Jun Zhou 0018

dblp:99/3847-18 · DBLP profile ↗
← Back
47ranked-venue papers
17as first author
28since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 7 first-author · 17 since 2021Computer networks · 14 · 5 first-author · 7 since 2021Systems, architecture and hardware · 7 · 4 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Generalized Collusion and Hop-Skipping Resistant Autonomous Path Proxy Re-Encryption for Blockchain
abstract
Blockchain has become a superior carrier for data storage due to its decentralization and immutability. How to realize privacy-preserving data sharing and controlled transfer of blockchain data access rights has become a challenging issue. Autonomous path proxy re-encryption allows the delegator to designate a series of delegatees to obtain decryption privileges according to a predefined sequence in a multi-hop manner. However, it faces the hop-skipping issue, where a malicious proxy can directly re-encrypt the ciphertext to the delegatees several hops afterwards, by skipping one or more delegatees in between, destroying the decryption privileges of the skipped delegatees. Furthermore, the intrinsic nature of proxy re-encryption makes it vulnerable to collusion attack, wherein the proxy and a delegatee might collude to construct a decryption device which can decrypt all the delegator’s ciphertexts, posing a serious threat to the delegator’s privacy. To address these challenging issues, we propose a generalized collusion and hop-skipping resistant autonomous path proxy re-encryption for blockchain (CHRAP-PRE). First, we decentralize the proxy’s privileges of re-encrypting ciphertexts to resist collusion attack. Second, we carefully design the decryption token mechanism so that only the person who gets the correct token can do the decryption, which is authorized by all previous persons in the path, thus controlling the decryption privileges to solve the hop-skipping problem. Finally, we formally prove that our proposed CHRAP-PRE achieves IND-HRA security under the Decisional Bilinear Diffie-Hellman (DBDH) assumption, resisting both collusion and hop-skipping attacks. Our comprehensive performance evaluation demonstrates that our scheme offers enhanced security while reducing communication overhead compared to the state-of-the-art.
Yile Chen 0007, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Chunpeng Ge 0001
IEEE Internet Things J.2
2026 Efficient Fine-Grained Accountable Weighted Threshold Signature for Conditional Privacy-Preserving Lending Transactions in Blockchain
abstract
Blockchain technology, with its characteristics of decentralization, immutability and traceability, provides a new platform and technical means for financial transactions, such as lending systems. There are critical security and efficiency demands: Firstly, due to the high volume of real-time concurrent lending transactions, the system must be highly efficient. Furthermore, to achieve fine-grained accountability for illegal lending approval under regulatory oversight, a weighted threshold architecture is required to enable multi-auditor reviews aligned with hierarchical differences among auditors (e.g., seniority or authority levels), and ensure compliance and fairness. Unfortunately, the existing work of threshold signatures face significant limitations: fully anonymous schemes lead to accountability challenges (e.g., difficulty in tracing malicious actors); node interactions during initialization result in prohibitively high overhead; excessive disclosure of identity information severely compromises signer privacy. These shortcomings render traditional schemes unsuitable for lending transactions in blockchain. In order to address these issues, we firstly propose an efficient fine-grained accountable weighted threshold signature (FAWTS). It enables non-interactive initialization without trusted third parties, achieves fine-grained accountability and introduces dynamic weighted thresholds. Then based on FAWTS, we design a conditional privacy-preserving lending transactions in blockchain, which assigns dynamic weighted thresholds for multiple auditors/lending transactions, enables fine-grained tracing of malicious auditors and achieves non-interactive auditor selection to meet high real-time processing demands. Finally, we formally prove that our proposed schemes achieve both the unforgeability and privacy requirements, while significantly reducing computational and communication overhead under extended functionalities.
Siqi Fang, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2026 Blockchain-Assisted Weighted Threshold EdDSA With Rational Identifiable Aborts
abstract
The security of distributed systems, especially blockchain-based applications, relies heavily on threshold signature protocols to maintain decentralization. Identifiable aborts are critical in these protocols, enabling detection and attribution of malicious behavior. However, existing threshold EdDSA schemes with identifiable aborts often rely on zeroknowledge proofs, which significantly increase computational overhead. Additionally, these schemes suffer from inefficient abort handling and difficulty defending against DDoS attacks targeting abort mechanisms. Furthermore, weighted threshold signature schemes frequently encounter weight centralization, where high-weight participants dominate decision-making. In this paper, we propose a threshold EdDSA protocol, named EdFROST, which is unforgeable and supports identifiable aborts under a chosen-message attack (IA-CMA), based on FROST3 proposed by Ruffing et al. (ACM CCS '22). Leveraging EdFROST, we present the first weighted threshold EdDSA scheme that considers both the number of participants and arbitrary weight distribution to mitigate the risk of weight centralization. We also design a game-theoretic incentive model, implemented via tamper-proof chaincode, achieving rational identifiable aborts with a unique sequential equilibrium. This model incentivizes honest behavior to maximize individual benefits while ensuring efficient abort handling and resisting DDoS attacks targeting IA. Experimental results demonstrate that the EdFROST and chaincode are efficient and lightweight, making them well-suited for large-scale distributed systems.
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Jianting Ning
IEEE Trans. Dependable Secur. Comput.2
2026 Weighted Threshold Anonymous Credentials With Redactable Fine-Grained Blind Signature for Auditable Lending System in Blockchains
abstract
Anonymous credentials are ideal for decentralized systems like blockchains, as they enhance privacy, security, and regulatory compliance while maintaining flexibility and adaptability. These decentralized systems often require features such as weighted threshold issuance and tracing for elasticity of decision-making, fine-grained blindness for user privacy control, and issuer-hiding to reduce potential external threats. However, the latest advancements in anonymous credential schemes cannot meet all of these essential properties for blockchain systems. To address these challenges, we propose weighted threshold anonymous credentials with redactable fine-grained blind signature (WTAC). Firstly, by leveraging unlinkable redactable signatures (URS) and functional encryption techniques, our redactable fine-grained blind signature supports selective disclosure and permits credential issuers to learn a particular function value related to the attributes during issuance without revealing the actual attribute content. Secondly, we utilize weighted ramp secret-sharing (WRSS) and randomizable signatures to achieve weighted threshold anonymous credentials, which are issuer-hiding to both users and verifiers. Moreover, we provide a concrete construction instantiated by the Fiat-Shamir paradigm and demonstrate its application, a privacy-preserving auditable lending system in blockchain scenarios, achieving the integration of user privacy and regulatory compliance. Finally, we give a formal security proof of anonymity, fine-grained blindness, traceability, non-frameability, and issuer-hiding. Performance evaluation shows the practicability and efficiency of our proposed WTAC.
Xianrui Zhang, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Jianting Ning
IEEE Trans. Dependable Secur. Comput.2
2026 Secure Off-Chain Payment Protocol From Ciphertext Unlinkable Autonomous Path Proxy Re-Encryption in Blockchain
abstract
Secure off-chain payment plays an important role in blockchain ecosystems, requiring atomicity guarantees where either all payment channels update their balances or none do. While the Lightning Network achieves this through multi-hop Hash Time-Lock Contracts (HTLCs), a critical flaw persists. Specifically, contract conditions (e.g., hash preimages) are transmitted in plaintext across payment paths. Consequently, malicious intermediate nodes can launch interception attacks by claiming funds from predecessors without releasing the corresponding coins to successors. To mitigate this risk, we propose a secure off-chain payment protocol. Firstly, a new cryptographic primitive, namely ciphertext unlinkable autonomous path proxy re-encryption scheme (CUAP-PRE), is proposed. Unlike traditional multi-hop proxy re-encryption, it prevents malicious nodes by enabling the delegator to designate all delegatees he trusts. In addition, ciphertext unlinkability resists homology inference attacks and delegation path tracing to ensure anonymity. Building on CUAP-PRE, a secure off-chain payment protocol (SOCP) in blockchain is designed with an enhanced multi-hop Hash Time-Lock Contract of the Payment-Channel Network (PCN). The receiver at the end of one path of payment channel can control the decryption rights of payment condition in multi-hop delegation manner with reversed order, to unlock the corresponding bitcoins on hold. We then present formal security proofs to demonstrate that the proposed CUAP-PRE and SOCP are postcompromise secure under the Decisional Bilinear Diffie-Hellman (DBDH) assumption in the random oracle model. Comprehensive evaluations also demonstrate the effectiveness and practicability of our proposal.
Yile Chen 0007, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Trans. Inf. Forensics Secur.2
2026 Efficient Malicious Multiparty Private Set Intersection Supporting Cardinality, Sharing, and Batching
abstract
Efficient and maliciously secure multiparty private set intersection (mPSI)—especially for variants enabling cardinality (mPSI-CA) or secret shared outputs with low communication overhead—faces ongoing challenges regarding performance and scalability. However, existing approaches are either based on strong security assumptions of non-colluding centers or are relatively expensive in terms of computational and communication overheads. Addressing these limitations, this paper introduces a new suite of protocols and formalizes them in a real/ideal model to prove the security of the protocols. Firstly, our core mPSI protocol achieves malicious security under the standard honest majority model, relying solely on symmetric-key primitives. The approach employs a lightweight, oblivious key-value store (OKVS)-based architecture where each non-pivot party sends only a single message to a designated pivot. This approach, inspired by Nevoet al.(CCS 2021), minimizes client overhead by carefully delegating core computations. We extend this framework to support cardinality (mPSI-CA) and secret sharing (mPSI-SS) functionalities, which require an additional non-collusion assumption among specific parties. We also introduce a Chinese Remainder Theorem (CRT)-based batching technique for parallel mPSI, achieving near-linear communication savings by compressing multiple OKVS structures. This method generally trades higher computational costs (from polynomial operations and CRT) for communication efficiency, but it is highly effective when communication is paramount or when batching numerous instances of small item sets, where encoding computations can be competitive. Finally, our implementation and evaluation of the proposed mPSI and mPSI-CA protocols in both LAN and WAN settings demonstrate their practical advantages. For instance, in the LAN setting depicted (15 parties,t= 7,m= 220), our mPSI protocol is 3.0× faster and uses 2.5× less communication than Nevoet al.(CCS 2021). Against the approach of Gaoet al.(CCS 2024), our maliciously secure protocol is 1.4× faster with comparable communication overhead under weaker assumptions.
Xiyuan Han, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Trans. Inf. Forensics Secur.2
2025 Traceable Multi-signature Scheme with Distributed Combiners and Lightweight Setup for Accountable Blockchain Transactions
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong
ISPEC2
2025 A Ring Signature With Aggregation for Ensuring Privacy in Blockchain Transactions
abstract
Ring signatures are a crucial cryptographic tool underpinning blockchains and blockchain-based systems, and there are ongoing efforts to design different ring signatures to provide varying properties in a range of applications (e.g., batch verification of numerous ring signatures). In this article, we propose an efficient aggregate ring signature (ARS) scheme for anonymous transaction verification in blockchain. First, a comprehensive definition and the formal security model of our proposed ARS scheme are given, where the true identity of the signer will be protected against both the verifier and other signers contributing to the signature. Furthermore, we present a concrete ARS scheme that can aggregate multiple signatures produced by different signers of the same ring, by exploiting the compressed$\Sigma $-protocol. There are no interactions required among signers and only one single round between each signer and the aggregator. Building on the proposed ARS scheme, we present a confidential transaction (CT) protocol called ARSCT. The latter allows multiple transactions to be aggregated into one transaction. Finally, the formal security proof demonstrates our proposed ARS scheme achieves both anonymity and unforgeability, where signers’ anonymity is protected against both the verifier and the aggregator. Performance evaluations show that in simultaneous multiple signers situation, our scheme outperforms other mainstream ring signature schemes in verification efficiency.
Xiaohui Tong, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2025 Linkable, k-Times Traceable, and Revocable Ring Signature for Fine-Grained Accountability in Blockchain Transactions
abstract
Ring signatures are a useful cryptographic technique for anonymous transactions on the blockchain, which allows a user to sign a message on behalf of a group, without revealing which specific member of the group did the signing. However, the anonymity it provides can at times be too powerful and needs to be controlled when used in practice (e.g., on a reliable blockchain anonymous transaction system). In order to address this issue, we propose a linkable, k-times traceable and revocable ring signature (Lk-TRS). Specifically, with respect to the same issue, Lk-TRS not only establishes links among fewer than k signatures of a signer but also enables tracing of the identity when the signer signs k times. Based on our Lk-TRS, we propose a blockchain anonymous transaction system that supports the identity binding of a single user to multiple accounts, as well as the dynamic joining and exiting of users. This ensures the system meets practical requirements and offers runtime flexibility. We prove that our Lk-TRS achieves anonymity, unforgeability, linkability, k-traceability, and exculpability. Compared to the state-of-the-art, our Lk-TRS is more practical for large blockchain systems, maintaining a constant signature size regardless of the ring size.
Jinghuan Xie, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2025 MuEOC: Efficient SGX-Based Multi-Key Homomorphic Outsourcing Computation for E-Health System
abstract
While techniques such as Homomorphic Encryption (HE) and Intel Software Guard Extensions (SGX) have been leveraged to secure outsourced electronic health record (EHR) computation, there are a number of known limitations (e.g., performance bottlenecks, lack of desired functionalities, or the reliance on a trusted third party). To address these challenging issues, this paper proposes MuEOC, an SGX-based multi-key homomorphic outsourcing computation scheme without a trusted third party. MuEOC is designed to support arbitrary depth multiplication and multi-key setup. In our approach, we first propose an SGX-assisted fully homomorphic encryption scheme (XFHE) under the randomized AGCD assumption. This allows us to replace costly bootstrapping with re-encryption in the enclave, and enable key-switching and Galois automorphism. Using XFHE as a building block, we construct a high-performance multi-key outsourcing computing protocol without the trusted third-party setup. Leveraging SGX, the MuEOC incorporates efficient sub-protocols of secure ciphertext transformation, secure polynomial evaluation, secure inner product, and secure non-linear function evaluation. We also present formal security proof which shows that our proposal guarantees the privacy of input EHR data and medical analysis results under the semi-honest model. Finally, experimental results demonstrate the outstanding efficiency of MuEOC.
Yisong Wang 0002, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.2
2025 Efficient Multilevel Threshold Changeable Homomorphic Data Encapsulation With Application to Privacy-Preserving Vehicle Positioning
abstract
Although the global navigation satellite system (GNSS) has been successfully applied in search and rescue operations for locating lost or damaged vehicles due to its significance in precise positioning, there are still challenges. To enhance the accuracy of localization, positioning can be done with the collaborative estimation provided by neighbouring mobile terminals as reference vehicles. Meanwhile, there are security and privacy implications associated with such an approach – e.g., potential for privacy leakage of both the positioning-related data (e.g., positions of reference vehicles, distances between reference vehicles and the target vehicle) and the estimated positions of the target vehicle. Such concerns are important to address in deployments for sensitive applications such as defense. For example, the location information of a damage vehicle on the battlefield should only be securely evaluated by search unit and be successfully decrypted by an authorized set of officers in rescue unit with the required authorization levels. Accordingly, the threshold should be flexibly allocated and changed for types of security surroundings. However, existing techniques of threshold public key homomorphic encryption approaches are not only computationally and communication intensive, but merely support a fixed pre-defined threshold. To address these challenges, we propose an efficient multilevel threshold changeable homomorphic data encapsulation mechanism (MCTh-HDEM). In MCTh-HDEM, we leverage the technique of multilevel threshold changeable secret sharing in order to support both batch encryption and lightweight matrix calculations in the encrypted domain, and also multilevel threshold changeable decryption. Then, we design a lightweight privacy-preserving vehicle positioning scheme (PPVPS), by refining our proposed MCTh-HDEM. The position of the lost and damaged target vehicle on the battlefield would be efficiently inferred by a set of reference vehicles in search unit while protecting positioning related data, and the target vehicle location can be flexibly decrypted by rescue unit. Finally, we give the formal security proofs of our proposed MCTh-HDEM and PPVPS. The performance evaluation and extensive experimental results demonstrate the efficiency and accuracy of our proposal.
Tianhui Zhou, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Trans. Intell. Transp. Syst.2
2024 An Efficient Integer-Wise ReLU on TFHE
Junping Wan, Zoe Lin Jiang, Jun Zhou 0018, Zhenfu Cao
ACISP (1)4
2024 Communication-Efficient Secure Neural Network via Key-Reduced Distributed Comparison Function
Peng Yang 0016, Zoe Lin Jiang, Shiqi Gao, Jun Zhou 0018, Yangyiye Jin, Siu-Ming Yiu
ProvSec (2)5
2024 Updatable Private Set Intersection With Forward Privacy
abstract
Private set intersection (PSI) facilitates the computation of intersection between the private sets of two parties, ensuring that no additional information beyond the intersection itself is revealed. However, most state-of-the-art are limited to static PSI, leaving updatable PSI untouched. Existing PSI protocols will cost huge computational resources to compute intersection on updated sets. More seriously, none of the existing updatable PSI approaches can achieve both secure addition and deletion operations in once update. To address these challenges, we propose Forward Private Updatable PSI (FUPSI) for two-party setting. FUPSI is designed to support addition and deletion simultaneously, while ensuring forward privacy against semi-honest adversaries. In this work, we analyze the infeasibility of secure synchronous addition and deletion in the existing updatable PSI approaches, by presenting a practical attack which would lead to privacy leakages while deletion function is performed. Then, to resist this attack against semi-honest adversaries, we demonstrate how FUPSI can protect the forward privacy of user sets, by utilizing a variant of keyword Private Information Retrieval (PIR) to hide sensitive intermediate parameters. Specifically in FUPSI, two parties execute keyword PIR to retrieve a flag indicating that the current element is added or deleted so as to determine whether it is in the participants’ datasets. Finally, we provide the formal security proof for our proposed FUPSI, and extensive experimental results demonstrate efficiency and the practicality of our proposal. For instance, the communication complexity of our proposal is only logarithmically related to the size of update sets and the computational overhead is mainly composed of logarithmical times PIR calculations. Owing to the variant of keyword PIR, our work also incurs minimal communication overhead even for enormous datasets, which performs well in updatable settings and slow networks.
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Trans. Inf. Forensics Secur.2
2023 An Efficient Autonomous Path Proxy Re-encryption Without Pairing for Cloud-Assisted mHealth
Linghui Chen, Zhiguo Wan, Jun Zhou 0018, Ivan Edmar Carvajal Roca
Inscrypt (2)3
2023 Mining for Better: An Energy-Recycling Consensus Algorithm to Enhance Stability with Deep Learning
Zhen Xia, Zhenfu Cao, Xiaolei Dong, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su
ISPEC5
2023 MMDSSE: Multi-client and Multi-keyword Dynamic Searchable Symmetric Encryption for Cloud Storage
abstract
Since data outsourcing poses privacy concerns with data leakage, searchable symmetric encryption (SSE) has emerged as a powerful solution that enables clients to perform query operations on encrypted data while preserving their privacy. Dynamic SSE schemes have been proposed to handle update operations. However, it is shown that updates might increase the risk of information leakage. Meanwhile, to meet the requirement of real-world applications, it is desirable to have the searchable encryption scheme which supports both multiple clients and multi-keyword queries. To address these issues, this paper proposes MMDSSE, a multi-client forward secure dynamic SSE scheme that supports multi-keyword queries. MMDSSE allows the clients narrow down the results by providing an arbitrary subset of the entire archive, and thus suitable for cloud storage environment. Security analysis and experimental evaluations show that MMDSSE is secure and efficient.
Panyu Wu, Zhenfu Cao, Xiaolei Dong, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su
PST6
2023 MDPPC: Efficient Scalable Multiparty Delegated PSI and PSI Cardinality
abstract
Private Set Intersection (PSI) is one of the most important functions in secure multiparty computation (MPC). PSI protocols have been a practical cryptographic primitive and there are many privacy-preserving applications based on PSI protocols such as computing conversion of advertising and distributed computation. Private Set Intersection Cardinality (PSI-CA) is a useful variant of PSI protocol. PSI and PSI-CA allow several parties, each holding a private set, to jointly compute the intersection and cardinality, respectively without leaking any additional information. Nowadays, most PSI protocols mainly focus on two-party settings, while in multiparty settings, parties are able to share more valuable information and thus more desirable. On the other hand, with the advent of cloud computing, delegating computation to an untrusted server becomes an interesting problem. However, most existing delegated PSI protocols are unable to efficiently scale to multiple clients. In order to solve these problems, this paper proposes MDPPC, an efficient PSI protocol which supports scalable multiparty delegated PSI and PSI-CA operations. Security analysis shows that MDPPC is secure against semi-honest adversaries and it allows any number of colluding clients. For 15 parties with set size of 220on server side and 216on clients side, MDPPC costs only 81 seconds in PSI and 80 seconds in PSI-CA, respectively. The experimental results show that MDPPC has high scalability.
Xiaolei Dong, Zhenfu Cao, Yunbo Yang, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su, Zongyang Hou
PST6
2023 BLDSS: A Blockchain-Based Lightweight Searchable Data Sharing Scheme in Vehicular Social Networks
abstract
Vehicular social networks (VSNs) are likely to play an increasingly important role of the future smart cities, supporting traffic management, real-time warning, and sharing data (e.g., condition, vehicular, and warning). However, there are existing security and privacy issues with vehicular data, which directly lead to the insufficient utilization of vehicular data. In this article, a blockchain-based lightweight searchable data sharing scheme is presented. Specifically, the proposed protocol achieves efficient data matching and data sharing by uniting the feature of public-key encryption with equality test (PKE-ET) and proxy re-encryption (PRE), meanwhile ensuring reliable matching results by invoking smart contacts. Moreover, a reputation-based dynamic PBFT consensus mechanism is provided. By analyzing the reputation and behavior of the consensus nodes, we further reduce the probability of malicious nodes becoming the consensus nodes, thus decreasing the computing overhead and communication costs in the consensus process. Finally, the security of the proposed protocol is demonstrated based on a computation Diffie–Hellman assumption in the Random Oracle model. According to the performance analysis, it was found that compared to the other protocols, the proposed protocol is computationally lightweight.
Yuanjian Zhou, Zhenfu Cao, Xiaolei Dong, Jun Zhou 0018
IEEE Internet Things J.4
2023 Lightweight Privacy-Preserving Distributed Recommender System Using Tag-Based Multikey Fully Homomorphic Data Encapsulation
abstract
Recommender systems facilitate personalized service provision through the statistical analysis and model training of user historical data (e.g., browsing behavior, travel history, etc). To address the underpinning privacy implications associated with such systems, a number of privacy-preserving recommendation approaches have been presented. There are, however, limitations in many of these approaches. For example, approaches that apply public key (fully) homomorphic encryption (FHE) on different users. historical ratings under a unique public key of a target recommendation user incur significant computational overheads on resource-constrained local users and may not be scalable. On the other hand, approaches without utilizing public key FHE can neither resist chosen ciphertext attack (CCA), nor be straightforwardly applied to the setting of distributed servers. In this paper, a lightweight privacy-preserving distributed recommender system is proposed. Specifically, we present a new cryptographic primitive (i.e., tag-based multikey fully homomorphic data encapsulation mechanism; TMFH-DEM) designed to achieve CCA security for both input privacy and result privacy. TMFH-DEM enables a set of distributed servers to collaboratively execute efficient privacy-preserving outsourced computation on multiple inputs encrypted under different secret keys from different data owners, without using public key FHE. Building on TMFH-DEM, we propose a lightweight privacy-preserving distributed recommender system, which flexibly returns all the recommended items with certain predicted ratings for all target users. Formal security proof shows that our proposal achieves both user historical rating data privacy and recommendation result privacy. Findings from our evaluations demonstrate its practicability in terms of scalability, recommendation accuracy, computational and communication efficiency.
Jun Zhou 0018, Guobin Gao, Zhenfu Cao, Kim-Kwang Raymond Choo, Xiaolei Dong
IEEE Trans. Dependable Secur. Comput.1
2023 A Differentially Private Federated Learning Model Against Poisoning Attacks in Edge Computing
abstract
Federated learning is increasingly popular, as it allows us to circumvent challenges due to data islands, by training a global model using data from one or more data owners/sources. However, in edge computing, resource-constrained end devices are vulnerable to be compromised and abused to facilitate poisoning attacks. Privacy-preserving is another important property to consider when dealing with sensitive user data on end devices. Most existing approaches only consider either defending against poisoning attacks or supporting privacy, but not both properties simultaneously. In this paper, we propose a differentially private federated learning model against poisoning attacks, designed for edge computing deployment. First, we design a weight-based algorithm to perform anomaly detection on the parameters uploaded by end devices in edge nodes, which improves detection rate using only small-size validation datasets and minimizes the communication cost. Then, differential privacy technology is leveraged to protect the privacy of both data and model in an edge computing setting. We also evaluate and compare the detection performance in the presence of random and customized malicious end devices with the state-of-the-art, in terms of attack resiliency, communication and computation costs. Experimental results demonstrate that our scheme can achieve an optimal tradeoff between security, efficiency and accuracy.
Jun Zhou 0018, Yisong Wang 0002, Shouzhen Gu, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.1
2023 Generalized Autonomous Path Proxy Re-Encryption Scheme to Support Branch Functionality
abstract
Proxy Re-Encryption (PRE), a special cryptographic primitive, can efficiently perform ciphertext conversion on the cloud. To enable the data owner (i.e. delegator) to authorize a file access path according to the different priorities of the users (i.e. delegatees), autonomous path proxy re-encryption (AP-PRE) was proposed, where the delegator can generate a proxy re-encryption autonomous path in order of the delegatees’ priority. If one delegatee does not hold the decryption right, the ciphertext can be converted to a new ciphertext that can be decrypted by the next delegatee with lower priority in the path. Although AP-PRE enables the delegator to pre-define the whole decryption path, the access policy only supports a linked path and the data owner disallows the nodes in the proxy path to generate delegating branches to access its data. Such a linked path may be too long in practice, especially when the system scales up (i.e. the average complexity of encrypted data access isO(n)wherendenotes the number of delegatees). Hence, we propose a generalized autonomous path proxy re-encryption (APB-PRE) scheme for supporting branch functionality. Firstly, by setting the token and a carefully designed ciphertext structure, the branch functionality of the path delegation is realized. Specifically, we utilize the bilinearity of bilinear pairing to construct the token for the transition of the label embedded in the ciphertext in different paths, resulting in a far more flexible access structure with a tree-like topology. In APB-PRE, the delegatees with lower priority who need to share data can complete the decryption task earlier, without affecting the decryption of the high-priority delegatees. Finally, we prove that it achieves IND-HRA security under the Decisional Bilinear Diffie-Hellman (DBDH) assumption. Benefiting from the creation of branching paths, users on the branching path can get the re-encrypted ciphertext much earlier. Therefore, the average complexity of encrypted data access reduces toO(log n)compared to AP-PRE. The experimental results show that our proposal can extend the branching functionalities of AP-PRE with only moderate computational cost.
Zhongyun Lin, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Trans. Inf. Forensics Secur.2
2023 EPNS: Efficient Privacy-Preserving Intelligent Traffic Navigation From Multiparty Delegated Computation in Cloud-Assisted VANETs
abstract
Real-time navigation is a fundamental service with the emerging techniques of intelligent transportation and crowdsensing. Unfortunately, the breach of location privacy significantly impedes its wide adoption. Most existing state-of-the-art exploit either pseudonyms or public key fully homomorphic encryption (FHE) to protect location privacy, which requires an online certificate authority (CA) or loads intolerably heavy computational/communication overhead on resource-constrained vehicular users. In this paper, a new cryptographic primitive named efficient multiparty delegated computation (MPDC) is firstly proposed, where any one-way trapdoor permutation is required to perform constant times (i.e. twice) on each resource-constrained data provider, to encrypt a batch of messages and enable types of secure evaluations over ciphertexts encrypted under multiple keys of multiple parties. Based on MPDC, we devise a lightweight privacy-preserving real-time intelligent traffic navigation scheme (EPNS) in cloud-assisted VANETs. The proposed approach predicts an optimal driving route of shortest time without disclosing either vehicular users' private location or the navigation result to the collusion between the semi-trusted cloud/cryptography service provider (CSP) and unauthorized users, by securely evaluating auto-regression moving average (ARMA) model with spatiotemporal correlations of high accuracy and efficiency. Finally, formal security proofs and the extensive evaluations demonstrate the utility and the practicability of our approaches.
Jun Zhou 0018, Shiying Chen, Kim-Kwang Raymond Choo, Zhenfu Cao, Xiaolei Dong
IEEE Trans. Mob. Comput.1
2022 Multi-interest Sequence Modeling for Recommendation with Causal Embedding
abstract
Recent methods in sequential recommendation focus on learning multi-interest embedding vectors from a user's behavior sequence for the next-item recommendation. However, behavior sequential data may result from users' conformity towards popular items, which entangles users' real interests and tends to recommend popular items by using interest embeddings. In this paper, we propose a novel multi-interest framework with causal embedding for sequential recommendation, called MiceRec. Specifically, we first obtain two embedding layers from behavior sequence by assigning items with separate embeddings for interest and conformity, then extract multiple pure interests from one embedding layer, while the other for users' conformity extraction. According to the colliding effect of causal inference, we mine cause-specific data for training causal embeddings. Our framework significantly outperforms state-of-the-art solutions on two real-world datasets1. We further demonstrate that the learned multi-interest embeddings successfully separate from each other, and show that conformity information is almost squeezed out from interest embeddings.
Caiqi Sun, Penghao Lu, Lei Cheng 0005, Zhenfu Cao, Xiaolei Dong, Yili Tang, Jun Zhou 0018, Linjian Mo
SDM7
2022 Efficient Privacy-Preserving Outsourced Discrete Wavelet Transform in the Encrypted Domain
abstract
Signal processing in the encrypted domain is a potential tool to protect sensitive signals against untrusted cloud servers and unauthorized users in the delegated computing setting, without affecting the accuracy of large volume of signal analyzing and processing. Most existing approaches use Paillier’s public key additively homomorphic encryption to encrypt each signal in a large bundle; thus, incurring significant computational costs at local, often resource-constrained, devices while guaranteeing only signal input privacy. To address these limitations, in this paper, an efficient privacy-preserving outsourced discrete wavelet transform scheme (PPDWT), comprising PPDWT-1 and PPDWT-2, without leveraging public key (fully) homomorphic encryption is proposed. Specifically, PPDWT-1 is proposed to achieve signal input privacy against the collusion between the honest-but-curious cloud and unauthorized users, and the proposed PPDWT-2 protects both signal input privacy and coefficient privacy against collusion attacks. Both constructions leverage the offline execution of any one-way trapdoor permutation only once to encrypt batch signals, and permit signal processing in the encrypted domain. In our approach, only authorized users can successfully decipher the result of discrete wavelet transform. Compared to the$O(|l|)$computational complexity on the user’s end in existing state-of-the-art public key homomorphic encryption-based techniques, our approach only incurs$O(1)$computational complexity which is independent to size of the signal inputs$|l|$. We also discuss the expanding factor, the upper bound and various extensions to privacy-preserving discrete cosine/fourier transform in the encrypted domain. Finally, our proposed PPDWT is formally proved secure under the universal composability (UC) model. We then evaluate the proposed approach using case studies to demonstrate its effectiveness and practicability.
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Trans. Cloud Comput.1
2022 SAVE: Efficient Privacy-Preserving Location-Based Service Bundle Authentication in Self-Organizing Vehicular Social Networks
abstract
Self-organizing vehicular social networks underpin many location-based services (LBS) such as those that collect and share environmental information (e.g., traffic and weather conditions) among vehicular users and the infrastructure. There are, however, security and privacy considerations in the sharing of such information, and one popular approach is to design lightweight authentication solutions for LBS. Existing approaches may suffer from limitations such as significant computational and/or storage overheads, latency and time delays, and consequently impractical for resource-constrained on-board units. In this paper, we propose an efficient privacy-preserving LBS bundle authentication scheme (hereafter referred to as SAVE) through secure redundancy filtering in self-organizing vehicular social networks. Firstly, an enhanced self-healing key distribution protocol with distributed revocation is proposed to reduce communication cost for retransmitting lost key material and resist free-riding attacks to enhance the authentication efficiency. Then, based on it, a generalized version of online/offline aggregate signature is proposed to achieve batch LBS bundle verification based on arbitrary one-way function holding the property of multiplicative homomorphism. Finally, an efficient zero-knowledge range proof based on lightweight one-way hash chain is designed to decide the redundancy of LBS bundles without disclosing vehicular users’ location privacy. Formal security proof and extensive simulation results demonstrate that our proposed SAVE achieves identity privacy, two levels of location privacy and the practicability in reality.
Ying Chen 0030, Tianhui Zhou, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Trans. Intell. Transp. Syst.3
2021 PADP: Efficient Privacy-Preserving Data Aggregation and Dynamic Pricing for Vehicle-to-Grid Networks
abstract
With the fast development of Internet of Things (IoT) especially for smart grid and electric vehicle (EV) networking, vehicle-to-grid (V2G) communications have been increasingly studied and recognized as one of the most convincing tools for general road transportation, to effectively reduce the oil demands and gas emissions. Unfortunately, a series of security and privacy issues have significantly impeded its wide adoption. The existing work mainly focused on the static environment, which cannot be directly applied to the mobile setting where EVs travel across regions. The dynamic pricing metric in V2G networks depends on the real-time electricity usage aggregation in one region. To address this issue, in this article, an efficient privacy-preserving data aggregation and dynamic pricing service PADP in V2G IoT is proposed, by designing an identity-based sequential aggregate signed data (SASD) based on factoring and a threshold homomorphic encryption. In the proposed threshold homomorphic encryption, a legal ciphertext can be generated if and only if no less than threshold k individual illegal ciphertexts are aggregated. Therefore, the aggregated power consumption data can be successfully decrypted while the individual power consumption privacy of honest EV users can be well protected against even the collusion between a malicious power charging station and compromised EVs. Furthermore, the technique of SASD guarantees entity authentication with a minimized amount of transmitted data. Finally, formal security proof and extensive performance evaluation demonstrate the effectiveness and practicability of our proposed PADP.
Linghui Chen, Jun Zhou 0018, Ying Chen 0030, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2021 PVOPM: Verifiable Privacy-Preserving Pattern Matching with Efficient Outsourcing in the Malicious Setting
abstract
Outsourced pattern matching delegates the task of finding all positions pattern$P$appears in text$T$to the cloud from resource-constrained devices. Unfortunately, it has brought a series of security and privacy issues. Most of the state-of-the-art either disclosed text/pattern privacy or exploited the computationally-intensive techniques of public key fully homomorphic encryption (FHE), commitment schemes and zero knowledge proof to achieve both text/pattern privacy and verifiability. To address these issues, as a building block, an efficient privacy preserving verifiable outsourced discrete fourier transform protocol OVFT is first devised based on any one-way trapdoor permutation (OWTP). Based on OVFT, we propose an efficient secure verifiable outsourced polynomial multiplication protocol OPVML which is further exploited in designing our final protocol PVOPM for verifiable privacy-preserving outsourced pattern matching. Without exploiting public key FHE, the proposed PVOPM achieves both verifiability and text/pattern privacy against the collusion between the cloud and malicious receiver/sender, by generating authentication proofs of constant size and executing constant times of any one-way trapdoor permutation, independent to both the text size$n$and the pattern size$m$. Finally, formal security proof under universal composable (UC) model and extensive evaluations demonstrate the efficiency and practicability of our proposed PVOPM.
Jun Zhou 0018, Kim-Kwang Raymond Choo, Zhenfu Cao, Xiaolei Dong
IEEE Trans. Dependable Secur. Comput.1
2020 PVIDM: Privacy-preserving verifiable shape context based image denoising and matching with efficient outsourcing in the malicious setting
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong
Comput. Secur.1
2020 Lightweight Privacy-Preserving Training and Evaluation for Discretized Neural Networks
abstract
Machine learning, particularly the neural network (NN), is extensively exploited in dizzying applications. In order to reduce the burden of computing for resource-constrained clients, a large number of historical private datasets are required to be outsourced to the semi-trusted or malicious cloud for model training and evaluation. To achieve privacy preservation, most of the existing work either exploited the technique of public key fully homomorphic encryption (FHE) resulting in considerable computational cost and ciphertext expansion, or secure multiparty computation (SMC) requiring multiple rounds of interactions between user and cloud. To address these issues, in this article, a lightweight privacy-preserving model training and evaluation scheme LPTE for discretized NNs (DiNNs) is proposed. First, we put forward an efficient single key fully homomorphic data encapsulation mechanism (SFH-DEM) without exploiting public key FHE. Based on SFH-DEM, a series of atomic calculations over the encrypted domain, including multivariate polynomial, nonlinear activation function, gradient function, and maximum operations are devised as building blocks. Furthermore, a lightweight privacy-preserving model training and evaluation scheme LPTE for DiNNs is proposed, which can also be extended to convolutional NN. Finally, we give the formal security proofs for dataset privacy, model training privacy, and model evaluation privacy under the semi-honest environment and implement the experiment on real dataset MNIST for recognizing handwritten numbers in DiNN to demonstrate the high efficiency and accuracy of our proposed LPTE.
Jun Zhou 0018, Zhenfu Cao, Athanasios V. Vasilakos, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2020 Blockchain-Based Lightweight Certificate Authority for Efficient Privacy-Preserving Location-Based Service in Vehicular Social Networks
abstract
Blockchain can be utilized to enhance both security and efficiency for location-based service (LBS) in vehicular social networks (VSNs), due to its inherent decentralization, anonymity, and trust properties. Unfortunately, the existing approaches either lack effective authentication, which is vulnerable to the man-in-the-middle attack, or require an online certificate authority (CA) where frequent interactions with resource-constrained vehicles are required. To address these challenging issues, in this article, a lightweight threshold CA for consortium blockchain along with a privacy-preserving LBS protocol in blockchain enforced VSNs is proposed. First, a lightweight threshold CA framework LTCA is proposed by devising a threshold proxy signature, where the proxy signing key is issued by a coalition of threshold number of CAs playing the roles of authorized nodes in the consortium blockchain. Without the intervene of an online CA, each vehicle in the online phase can authenticate its identity by itself each time its blockchain address (i.e., account address) is updated. Then, based on the proposed LTCA, an efficient privacy-preserving LBS protocol PPVC is contrived to protect each vehicle’s conditional identity privacy with a moderate cost. Finally, both security analysis and performance evaluation demonstrate the effectiveness and efficiency of our proposed LTCA and PPVC in blockchain enforced VSNs.
Huajie Shen, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2020 LPPA: Lightweight Privacy-Preserving Authentication From Efficient Multi-Key Secure Outsourced Computation for Location-Based Services in VANETs
abstract
Location-based service (LBS) in vehicular ad hoc networks (VANETs) has significantly benefited information acquisition from geographically-based social networking. Authentication guarantees the unforgeability and the effectiveness of the LBS information. Unfortunately, owing to a large quantity of redundant or useless LBS messages disseminated in VANETs, the heavy authentication overhead of the existing work adopting a periodically released authentication key, filtering with message identifiers or exploiting public key (fully) homomorphic encryption (FHE), is either intolerable by resource-constrained on-board units (OBUs) or inappropriate to the realtime controlling requirement for VANETs. In this paper, an efficient multi-key secure outsourced computation scheme MSOC without exploiting public key FHE is first proposed, in the setting of two non-colluding servers, namely the cloud and the cryptographic service provider (CSP). Then, based on MSOC, an efficient and secure comparison protocol LSCP is devised, without the interaction between the server and the users. Furthermore, a lightweight privacy-preserving authentication protocol LPPA for LBS in VANETs is proposed, by eliminating duplicate and useless encrypted LBS messages before authentication is executed, through a newly devised efficient privacy-preserving information filtering system. Both user’s location privacy and interest privacy are well protected against even the collusion between the roadside units (RSUs) serving as the cloud (or CSP) and malicious users. Especially, the property of ciphertext re-encryption of our proposed MSOC also guarantees the interest pattern privacy whether two users accept the same LBS information. Finally, formal security proof and extensive simulation results verify the effectiveness and practicability of our proposed LPPA.
Jun Zhou 0018, Zhenfu Cao, Zhan Qin, Xiaolei Dong, Kui Ren 0001
IEEE Trans. Inf. Forensics Secur.1
2019 PPSAS: Lightweight Privacy-preserving Spectrum Aggregation and Auction in Cognitive Radio Networks
abstract
Cognitive radio network (CRN) enables dynamic spectrum management where spectrum aggregation and sharing have significantly facilitated relieving the supply-demand gap among skyrocketing number of mobile devices. Secondary users (SUs) can collaboratively detect and exploit the available spectrums of primary users (PUs) from different locations. Unfortunately, it has brought a series of security threats leaking user's location privacy to unauthorized entities. The existing work either had privacy breaches or depended on computationally-intensive public key homomorphic encryption loading intolerably high complexity on resource-constrained SUs. To well address these issues, in this paper, a lightweight privacy-preserving spectrum aggregation and auction scheme PPSAS is proposed in CRNs without leveraging public key homomorphic encryption. Firstly, a new primitive of efficient privacy preserving multiparty data aggregation protocol PPMDA is proposed based on any one-way trapdoor permutation. Then based on PPMDA, an efficient privacy preserving spectrum aggregation scheme PPSRA and spectrum auction scheme PPSSA are respectively devised to constitute our proposed PPSAS. Especially, a decentralized PPMDA is extended to resist collusion attack and a secure extended outsourced stable complete marriage matching protocol is given to flexibly realize SU/auctioneer optimization. Finally, formal security proof and extensive simulations demonstrate that our proposed PPSAS well protects the SUs' location privacy against collusion attacks and possesses the advantages over the sate-of-the-art in terms of auctioneer's revenue, SUs' satisfaction, computational and communication overhead.
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong
ICDCS1
2019 GTSIM-POP: Game theory based secure incentive mechanism and patient-optimized privacy-preserving packet forwarding scheme in m-healthcare social networks
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Athanasios V. Vasilakos
Future Gener. Comput. Syst.1
2018 PPOIM: Privacy-Preserving Shape Context Based Image Denoising and Matching with Efficient Outsourcing
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong
ICICS2
2018 Data service generation framework from heterogeneous printed forms using semantic link discovery
Han Yu 0005, Hongming Cai 0001, Jun Zhou 0018, Lihong Jiang
Future Gener. Comput. Syst.3
2018 Model-Driven Development Patterns for Mobile Services in Cloud of Things
abstract
Cloud of Things (CoT) is an integration of Internet of Things (IoT) and cloud computing for intelligent and smart application especially in mobile environment. Model Driven Architecture (MDA) is used to develop Software as a Service (SaaS) so as to facilitate mobile application development by relieving developers from technical details. However, traditional service composition or mashup are somewhat unavailable due to complex relations and heterogeneous deployed environments. For the purpose of building cloud-enabled mobile applications in a configurable and adaptive way, Model-Driven Development Patterns based on semantic reasoning mechanism are provided towards CoT application development. Firstly, a meta-model covering both multi-view business elements and service components are provided for model transformation. Then, based on formal representation of models, three patterns from different tiers of Model-View-Controller (MVC) framework are used to transform business models into service component system so as to configure cloud services rapidly. Lastly, a related software platform is also provided for verification. The result shows that the platform is applicable for rapid system development by means of various service integration patterns.
Hongming Cai 0001, Yizhi Gu, Athanasios V. Vasilakos, Boyi Xu, Jun Zhou 0018
IEEE Trans. Cloud Comput.5
2016 PPOPM: More Efficient Privacy Preserving Outsourced Pattern Matching
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong
ESORICS (1)1
2016 Efficient privacy-preserving temporal and spacial data aggregation for smart grid communications
abstract
Summary Smart grid is ever‐increasingly adopted by nations and governments for its grand development with the underlying technologies of power management and information communications. The real‐time electricity usage can be monitored and aggregated by the smart meters deployed in the household for further analysis, control, and pricing. However, the existing solutions mainly depend on Paillier's additive homomorphic encryptions taking high computational complexity, and the aggregation mainly focused on the time series data generated by one single user. In this paper, we propose an efficient privacy‐preserving temporal and spacial data aggregation from one‐way functions in smart grid communications, which also allows spacial data aggregation from multiple users. The proposed construction can guarantee the unconditional security of users' metering power data privacy from the community gateway and the operation center, and the Adaptive Chosen Ciphertext Attack (CCA2) security of the aggregation result that can only be accessed by the authorized operating center. Both temporal and spacial data aggregation only require computing the underlying one‐way function once. The formal security proof and performance evaluations demonstrate the efficiency and the practicability of our scheme. Copyright © 2015 John Wiley & Sons, Ltd.
Xiaolei Dong, Jun Zhou 0018, Zhenfu Cao
Concurr. Comput. Pract. Exp.2
2016 Secure and efficient fine-grained multiple file sharing in cloud-assisted crowd sensing networks
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong
Peer-to-Peer Netw. Appl.1
2015 EVOC: More efficient verifiable outsourced computation from any one-way trapdoor function
abstract
Verifiable outsourced computation enables a computational resource-constrained mobile device to outsource the computation of a function F on multiple inputs x1, …, xnto the cloud that is generally assumed to possess abundant powers. The most existing work depends on Yao's Garbled Circuit and fully homomorphic encryptions that took considerable computational overhead on weak clients. In this paper, a more efficient verifiable outsourced computation of encrypted data EVOC supporting any functions from any one-way trapdoor function is proposed, based on our newly-devised privacy preserving data aggregation supporting both addition and multiplication operations without exploiting fully homomorphic encryption (FHE). It solves the open problem suggested by Gennaro et al. that how to devise a verifiable computation scheme that used a more efficient primitive than FHE. Finally, the formal security proof and extensive efficiency evaluations demonstrate our proposed EVOC satisfies the target security and privacy requirements and far outperforms the state-of-the-art in terms of computational and communication complexity.
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Xiaodong Lin 0001
ICC1
2015 TR-MABE: White-box traceable and revocable multi-authority attribute-based encryption and its applications to multi-level privacy-preserving e-healthcare cloud computing systems
abstract
Cloud-assisted e-healthcare systems significantly facilitate the patients to outsource their personal health information (PHI) for medical treatment of high quality and efficiency. Unfortunately, a series of unaddressed security and privacy issues dramatically impede its practicability and popularity. In e-healthcare systems, it is expected that only the primary physicians responsible for the patients treatment can not only access the PHI content but verify the real identity of the patient. Secondary physicians participating in medical consultation and/or research tasks, however, are only permitted to view or use the content of the protected PHI, while unauthorized entities cannot obtain anything. Existing work mainly focuses on patients conditional identity privacy by exploiting group signatures, which are very computationally costly. In this paper, we propose a white-box traceable and revocable multi-authority attribute-based encryption named TR-MABE to efficiently achieve multilevel privacy preservation without introducing additional special signatures. It can efficiently prevent secondary physicians from knowing the patients identity. Also, it can efficiently track the physicians who leak secret keys used to protect patients identity and PHI. Finally, formal security proof and extensive simulations demonstrate the effectiveness and practicability of our proposed TR-MABE in e-healthcare cloud computing systems.
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Xiaodong Lin 0001
INFOCOM1
2015 4S: A secure and privacy-preserving key management scheme for cloud-assisted wireless body area network in m-healthcare social networks
Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Naixue Xiong, Athanasios V. Vasilakos
Inf. Sci.1
2015 Secure and privacy preserving protocol for cloud-based vehicular DTNs
abstract
Cloud-assisted vehicular delay tolerant networks (DTNs) have been utilized in wide-ranging applications where a continuous end-to-end connection is unavailable, the message transmission is fulfilled by the cooperation among vehicular nodes and follows a store-carry-and-forward manner, and the complex computational work can be delegated to the disengaged vehicles in the parking lots which constitute the potential vehicular cloud. Nevertheless, the existing incentive schemes as well as the packet forwarding protocols cannot well model continuous vehicle collaboration, resist vehicle compromise attacks and collusion attacks, leaving the privacy preservation issues untouched. In this paper, a novel threshold credit-based incentive mechanism (TCBI) is proposed based on the modified model of population dynamics to efficiently resist the node compromise attacks, stimulate the cooperation among intermediate nodes, maximize vehicular nodes’ interest, and realize the fairness of possessing the same opportunity of transmitting packets for credits. Then, a TCBI-based privacy-preserving packet forwarding protocol is proposed to solve the open problem of resisting layer-adding attack by outsourcing the privacy-preserving aggregated transmission evidence generation for multiple resource-constrained vehicles to the cloud side from performing any one-way trapdoor function only once. The vehicle privacy is well protected from both the cloud and transportation manager. Finally, formal security proof and the extensive simulation show the effectiveness of our proposed TCBI in resisting the sophisticated attacks and the efficiency in terms of high reliability, high delivery ratio, and low average delay in cloud-assisted vehicular DTNs.
Jun Zhou 0018, Xiaolei Dong, Zhenfu Cao, Athanasios V. Vasilakos
IEEE Trans. Inf. Forensics Secur.1
2015 PSMPA: Patient Self-Controllable and Multi-Level Privacy-Preserving Cooperative Authentication in Distributedm-Healthcare Cloud Computing System
abstract
Distributed m-healthcare cloud computing system significantly facilitates efficient patient treatment for medical consultation by sharing personal health information among healthcare providers. However, it brings about the challenge of keeping both the data confidentiality and patients’ identity privacy simultaneously. Many existing access control and anonymous authentication schemes cannot be straightforwardly exploited. To solve the problem, in this paper, a novel authorized accessible privacy model (AAPM) is established. Patients can authorize physicians by setting an access tree supporting flexible threshold predicates. Then, based on it, by devising a new technique of attribute-based designated verifier signature, a patient self-controllable multi-level privacy-preserving cooperative authentication scheme (PSMPA) realizing three levels of security and privacy requirement in distributed m-healthcare cloud computing system is proposed. The directly authorized physicians, the indirectly authorized physicians and the unauthorized persons in medical consultation can respectively decipher the personal health information and/or verify patients’ identities by satisfying the access tree with their own attribute sets. Finally, the formal security proof and simulation results illustrate our scheme can resist various kinds of attacks and far outperforms the previous ones in terms of computational, communication and storage overhead.
Jun Zhou 0018, Xiaodong Lin 0001, Xiaolei Dong, Zhenfu Cao
IEEE Trans. Parallel Distributed Syst.1
2014 An ElGamal-based efficient and privacy-preserving data aggregation scheme for smart grid
abstract
Smart Grid technologies are ever-increasingly being adopted by nations and governments, primarily for a huge technological advancement in the areas of power management and information and communications. The smart meters deployed in a household can monitor electricity usage in real-time, and aggregate the data for further analysis and control; however, the existing solutions mainly depend on Paillier's additive homomorphic encryptions, which are of high computational complexity. This inefficiency makes them impracticable in smart grid, which embraces thousands of users and requires frequent data aggregation. In this paper, we propose a privacy-preserving aggregation framework, followed by a concrete construction using Elgamal encryption, which is secure under chosen plaintext attack (CPA) but not chosen ciphertext attack (CCA). Then, we further extend the concrete construction into a CCA-secure counterpart. In addition to efficient data aggregation, the proposed scheme can protect the user's meter data from sophisticated attacks, which are sponsored by the community gateway and the users. The formal security proof and performance evaluations illustrate the efficiency and the practicability of our scheme as well as its strong security.
Xiaolei Dong, Jun Zhou 0018, Khalid Nawaf Alharbi, Xiaodong Lin 0001, Zhenfu Cao
GLOBECOM2
2012 TIS: A threshold incentive scheme for secure and reliable data forwarding in vehicular Delay Tolerant Networks
abstract
Delay Tolerant Networks (DTNs) have been utilized in wide-raging applications where a continuous end-to-end connection is unavailable and the message transmission is fulfilled by the cooperation among DTN nodes and follows a store-carry-and-forward manner such as vehicular networks. A series of incentive schemes were proposed to stimulate the selfish nodes to take on the energy-consuming job of forwarding bundles. However, the Onboard Units (OBU) equipped on vehicles are vulnerable to node compromise attack and the existing incentive mechanisms cannot well resist such sophisticated attacks sponsored by colluding vehicles and model the continuous collaboration among vehicles. In this paper, a novel threshold credit-based incentive mechanism is proposed based on the modified model of population dynamics to efficiently prevent the node compromise attacks, stimulate the cooperation among intermediate nodes, maximize vehicular nodes' interests and realize the fairness of possessing the same opportunity to forward packets for credits. Then, based on it, a secure and reliable packet forwarding protocol TIS is proposed. By devising a time order-preserving aggregated signature scheme, it also effectively solves the open problem of resisting the layer-adding attack launched by the collusion of intermediate vehicles. Finally, the security analysis and the extensive simulations show the effectiveness of our proposed TIS in resisting the sophisticated attacks mentioned above and the efficiency in terms of high reliability, high delivery ratio and low average delay in vehicular DTNs.
Jun Zhou 0018, Zhenfu Cao
GLOBECOM1