coverage in the network. The phenomenon of clustering in networks of wireless sensor nodes raises interesting questions for future research and development. The article provides a foundation for the design to optimize network performance with the constraint of sensing coverage. Renita Machado, Wensheng Zhang 0001, Grace Guiling Wang, Sirin Tekinay |
ACM Trans. Sens. Networks | 2 |
| 2009 | A Power-Efficient Scheme for Securing Multicast in Hierarchical Sensor NetworksabstractHierarchical architectures are more and more widely adopted for organizing wireless sensor networks. In such architectures, middle-tier nodes take important roles, and preventing a malicious node from impersonating a middle-tier node and injecting falsified messages becomes critical. In this paper, we propose an energy efficient, distributed scheme to secure the multicast messages from the middle-tier nodes. Our scheme does not require a priori knowledge about the hierarchical relation between middle-tier nodes and lowest-tier nodes, and is adaptive to changes of this relation. Extensive simulations are conducted to evaluate our scheme, and the results show that the scheme is energy efficient. Jie Tian 0002, Grace Guiling Wang, Tan Yan, Wensheng Zhang 0001 |
ICCCN | 4 |
| 2009 | Network Planning for Heterogeneous Wireless Sensor Networks in Environmental SurvivabilityabstractTo deal with the problem of hostile environments, we proposed to construct heterogeneous sensor networks composed of both regular nodes and robust nodes, where robust nodes are better equipped for hostile environments and hence are more expensive than regular nodes. We study the problem of network design in heterogeneous wireless sensor networks that involves optimization of network costs associated with different classes of nodes versus maximizing coverage and network lifetime. We consider the design of heterogeneous networks with the objectives of minimizing costs and maximizing network lifetime. The association we present in heterogeneous sensor network design between optimizing the number of nodes in each class with cost constraints and network lifetime for corresponding network composition maybe of independent interest in the design of networks in general. Renita Machado, Wensheng Zhang 0001, Grace Guiling Wang |
ICTAI | 2 |
| 2009 | ElliPS: A Privacy Preserving Scheme for Sensor Data Storage and QueryabstractWith in-network sensor data storage and query, storage nodes are responsible for storing the data collected by sensor nodes and answering queries from users. Thus, without proper protection for data types and user queries, compromise of storage nodes and/or sensor nodes may reveal sensitive information about the sensed environment as well as users' private interests and query patterns. In this paper, we explore trade-offs between privacy, computation overhead, communication overhead, network flexibility and network complexity, and propose ElliPS (Elliptic curve based Privacy Scheme) to provide joint protection on data type privacy and query privacy in the presence of sensor node compromise, storage node compromise, or under collusive attacks by compromised sensor nodes and storage nodes together. Extensive analysis and simulation are conducted to verify the security properties and efficiency of the proposed scheme. Nalin Subramanian, Ka Yang, Wensheng Zhang 0001, Daji Qiao |
INFOCOM | 3 |
| 2009 | EagleVision: A pervasive mobile device protection systemabstractMobile devices like laptops, iPhones and PDAs are highly susceptible to theft in public places like airport terminal, library and cafe. Moreover, the exposure of sensitive data stored in the mobile device could be more damaging than the loss of device itself. In this work, we propose and implement a Ka Yang, Nalin Subramanian, Daji Qiao, Wensheng Zhang 0001 |
MobiQuitous | 4 |
| 2009 | Node Reclamation and Replacement for Long-lived Sensor NetworksabstractWhen deployed for long-term tasks, the energy required to support sensor nodes' activities is far more than the energy that can be preloaded in their batteries. No matter how the battery energy is conserved, once the energy is used up, the network life terminates. Therefore, guaranteeing long- term energy supply has persisted as a big challenge. To address this problem, we propose a node replacement and reclamation (NRR) strategy, with which a mobile robot or human labor called mobile repairman (MR) periodically traverses the sensor network, reclaims nodes with low or no power supply, replaces them with fully-charged ones, and brings the reclaimed nodes back to an energy station for recharging. To effectively and efficiently realize the strategy, we develop an adaptive rendezvous- based two-tier scheduling (ARTS) scheme to schedule the replacement/reclamation activities of the MR and the duty cycles of nodes. Extensive simulations have been conducted to verify the effectiveness and efficiency of the ARTS scheme. Bin Tong, Grace Guiling Wang, Wensheng Zhang 0001, Chuang Wang 0002 |
SECON | 3 |
| 2009 | Catching Packet Droppers and Modifiers in Wireless Sensor NetworksabstractPacket dropping and modification are common attacks that can be launched by an adversary to disrupt communication in wireless multi-hop sensor networks. Many schemes have been proposed to mitigate the attacks but none can effectively and efficiently identify the intruders. To address the problem, we propose a simple yet effective scheme, which can identify misbehaving forwarders that drop or modify packets. Extensive analysis and simulations using ns2 simulator have been conducted and verified the effectiveness and efficiency of the scheme. Chuang Wang 0002, Taiming Feng, Grace Guiling Wang, Wensheng Zhang 0001 |
SECON | 5 |
| 2009 | Predistribution and local collaboration-based group rekeying for wireless sensor networks
Wensheng Zhang 0001, Sencun Zhu, Guohong Cao |
Ad Hoc Networks | 1 |
| 2009 | Editorial for special issue on privacy and security in wireless sensorand ad hoc networks
Wensheng Zhang 0001, Sencun Zhu, Guohong Cao |
Ad Hoc Networks | 1 |
| 2009 | pDCS: Security and Privacy Support for Data-Centric Sensor NetworksabstractThe demand for efficient data dissemination/access techniques to find relevant data from within a sensor network has led to the development of data-centric sensor (DCS) networks, where the sensor data instead of sensor nodes are named based on attributes such as event type or geographic location. However, saving data inside a network also creates security problems due to the lack of tamper resistance of the sensor nodes and the unattended nature of the sensor network. For example, an attacker may simply locate and compromise the node storing the event of his interest. To address these security problems, we present pDCS, a privacy-enhanced DCS network which offers different levels of data privacy based on different cryptographic keys. pDCS also includes an efficient key management scheme to facilitate the management of multiple types of keys used in the system. In addition, we propose several query optimization techniques based on Euclidean Steiner tree and keyed bloom filter (KBF) to minimize the query overhead while preserving query privacy. Finally, detailed analysis and simulations show that the KBF scheme can significantly reduce the message overhead with the same level of query delay and maintain a very high level of query privacy. Sencun Zhu, Wensheng Zhang 0001, Guohong Cao, Yi Yang 0002 |
IEEE Trans. Mob. Comput. | 3 |
| 2008 | Intelligent p-Cycle Protection for Multicast Sessions in WDM NetworksabstractIn WDM networks, it is important to maintain the survivability of communication sessions when link failure occurs due to the high bandwidth provided by a fiber link. Especially, link failures have more serious impact on multicast sessions than on unicast ones, making it more critical to protect multicast sessions. For this sake, researchers have proposed tree-based, path-based, and segment-based protection schemes, which however require long restoration time. In this paper, we propose a new solution based on p-cycles to address the problem. Specifically, we identify and address the challenges in applying p-cycles for multicast protection, and develop an intelligent p-cycle (IpC) scheme that forms p-cycles on-demand to protect dynamic multicast requests. Extensive simulations have been conducted to evaluate our IpC scheme, and the results show that it outperforms existing solutions. Taiming Feng, Lu Ruan 0001, Wensheng Zhang 0001 |
ICC | 3 |
| 2008 | Confidentiality Protection for Distributed Sensor Data AggregationabstractEfficiency and security are two basic requirements for sensor network design. However, these requirements could be sharply contrary to each other in some scenarios. For example, in- network data aggregation can significantly reduce communication overhead and thus has been adopted widely as a means to improve network efficiency; however, the adoption of in-network data aggregation may prevent data from being encrypted since it is a prerequisite for aggregation that data be accessible during forwarding. We address this dilemma by proposing a family of secret perturbation-based schemes that can protect sensor data confidentiality without disrupting additive data aggregation. Extensive simulations are also conducted to evaluate the proposed schemes. The results show that our schemes provide confidentiality protection for both raw and aggregated data items with an overhead lower than that of existing related schemes. Taiming Feng, Chuang Wang 0002, Wensheng Zhang 0001, Lu Ruan 0001 |
INFOCOM | 3 |
| 2008 | Sensor-Aided Overlay Deployment and Relocation for Vast-Scale Sensor NetworksabstractThe overlay-based network architecture has been recognized as an effective way to deal with the funneling effect in sensor networks, where sensors closer to the sink are usually responsible for relaying more network traffic. Such funneling effect is particularly harmful when the number of sensors in the network is vast. In an overlay-based sensor network, a special type of resource-rich multi-radio mobile wireless devices (we call them syphons) are deployed along with sensors. Syphons form an overlay network and help nearby sensors relay their data to the sink via the overlay network, thus mitigating the funneling effect. In this paper, we study one of the fundamental challenges in overlay-based sensor networks: syphon deployment problem, i.e., how to deploy a limited number of syphons to cover a vast sensing field while maintaining the connectivity and balanced loads among them. We propose a novel sensor-aided overlay deployment and relocation (SODaR) protocolas a possible solution. The key idea is to take advantage of sensors' assistance and to relocate syphons by circling them around the sink in an orderly manner until all syphons are connected. Simulation results show that, with SODaR, syphons are able to self-form and self-maintain a connected tree structure which provides excellent load balancing among syphons with modest message and movement overhead. Guanqun Yang, Bin Tong, Daji Qiao, Wensheng Zhang 0001 |
INFOCOM | 4 |
| 2008 | Lightweight and Compromise-Resilient Message Authentication in Sensor NetworksabstractNumerous authentication schemes have been proposed in the past for protecting communication authenticity and integrity in wireless sensor networks. Most of them however have following limitations: high computation or communication overhead, no resilience to a large number of node compromises, delayed authentication, lack of scalability, etc. To address these issues, we propose in this paper a novel message authentication approach which adopts a perturbed polynomial-based technique to simultaneously accomplish the goals of lightweight, resilience to a large number of node compromises, immediate authentication, scalability, and non-repudiation. Extensive analysis and experiments have also been conducted to evaluate the scheme in terms of security properties and system overhead. Wensheng Zhang 0001, Nalin Subramanian, Grace Guiling Wang |
INFOCOM | 1 |
| 2008 | GP^2S: Generic Privacy-Preservation Solutions for Approximate Aggregation of Sensor Data (concise contribution)abstractProtecting privacy in sensor networks poses new challenges because of the potential incompatibilities between new privacy-preserving mechanisms and mechanisms already implemented in sensor networks (such as in-network data aggregation). To address this problem, we propose in this paper a set of new privacy-preservation data aggregation schemes. Different from past research, our solutions have the following features: supporting data aggregation for a variety of queries; providing privacy protection for both individual data and aggregate data; being resilient to any number of node collusion; being highly efficient. Wensheng Zhang 0001, Chuang Wang 0002, Taiming Feng |
PerCom | 1 |
| 2008 | A Three-Tier Framework for Intruder Information Sharing in Sensor NetworksabstractIn sensor networks, an intruder (i.e., compromised node) identified and isolated in one place can be relocated and/or duplicated to other places to continue attacks; hence, detection and isolation of the same intruder or its clones may have to be conducted repeatedly, wasting scarce network resources. Therefore, once an intruder is identified, it should be known to all innocent nodes such that the intruder or its clones can be recognized when appearing elsewhere. However, secure, efficient and scalable sharing of intruder information remains a challenging and unsolved problem. To address this problem, we propose a three-tier framework, consisting of a verifiable intruder reporting (VIR) scheme, a quorum based caching (QBC) scheme for efficiently propagating intruder reports to the whole network, and a collaborative bloom filter (CBF) scheme for handling intruder information locally. Extensive analysis and evaluations are also conducted to verify the efficiency and scalability of the proposed framework. Bin Tong, Santosh Panchapakesan, Wensheng Zhang 0001 |
SECON | 3 |
| 2008 | A heterogeneity-aware framework for group key management in wireless mesh networksabstractIn this work we proposed a novel heterogeneity-aware group key management framework (HAGK) for wireless mesh networks (WMNs). In our framework a WMN multicast session involves both stationary backbone nodes and mobile client nodes: for backbone nodes which are topologically-stable but may spread over a large area, the distributed thresholdbased group key management technique is applied; for client nodes associated with each backbone node which are mobile but confined in a limited area, the logical key hierarchical technique is applied. The results showed that HAGK reduces rekeying delay and storage overhead at end nodes with minimum communication costs. In addition, the framework is resilient to attacks. Categories and Subject Descriptors Johnny S. Wong, Wensheng Zhang 0001 |
SecureComm | 3 |
| 2008 | Slede: a domain-specific verification framework for sensor network security protocol implementationsabstractFinding flaws in security protocol implementations is hard. Finding flaws in the implementations of sensor network security protocols is even harder because they are designed to protect against more system failures compared to traditional protocols. Formal verification techniques such as model checking, theorem proving, etc, have been very successful in the past in detecting faults in security protocol specifications; however, they generally require that a formal description of the protocol, often called model, is developed before the verification can start. Youssef Hanna, Hridesh Rajan, Wensheng Zhang 0001 |
WISEC | 3 |
| 2008 | Defending against cache consistency attacks in wireless ad hoc networks
Wensheng Zhang 0001, Guohong Cao |
Ad Hoc Networks | 1 |
| 2008 | Least privilege and privilege deprivation: Toward tolerating mobile sink compromises in wireless sensor networksabstractMobile sinks are needed in many sensor network applications for efficient data collection, data querying, localized sensor reprogramming, identifying, and revoking compromised sensors, and other network maintenance. Employing mobile sinks however raises a new security challenge: if a mobile sink is given too many privileges, it will become very attractive for attack and compromise. Using a compromised mobile sink, an adversary may easily bring down or even take over the sensor network. Thus, security mechanisms that can tolerate mobile sink compromises are essential. In this article, based on the principle of least privilege , we first propose an efficient scheme to restrict the privilege of a mobile sink without impeding its ability to carry out any authorized operations for an assigned task. In addition, we present an extension to allow conditional trajectory change due to unexpected events. To further reduce the possible damage caused by a compromised mobile sink, we propose efficient message forwarding schemes for deleting the privilege assigned to a compromised mobile sink immediately after its compromise has been detected. Through detailed analysis, simulation, and real implementation, we show that our schemes are secure and efficient, and are highly practical for sensor networks consisting of the current generation of sensors. Sencun Zhu, Wensheng Zhang 0001, Guohong Cao |
ACM Trans. Sens. Networks | 3 |
| 2007 | pDCS: Security and Privacy Support for Data-Centric Sensor NetworksabstractThe demand for efficient data dissemination/access techniques to find the relevant data from within a sensor network has led to the development of data-centric sensor networks (DCS), where the sensor data as contrast to sensor nodes are named based on attributes such as event type or geographic location. However, saving data inside a network also creates security problems due to the lack of tamper-resistance of the sensor nodes and the unattended nature of the sensor network. For example, an attacker may simply locate and compromise the node storing the event of his interest. To address these security problems, we present pDCS, a privacy-enhanced DCS network which offers different levels of data privacy based on different cryptographic keys. In addition, we propose several query optimization techniques based on Euclidean Steiner Tree and Keyed Bloom Filter to minimize the query overhead while providing certain query privacy. Finally, detailed analysis and simulations show that the Keyed Bloom Filter scheme can significantly reduce the message overhead with the same level of query delay and maintain a very high level of query privacy. Sencun Zhu, Wensheng Zhang 0001, Guohong Cao |
INFOCOM | 3 |
| 2007 | A random perturbation-based scheme for pairwise key establishment in sensor networksabstractA prerequisite for secure communications between two sensor nodes is that these nodes exclusively share a pairwise key. Although numerous pairwise key establishment (PKE) schemes have been proposed in recent years, most of them have no guarantee for direct key establishment, no resilience to a large number of node compromises, no resilience to dynamic network topology, or high overhead. To address these limitations, we propose a novel random perturbation-based (RPB) scheme in this paper. The scheme guarantees that any two nodes can directly establish a pairwise key without exposing any secret to other nodes. Even after a large number of nodes have been compromised, the pairwise keys shared by non-compromised nodes remain highly secure. Moreover, the scheme adapts to changes in network topology and incurs low computation and communication overhead. To the best of our knowledge, the RPB scheme is the only one that provides all these salient features without relying on public key cryptography. Through prototype-based evaluation, we show that the RPB scheme is highly efficient and practical for current generation of sensor nodes. In particular, to support a sensor network with up to 216 nodes, establishing a pairwise key of 80 bits between any two 8-bit, 7.37-MHz MICA2 motes only requires about 0.13 second of CPU time, 0.33 KB RAM space, and 15 KB ROM space per node. Wensheng Zhang 0001, Sencun Zhu, Guohong Cao |
MobiHoc | 1 |
| 2007 | Securing Distributed Data Storage and Retrieval in Sensor NetworksabstractSensor networks have been an attractive platform for pervasive computing and communication. Due to the lack of physical protection, however, sensor networks are vulnerable to attacks if deployed in hostile environments. When a sensor network is under attack, the most fundamental concern is that information communicated or stored in the network remains safe. The past research has focused on securing information in communication, but how to secure information in storage has been generally overlooked. Meanwhile, distributed data storage and retrieval have become popular for efficient data management in sensor networks, which renders the absence of schemes for securing stored information to be a more severe problem. Hence, we propose in this paper three schemes to deal with the problem. All the schemes have the following properties: (i) only authorized entities can access data stored in the sensor network; (ii) the schemes are resilient to a large number of sensor node compromises. The second and the third schemes do not involve any centralized entity except for a few initialization or renewal operations, and thus support secure, distributed data storage and retrieval. The third scheme further provides high scalability and flexibility, and hence is most suitable in real applications. The effectiveness and efficiency of the proposed schemes have also been verified through extensive analysis and TOSSIM-based simulations Nalin Subramanian, Chanjun Yang, Wensheng Zhang 0001 |
PerCom | 3 |
| 2007 | Protecting storage location privacy in sensor networksabstractNumerous schemes have been proposed to facilitate data collection and provision in sensor networks, among which the Data-Centric Storage (DCS) scheme is an energy-efficient solution and a popular choice for many sensor network applications. However, since each sensor node in the DCS system knows the locations of all storage nodes, the DCS system is extremely vulnerable to security attacks as a single compromised sensor node will expose all the storage locations to the adversary. To address this problem, we propose a randomized storage concealment scheme along with a supplementary storage migration scheme. In the randomized storage concealment scheme, sensor nodes cooperate to forward data towards the storage nodes without keeping explicit storage locations; instead, each sensor node only maintains the IDs of its randomly-picked next-hop nodes towards the storage nodes. This scheme increases the difficulty significantly for the adversary to derive the storage locations. Nevertheless, the protection provided by this scheme degrades gradually as more and more sensor nodes are compromised. Hence, we further introduce a storage migration scheme to supplement the randomized storage concealment scheme, which directs the storage duties to migrate periodically among sensor nodes. Extensive analysis and simulations are conducted to show that the proposed schemes can effectively protect the storage location privacy with modestly added overhead. Wensheng Zhang 0001, Daji Qiao |
QSHINE | 2 |
| 2007 | Securing distributed data storage and retrieval in sensor networks
Nalin Subramanian, Chanjun Yang, Wensheng Zhang 0001 |
Pervasive Mob. Comput. | 3 |
| 2007 | Data Dissemination with Ring-Based Index for Wireless Sensor NetworksabstractIn wireless sensor networks, sensor nodes are capable of not only measuring real world phenomena, but also storing, processing, and transferring these measurements. Many techniques have been proposed for disseminating sensing data. However, most of them are not efficient in the scenarios where a huge amount of sensing data are generated, but only a small portion of them are queried. In this paper, we first propose an index-based data dissemination scheme to address the problem. With this scheme, sensing data are collected, processed, and stored at the nodes close to the detecting nodes, and the location information of these storing nodes is pushed to some index nodes, which act as the rendezvous points for sinks and sources. To address the issues of fault tolerance and load balance, we extend the scheme with an adaptive ring-based index (ARI) technique in which the index nodes for one event type form a ring surrounding the location which is determined by the event type, and the ring can be dynamically reconfigured. Considering that frequently updating or querying index nodes may cause high overhead, we also propose a lazy index updating (LIU) mechanism and a lazy index querying (LIQ) mechanism to reduce the overhead. Analysis and simulations are conducted to evaluate the performance of the proposed scheme. The results show that the proposed scheme outperforms the external storage-based scheme, the DCS scheme, and the local storage-based schemes with flood-response style. The results also show that using ARI can tolerate clustering failures and achieve load balance and using LIU (LIQ) can further improve the system performance. is pushed to some index nodes, Wensheng Zhang 0001, Guohong Cao, Thomas La Porta |
IEEE Trans. Mob. Comput. | 1 |
| 2007 | Dynamic proxy tree-based data dissemination schemes for wireless sensor networks
Wensheng Zhang 0001, Guohong Cao, Thomas La Porta |
Wirel. Networks | 1 |
| 2006 | A 3D Integral Data Model for Subsurface Entities Based on Extended GTPabstract3D integral modeling of geology-excavation entities is an important issue of 3D GIS. Based on the past research results of Generalized Tri-Prism (GTP), its modeling object, constituent primitives and topological description mode are extended and amended. According to the extended-GTP model, 8 kinds of geometric primitives and 6 kinds of geological primitives are abstracted from geology-excavation entities, and 3D integral model of geology-excavation entities is put forward. Considering the characteristics of borehole data and GTP modeling process, the 3D constructing inference rule of geological model, which can solve referencing and automatic modeling problem of complex geological entities like bifurcation, pinch-out and fault, is detailed studied. In order to ensure the uniqueness, liability and local operation of converting from GTP into tetrahedron, the Smallest Vertex Identifier (SVID) method is proposed. An experimental system of 3D integral modeling of geology-excavation entities is developed and practically applied in Central Business District (CBD) in Beijing. Xuexi Chen, Junhai Gao, Wensheng Zhang 0001, Changao Shi |
IGARSS | 5 |
| 2006 | SAP: seamless authentication protocol for vertical handoff in heterogeneous wireless networksabstract802.11 standards support high data rates for a low price and thus provides an economical way for WLANs. On the other hand, 3G standards offer a much wider area of coverage that enables ubiquitous connectivity. The integration of them takes advantages from both sides and offers the possibility of achieving anywhere, anytime cost-efficient Internet access. To facilitate such integration, seamless vertical handoff is one of the major challenges because it needs to make physical movement transparent to mobile users and preserves application-level connectivity. Previous works did not consider the impact of authentication mechanisms on the performance of vertical handoff, especially on its delay. In a 3G-WLAN integration environment, since 3G and WLAN may use different authentication servers, when a mobile terminal hands over across them, certain authentication procedure needs to be performed. According to the literature, such authentication delay may be as high as hundreds of milliseconds, which is intolerable for delay-sensitive applications. We present seamless authentication protocols (SAPs) for vertical handoff in wireless heterogeneous networks, to reduce this delay. Simulation results show that SAP significantly reduces the delay caused by authentication procedures in vertical handoff. Scott C.-H. Huang, Hao Zhu 0007, Wensheng Zhang 0001 |
QSHINE | 3 |
| 2005 | Sensor relocation in mobile sensor networksabstractRecently there has been a great deal of research on using mobility in sensor networks to assist in the initial deployment of nodes. Mobile sensors are useful in this environment because they can move to locations that meet sensing coverage requirements. This paper explores the motion capability to relocate sensors to deal with sensor failure or respond to new events. We define the problem of sensor relocation and propose a two-phase sensor relocation solution: redundant sensors are first identified and then relocated to the target location. We propose a Grid-Quorum solution to quickly locate the closest redundant sensor with low message complexity, and propose to use cascaded movement to relocate the redundant sensor in a timely, efficient and balanced way. Simulation results verify that the proposed solution outperforms others in terms of relocation time, total energy consumption, and minimum remaining energy. Grace Guiling Wang, Guohong Cao, Thomas La Porta, Wensheng Zhang 0001 |
INFOCOM | 4 |
| 2005 | Group rekeying for filtering false data in sensor networks: a predistribution and local collaboration-based approachabstractWhen a sensor network is deployed in hostile environments, the adversary may compromise some sensor nodes, and use the compromised nodes to inject false sensing reports or modify the reports sent by other nodes. In order to defend against the attacks with low cost, researchers have proposed symmetric group key-based en-route filtering schemes, such as SEF [F. Ye et al., March 2004] and I-LHAP [S. Zhu et al., 2004]. However, if the adversary has compromised a large number of nodes, many group keys can be captured, and the filtering schemes may become ineffective or even useless. To deal with node compromise, the compromised nodes should be identified and the innocent nodes should update their group keys. Some existing intruder identification schemes can be used to identify the compromised nodes, but most existing group rekeying schemes are not suitable for sensor networks since they have large overhead and are not scalable. To address the problem, we propose a family of predistribution and local collaboration-based group rekeying (PCGR) schemes. These schemes are designed based on the ideas that future group keys can be preloaded to the sensor nodes before deployment, and neighbors can collaborate to protect and appropriately use the preloaded keys. Extensive analyses and simulations are conducted to evaluate the proposed schemes, and the results show that the proposed schemes can achieve a good level of security, outperform most previous group rekeying schemes, and significantly improve the effectiveness of filtering false data. Wensheng Zhang 0001, Guohong Cao |
INFOCOM | 1 |
| 2005 | Least privilege and privilege deprivation: towards tolerating mobile sink compromises in wireless sensor networksabstractMobile sinks are needed in many sensor network applications for efficient data collection, data querying, localized sensor reprogramming, identifying and revoking compromised sensors, and other network maintenance. Employing mobile sinks however raises a new security challenge: if a mobile sink is given too many privileges, it will become very attractive for attack and compromise. Using a compromised mobile sink, an adversary may easily bring down or even take over the sensor network. Thus, security mechanisms that can tolerate mobile sink compromises are essential. In this paper, based on the principle of least privilege, we first propose several efficient schemes to restrict the privilege of a mobile sink without impeding its capability of carrying out any authorized operations for an assigned task. To further reduce the possible damages caused by a compromised mobile sink, we then propose efficient message forwarding schemes for depriving the privilege assigned to a compromised mobile sink immediately after its compromise has been detected. Through detailed analysis and simulations, we show that our schemes are secure and efficient, and are highly practical for sensor networks consisting of the current generation of sensors. Wensheng Zhang 0001, Sencun Zhu, Guohong Cao |
MobiHoc | 1 |
| 2005 | Defend Against Cache Consistency Attacks in Wireless Ad Hoc NetworksabstractCaching techniques can be used to reduce bandwidth consumption and data access delay in wireless ad hoc networks. When cache is used, cache consistency issues must be addressed. To maintain strong cache consistency in some strategic scenarios (e.g., battle fields), the invalidation-based approach is preferred due to its low overhead. However, this approach may suffer from some security attacks. For example, a malicious node (intruder) may drop, insert or modify invalidation messages to mislead the receivers to use stale data or unnecessarily invalidate the data that is still valid. In this paper, we propose a solution based on the IR-based cache invalidation strategy to prevent intruders from dropping or modifying the invalidation messages. Although digital signatures can be used to protect IRs, it has significantly high overhead in terms of computation and bandwidth consumption. To address this problem, we propose a family of randomized grouping based schemes for intrusion detection and damage recovery. Extensive analysis and simulations are used to evaluate the proposed schemes. The results show that our solution can achieve a good level of security with low overhead. Wensheng Zhang 0001, Guohong Cao |
MobiQuitous | 1 |
| 2004 | Optimizing Tree Reconfiguration for Mobile Target Tracking in Sensor NetworksabstractSensor nodes have limited sensing range and are not very reliable. To obtain accurate sensing data, many sensor nodes should he deployed and then the collaboration among them becomes an important issue. In W. Zhang and G. Cao, a tree-based approach has been proposed to facilitate sensor nodes collaborating in detecting and tracking a mobile target. As the target moves, many nodes in the tree may become faraway from the root of the tree, and hence a large amount of energy may be wasted for them to send their sensing data to the root. We address the tree reconfiguration problem. We formalize it as finding a min-cost convoy tree sequence, and solve it by proposing an optimized complete reconfiguration scheme and an optimized interception-based reconfiguration scheme. Analysis and simulation are conducted to compare the proposed schemes with each other and with other reconfiguration schemes. The results show that the proposed schemes are more energy efficient than others. Wensheng Zhang 0001, Guohong Cao |
INFOCOM | 1 |
| 2004 | Dynamic proxy tree-based data dissemination schemes for wireless sensor networksabstractIn wireless sensor networks, efficiently disseminating data from a dynamic source to multiple mobile sinks is important for applications such as mobile target detection and tracking. A tree-based multicasting scheme can be used. However, due to the short communication range of each sensor node and the frequent movement of sources and sinks, a sink may fail to receive data due to broken paths, and the tree should frequently be reconfigured to reconnect sources and sinks. To address the problem, we propose a dynamic proxy tree-based framework. A big challenge in implementing the framework is how to reconfigure the proxy tree efficiently as sources and sinks change. We model the problem as on-line construction of a minimum Steiner tree in a Euclidean plane, and propose centralized schemes to solve it. Considering the strict energy constraints in wireless sensor networks, we further propose two distributed on-line schemes, a shortest path-based (SP) scheme and a spanning range-based (SR) scheme. Extensive simulations are conducted to evaluate the schemes. The results show that the distributed schemes have similar performance to the centralized ones, and among the distributed schemes, SR outperforms SP. Wensheng Zhang 0001, Guohong Cao, Thomas La Porta |
MASS | 1 |
| 2004 | DCTC: dynamic convoy tree-based collaboration for target tracking in sensor networksabstractMost existing work on sensor networks concentrates on finding efficient ways to forward data from the information source to the data centers, and not much work has been done on collecting local data and generating the data report. This paper studies this issue by proposing techniques to detect and track a mobile target. We introduce the concept of dynamic convoy tree-based collaboration, and formalize it as a multiple objective optimization problem which needs to find a convoy tree sequence with high tree coverage and low energy consumption. We propose an optimal solution which achieves 100% coverage and minimizes the energy consumption under certain ideal situations. Considering the real constraints of a sensor network, we propose several practical implementations: the conservative scheme and the prediction-based scheme for tree expansion and pruning; the sequential and the localized reconfiguration schemes for tree reconfiguration. Extensive experiments are conducted to compare the practical implementations and the optimal solution. The results show that the prediction-based scheme outperforms the conservative scheme and it can achieve similar coverage and energy consumption to the optimal solution. The experiments also show that the localized reconfiguration scheme outperforms the sequential reconfiguration scheme when the node density is high, and the trend is reversed when the node density is low. Wensheng Zhang 0001, Guohong Cao |
IEEE Trans. Wirel. Commun. | 1 |
| 2003 | Data Dissemination with Ring-Based Index for Wireless Sensor NetworksabstractIn current sensor networks, sensor nodes are capable of not only measuring real world phenomena, but also storing, processing and transferring these measurements. Many data dissemination techniques have been proposed for sensor networks. However, these techniques may not work well in a large scale sensor network where a huge amount of sensing data are generated, but only a small portion of them are queried. In this paper, we propose an index-based data dissemination scheme to address the problem. This scheme is based on the idea that sensing data are collected, processed and stored at the nodes close to the detecting nodes, and the location information of these storing nodes is pushed to some index nodes, which act as the rendezvous points for sinks and sources. We further extend the scheme with an adaptive ring-based index (ARI) technique, in which the index nodes for one event type form a ring surrounding the location which is determined by the event type, and the ring can be dynamically reconfigured for fault tolerance and load balance. Analysis and simulations are conducted to evaluate the performance of the proposed index-based scheme. The results show that the index-based scheme outperforms the external storage-based scheme, the DCS scheme, and the local storage-based schemes with flood-response style. The results also show that using ARI can tolerate clustering failures and achieve load balance. Wensheng Zhang 0001, Guohong Cao, Thomas La Porta |
ICNP | 1 |
| 2002 | Improving Bluetooth network performance through a time-slot leasing approachabstractBluetooth is a promising technology aimed at supporting short-range wireless communication. To achieve the advantage of simplicity and low-power, the master/slave model is used. However, this model has some drawbacks since no direct link exists between any two slaves in a piconet. Consequently, slave-to-slave communications must go through the master, and the master has to use extra bandwidth to forward the packets exchanged between slaves. We propose a time-slot leasing (TSL) and an enhanced TSL (ETSL) approach to address these drawbacks. Simulation results demonstrate that the TSL approach, especially the ETSL approach, can significantly improve the system performance compared to the standard master/slave model. Wensheng Zhang 0001, Hao Zhu 0007, Guohong Cao |
WCNC | 1 |