VLDB 2026 Research / reviewers in the wild / expert
Rong Hao
dblp:95/69
· DBLP profile ↗
39ranked-venue papers
0as first author
19since 2021 · last 2026
0000-0002-2878-6661ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 5 since 2021Databases, data management, data science and information retrieval · 8 · 2 since 2021Systems, architecture and hardware · 7 · 5 since 2021Software engineering, systems software and programming languages · 5 · 2 since 2021Computer networks · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Theory of computation · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy-Preserving Graph Similarity Matching Query Over Encrypted Graph Database
Xinrui Ge, Jia Yu 0003, Rong Hao |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2025 | Popularity-based multiple-replica cloud storage integrity auditing for big data
Rong Hao |
Future Gener. Comput. Syst. | 2 |
| 2025 | Enabling flexible multiple-replica cloud storage integrity auditing for cloud-based IoT data
Rong Hao |
J. Syst. Archit. | 2 |
| 2024 | Towards efficient Secure Boolean Range Query over encrypted spatial data
Jia Yu 0003, Xinrui Ge, Rong Hao |
Comput. Secur. | 4 |
| 2024 | Enabling Privacy-Preserving Boolean kNN Query Over Cloud-Based Spatial DataabstractWith the rapid development of IoT technology, a vast quantity of spatial data with text information is generated, because of the explosive growth of the spatial data, users usually encrypt these data and outsource them to the cloud for enjoying the storage and computing capability. Privacy-preserving Boolean k Nearest Neighbor (kNN) query is a typical query technique over the spatial data. It finds k objects that exactly match the query keyword and are nearest to the query point upon encrypted spatial data. We propose a scheme which supports the privacy-preserving Boolean kNN query over the cloud-based spatial data in this article. In order to efficiently obtain the spatial objects containing the query keywords, we ask the cloud to pick the objects containing the query keyword with the lowest frequency. Then, the cloud filters out the objects that do not contain other query keywords. Since the number of objects containing the query keyword with the lowest frequency is minimal, the number of objects to filter is also minimal. In this way, the query efficiency is improved. In order to realize convenient and safe distance comparison over the encrypted spatial data, we convert the coordinates to the vectors. The distance between the two points can be expressed as the inner product of the two vectors. Furthermore, we use the enhanced asymmetric scalar-product-preserving encryption algorithm to protect the data privacy. We prove that the proposed scheme satisfies the CQA2-security. Meanwhile, we conduct experiments using the real data sets to show the performance of the proposed scheme. Yunjiao Song, Jia Yu 0003, Xinrui Ge, Rong Hao |
IEEE Internet Things J. | 4 |
| 2024 | Enabling privacy-preserving non-interactive computation for Hamming distance
Wenjing Gao, Wei Liang 0005, Rong Hao |
Inf. Sci. | 3 |
| 2024 | Privacy-preserving verifiable fuzzy phrase search over cloud-based data
Rong Hao, Xinrui Ge, Jia Yu 0003 |
J. Inf. Secur. Appl. | 2 |
| 2024 | Privacy-Preserving Graph Matching Query Supporting Quick Subgraph ExtractionabstractGraph matching, as one of the most fundamental problems in graph database, has a wide range of applications. Due to the large scale of graph database and the hardness of graph matching, graph user tends to outsource the encrypted graphs to the cloud. The complex graph matching is performed by the cloud. Several schemes have been proposed to support graph matching query over encrypted graphs. However, none of them can realize efficient subgraph extraction when the matched subgraph needs to be exactly located at the data graph. The graph user has to perform the complex subgraph isomorphism (NP-complete problem) operation to extract the isomorphic subgraph from the matched data graph in state-of-the-art schemes. In order to solve this problem, we propose a privacy-preserving graph matching query scheme supporting quick subgraph extraction in this paper. In our design, two non-colluding cloud servers are adopted to accomplish the matching operation jointly. Neither of them can infer the plaintexts of graphs. Two cloud servers jointly get a matched matrix to represent the matching relationship between vertices in data graph and query graph. Graph user can directly and quickly extract the subgraph isomorphic to query graph from data graph based on the matched matrix. No subgraph isomorphism operation is involved for graph user. The time complexity of subgraph extraction is$O(m^{2})$in our scheme, where$m$is the number of vertices in query graph. The extensive experiments with real-world database demonstrate the efficiency of the proposed privacy-preserving graph matching scheme. Xinrui Ge, Jia Yu 0003, Rong Hao |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Privacy-Preserving Time-Based Auditing for Secure Cloud StorageabstractCloud storage auditing mechanism is used to check whether the data of users stored in the cloud is intact. Most existing auditing schemes for secure cloud storage are designed to check the integrity for specified files based on file identities. In some scenarios, the user would like to check the integrity of the files generated and uploaded to the cloud in a certain time period. Existing cloud storage auditing schemes cannot work well for supporting this practical requirement because the private information will be exposed. To satisfy this requirement, we propose a brand-new paradigm termed as privacy-preserving time-based auditing for secure cloud storage. The proposed paradigm allows the user to check whether the files generated and uploaded in a certain time period are intactly stored in the cloud. When intending to check the integrity of the files uploaded in this time period, the user only provides the challenged time period t to the Third Party Auditor (TPA). The TPA can verify the integrity of all the files based on this time period, but cannot know how many files and which files the user has generated and uploaded to the cloud in this time period. To decrease the complex overhead associated with certificate management, we introduce an identity-based auditing mechanism. We provide a specific security analysis to show the correctness, auditing soundness and privacy preserving of this scheme. The experiments demonstrate the efficiency of the proposed scheme. Jia Yu 0003, Wenting Shen, Rong Hao |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Privacy-Preserving Naïve Bayesian Classification for Health Monitoring SystemsabstractAs the Internet of Medical Things booms, the cloud-assisted health monitoring service has attracted extensive attention. The medical institutions often use the Naïve Bayesian classification technology to establish the medical inference models. These models can be outsourced to cloud servers, allowing the remote users without models to utilize well-performing models for medical diagnosis. Existing Naïve Bayesian secure outsourcing schemes mostly use heavy cryptographic primitives or pure additive secret sharing (ASS) technology. In this article, we use searchable encryption technology combined with ASS to design a privacy-preserving Naïve Bayesian classification scheme that can protect the medical institutions' models, the users' medical data, and the final inference result made by cloud servers. Compared with the state-of-the-art, our scheme further reduces the number of communications between the user and the cloud server and reduces the computation complexity of cloud servers from$O(dtf)$to$O(dt)$. We provide the formal security analysis to show that our scheme ensures the necessary security. Through experiments on multiple datasets, we show that our scheme can efficiently handle the classification requests in the test dataset in less than 100 ms. Rong Hao, Jia Yu 0003, Ming Yang 0023 |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | Enabling Privacy-Preserving $K$K-Hop Reachability Query Over Encrypted GraphsabstractK-hop Reachability Query (KRQ) is one of fundamental graph queries, which can answer whether a node u can reach a node v within K hops. With the scale of graph data increasing, data owner desires to outsource the local graphs to cloud server. To protect the graph privacy, data owner encrypts graphs before outsourcing them to the cloud server. It imposes a great challenge to KRQ over encrypted graphs. How to realize Privacy-Preserving K-hop Reachability Query (PPKRQ) over encrypted graphs is still an unexplored problem. In this paper, we explore this problem and propose a practical scheme. In order to efficiently answer KRQ over encrypted graphs, we construct the encrypted Breadth-First Spanning Tree table and adjacent list D (BFST-D). Based on encrypted BFST table, we can directly judge whether two query nodes are reachable within K hops when they are in one spanning tree. The encrypted adjacent list D can help answer that two query nodes in different spanning trees. To protect the privacy, we utilize the Paillier cryptographic and Order-Revealing Encryption (ORE) to support the comparison and computation over ciphertexts. As a result, our scheme achieves the sensitive information privacy without losing the ability of querying over encrypted graphs. The security analysis shows that our proposed scheme is secure based on semi-honest cloud server. The extensive experiments show the efficiency of our scheme. Yunjiao Song, Xinrui Ge, Jia Yu 0003, Rong Hao, Ming Yang 0023 |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | Privacy-Preserving Face Recognition With Multi-Edge Assistance for Intelligent Security SystemsabstractFace recognition is one of the key technologies in intelligent security systems. Data privacy and identification efficiency have always been concerns about face recognition. Existing privacy-preserving protocols only focus on the training phase of face recognition. Since intelligent security systems mainly complete the calculation of large-scale face data in the identification phase, existing privacy-preserving protocols cannot be well applied to intelligent security systems. In this article, we propose the first privacy-preserving face recognition protocol for the calculations in the identification phase for intelligent security systems. We introduce the Householder matrix to blind user data including model data and face data, which enables the proposed protocol to support privacy-preserving face recognition on semi-trusted edge servers. Utilizing edge computing, fast response for large-scale face recognition can be achieved. The user can offload heavy calculations of matrix multiplication and Euclidean distances to edge servers simultaneously. The proposed protocol supports parallel computing based on multiple edge servers and thus enhances the efficiency of face recognition in intelligent security systems. Moreover, the recognition accuracy in the proposed protocol is the same as that in the original PCA-based face recognition algorithm. The security analysis demonstrates that the protocol protects the privacy of user data. The numerical analysis and simulation experiments are carried out to show the efficiency and feasibility of the proposed protocol. Wenjing Gao, Jia Yu 0003, Rong Hao, Fanyu Kong 0002 |
IEEE Internet Things J. | 3 |
| 2023 | Secure auditing and deduplication with efficient ownership management for cloud storage
Lujun Xu, Rong Hao |
J. Syst. Archit. | 3 |
| 2023 | Verifiable fuzzy keyword search supporting sensitive information hiding for data sharing in cloud-assisted e-healthcare systems
Rong Hao, Xinrui Ge, Jia Yu 0003 |
J. Syst. Archit. | 2 |
| 2022 | Secure Edge-Aided Computations for Social Internet-of-Things SystemsabstractDevices in the Internet-of-Things (IoT) are networked and perform massive computations to support various social IoT systems. Applications in social IoT systems often involve complicated computations that are out of the computation capacity of some resource-constrained IoT devices. Thus, how to enable resource-constrained IoT devices to accomplish complex computations efficiently and securely is of significant importance. To address this problem, we develop a secure edge-aided computation scheme for the social IoT systems. We scope the framework of edge-aided computations and identify the security threats in such a system. We define the security requirements that the outsourcing algorithms should meet. Then, we provide two examples of secure outsourcing algorithms (matrix multiplication and modular exponentiation) that meet the given security requirements. The efficiency and security of the proposed algorithms are supported through the theoretical analysis and experimental results. Hanlin Zhang 0001, Jia Yu 0003, Mohammad S. Obaidat, Pandi Vijayakumar, Linqiang Ge, Jie Lin 0002, Jianxi Fan, Rong Hao |
IEEE Trans. Comput. Soc. Syst. | 8 |
| 2022 | Verifiable Keyword Search Supporting Sensitive Information Hiding for the Cloud-Based Healthcare Sharing SystemabstractWith the integration of the healthcare system, Internet of Things, and cloud storage service, more and more medical institutions upload their electronic medical records (EMRs) to the cloud to reduce the local storage burden and realize data sharing among external researchers. To secure the sensitive information, EMRs usually should be encrypted before being stored on the cloud. However, the existing searchable encryption schemes that encrypt the entire EMRs can hide the sensitive information, but this results in the shared EMRs being unable to be used by researchers. In addition, if the queried and extracted EMRs are incorrect, it will lead to misdiagnosis and even endanger the patient’s life. In order to solve the aforementioned problems, in this article, we propose a verifiable keyword search scheme supporting sensitive information hiding for the cloud-based healthcare sharing system. The sensitive information is encrypted, while other contents in EMR can be shared among users in this scheme. Doctors and researchers can quickly perform search operations based on keywords to extract the EMRs they require. This time complexity is$O(n)$, where$n$is the number of attribute values in the record. But the sensitive information is hidden for the researchers. Furthermore, the correctness of EMRs can be verified when they are extracted from the cloud. This time complexity is max$\lbrace O(n^{\prime }),O(N^{\prime })\rbrace$, where$n^{\prime }$is the number of query keywords and$N^{\prime }$is the number of the retrieved records. We expound the security and carry out experiments to estimate the efficiency of the proposed scheme. Xinrui Ge, Jia Yu 0003, Rong Hao, Haibin Lv |
IEEE Trans. Ind. Informatics | 3 |
| 2021 | Data Integrity Auditing without Private Key Storage for Secure Cloud StorageabstractUsing cloud storage services, users can store their data in the cloud to avoid the expenditure of local data storage and maintenance. To ensure the integrity of the data stored in the cloud, many data integrity auditing schemes have been proposed. In most, if not all, of the existing schemes, a user needs to employ his private key to generate the data authenticators for realizing the data integrity auditing. Thus, the user has to possess a hardware token (e.g., USB token, smart card) to store his private key and memorize a password to activate this private key. If this hardware token is lost or this password is forgotten, most of the current data integrity auditing schemes would be unable to work. In order to overcome this problem, we propose a new paradigm called data integrity auditing without private key storage and design such a scheme. In this scheme, we use biometric data (e.g., iris scan, fingerprint) as the user’s fuzzy private key to avoid using the hardware token. Meanwhile, the scheme can still effectively complete the data integrity auditing. We utilize a linear sketch with coding and error correction processes to confirm the identity of the user. In addition, we design a new signature scheme which not only supports blockless verifiability, but also is compatible with the linear sketch. The security proof and the performance analysis show that our proposed scheme achieves desirable security and efficiency. Wenting Shen, Jing Qin 0002, Jia Yu 0003, Rong Hao, Jiankun Hu, Jixin Ma 0001 |
IEEE Trans. Cloud Comput. | 4 |
| 2021 | Towards Achieving Keyword Search over Dynamic Encrypted Cloud Data with Symmetric-Key Based VerificationabstractVerifiable Searchable Symmetric Encryption, as an important cloud security technique, allows users to retrieve the encrypted data from the cloud through keywords and verify the validity of the returned results. Dynamic update for cloud data is one of the most common and fundamental requirements for data owners in such schemes. To the best of our knowledge, the existing verifiable SSE schemes supporting data dynamic update are all based on asymmetric-key cryptography verification, which involves time-consuming operations. The overhead of verification may become a significant burden due to the sheer amount of cloud data. Therefore, how to achieve keyword search over dynamic encrypted cloud data with efficient verification is a critical unsolved problem. To address this problem, we explore achieving keyword search over dynamic encrypted cloud data with symmetric-key based verification and propose a practical scheme in this paper. In order to support the efficient verification of dynamic data, we design a novel Accumulative Authentication Tag (AAT) based on the symmetric-key cryptography to generate an authentication tag for each keyword. Benefiting from the accumulation property of our designed AAT, the authentication tag can be conveniently updated when dynamic operations on cloud data occur. In order to achieve efficient data update, we design a new secure index composed by a search table ST based on the orthogonal list and a verification list VL containing AATs. Owing to the connectivity and the flexibility of ST, the update efficiency can be significantly improved. The security analysis and the performance evaluation results show that the proposed scheme is secure and efficient. Xinrui Ge, Jia Yu 0003, Hanlin Zhang 0001, Chengyu Hu 0001, Zengpeng Li 0001, Zhan Qin, Rong Hao |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2021 | Comments on "SEPDP: Secure and Efficient Privacy Preserving Provable Data Possession in Cloud Storage"abstractProvable Data Possession is viewed as an important technique to check the integrity of the data stored in remote servers. Recently, a new provable data possession scheme [Secure and Efficient Privacy Preserving Provable Data Possession in Cloud Storage, IEEE Transactions on Services Computing, (2018) DOI: 10.1109/TSC.2018.2820713] was proposed. The authors claimed this scheme can guarantee the storage correction. In this paper, we show this scheme cannot satisfy this fundamental security. Specifically, we demonstrate the malicious cloud can generate a proof to pass the third party auditor's verification even if it does not store the user's whole file. Jia Yu 0003, Rong Hao |
IEEE Trans. Serv. Comput. | 2 |
| 2020 | Enabling Efficient User Revocation in Identity-Based Cloud Storage Auditing for Shared Big DataabstractCloud storage auditing schemes for shared data refer to checking the integrity of cloud data shared by a group of users. User revocation is commonly supported in such schemes, as users may be subject to group membership changes for various reasons. Previously, the computational overhead for user revocation in such schemes is linear with the total number of file blocks possessed by a revoked user. The overhead, however, may become a heavy burden because of the sheer amount of the shared cloud data. Thus, how to reduce the computational overhead caused by user revocations becomes a key research challenge for achieving practical cloud data auditing. In this paper, we propose a novel storage auditing scheme that achieves highly-efficient user revocation independent of the total number of file blocks possessed by the revoked user in the cloud. This is achieved by exploring a novel strategy for key generation and a new private key update technique. Using this strategy and the technique, we realize user revocation by just updating the non-revoked group users' private keys rather than authenticators of the revoked user. The integrity auditing of the revoked user's data can still be correctly performed when the authenticators are not updated. Meanwhile, the proposed scheme is based on identity-base cryptography, which eliminates the complicated certificate management in traditional Public Key Infrastructure (PKI) systems. The security and efficiency of the proposed scheme are validated via both analysis and experimental results. Yue Zhang 0035, Jia Yu 0003, Rong Hao, Cong Wang 0001, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Comment on "Privacy-preserving public auditing for non-manager group shared data"
Jianli Bai, Rong Hao |
J. Supercomput. | 2 |
| 2019 | Cloud storage auditing with deduplication supporting different security levels according to data popularity
Huiying Hou, Jia Yu 0003, Rong Hao |
J. Netw. Comput. Appl. | 3 |
| 2019 | Enabling Identity-Based Integrity Auditing and Data Sharing With Sensitive Information Hiding for Secure Cloud StorageabstractWith cloud storage services, users can remotely store their data to the cloud and realize the data sharing with others. Remote data integrity auditing is proposed to guarantee the integrity of the data stored in the cloud. In some common cloud storage systems such as the electronic health records system, the cloud file might contain some sensitive information. The sensitive information should not be exposed to others when the cloud file is shared. Encrypting the whole shared file can realize the sensitive information hiding, but will make this shared file unable to be used by others. How to realize data sharing with sensitive information hiding in remote data integrity auditing still has not been explored up to now. In order to address this problem, we propose a remote data integrity auditing scheme that realizes data sharing with sensitive information hiding in this paper. In this scheme, a sanitizer is used to sanitize the data blocks corresponding to the sensitive information of the file and transforms these data blocks' signatures into valid ones for the sanitized file. These signatures are used to verify the integrity of the sanitized file in the phase of integrity auditing. As a result, our scheme makes the file stored in the cloud able to be shared and used by others on the condition that the sensitive information is hidden, while the remote data integrity auditing is still able to be efficiently executed. Meanwhile, the proposed scheme is based on identity-based cryptography, which simplifies the complicated certificate management. The security analysis and the performance evaluation show that the proposed scheme is secure and efficient. Wenting Shen, Jing Qin 0002, Jia Yu 0003, Rong Hao, Jiankun Hu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2018 | Intrusion-resilient identity-based signatures: Concrete scheme in the standard model and generic construction
Jia Yu 0003, Rong Hao, Hui Xia 0001, Hanlin Zhang 0001, Xiangguo Cheng, Fanyu Kong 0002 |
Inf. Sci. | 2 |
| 2017 | Remote data possession checking with privacy-preserving authenticators for cloud storage
Wenting Shen, Guangyang Yang, Jia Yu 0003, Hanlin Zhang 0001, Fanyu Kong 0002, Rong Hao |
Future Gener. Comput. Syst. | 6 |
| 2017 | Enabling efficient and verifiable multi-keyword ranked search over encrypted cloud data
Xiuxiu Jiang, Jia Yu 0003, Jingbo Yan, Rong Hao |
Inf. Sci. | 4 |
| 2017 | Light-weight and privacy-preserving secure cloud auditing scheme for group users via the third party medium
Wenting Shen, Jia Yu 0003, Hui Xia 0001, Hanlin Zhang 0001, Xiuqing Lu, Rong Hao |
J. Netw. Comput. Appl. | 6 |
| 2017 | How to securely outsource the inversion modulo a large composite number
Qianqian Su, Jia Yu 0003, Chengliang Tian, Hanlin Zhang 0001, Rong Hao |
J. Syst. Softw. | 5 |
| 2016 | IRIBE: Intrusion-resilient identity-based encryption
Jia Yu 0003, Rong Hao, Huawei Zhao, Minglei Shu, Jianxi Fan |
Inf. Sci. | 2 |
| 2016 | Enabling public auditing for shared data in cloud storage supporting identity privacy and traceability
Guangyang Yang, Jia Yu 0003, Wenting Shen, Qianqian Su, Zhangjie Fu 0001, Rong Hao |
J. Syst. Softw. | 6 |
| 2014 | Key-insulated aggregate signature
Huiyan Zhao, Jia Yu 0003, Shaoxia Duan, Xiangguo Cheng, Rong Hao |
Frontiers Comput. Sci. | 5 |
| 2014 | One forward-secure signature scheme using bilinear maps and its applications
Jia Yu 0003, Fanyu Kong 0002, Xiangguo Cheng, Rong Hao |
Inf. Sci. | 4 |
| 2012 | Erratum to the paper: Forward-Secure Identity-Based Public-Key Encryption without Random Oracles
Jia Yu 0003, Fanyu Kong 0002, Xiangguo Cheng, Rong Hao, Jianxi Fan |
Fundam. Informaticae | 4 |
| 2012 | Intrusion-resilient identity-based signature: Security definition and construction
Jia Yu 0003, Fanyu Kong 0002, Xiangguo Cheng, Rong Hao, Jianxi Fan |
J. Syst. Softw. | 4 |
| 2011 | Forward-Secure Identity-Based Public-Key Encryption without Random OraclesabstractIn traditional identity-based encryption schemes, security will be entirely lost once secret keys are exposed. However, with more and more use of mobile and unprotected devices, key exposure seems unavoidable. To deal with this problem, we newly propose a forward-secure identity-based public-key encryption scheme. In this primitive, the exposure of the secret key in one period doesn't affect the security of the ciphertext generated in previous periods. Any parameter in our scheme has at most log-squared complexity in terms of the total number of time periods. We also give the semantic security notions of forward-secure identity-based public-key encryption. The proposed scheme is proven semantically secure in the standard model. As far as we are concerned, it is the first forward-secure identity-based public-key encryption scheme without random oracles. Jia Yu 0003, Fanyu Kong 0002, Xiangguo Cheng, Rong Hao, Jianxi Fan |
Fundam. Informaticae | 4 |
| 2011 | Forward-secure identity-based signature: Security notions and construction
Jia Yu 0003, Rong Hao, Fanyu Kong 0002, Xiangguo Cheng, Jianxi Fan, Yangkui Chen |
Inf. Sci. | 2 |
| 2008 | Construction of Yet Another Forward Secure Signature Scheme Using Bilinear Maps
Jia Yu 0003, Fanyu Kong 0002, Xiangguo Cheng, Rong Hao |
ProvSec | 4 |
| 2008 | Cryptanalysis of Vo-Kim Forward Secure Signature in ICISC 2005
Jia Yu 0003, Fanyu Kong 0002, Xiangguo Cheng, Rong Hao |
ProvSec | 4 |
| 2008 | A Publicly Verifiable Dynamic Sharing Protocol for Data Secure StorageabstractHow to protect the security of vital data is one of the most important issues of the database security. An efficient method is to divide the vital data into multiple parts that are stored among a group of servers by secret sharing technique. In this paper, we propose a publicly verifiable dynamic sharing protocol for data secure storage. In this protocol, the important data can be publicly verifiably shared among multiple servers, at the same time, the protocol can dynamically recover the bad shares in the system if some servers are attacked. Different from previous protocols, the new protocol is not only efficient but also practical in many circumstances because all operations can be verified by everyone not only shareholders. Jia Yu 0003, Fanyu Kong 0002, Rong Hao |
WAIM | 3 |