VLDB 2026 Research / reviewers in the wild / expert
Baodong Qin
dblp:94/6901
· DBLP profile ↗
55ranked-venue papers
17as first author
18since 2021 · last 2026
0000-0001-7617-5462ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 11 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 3 first-author · 1 since 2021Computer networks · 6 · 4 since 2021Databases, data management, data science and information retrieval · 6 · 3 first-authorTheory of computation · 5 · 2 since 2021Systems, architecture and hardware · 4 · 3 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Distributed Privacy-Preserving Reinforcement Learning via Sparse Matrix Encryption for IoTabstractReinforcement learning (RL) has been increasingly adopted in IoT systems for tasks such as resource allocation and control. However, in privacy-critical and resource-constrained environments, existing privacy-preserving RL schemes suffer from high computational cost, slow convergence, and limited scalability due to the use of homomorphic encryption or differential privacy. We propose a distributed privacy-preserving Q-learning framework that enables secure and efficient policy updates across multiple clients. Each client independently trains a local Q-table and encrypts it using a sparse matrix transformation combined with additive secret sharing of structured perturbations. The encrypted Q-tables are uploaded to a cloud server for aggregation and averaging without decryption. The encrypted global Q-table is then returned and decrypted locally using the inverse sparse matrix. Experimental results on four benchmark environments (CartPole-v1, MountainCar-v0, Acrobot-v1, and LunarLander-v3) show that our scheme achieves up to 92% reduction in computation time compared to the FHE-based method, while maintaining comparable reward performance and faster convergence. Tong Ji, Yunting Tao, Fanyu Kong 0002, Chunpeng Ge 0001, Baodong Qin, Jia Yu 0003 |
IEEE Internet Things J. | 6 |
| 2026 | EvaFL: An Efficient Verifiable Privacy-Preserving Federated Learning Against Malicious ServersabstractFederated Learning (FL) preserves client data privacy by distributing model training but remains vulnerable to inference attacks (e.g., gradient inversion). Existing secure aggregation schemes mitigate basic privacy threats, but most of them are under the semi-honest server assumption. Malicious servers can corrupt the global model through forging aggregation results. Moreover, the high interaction rounds and communication complexity of the existing schemes still constrain their feasibility in large-scale distributed deployment scenarios. To tackle these challenges, we propose EvaFL, an efficient verifiable privacy-preserving federated learning against malicious servers, which reduces the communication overhead and privacy threats from malicious severs. We propose the system model of EvaFL and give the concrete protocol. We leverage the linear homomorphism property of Shamir secret sharing under discrete logarithm assumption to reuse the mask seed shares, which avoids the communication overhead caused by share distribution in multiple rounds of iterations. In addition, by integrating consistency checking into the unmasking step, we further reduce one round interaction. To resist malicious servers, we adopt linear homomorphic hash to realize the correctness verification of the aggregation results. Finally, we implement and evaluate our EvaFL based on MNIST and CIFAR10 datasets to show its feasibility for privacy training. The single round aggregation completion time of EvaFL is reduced by 69% compared to BBGLR (CCS 2020) and by 11% compared to Flamingo (S&P 2023). Xiaoyi Yang 0001, Xing Zou, Qian Chen 0032, Baodong Qin, Yanqi Zhao, Yong Yu 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | R+R: Anonymous Authentication and Key Agreement, RevisitedabstractIn NDSS 2024, Yu et al. proposed AAKA, an Anonymous Authentication and Key Agreement scheme designed to protect users' privacy from mobile tracking by Mobile Network Operators (MNOs). AAKA aims to provide both anti-tracking privacy and traceability (lawful de-anonymization), allowing subscribers to access the network via anonymous proofs while enabling a Law Enforcement Agency (LEA) to trace the real identity if misbehaviors are detected. However, we identify that the AAKA scheme in NDSS 2024 is insecure since the subscriber's identity is exposed within the protocol, thereby failing to achieve the claimed privacy and traceability. Building on the repair of AAKA, we propose AAKA +, Anonymous Authentication and Key Agreement with Verifier-Local Revocation, a new mobile authentication scheme, to ensure privacy against mobile tracking. In addition to the privacy and traceability introduced in NDSS 2024, AAKA + additionally allows the MNO to immediately assert whether the associated subscriber has been traced and revoked upon receiving an anonymous proof We formally define the syntax and the security model of AAKA + and propose two concrete schemes, AAKA+BB andAAKA+PS, based on the Boneh-Boyen signature and the Pointcheval-Sanders signature schemes, respectively. Both AAKA+BB and AAKA+PS are pairing-free on the user equipment side and compatible with existing cellular infrastructure. Experimental results show that our schemes are practical, with anonymous proof generation taking approximately 18 milliseconds for a constrained device. Yanqi Zhao, Xiaoyi Yang 0001, Jianting Ning, Baodong Qin, Yong Yu 0002 |
ACSAC | 6 |
| 2025 | Cryptanalysis of Keyword Confidentiality in a Searchable Public-Key Encryption Scheme Against Malicious ServerabstractPublic‐key authenticated encryption with keyword search (PAEKS) is a novel cryptographic primitive to resist against keyword‐guessing attacks (KGAs) and preserve the privacy of keywords in both ciphertexts and trapdoors. Recently, a designated‐server PAEKS (dPAEKS) scheme was proposed to withstand KGAs. The scheme was claimed to satisfy both multi‐ciphertext indistinguishability (MCI) and multi‐trapdoor privacy (MTP). However, our cryptanalysis demonstrates that it is insecure against KGAs, where a malicious server (inside attacker) can obtain the information of the keywords embedded in the ciphertext and the trapdoor. As a result, both the MCI and MTP of the scheme are broken. In addition, the paper also shows that it is possible to break the security of MTP, even for an outside attacker. Finally, we also provide a method to fix these security flaws. Baodong Qin, Dong Zheng 0001 |
IET Inf. Secur. | 2 |
| 2025 | PPFL: Privacy-Preserving Federated Learning Based on Differential Privacy and Personalized Data TransformationabstractFederated learning (FL) prevents direct exposure of raw data. However, it remains vulnerable to privacy and security threats such as inference and poisoning attacks. Traditional differential privacy (DP) methods utilize noise injection to mitigate these attacks, which inherently degrades the accuracy of the model. In this paper, we propose a robust FL framework with two alternative effective defense mechanisms to enhance privacy preservation for various scenarios. We first propose a dual-layer client-server collaborative differential privacy (CLDP). Clients utilize adaptive local differential privacy (LDP) for data privacy, while the server uses central differential privacy (CDP) on the global model to mitigate poisoning attacks. Second, we propose enhanced central differential privacy (ECDP), a layer-specific protection mechanism that strategically injects targeted noise into non-batch normalization layers to further preserve data privacy. To mitigate noise-induced model performance degradation, our solution combines personalized data transformation and gradient sparsification, effectively alleviating both non-IID data distribution skew and cumulative noise effects. Architecturally, we decentralize the federated learning system through edge node integration, thereby eradicating single points of failure. Experimental results demonstrate that our framework achieves a superior accuracy-privacy trade-off under strict privacy constraints, providing robust protection without compromising practical utility. Jiali Han, Liangliang Wang 0001, Zhiquan Liu 0001, Baodong Qin, Kai Zhang 0016, Weiwei Li 0007 |
IEEE Internet Things J. | 4 |
| 2025 | Privacy-Preserving Multi-Key Image Retrieval in Cloud EnvironmentabstractThe rapid development of cloud computing has created more favorable conditions for the practical application of privacy-preserving image retrieval technology. However, most existing schemes fail to fully leverage the potential of cloud computing and still face several challenges, primarily in terms of low retrieval precision, weak security, and reliance on the single-key mechanism. To this end, we propose a privacy-preserving multi key image retrieval in cloud environment, named PPMKIR. First, PPMKIR utilizes a convolutional neural network EfficientNetB7 to extract image feature vectors and employs the mini-batch K Means algorithm for feature clustering. Then, PPMKIR encrypts the obtained clusters using the threshold Paillier cryptosystem and constructs a novel index forest based on the encrypted clusters to aggregate data from different sources. Additionally, PPMKIR introduces a tailored search algorithm for the index forest, significantly accelerating the image retrieval process. Comprehensive security analysis demonstrates that PPMKIR not only protects the privacy of outsourced data and queries but also ensures strong security at all stages of the system. Extensive experiments on real-world image datasets validate that PPMKIR achieves outstanding retrieval precision and efficiency. Zhiquan Liu 0001, Yinbin Miao, Baodong Qin |
IEEE Trans. Cloud Comput. | 5 |
| 2025 | An Efficient Fuzzy Certificateless Signature-Based Authentication Scheme Using Anonymous Biometric Identities for VANETsabstractVehicular ad hoc networks (VANETs) are essential technologies to ensure safe road traffic management and enhance driving convenience. Nowadays, diversified authentication schemes have been developed in VANETs for the purpose of safer communication between nodes. For instance, biometric technology which employs biometric information as users’ authentic identity is widely adopted in message authentication due to its visible benefits. Nonetheless, there is a significant problem in current biometric identity-based authentication schemes that noise is inevitable in each collection of biometric information, making these schemes lack critical error tolerance. Additionally, anonymous biometric identity is difficult to be realized, which fails to meet the basic standard of VANETs. For solving the above key issues, we propose the first efficient fuzzy certificateless signature-based (FCLS) authentication scheme using anonymous biometric identities for VANETs. In virtue of its superior error tolerance, it enables authentication between two identities represented by two attribute sets within a certain Hamming distance. Besides, the newly developed authentication scheme realizes effective conditional privacy so that drivers’ real biometric identities can be ensured. Through the formal security proof, this FCLS scheme is existentially unforgeable against adaptive chosen message attack (EU-CMA) in the random oracle model (ROM), which reaches the higher security. Compared with current advanced schemes, the new authentication scheme is more efficient in computation and communication according to performance analysis. Liangliang Wang 0001, Jiangwei Xu, Baodong Qin, Mi Wen, Kefei Chen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | EFTA: An Efficient and Fault-Tolerant Data Aggregation Scheme without TTP in Smart GridabstractAbstract With the rapid construction and implementation of smart grid, lots of studies have been conducted to explore how to ensure the security of information privacy. At present, most privacy-preserving data aggregation schemes in smart grid achieve privacy data protection through homomorphically encrypted data aggregation. However, these data aggregation schemes tend to rely on a trusted third party (TTP), and fail to efficiently handle the case of a meter failure. Besides, they are less flexible for overall user management, and resistance to collusion attacks needs to be improved. In this paper, we propose an efficient and robust privacy-preserving data aggregation scheme without TTP, called EFTA. Overall, the scheme eliminates the reliance on a TTP, combines with Shamir threshold secret sharing scheme to increase overall fault tolerance, supports flexible and dynamic user management, and effectively defends against entity initiated collusion attacks. According to security and performance analysis results, the scheme proposed in this paper meets the multiple security requirements of smart grid, and is more efficient in terms of overall overhead compared to the existing privacy-preserving data aggregation schemes. Xianyun Mei, Liangliang Wang 0001, Baodong Qin, Kai Zhang 0016, Yu Long 0001 |
Comput. J. | 3 |
| 2024 | A pairing-free certificate-based key-insulated aggregate signature scheme for wireless medical sensor networks
Liangliang Wang 0001, Kai Zhang 0016, Yu Long 0001, Baodong Qin |
Peer Peer Netw. Appl. | 5 |
| 2024 | Further construction of even-variable balanced rotation symmetric Boolean functions with optimal algebraic immunity
Qinglan Zhao, Dong Zheng 0001, Baodong Qin |
Theor. Comput. Sci. | 5 |
| 2023 | A unified construction of weightwise perfectly balanced Boolean functions
Qinglan Zhao, Baodong Qin, Dong Zheng 0001 |
Discret. Appl. Math. | 4 |
| 2023 | Password-authenticated proofs of retrievability for multiple devices checking cloud data
Hui Cui 0001, Zhiguo Wan, Huayi Qi, Baodong Qin, Xun Yi |
J. Inf. Secur. Appl. | 4 |
| 2023 | A lattice-based designated-server public-key authenticated encryption with keyword search
Yajun Fan, Baodong Qin, Dong Zheng 0001 |
J. Syst. Archit. | 2 |
| 2022 | Blockchain-Based Auditable Privacy-Preserving Data Classification for Internet of ThingsabstractInternet of Things (IoT) connects massive physical devices to capture and collect useful data, which are used to make accurate decisions by taking advantage of the machine learning techniques. However, the collected data may contain users’ sensitive information. When guaranteeing the utility of data, we need to consider privacy of users’ data. To balance the utility and the privacy of data, the existing approaches usually adopt the privacy-preserving signature technology, where the privacy-preserving data are classified by a designated converter (data processor) interacting with a semihonest verifier (data center). However, for the malicious behavior of the data center and data processor, this kind of approach is insufficient. To prevent the malicious data center/data processor while guaranteeing the utility and privacy of data, we propose blockchain-based auditable privacy-preserving data classification (PPDC) scheme for IoT. We put forth a new controllably linkable group signature (CL-GS) to balance the utility and privacy of data and take advantage of blockchain to audit the correctness of privacy-preserving data classification against malicious data processor/data center. We formalize the system model of the auditable privacy-preserving data classification in the blockchain setting and its security model. Then, we present a concrete construction and prove its security in the random oracle model. Finally, we deploy a prototype system to evaluate the performance ofPPDC. Yanqi Zhao, Xiaoyi Yang 0001, Yong Yu 0002, Baodong Qin, Xiaojiang Du, Mohsen Guizani |
IEEE Internet Things J. | 4 |
| 2022 | Non-Malleable Functions and their Applications
Yu Chen 0003, Baodong Qin, Jiang Zhang 0001, Yi Deng 0002, Sherman S. M. Chow |
J. Cryptol. | 2 |
| 2022 | Efficient two-party SM2 signing protocol based on secret sharing
Shengling Geng, Baodong Qin |
J. Syst. Archit. | 4 |
| 2021 | Forward-Secure Revocable Identity-Based Encryption
Baodong Qin, Dong Zheng 0001, Hui Cui 0001, Yiyuan Luo |
ICICS (2) | 1 |
| 2021 | Improved Security Model for Public-Key Authenticated Encryption with Keyword Search
Baodong Qin, Hui Cui 0001, Dong Zheng 0001 |
ProvSec | 1 |
| 2020 | Space efficient revocable IBE for mobile devices in cloud computing
Baodong Qin, Ximeng Liu, Zhuo Wei, Dong Zheng 0001 |
Sci. China Inf. Sci. | 1 |
| 2020 | Key regeneration-free ciphertext-policy attribute-based encryption and its application
Hui Cui 0001, Robert H. Deng, Baodong Qin, Jian Weng 0001 |
Inf. Sci. | 3 |
| 2020 | Public-key authenticated encryption with keyword search revisited: Security model and constructions
Baodong Qin, Yu Chen 0003, Qiong Huang 0001, Ximeng Liu, Dong Zheng 0001 |
Inf. Sci. | 1 |
| 2020 | Robust digital signature revisited
Hui Cui 0001, Baodong Qin, Willy Susilo, Surya Nepal |
Theor. Comput. Sci. | 2 |
| 2020 | An Efficient Searchable Public-Key Authenticated Encryption for Cloud-Assisted Medical Internet of ThingsabstractIn recent years, it has become popular to upload patients’ medical data to a third-party cloud server (TCS) for storage through medical Internet of things. It can reduce the local maintenance burden of the medical data and importantly improve accuracy in the medical treatment. As remote TCS cannot be fully trusted, medical data should be encrypted before uploading, to protect patients’ privacy. However, encryption makes search capabilities difficult for patients and doctors. To address this issue, Huang et al. recently put forward the notion of Public-key Authenticated Encryption with Keyword Search (PAEKS) against inside keyword guessing attacks. However, the existing PAEKS schemes rely on time-consuming computation of parings. Moreover, some PAEKS schemes still have security issues in a multiuser setting. In this paper, we propose a new and efficient PAEKS scheme, which uses the idea of Diffie-Hellman key agreement to generate a shared secret key between each sender and receiver. The shared key will be used to encrypt keywords by the sender and to generate search trapdoors by the receiver. We prove that our scheme is semantically secure against inside keyword guessing attacks in a multiuser setting, under the oracle Diffie-Hellman assumption. Experimental results demonstrate that our PAEKS scheme is more efficient than that of previous ones, especially in terms of keyword searching time. Tianyu Chi, Baodong Qin, Dong Zheng 0001 |
Wirel. Commun. Mob. Comput. | 2 |
| 2019 | (Dual) server-aided revocable attribute-based encryption with decryption key exposure resistance
Baodong Qin, Qinglan Zhao, Dong Zheng 0001, Hui Cui 0001 |
Inf. Sci. | 1 |
| 2019 | Tightly Secure Lossy Trapdoor Functions: Constructions and ApplicationsabstractLossy trapdoor functions (LTFs), introduced by Peiker and Waters in STOC’08, are functions that may be working in another injective mode or a lossy mode. Given such a function key, it is impossible to distinguish an injective key from a lossy key for any (probabilistic) polynomial-time adversary. This paper studies lossy trapdoor functions with tight security. First, we give a formal definition for tightly secure LTFs. Loosely speaking, a collection of LTFs is tightly secure if the advantage to distinguish a tuple of injective keys from a tuple of lossy keys does not degrade in the number of function keys. Then, we show that tightly secure LTFs can be used to construct public-key encryption schemes with tight CPA security in a multiuser, multichallenge setting, and with tight CCA security in a multiuser, one-challenge setting. Finally, we present a construction of tightly secure LTFs from the decisional Diffie-Hellman assumption. Baodong Qin |
Secur. Commun. Networks | 1 |
| 2019 | A QR Code Secret Hiding Scheme against Contrast Analysis Attack for the Internet of ThingsabstractDue to the advantages of larger content and error correction capability, quick response (QR) code is commonly used as a tagging technology for the Internet of Things (IoT) recently. However, the cover message of QR code can be easily decoded by a QR code reader, which causes the security and privacy of the cover message to raise the important issues. In this paper we present a new secret hiding scheme based on QR code. The proposed scheme has low computational complexity and is suitable for low-power devices in IoT systems because of utilizing the error correction property of QR code to hide secret information. The proposed scheme hides the secret information without changing the cover message of QR code and the user can get the cover message by using a general scanner, which contributes to reducing attacker’s curiosity. The hidden secret information can be read by a special scanner with the help of the user key. One thing which is better than other known schemes is that the proposed scheme can resist contrast analysis attack. In addition, experimental results show the proposed scheme has feasibility, low computational complexity, and high hiding payload. Qinglan Zhao, Shuntong Yang, Dong Zheng 0001, Baodong Qin |
Secur. Commun. Networks | 4 |
| 2018 | Regularly Lossy Functions and Applications
Yu Chen 0003, Baodong Qin, Haiyang Xue |
CT-RSA | 2 |
| 2018 | Chameleon all-but-one extractable hash proof and its applications
Hui Li 0006, Baodong Qin, Dong Zheng 0001 |
Sci. China Inf. Sci. | 3 |
| 2018 | LR-RRA-CCA secure functional encryption for randomized functionalities from trapdoor HPS and LAF
Huige Wang, Kefei Chen, Baodong Qin, Ziyuan Hu |
Sci. China Inf. Sci. | 3 |
| 2018 | Bounded Revocable and Outsourceable ABE for Secure Data SharingabstractWith the progress of cloud computing, many users hope in time to upload their data into cloud for sharing. For sensitive data, the owner must encrypt it before sending it to cloud server. The state of the art method for fine-grained access control on encrypted data is attribute-based encryption (ABE). Though ABE is believed to be an outstanding technique for secure data sharing, it has many efficiency drawbacks. For example, its ciphertext size and decryption time increase linearly with the number of attributes used during encryption and decryption, and it is hard to revoke a user’s access ability. In this paper, we propose a method to outsource the decryption of ABE via public cloud computing, and to control a user’s decryption capacity through a bounded revocation technique. The public cloud server can transform any user’s ABE ciphertexts into short ElGamal-type ciphertexts via the user’s public transformation key. The transformed ciphertexts are actually ElGamal-type identity-based ciphertexts obtained through a bounded-collision identity-based encryption scheme, and the decryption time only requires one exponentiation. Our scheme can revoke user’s decryption ability. But it limits to scenario with bounded number of revocation. Baodong Qin, Qinglan Zhao, Dong Zheng 0001 |
Comput. J. | 1 |
| 2018 | Tightly CCA-secure identity-based encryption with ciphertext pseudorandomness
Shuai Han 0001, Shengli Liu 0001, Baodong Qin, Dawu Gu |
Des. Codes Cryptogr. | 3 |
| 2018 | Regular lossy functions and their applications in leakage-resilient cryptography
Yu Chen 0003, Baodong Qin, Haiyang Xue |
Theor. Comput. Sci. | 2 |
| 2017 | Server-Aided Revocable Attribute-Based Encryption Resilient to Decryption Key Exposure
Baodong Qin, Qinglan Zhao, Dong Zheng 0001, Hui Cui 0001 |
CANS | 1 |
| 2017 | Fuzzy Public-Key Encryption Based on Biometric Data
Hui Cui 0001, Man Ho Au, Baodong Qin, Robert H. Deng, Xun Yi |
ProvSec | 3 |
| 2017 | A new construction on randomized message-locked encryption in the standard model via UCEs
Huige Wang, Kefei Chen, Baodong Qin, Xuejia Lai, Yunhua Wen |
Sci. China Inf. Sci. | 3 |
| 2017 | Related-key secure key encapsulation from extended computational bilinear Diffie-Hellman
Baodong Qin, Shengli Liu 0001, Shifeng Sun 0001, Robert H. Deng, Dawu Gu |
Inf. Sci. | 1 |
| 2017 | Public key encryption resilient to leakage and tampering attacks
Shifeng Sun 0001, Dawu Gu, Parampalli Udaya, Yu Yu 0001, Baodong Qin |
J. Comput. Syst. Sci. | 5 |
| 2017 | An Efficient Privacy-Preserving Outsourced Computation over Public DataabstractIn this paper, we propose a new efficient privacy-preserving outsourced computation framework over public data, called EPOC. EPOC allows a user to outsource the computation of a function over multi-dimensional public data to the cloud while protecting the privacy of the function and its output. Specifically, we introduce three types of EPOC in order to tradeoff different levels of privacy protection and performance. We present a new cryptosystem called Switchable Homomorphic Encryption with Partially Decryption (SHED) as the core cryptographic primitive for EPOC. We introduce two coding techniques, called message pre-coding technique and message extending and coding technique respectively, for messages encrypted under a composite order group. Furthermore, we propose a Secure Exponent Calculation Protocol with Public Base (SEPB), which serves as the core sub-protocol in EPOC. Detailed security analysis shows that the proposed EPOC achieves the goal of outsourcing computation of a private function over public data without privacy leakage to unauthorized parties. In addition, performance evaluations via extensive simulations demonstrate that EPOC is efficient in both computation and communications. Ximeng Liu, Baodong Qin, Robert H. Deng, Yingjiu Li |
IEEE Trans. Serv. Comput. | 2 |
| 2016 | How to Make the Cramer-Shoup Cryptosystem Secure Against Linear Related-Key Attacks
Baodong Qin, Shuai Han 0001, Yu Chen 0003, Shengli Liu 0001, Zhuo Wei |
Inscrypt | 1 |
| 2016 | Server-Aided Revocable Attribute-Based Encryption
Hui Cui 0001, Robert H. Deng, Yingjiu Li, Baodong Qin |
ESORICS (2) | 4 |
| 2016 | RKA-Secure Public Key Encryptions Against Efficiently Invertible FunctionsabstractRelated-key attacks (RKAs) are a flavor of powerful physical attacks, which allow an adversary to modify the secret key stored in a cryptographic device and subsequently observe the effect of such modifications on the output of the device. Designing secure encryption schemes against such attacks is a challenging task, especially for a large class of such physical attacks which are usually captured by related-key derivation functions. In this work, we achieve the security of public key encryptions (PKEs) against a new and broad function class that consists of almost all efficiently invertible functions in two different ways. Specifically, we first give a generic construction of PKE which is proven secure against such a broad function class under the standard chosen-ciphertext security. Moreover, we present two practical concrete constructions, both of which are shown to be secure against such function class under standard assumptions in the standard model. At last, we give a detailed performance analysis, which shows that our constructions can not only resist to a large class of RKAs but also achieve a good efficiency. Shifeng Sun 0001, Joseph K. Liu, Yu Yu 0001, Baodong Qin, Dawu Gu |
Comput. J. | 4 |
| 2016 | Escrow free attribute-based signature with self-revealability
Hui Cui 0001, Guilin Wang, Robert H. Deng, Baodong Qin |
Inf. Sci. | 4 |
| 2016 | Certificateless encryption secure against selective opening attackabstractAbstract The notion of selective opening attacks (SOAs) was first introduced by Dworket al. at FOCS'99. Informally, an encryption scheme is SOA secure if an adversary is given a vector of ciphertexts and can adaptively corrupt some fraction of them by obtaining not only their messages but also their randomness, the uncorrupted ciphertexts retain secure. Provably achieving security against SOA has been proven extremely challenging. In this paper, we propose a security model to capture simulation‐based selective opening chosen‐plaintext attacks (SIM‐SO‐CPA) for certificateless encryption. We provide a concrete construction and prove its security in our simulation‐based selective opening chosen‐plaintext attack security model, based on the real or random and computational Diffie–Hellman assumptions. Compared with previous SOA‐secure public key encryption and identity‐based encryption, our certificateless encryption scheme is more simple and efficient. Copyright © 2017 John Wiley & Sons, Ltd. Huige Wang, Kefei Chen, Baodong Qin |
Secur. Commun. Networks | 3 |
| 2016 | A Privacy-Preserving Outsourced Functional Computation Framework Across Large-Scale Multiple Encrypted DomainsabstractIn this paper, we propose a framework for privacy-preserving outsourced functional computation across large-scale multiple encrypted domains, which we refer to as POFD. With POFD, a user can obtain the output of a function computed over encrypted data from multiple domains while protecting the privacy of the function itself, its input and its output. Specifically, we introduce two notions of POFD, the basic POFD and its enhanced version, in order to tradeoff the levels of privacy protection and performance. We present three protocols, named Multi-domain Secure Multiplication protocol (MSM), Secure Exponent Calculation protocol with private Base (SECB), and Secure Exponent Calculation protocol (SEC), as the core sub-protocols for POFD to securely compute the outsourced function. Detailed security analysis shows that the proposed POFD achieves the goal of calculating a user-defined function across different encrypted domains without privacy leakage to unauthorized parties. Our performance evaluations using simulations demonstrate the utility and the efficiency of POFD. Ximeng Liu, Baodong Qin, Robert H. Deng, Rongxing Lu, Jianfeng Ma 0001 |
IEEE Trans. Computers | 2 |
| 2016 | Privacy-Preserving Outsourced Calculation on Floating Point NumbersabstractIn this paper, we propose a framework for privacy-preserving outsourced calculation on floating point numbers (POCF). Using POCF, a user can securely outsource the storing and processing of floating point numbers to a cloud server without compromising on the security of the (original) data and the computed results. In particular, we first present privacy-preserving integer processing protocols for common integer operations. We then present an approach to outsourcing floating point numbers for storage in a privacy-preserving way, and securely processing commonly used floating point number operations on-the-fly. We prove that the proposed POCF achieves the goal of floating point number processing without privacy leakage to unauthorized parties, and demonstrate the utility and the efficiency of POCF using simulations. Ximeng Liu, Robert H. Deng, Wenxiu Ding, Rongxing Lu, Baodong Qin |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2016 | Privacy-Preserving Patient-Centric Clinical Decision Support System on Naïve Bayesian ClassificationabstractClinical decision support system, which uses advanced data mining techniques to help clinician make proper decisions, has received considerable attention recently. The advantages of clinical decision support system include not only improving diagnosis accuracy but also reducing diagnosis time. Specifically, with large amounts of clinical data generated everyday, naïve Bayesian classification can be utilized to excavate valuable information to improve a clinical decision support system. Although the clinical decision support system is quite promising, the flourish of the system still faces many challenges including information security and privacy concerns. In this paper, we propose a new privacy-preserving patient-centric clinical decision support system, which helps clinician complementary to diagnose the risk of patients' disease in a privacy-preserving way. In the proposed system, the past patients' historical data are stored in cloud and can be used to train the naïve Bayesian classifier without leaking any individual patient medical data, and then the trained classifier can be applied to compute the disease risk for new coming patients and also allow these patients to retrieve the top- k disease names according to their own preferences. Specifically, to protect the privacy of past patients' historical data, a new cryptographic tool called additive homomorphic proxy aggregation scheme is designed. Moreover, to leverage the leakage of naïve Bayesian classifier, we introduce a privacy-preserving top- k disease names retrieval protocol in our system. Detailed privacy analysis ensures that patient's information is private and will not be leaked out during the disease diagnosis phase. In addition, performance evaluation via extensive simulations also demonstrates that our system can efficiently calculate patient's disease risk with high accuracy in a privacy-preserving way. Ximeng Liu, Rongxing Lu, Jianfeng Ma 0001, Baodong Qin |
IEEE J. Biomed. Health Informatics | 5 |
| 2015 | Server-Aided Revocable Identity-Based EncryptionabstractEfficient user revocation in Identity-Based Encryption (IBE) has been a challenging problem and has been the subject of several research efforts in the literature. Among them, the tree-based revocation approach, due to Boldyreva, Goyal and Kumar, is probably the most efficient one. In this approach, a trusted Key Generation Center (KGC) periodically broadcasts a set of key updates to all (non-revoked) users through public channels, where the size of key updates is only $$O(r\log \frac{N}{r})$$ , with N being the number of users and r the number of revoked users, respectively; however, every user needs to keep at least $$O(\log N)$$ long-term secret keys and all non-revoked users are required to communicate with the KGC regularly. These two drawbacks pose challenges to users who have limited resources to store their secret keys or cannot receive key updates in real-time. To alleviate the above problems, we propose a novel system model called server-aided revocable IBE. In our model, almost all of the workloads on users are delegated to an untrusted server which manages users’ public keys and key updates sent by a KGC periodically. The server is untrusted in the sense that it does not possess any secret information. Our system model requires each user to keep just one short secret key and does not require users to communicate with either the KGC or the server during key updating. In addition, the system supports delegation of users’ decryption keys, namely it is secure against decryption key exposure attacks. We present a concrete construction of the system that is provably secure against adaptive-ID chosen plaintext attacks under the DBDH assumption in the standard model. One application of our server-aided revocable IBE is encrypted email supporting lightweight devices (e.g., mobile phones) in which an email server plays the role of the untrusted server so that only non-revoked users can read their email messages. Baodong Qin, Robert H. Deng, Yingjiu Li, Shengli Liu 0001 |
ESORICS (1) | 1 |
| 2015 | Multi-Authority Attribute Based Encryption Scheme with RevocationabstractAttribute Based Encryption (ABE) scheme can achieve information sharing of one-to-many users, without considering the number of users and the users identity. But, the traditional single Attribute Authority (AA) ABE scheme can hardly meet requirements of different agencies in distributed application environment and it is easy to form the system performance bottlenecks. Based on ciphertext-policy ABE scheme, this paper proposes a multi-authority revocable ABE scheme, where the classification manages user attributes, effectively relieving the management burden of single organization. In addition, it can achieve fine grained access control of shared information by adopting tree access strategy and secret sharing scheme, and support system attribute revocation. Finally, we show that the scheme is secure against chosen plaintext attack under the Decisional Bilinear Diffie-Hellman (DBDH) assumption. Xiaofang Huang, Qi Tao, Baodong Qin, ZhiQin Liu |
ICCCN | 3 |
| 2015 | Efficient chosen-ciphertext secure public-key encryption scheme with high leakage-resilienceabstractA leakage‐resilient public‐key encryption (PKE) scheme provides security even if an adversary obtains some information on the secret key. In recent years, much attention has been focused on designing provably secure PKE in the presence of key‐leakage and almost all the constructions rely on an important building block namely hash proof system (HPS). However, in the setting of adaptive chosen‐ciphertext attacks (CCA2), there are not many HPS‐based leakage‐resilient PKE schemes available. Moreover, most of them have an unsatisfactory leakage rate. In this study, the authors propose a new method of constructing leakage‐resilient CCA2‐secure PKE scheme from any tag‐based strongly universal 2 HPS. The striking advantage of the authors scheme is the leakage rate, which is the best one among all known HPS‐based indistinguishability key leakage CCA2‐secure constructions. In particular, they present an instantiation under the n ‐linear assumption. In the cases of n = 1 (resp. n = 2), they actually obtain a decisional Diffie–Hellman (DDH)‐based [resp. decisional linear (DLIN)‐based] PKE scheme, where the leakage rate can be made to 1/4 (resp. 1/6). The authors DDH‐based scheme achieves the best leakage rate among all known DDH‐based (Cramer–Shoup‐type) schemes. Their DLIN‐based scheme is the first one that can achieve leakage of L /6 bits without pairing, where L is the length of the secret key. Baodong Qin, Shengli Liu 0001, Kefei Chen |
IET Inf. Secur. | 1 |
| 2015 | Attribute-Based Encryption With Efficient Verifiable Outsourced DecryptionabstractAttribute-based encryption (ABE) with outsourced decryption not only enables fine-grained sharing of encrypted data, but also overcomes the efficiency drawback (in terms of ciphertext size and decryption cost) of the standard ABE schemes. In particular, an ABE scheme with outsourced decryption allows a third party (e.g., a cloud server) to transform an ABE ciphertext into a (short) El Gamal-type ciphertext using a public transformation key provided by a user so that the latter can be decrypted much more efficiently than the former by the user. However, a shortcoming of the original outsourced ABE scheme is that the correctness of the cloud server's transformation cannot be verified by the user. That is, an end user could be cheated into accepting a wrong or maliciously transformed output. In this paper, we first formalize a security model of ABE with verifiable outsourced decryption by introducing a verification key in the output of the encryption algorithm. Then, we present an approach to convert any ABE scheme with outsourced decryption into an ABE scheme with verifiable outsourced decryption. The new approach is simple, general, and almost optimal. Compared with the original outsourced ABE, our verifiable outsourced ABE neither increases the user's and the cloud server's computation costs except some nondominant operations (e.g., hash computations), nor expands the ciphertext size except adding a hash value (which is <;20 byte for 80-bit security level). We show a concrete construction based on Green et al.'s ciphertext-policy ABE scheme with outsourced decryption, and provide a detailed performance evaluation to demonstrate the advantages of our approach. Baodong Qin, Robert H. Deng, Shengli Liu 0001, Siqi Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Key-Dependent Message Chosen-Ciphertext Security of the Cramer-Shoup Cryptosystem
Baodong Qin, Shengli Liu 0001, Zhengan Huang |
ACISP | 1 |
| 2013 | Leakage-Resilient Chosen-Ciphertext Secure Public-Key Encryption from Hash Proof System and One-Time Lossy Filter
Baodong Qin, Shengli Liu 0001 |
ASIACRYPT (2) | 1 |
| 2013 | Efficient chosen ciphertext secure public-key encryption under factoring assumptionabstractABSTRACT In EUROCRYPT 2009, Hofheinz and Kiltz introduced a new practical chosen ciphertext secure public‐key encryption scheme under the assumption that factoring is intractable. They also proposed a variant that features a slightly more efficient decryption but unfortunately leads to large public key, of size about O(k), where k is a security parameter. In this paper, we propose a novel method to balance the efficiency and the key size of those previous two schemes. Although the public key in our scheme only consists of one RSA modulus and three group elements, it is still more efficient at decrypting than Hofheinz and Kiltz's scheme. By remarking that under certain assumptions factoring the modulus is still hard over much smaller subgroups of signed quadratic residues (i.e., semismooth subgroup), we were able to construct a new scheme that performs extremely efficient decryption. In fact, to date, this is the most efficient scheme for decryption among all public‐key encryption schemes (mainly including Hofheinz and Kiltz's schemes and their follow‐up works) whose security against chosen ciphertext attacks is based on the intractability of factoring in the standard model. Copyright © 2012 John Wiley & Sons, Ltd. Baodong Qin, Shengli Liu 0001 |
Secur. Commun. Networks | 1 |
| 2008 | Cryptanalysis of a Type of CRT-Based RSA Algorithms
Baodong Qin, Fanyu Kong 0002 |
J. Comput. Sci. Technol. | 1 |
| 2007 | Cryptanalysis of Server-Aided RSA Key Generation Protocols at MADNES 2005
Fanyu Kong 0002, Jia Yu 0003, Baodong Qin, Daxing Li |
ATC | 3 |