VLDB 2026 Research / reviewers in the wild / expert
Yi Mu 0001
dblp:m/YiMu
· DBLP profile ↗
355ranked-venue papers
9as first author
45since 2021 · last 2026
0000-0002-1637-845XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 195 · 7 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 47 · 4 since 2021Databases, data management, data science and information retrieval · 26 · 5 since 2021Systems, architecture and hardware · 25 · 8 since 2021Computer networks · 21 · 1 first-author · 7 since 2021Theory of computation · 17 · 1 since 2021Software engineering, systems software and programming languages · 11 · 1 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 9 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dynamic Hub Labeling for Shortest Distance Queries on Structured Encrypted Graphs
Mengdi Hu, Lanxiang Chen, Yi Mu 0001 |
VLDB J. | 3 |
| 2025 | Laconic updatable private set intersection
Xiangqian Kong, Lanxiang Chen, Yizhao Zhu, Yi Mu 0001 |
J. Inf. Secur. Appl. | 4 |
| 2025 | Leakage Reduced Searchable Symmetric Encryption for Multi-Keyword QueriesabstractConjunctive keyword queries on untrusted cloud servers represent one of the most common forms of search in encrypted environments. Extensive research has been devoted to developing efficient schemes that support multi-keyword queries. In particular, the Oblivious Cross-Tags (OXT) protocol has received significant attention and is widely regarded as a benchmark in this domain. However, existing schemes fail to simultaneously hide the Keyword-Pair Result Pattern (KPRP) and the conditional Intersection Pattern (IP), potentially leaking additional information to the server. In this work, we propose a novel searchable symmetric encryption (SSE) scheme, referred to asResult Hiding Search (RHS), which aims to minimize result pattern leakage and achieve query result hiding during the index retrieval phase by integrating Private Set Intersection (PSI) techniques. Our scheme enhances privacy by employing PSI for secure membership testing. To improve query efficiency, we shift the expensive complex computation to the offline phase, and utilize efficient pseudorandom functions and hash functions during the online phase. Moreover, we propose a variant of RHS, called vRHS, designed to reduce client-side storage overhead. A simulation-based security proof demonstrates that our scheme is robust against non-adaptive adversaries. Comprehensive experimental evaluation further shows that our approach achieves better security and efficiency trade-offs compared to existing SSE schemes. Qinghua Deng, Lanxiang Chen, Yizhao Zhu, Yi Mu 0001 |
IEEE Trans. Cloud Comput. | 4 |
| 2025 | Private Reachability Queries on Structured Encrypted Temporal Bipartite GraphsabstractA temporal bipartite graph is a graph model that incorporates time-related information into its edges, making it suitable for modeling real-world phenomena like disease outbreaks. However, this temporal information is often sensitive. To protect the privacy of graph data, researchers have explored various approaches to preserve privacy in graph queries, with reachability queries being popular and fundamental as they determine the possibility of reaching one node from others in a graph. While privacy-preserving reachability queries have been extensively studied, existing efforts often overlook the valuable attribute information present in both edges and nodes of the graphs. Moreover, reachability queries on temporal bipartite graphs have not received sufficient attention in the literature. To bridge this gap, we propose a novel approach to achieve various privatereachabilityqueries onstructured encryptedtemporalbipartitegraphs ($\mathsf{RQ}$-$\mathsf{STBG}$) through a real-world scenario. Specifically, we construct a minimal index using hierarchical 2-hop labels and integrate structured encryption, order-revealing encryption, and garbled Bloom filters to support reachability queries with different label constraints. The proposed scheme is flexible and can cater to the query requirements of diverse users. Security analysis and experimental evaluations demonstrate that the proposed scheme achieves both preferable security and efficiency. Lanxiang Chen, Gaolin Chen, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Keyword-Pair Result Pattern Hiding Structured Encryption for Boolean QueriesabstractCash et al. [CRYPTO2013] proposed the oblivious cross-tags (OXT) protocol to enable highly scalable searchable symmetric encryption (SSE) with support for Boolean queries. More recently, Lai et al. [CCS2018] introduced the hidden cross-tags (HXT) protocol, an enhancement of OXT designed to eliminate “keyword-pair result pattern” (KPRP) leakage in conjunctive queries. However, while HXT prevents KPRP leakage in conjunctive queries, it suffers from low efficiency and remains vulnerable to KPRP leakage in disjunctive queries. In this paper, we propose the first efficient structured encryption scheme for Boolean queries (STE-BQ) that eliminates KPRP leakage for both disjunctive and conjunctive multi-keyword queries. Our approach introduces a novel index construction method based on prime number aggregation, which significantly reduces the number of comparisons required in multi-keyword searches, thereby improving efficiency. Security analysis confirms that STE-BQ satisfies CQA2-security. Experimental evaluations further demonstrate that STE-BQ achieves optimal performance in conjunctive query processing. While its disjunctive query time is slightly slower than that of OXT, STE-BQ is the only scheme that fully eliminates KPRP leakage for both conjunctive and disjunctive queries. Lanxiang Chen, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Practical and malicious private set intersection with improved efficiency
Yizhao Zhu, Lanxiang Chen, Yi Mu 0001 |
Theor. Comput. Sci. | 3 |
| 2024 | Monero With Multi-Grained RedactionabstractMonero is a privacy-centric cryptocurrency that allows users to obscure their transactions with multiple input and output addresses. Current research on Monero mainly focuses on identifying design vulnerabilities or optimizing towards stronger privacy, security, etc. For example, improving the design of ring confidential transaction (RingCT) protocol proposed by Noether et al. As revealed by Ali et al. in USENIX 2016, new blockchains have inadequate nodes and network computing resources to resist powerful attack (e.g., 51% attack). Obviously, Monero blockchain is not an exception. Ateniese et al. proposed the notion of redactable blockchain in EuroS$ \& amp;$P 2017, which begins the trend of formalizing blockchain with extra cryptographic primitives. The motivation is to turn an immutable blockchain into a mutable ledger by adapting the blockchain design and integrating with new cryptographic schemes. In such a setting, users could use their private keys to perform the secure multi-party computation to reverse blockchain history. The idea of redactable blockchain has attracted many researchers to pursuit this topic. However, few works have considered the privacy-preserving setting. Even fewer have practised their designs in an actual cryptocurrency. In this paper, we seek to adapt the RingCT protocol with several building blocks. Our proposal achieves most of the desired properties for blockchain redaction. It allows multiple tracing authorities to collaboratively trace users’ identities, and a system manager to perform multi-grained (including block-level, transaction-level, accumulator-level and commitment-level) redaction on block contents. Our proposal can be seen as an extension of RingCT protocol. We give rigorous security requirements and comprehensive analysis of our scheme. The performance evaluation suggested that our scheme suffers from some unscalabilities in large-scale implementations. A more elegant design to achieve stronger security and ideal scalability is deemed as a challenging and interesting future work. Ke Huang 0002, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaosong Zhang 0001, Xiong Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | A Pruned Pendant Vertex Based Index for Shortest Distance Query Under Structured Encrypted GraphabstractThe shortest distance query is used to determine the shortest distance between two vertices. Various graph encryption schemes have been proposed to achieve accurate, efficient and secure shortest distance queries for encrypted graphs. However, the majority of these schemes are inefficient or lack scalability due to the time-consuming index construction and large index storage. Moreover, none of them consider the trade-off between query efficiency and accuracy. To better trade off the query efficiency and accuracy, we propose a Pruned Pendant Vertex based Index for Shortest Distance Query ($\mathsf { PPVI}$-$\mathsf { SDQ}$) under structured encryption. The proposed scheme utilizes the structured encryption technique to encrypt a graph and build indexes. The main idea is to use the recursive method to repeatedly prune the pendant vertex, and thereby reducing the index size and construction time by minimizing the redundant data storage and graph traversal. The proposed scheme achieves accurate, efficient and secure shortest distance query with privacy-preserving for encrypted graph. The security analysis demonstrates that the proposed scheme satisfies CQA2-security. Experimental results with real datasets show that the scheme achieves the optimal accuracy and efficiency. Mengdi Hu, Lanxiang Chen, Gaolin Chen, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Efficient Public-Key Searchable Encryption Scheme From PSI With Scalable Proxy ServersabstractPublic-key Encryption with Keyword Search (PEKS) enables secure keyword searches within encrypted data. At the same time, Public-key Authenticated Encryption with Keyword Search (PAEKS) enhances security by permitting authorized users to search specific keyword sets, protecting against Internal Keyword Guessing Attacks (IKGA). However, to the best of our knowledge, existing PEKS and PAEKS schemes typically require to generate a distinct set of keyword ciphertext for each data user, leading to storage, computation, and communication costs and the lack of support for multiple-keyword search. In this article, we introduce a novel, efficient public-key searchable encryption scheme from the private set intersection (PSI) with scalable proxy servers, using a PSI protocol with multiple proxy server settings, which achieves sub-linear complexity. Our scheme is secure against IKGA and supports multiple keyword searches and sharing one encrypted keyword set by multiple users. We introduce an efficient system model with scalable proxy servers, significantly reducing computational overhead through a divide-and-conquer approach. Our proposed scheme supports multiple data users, and multiple keyword searches, utilizing a single set of keyword ciphertext for multiple data users. We formally define a security model and present a comprehensive security proof to demonstrate that our scheme maintains ciphertext-indistinguishability and trapdoor-indistinguishability. Xiangqian Kong, Lanxiang Chen, Yizhao Zhu, Yi Mu 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | Identity-Based Encryption With Continuous Leakage-Resilient CCA Security From Static Complexity AssumptionabstractAbstract Although a large number of provably secure cryptographic primitives have been proposed in the literature, many of these schemes might be broken in practice because of various leakage attacks. Therefore, the leakage resilience should be considered in designing these primitives. However, in identity-based cryptography, most of the existing leakage-resilient identity-based encryption (IBE) schemes suffer some limitations: they either resist the leakage attacks in the selective identity security model or achieve the chosen-ciphertext attack (CCA) security based on a non-static assumption. In this paper, an IBE scheme with adaptive leakage-resilient CCA security is proposed, and its security is rigorously proved in the random oracle model under a classic static complexity assumption, e.g. decisional bilinear Diffie–Hellman assumption. In our construction, all elements of ciphertext are randomly distributed in the adversary’s view. Hence, the adversary cannot obtain any useful information of the user’s private key from the given ciphertexts. Moreover, a unique property of our construction is that the leakage parameter is independent of the plaintext space, which contributes a better leakage rate. Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Yi Mu 0001, Mingwu Zhang |
Comput. J. | 6 |
| 2023 | Leakage-resilient identity-based cryptography from minimal assumptions
Yanwei Zhou, Bo Yang 0003, Zirui Qiao, Zhe Xia, Mingwu Zhang, Yi Mu 0001 |
Des. Codes Cryptogr. | 6 |
| 2023 | C-Wall: Conflict-Resistance in Privacy-Preserving Cloud StorageabstractFollowing the success of cloud computing, it has been shown its importance to realize various access control models in the cloud storage setting. Chinese Wall is a traditional access control model in business for solving the conflict of interest (CoI) problem, and it would be very interesting to achieve conflict-resistant in cloud storage system. However, the access control model does not ensure the privacy of users, and it may reveal the user's interest, investment tendency, etc. Therefore, it raises a big challenge to implement the Chinese Wall without compromising the user's privacy. In this paper, we focus on the Chinese Wall model and apply it to the cloud storage while protecting the access patterns of users. Specifically, we first formulate the tree-based Chinese Wall access control and then propose the Chinese Wall Protocol (called C-Wall). We prove that our C-Wall not only realizes the conflict-resistant but also protects the user's privacy with universally composable security. Besides, we also apply C-Wall to privacy-preserving cloud storage and propose the C2-Wall, which not only maintains C-Wall's features, but also ensures the sensitive files from being touched by "honest-but-curious" cloud servers. Furthermore, we evaluate our C2-Wall by theoretical analysis and experimental validation. Experimental results show its effectiveness and efficiency for practical deployment. Xiaoguo Li, Tao Xiang 0001, Yi Mu 0001, Fuchun Guo, Zhongyuan Yao |
IEEE Trans. Cloud Comput. | 3 |
| 2023 | Toward Secure Data Computation and Outsource for Multi-User Cloud-Based IoTabstractCloud computing has promoted the success of Internet of Things (IoT) with offering abundant storage and computation resources where the data from IoT sensors can be remotely outsourced to the cloud servers, whereas storing, exchanging and processing data collected through IoT sensors via centralised or decentralised cloud servers make cloud-based IoT systems prone to internal or external attacks. To protect IoT data against potential malicious users and adversaries, some cryptographic schemes have been applied to ensure confidentiality and integrity of IoT data. It is however a challenging task to perform any arithmetical computations once data items are encrypted. Fully-homomorphic encryption which is based on lattices can, in principle, provide a solution, but it is unfortunately inefficient in computation and hence cannot be applied to IoT. Fully-homomorphic encryption is feasible when we allow the involvement of a semi-trusted server. However, it is challenging to provide such a system in the situation of distributed environments for shared IoT data. We solve this problem and provide a fully-homomorphic encryption scheme for cloud-based IoT applications. We introduce a new method with the aid of a semi-trusted server that can help compute the homomorphic multiplications without gaining any useful information of the encrypted data. We show how our scheme is applied to multi-user IoT security and prove its semantic security. We also conduct experiments to justify its efficiency and applicability to multi-user cloud-based IoT systems. Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang |
IEEE Trans. Cloud Comput. | 2 |
| 2023 | Authenticable Data Analytics Over Encrypted Data in the CloudabstractStatistical analytics on encrypted data requires a fully-homomorphic encryption (FHE) scheme. However, heavy computation overheads make FHE impractical. In this paper we propose a novel approach to achieve privacy-preserving statistical analysis on an encrypted database. The main idea of this work is to construct a privacy-preserving calculator to calculate attributes’ count values for later statistical analysis. To authenticate these encrypted count values, we adopt an authenticable additive homomorphic encryption scheme to construct the calculator. We formalize the notion of an authenticable privacy-preserving calculator that has properties of broadcasting and additive homomorphism. Further, we propose a cryptosystem based on binary vectors to achieve complex logic expressions for statistical analysis on encrypted data. With the aid of the proposed cryptographic calculator, we design several protocols for statistical analysis including conjunctive, disjunctive and complex logic expressions to achieve more complicated statistical functionalities. Experimental results show that the proposed scheme is feasible and practical. Lanxiang Chen, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | BE-TRDSS: Blockchain-Enabled Secure and Efficient Traceable-Revocable Data-Sharing Scheme in Industrial Internet of ThingsabstractAs an important component of the Industrial Internet of Things (IIoT), the smart factory uses IIoT and equipment-monitoring technology to collect data to reasonably arrange the production. A large number of data is collected and uploaded to the IIoT cloud platform. However, the IIoT cloud platform is semitrusted and has structural limitations and vulnerability, which makes it necessary to realize data dynamic security sharing and malicious users' tracking. In this article, we show that the most recent work on this issue is still vulnerable to security threats at first. Then, a blockchain-enabled dynamic and traceable data-sharing scheme for a smart factory is proposed. Blockchain performs the user authentication and stores the ciphertext index and public keys to avoid tampering with shared data. The tracking algorithm tracks malicious users and adds them to a revocation list embedded in the ciphertext. And the authority can flexibly select domain or user revocation as required. The LSSS access policy is hidden to protect user privacy, and the cloud server uses the match test algorithm to detect whether users meet the hidden access policy. Additionally, online–offline encryption and outsourced decryption improve the efficiency of the scheme where the ciphertext and the pairing operations required for decryption achieve constant size. A performance analysis shows that the scheme can resist a variety of collusion attacks, and simulations show that it outperforms current schemes. Ruonan Ma, Leyou Zhang, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha |
IEEE Trans. Ind. Informatics | 4 |
| 2023 | Global Combination and Clustering Based Differential Privacy Mixed Data PublishingabstractWith the rapid advancement of information technology, a large amount of high-value data have been generated. To exploit the potential value of big data and at the same time to protect individuals' sensitive information, a global combination and clustering based differential privacy (DP) mixed data publishing method is proposed in this paper. The main idea of the proposed method is to improve the truthfulness of the published data as well as to enhance the utility by shifting the sensitivity of query function from a single record to a group of records using$k$-median clustering algorithm. Specifically, to improve the accuracy and utility of categorical attributes, a global combination method is proposed to take the correlation among categorical attributes into account. The proposed combination method takes all categorical attributes as a unit and then applies the exponential mechanism to improve the data utility. Then we combine it with the$k$-median clustering with differential privacy to publish the mixed data. Theoretical analysis shows that the proposed method satisfies$\varepsilon$-differential privacy. Experimental results on real datasets illustrate that the proposed method has a much lower information loss and time overhead than the state-of-the-art approach for the same parameters. Lanxiang Chen, Lingfang Zeng, Yi Mu 0001, Leilei Chen |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2023 | CASE-SSE: Context-Aware Semantically Extensible Searchable Symmetric Encryption for Encrypted Cloud DataabstractTraditional searchable symmetric encryption (SSE) schemes rarely support context-aware semantic extension, and then lead to the searched results being incomplete or deviating from the user’s query intention. To address this problem, a new context-aware semantically extensible searchable symmetric encryption based on Word2vec model (CASE-SSE) is proposed to achieve context-aware semantic extension in this article. The proposed scheme utilizes outsourced datasets as corpora to extract all keywords for training the Word2vec model, and the trained results is the ontology knowledge base that can be used to extend the semantics of query keywords directly. Further, to facilitate multi-keyword search using the extended query vector, we use the$k$-means clustering algorithm to classify outsourced datasets. We then construct an AVL-tree index and an inverted index based on the classified results, thereby achieving efficient context-aware semantically extensible SSE. The security analysis indicates it is secure and effective. The experimental results show that our scheme is superior in both efficiency and accuracy. Lanxiang Chen, Yujie Xue, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | Authenticable Additive Homomorphic Scheme and its Application for MEC-Based IoTabstractThe integration of Internet of Things (IoT) and cloud computing are always seen as promising technologies to enhance streamlined data collection, share and exchange. Although the advances in edge computing, particularly mobile edge computing (MEC), could enhance the performance of data collection and computation via computing offloading, security and privacy impediments have made new challenges to data integrity and confidentiality, in particular when multiple edges or nodes at different locations collect IoT data. Homomorphic encryption therefore has shown promising advantages for cloud computing, offering arithmetic operations to be carried out on the encrypted data without revealing the secret key. While fully homomorphic encryption introduced by Gentry, in 2009, allows both additive and multiplicative operations, it has shown significant implementation drawbacks due to the parameters generation and memory consumption. In this work, we focus on partially homomorphic encryption, which can be efficiently computed. However, it is challenging to add authentication feature for the verification and aggregation capability. We propose a novel secure and privacy preserving authenticable homomorphic encryption (AHEC) scheme. We demonstrate an application of our AHEC scheme for MEC-based IoT systems and provide security analysis to prove that our scheme is secure against chosen plaintext attack (IND-CPA) and unforgeability (UNF) under DDH-ZN2 and Lift-DH-ZN2 assumptions. Experimental results show that our proposed scheme is efficient for practical applications. Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang |
IEEE Trans. Serv. Comput. | 2 |
| 2022 | Blockchain-based random auditor committee for integrity verification
Lanxiang Chen, Qingxiao Fu, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Min-Shiang Hwang |
Future Gener. Comput. Syst. | 3 |
| 2022 | BA-RMKABSE: Blockchain-aided Ranked Multi-keyword Attribute-based Searchable Encryption with Hiding Policy for Smart Health System
Jian Su 0004, Leyou Zhang, Yi Mu 0001 |
Future Gener. Comput. Syst. | 3 |
| 2022 | Blockchain-based deduplication with arbitration and incentivesabstractAbstract Cloud storage is an ideal platform to accommodate massive data. However, with the increasing number of various devices and improved processing power, the amount of generated data is becoming gigantic. Therefore, this calls for a cost‐effective way to outsource massively generated data to a remote server. Cloud service providers utilise deduplication technique which deduplicates redundant data by aborting identical uploading requests and deleting redundant files. However, current deduplication mechanisms mainly focus on the storage saving of the server, and ignore the sustainable and long‐term financial interests of servers and users. This is not helpful to expand outsourcing and deduplication services. Blockchain is an ideal solution to achieve an economical and incentive‐driven deduplication system. Though some current research studiess have integrated deduplication with blockchain, they did not utilise blockchain as a financial tool. Meanwhile, it lacks an arbitration mechanism to settle disputes between the server and the user, especially in a Bitcoin payment where the payment is not confirmed immediately and a dispute may occur. This creates a burden to achieve fair and transparent incentive‐based deduplication service. In this work, we construct a deduplication system with financial incentives for the server and the user based on Bitcoin. The data owner will pay money via Bitcoin to the server for outsourcing the file, but this fee can be compensated by charging deduplication users with some fees to acquire the deduplication service. The server and the user can receive revenues using deduplication service. Disputes on the fair distribution of incentives can be settled by our arbitration protocol with chameleon hashes as arbitration tags. We give concrete construction and security requirements for our proposed . The security analysis shows that our is theoretically secure. The performance evaluation shows that our proposed is acceptably efficient for the deduplication. Meanwhile, we evaluate and conclude that 1% of outsourcing fee (or less) is a reasonable and preferable price for each deduplication user to pay as compensation for data owner. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Yongcheng Gong |
IET Inf. Secur. | 3 |
| 2022 | Secure Decentralized Attribute-Based Sharing of Personal Health Records With BlockchainabstractPersonal health records (PHRs) are located in a patient-centered electronic health system in which users can store and share medical information. However, PHRs have recently been plagued by security issues, such as the leakage of personal health information, illegal access to patient data, and data tampering. Recent security developments, such as introducing an access control policy with attribute-based encryption (ABE) or utilizing blockchain, have only been partially successful in solving these issues. Ongoing challenges to PHR sharing include single points of failure, node cheating attacks, and fair keyword search issues. In this article, we tackle these challenges by introducing a distributed PHR-sharing scheme based on blockchain and ciphertext policy ABE (CP-ABE), which allows for fast and efficient encryption and decryption. Blockchain maintains the integrity and the tracing source of the data while also recording all operations on the data in the form of transactions. In addition, the blockchain nodes act as attribute authorities to construct the CP-ABE cryptosystem. The tracing of malicious blockchain nodes is realized by tracing cryptography algorithms. Furthermore, the fair retrieval of ciphertext is achieved by employing smart contracts. To overcome the limited storage capacity of blockchain, we adopt both the on-chain and off-chain storage modes in our new system. Security analysis indicates that our new scheme remains intact when threatened by an indistinguishable chosen plaintext attack (IND-CPA) and an indistinguishable chosen keywords attack (IND-CKA). As such, we conclude that our proposed approach is feasible and efficient. Leyou Zhang, Tianshuai Zhang, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha |
IEEE Internet Things J. | 4 |
| 2022 | A Secure and Efficient Decentralized Access Control Scheme Based on Blockchain for Vehicular Social NetworksabstractThe vehicular social network (VSN) is an emerging mobile communication system combining a vehicle ad hoc network (VANET) with a social network. It provides a new means of sharing, disseminating, and delivering data for passengers, drivers, and vehicles. However, a VSN may expose users’ private information, such as identities, location information, and trajectories, and tampering with shared data may lead to security and safety problems in vehicle systems. Considering the security and privacy preservation of shared data, we propose a lightweight decentralized multiauthority access control scheme based on ciphertext-policy attribute-based encryption (CP-ABE) and blockchain, by which a decentralized multiauthorization node supports vehicle users by performing lightweight calculations with the assistance of the vehicle cloud service provider (VCSP). We use blockchain to record storage and access transactions, achieving self-verification by users and tamper-resistance of ciphertexts. An improved smart contract reduces the workload of verification by users and achieves privacy preservation by hiding the policy. It supports user revocation and outsourced decryption, enabling more flexibility and better performance. A security and performance analysis shows that our scheme has clear advantages over existing schemes. Leyou Zhang, Ye Zhang 0026, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha |
IEEE Internet Things J. | 4 |
| 2022 | Structured encryption for knowledge graphs
Yujie Xue, Lanxiang Chen, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng |
Inf. Sci. | 3 |
| 2022 | Controllable software licensing system for sub-licensing
Manli Yuan, Yi Mu 0001, Fatemeh Rezaeibagha, Li Xu 0002, Xinyi Huang 0001 |
J. Inf. Secur. Appl. | 2 |
| 2022 | Blockchain-enabled multi-authorization and multi-cloud attribute-based keyword search over encrypted data in the cloud
Qing Wu 0005, Taotao Lai, Leyou Zhang, Yi Mu 0001, Fatemeh Rezaeibagha |
J. Syst. Archit. | 4 |
| 2022 | A traceable and revocable multi-authority access control scheme with privacy preserving for mHealth
Leyou Zhang, Chuchu Zhao, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha |
J. Syst. Archit. | 4 |
| 2022 | Publicly verifiable secure communication with user and data privacy
Zhongyuan Yao, Yi Mu 0001 |
Pers. Ubiquitous Comput. | 2 |
| 2022 | Bidirectional and Malleable Proof-of-Ownership for Large File in Cloud StorageabstractCloud storage is a cost-effective platform to accommodate massive data at low cost. However, advances of cloud services propel data generation, which pushes storage servers to its limit. Deduplication is a popular technique enjoyed by most current cloud servers, which detects and deletes redundant data to save storage and bandwidth. For security concerns, proof-of-ownership (PoW) can be used to guarantee ownership of data such that no malicious user could pass deduplication easily or utilize such mechanism for malicious purposes. Generally, PoW is implemented in static data archive where the data file is supposed to be read-only. However, to satisfy users’ needs for dynamical manipulation on data and support real-time data services, it is required to devise efficient PoW for dynamic archive. Inspired by malleable signature, which offers authentication even after its committed message changes, we propose the notion of bidirectional and malleable proof-of-ownership ($\sf {BM\mbox{-}PoW}$) for the above challenge. Our proposed$\sf {BM\mbox{-}PoW}$consists of bidirectional PoW (${\mbox{B-PoW}}$), malleable PoW (${\mbox{M-PoW}}$) and dispute arbitration protocol$\sf {DAP}$. While our${\mbox{B-PoW}}$is proposed for a static setting, the${\mbox{M-PoW}}$caters specifically for dynamic manipulation of data. In addition, our proposed arbitration protocol$\sf {DAP}$achieves accountable redaction which can arbitrate the originality of file ownership. We provide the security analysis of our proposal, and performance evaluation that suggests our proposed${\mbox{B-PoW}}$is secure and efficient for large file in static data archive. In addition, our proposed${\mbox{M-PoW}}$achieves acceptable performance under dynamic setting where data is supposed to be outsourced first and updated later in dynamic data archive. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | Authenticated Data Redaction With Accountability and TransparencyabstractA common practice in data redaction is removing sensitive information prior to data publication or release. In data-driven applications, one must be convinced that the redacted data is still trustworthy. Meanwhile, the data redactor must be held accountable for (malicious) redaction, which could change/hide the meaning of the original data. Motivated by these concerns, we present a novel solution for authenticated data redaction based on a new Redactable Signature Scheme with Implicit Accountability ($\mathsf {RSS}$RSS-$\mathsf {IA}$IA). In the event of a dispute, not only the original data signer but also the redactor can generate an evidence tag to unequivocally identify the party who produced the data/signature pair. Without the evidence tag, the redaction operation is transparent. Furthermore, the redactor can independently prove the trustworthiness of the redacted data, without any interaction with the original data signer. Our design is built on a new approach which adds accountability to any transparent redactable signature schemes. We show that the proposed design satisfies all the security goals with affordable cost. As an extension, we show how to realize accountable, transparent and authenticated data redaction in the multi-redactor setting. Jinhua Ma, Xinyi Huang 0001, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Cloud-Based Outsourcing for Enabling Privacy-Preserving Large-Scale Non-Negative Matrix FactorizationabstractIt is inevitable and evident that outsourcing complicated intensive tasks to public cloud vendors would be the primary option for resource-constrained clients in order to save cost. Unfortunately, the public cloud vendors are usually untrusted. They may inadvertently leak the data or misuse the user’s data, compromise user’s privacy or intentionally corrupt computational results to make the system unreliable. It is therefore important how to stop this happening whilst embracing the computational power of public cloud vendors. Non-negative matrix factorization (NMF) is a significant method for conducting data dimension reduction, which has been widely used in large-scale data processing. Nevertheless, due to its non-polynomial hardness, NMF cannot be conducted efficiently using local computation resources, especially when dealing with big data. Motivated by this issue, we address this by presenting a novel outsourced scheme for NMF (O-NMF), which aims to lessen clients’ computing burden and tackle secure problems faced by outsourcing NMF. Particularly, based on two non-collusion servers, O-NMF exploits Paillier homomorphism to preserve data privacy. Additionally, O-NMF allows a verification mechanism to assist clients in verifying returned results with high probability. Security analysis and experimental evaluation demonstrates that the validity and practicality of O-NMF is also provided in this work. Anmin Fu, Zhenzhu Chen, Yi Mu 0001, Willy Susilo, Yinxia Sun |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | Privacy-Preserving Reverse Nearest Neighbor Query Over Encrypted Spatial DataabstractWith the advent of cloud computing, it has become more and more popular to outsource various services to the cloud for releasing the burden of local data storage and maintenance. However, it may cause serious privacy problems because the cloud may be untrusted. In this article, we study the privacy-preserving reverse nearest neighbor (PPRNN) query over encrypted spatial data. First, we introduce the concept of reference-locked order-preserving encryption (RL-OPE) with its construction and security proof, which reveals less information than traditional order-preserving encryption (OPE). Then, we present a novel PPRNN scheme in static setting based on structured encryption (SE) and the proposed RL-OPE, called sPPRNN. After that, we design a generic method that extends a PPRNN scheme in static setting to the counterpart in dynamic setting, called dPPRNN. Furthermore, we present a thorough privacy analysis of our proposal. Finally, we demonstrate its efficiency and effectiveness for practical deployment through extensive experiments. Xiaoguo Li, Tao Xiang 0001, Shangwei Guo, Hongwei Li 0001, Yi Mu 0001 |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | Secure Outsourced Attribute-Based Sharing Framework for Lightweight Devices in Smart Health SystemsabstractThe rapid evolution of the Internet of Things has led to the development of smart health. As a form of medical care that uses advanced Internet technology to realize better diagnosis and treatment of patients, smart health transitions medical services move toward real intelligence and greatly helps users. And in smart health, the secure sharing of personal health records (PHRs) is one of the main concerns of patients and medical personnel. Many attribute-based sharing models have been proposed to secure the sharing of PHRs, but there are still two problems to resolve. One is the potential disclosure of the patient data. The attribute-based model achieves flexible access control, but the access policies contain sensitive information of patients. The disclosure of the policy will lead to the leakage of data of the users. The other is the high computational and storage overhead, particularly in smart health systems with limited computing power. In this article, we present a Smart Health-Lightweight Fine-Grained Sharing (SH-LFGS) framework based on attribute-based encryption (ABE). It achieves a fully hidden access policy by adopting Viéte's formula. SH-LFGS introduces an online/offline mechanism in the PHR encryption phase and the outsourced verifiable decryption mechanism. Because the decrypting test requires only one bilinear pair operation, the SH-LFGS can achieve the task of lightweight computation. Analysis of the performance and security of the proposed model confirm its efficiency and security. Leyou Zhang, Wenting You, Yi Mu 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2021 | Privacy-Aware Image Authentication from Cryptographic PrimitivesabstractAbstract Image authentication is the process of verifying image origin, integrity and authenticity. In many situations, image authentication should allow reasonable image editing, which does not introduce any wrong information against the original one. While it has been studied both extensively and intensively with considerable efforts, there is no satisfactory method supporting region extraction. This paper presents a solution to address the issue of privacy protection in authenticated images. Our scheme allows anyone to extract sub-image blocks from an original image (authenticated by the image producer) and generate a proof tag to prove the credibility of the extracted image blocks. The process of proof tag generation does not require any interaction with the image producer. In addition, the image producer is able to define must-be-preserved image blocks (e.g. producer logo) during the extraction. We define the security property for the authenticated sub-images and give a generic design with two core primitives: an ordinary digital signature scheme and a cryptographic accumulator. The security of our design can be reduced to the underlying cryptographic primitives and its practical performance is demonstrated by a bunch of evaluations. We believe the proposed design, together with other image authentication methods, will further facilitate image relevant services and applications. Haixia Chen, Xinyi Huang 0001, Wei Wu 0001, Yi Mu 0001 |
Comput. J. | 4 |
| 2021 | Unlinkable and Revocable Secret HandshakeabstractAbstract In this paper, we introduce a new construction for unlinkable secret handshake that allows a group of users to perform handshakes anonymously. We define formal security models for the proposed construction and prove that it can achieve session key security, anonymity and affiliation hiding. In particular, the proposed construction ensures that (i) anonymity against protocol participants (including group authority) is achieved since a hierarchical identity-based signature is used in generating group user’s pseudonym-credential pairs and (ii) revocation is achieved using a secret sharing-based revocation mechanism. Yangguang Tian, Yingjiu Li, Yi Mu 0001, Guomin Yang |
Comput. J. | 3 |
| 2021 | Novel generic construction of leakage-resilient PKE scheme with CCA security
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang, Yi Mu 0001 |
Des. Codes Cryptogr. | 5 |
| 2021 | Enhanced bitcoin with two-factor authenticationabstractBitcoin transactions rely on digital signatures to prove the ownership of bitcoin. The private signing key of the bitcoin owner is the key component to enable a bitcoin transaction. If the signing key of a bitcoin is stolen, the theft who possesses the key can make a transaction of the bitcoin. In this paper, based on the distance-based encryption (DBE), we propose an enhanced version of bitcoin in order to protect the signing key. Our approach is based on our two-factor authentication, where the signing key cannot be retrieved without being identified via the password and biometric authentication scheme, and the user is only required to enter his password and fingerprint (or other biometric information such as a factual image) to retrieve the key. By doing this, we can effectively improve the bitcoin security and provide stronger authentication. An attractive feature of our scheme is that one of encryption schemes is asymmetric, in the sense that the decryption key (biometric information) is not stored in the device. We also provide the security model and proof to justify the security of our scheme. Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Leyou Zhang |
Int. J. Inf. Comput. Secur. | 2 |
| 2021 | Secure and Efficient Data Aggregation for IoT Monitoring SystemsabstractThe proliferation of Internet of Things (IoT) as a promising paradigm has contributed enormously to modern technology design. The wireless body sensor network (WBSN) technology is an application of IoT in healthcare, whereas data security and privacy impediments have raised some concerns. The collected data via IoT wireless body sensors is vulnerable to a variety of internal and external attacks. One solution is to encrypt or sign the collected data to provide confidentiality and integrity, but the computational complexity hinders the application in the real IoT-based healthcare devices. Although there have been some attempts to provide secure and efficient IoT schemes, there is a lack of achieving secure data analysis in modern healthcare. The aggregated data statistics about the patient's medical status is useful to doctors and healthcare providers. However, the dynamic data continually updating over time is challenging. In this article, we present an efficient and provably secure scheme, which is the first step toward secure data analysis for handling the data collection and analysis for IoT wireless body sensors. The main contribution of our work is a novel cryptographic accumulator based on our novel authenticated additive homomorphic encryption which can collect and accumulate data from IoT wireless wearable devices. These encrypted data can be used for analysis in an encrypted form so that the information is not revealed. To validate security and efficiency, we present security analysis and performance evaluations of our proposed scheme for IoT wireless body sensors. Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen |
IEEE Internet Things J. | 2 |
| 2021 | Secure and Privacy-Preserved Data Collection for IoT Wireless SensorsabstractThe captured data from smart devices via Internet of Things (IoT) wireless sensors are vulnerable to numerous online and offline attacks and unauthorized accesses, hence, some digital signature and encryption solutions have been designed to ensure public verifiability, data integrity, and confidentiality. However, there are still some issues to be addressed. For example, the data source is revealed to the public due to the public verifiability of digital signatures, in which authentication is transferrable. Moreover, computation of these data can only be done after decryption, restricting outsourced computation, such as a computing facility from a cloud. The best approach of private computation, which supports outsourced computation, is based on homomorphic encryption. However, significant computational overhead is a concern. To deal with these issues, in this article, we propose an efficient and provably secure scheme based on designated-verifier proofs, deniable authentication and homomorphic encryption for secure and lightweight data collection, batch verification, and data analysis in the privacy-preserved IoT wireless sensors applications. The main contribution of our work is the privacy-preserved IoT wireless sensors system along with a novel deniable authenticated homomorphic encryption scheme that can securely aggregate data from IoT wireless sensors for secure outsourced applications. To prove the security and efficiency of our proposed scheme, we provide formal security analysis and performance comparisons for IoT wireless sensors. Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Leyou Zhang, Xinyi Huang 0001 |
IEEE Internet Things J. | 2 |
| 2021 | An Enhanced Certificateless Aggregate Signature Without Pairings for E-Healthcare SystemabstractRecently, Gayathri et al. introduced an efficient certificateless aggregate signature (CLAS) for e-healthcare system and claimed that it can achieve efficient aggregation to different signatures on different messages from different medical sensors. In this article, we analyze it and find that the CLAS scheme and the underlying certificateless signature (CLS) scheme in it are not secure. Anyone can forge a valid aggregate/individual signature replacing the legitimate medical sensor only based on the public parameters set in Gayathri et al.'s CLAS scheme. Moreover, the malicious medical sensors can deny a valid aggregate signature (AS) by offering false individual signatures aggregated into this AS. We also present a secure CLAS scheme by aggregating an existing lightweight CLS scheme. The aggregation algorithm adopted in our new scheme is proven sound against inside attacks. Wenjie Yang 0001, Shangpeng Wang, Yi Mu 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Privacy-Preserving Flexible Access Control for Encrypted Data in Internet of ThingsabstractAlong with the development of edge computing and the cloud, the Internet of Things (IoT) is affecting and changing people’s lives. Data sharing has played an important role in the IoT, but the leakage of private user information poses a new security threat to the users. Thus, flexible fine-grained access control for such shared data is proposed in this article as an effective and secure method of eliminating vulnerabilities. However, the disclosure of access policies will also expose users’ private information. Recently, Yanget al.attempted to solve this problem and proposed a framework based on attribute-based encryption for shared data onto IEEE IoT-J(DOI: 10.1109/JIOT.2016.2571718). They hide the access policies by using a bloom filter (BF) and attempt to address privacy preservation in IoT. However, we demonstrate several security weaknesses of their framework and point out its vulnerability to dictionary attacks and access policy guessing attacks. Then, an improved IoT solution is proposed. Under this proposal, the attribute values are stored in BF while the attribute names are embedded in the access policy. The proposed scheme can resist dictionary attacks and access policy guessing attacks. In addition, it simultaneously realizes large attribute sets, an efficient decryption algorithm, and adaptive security. Security analysis and performance evaluations show that the presented scheme achieves higher security and implementation simplicity in the IoT than other currently available schemes. Leyou Zhang, Jun Wang 0109, Yi Mu 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Multiauthority Access Control With Anonymous Authentication for Personal Health RecordabstractA personal health record (PHR) system is a smart health system that serves patients and doctors. A PHR is usually stored in a cloud and managed by a semitrusted cloud provider. However, there is still a possibility of the exposure of personal health information to semitrusted parties and unauthorized users. To protect the privacy of patients and ensure that patients can control their PHRs, a patient-centric PHR sharing framework is proposed in this article. In this framework, all PHRs are protected with multiauthority attribute-based encryption before outsourcing, which solves the key hosting problem and achieves fine-grained access control to PHRs. Furthermore, an anonymous authentication between the cloud and the user is proposed to ensure data integrity on the cloud while not exposing the user's identity during authentication. The proposed authentication is issued from a new online-offline attribute-based signature. It can make the encrypted PHRs resist collusion attacks and not be forged during the period of sharing, which enhances patients' control of their PHRs. Online-offline and outsourcing decryption also reduces calculation costs and improves operational efficiency. Finally, comparisons are given based on numerical experiments. Leyou Zhang, Yadi Ye, Yi Mu 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Scalable and redactable blockchain with update and anonymity
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du |
Inf. Sci. | 3 |
| 2021 | Multicopy provable data possession scheme supporting data dynamics for cloud-based Electronic Medical Record system
Lei Zhou 0026, Anmin Fu, Yi Mu 0001, Huaqun Wang, Shui Yu 0001, Yinxia Sun |
Inf. Sci. | 3 |
| 2021 | Privacy-Preserving Proof of Storage for the Pay-As-You-Go Business ModelabstractProof of Storage (PoS) enables a cloud storage provider to prove that a client's data is intact. However, existing PoS protocols are not designed for the pay-as-you-go business model in which payment is made based on both storage volume and duration. In this paper, we propose two PoS protocols suitable for the pay-as-you-go storage business model. The first is a time encapsulated Proof of Retrievability (PoR) protocol that ensures retrievability of the original file upon successful auditing by a client. Considering the large size of outsourced data, we then extend the protocol to a privacy-preserving public auditing protocol which allows a third party auditor to audit outsourced data on behalf of its clients without sacrificing the privacy of the data or the timestamp (i.e., time of storage). We formalize the definition, system model and security model of the proposed PoS system and prove the security of the proposed protocols by a sequence of games in the algebraic group model with a random oracle. We analyze the performance of the protocols both theoretically and experimentally and show that the protocols are practical. Tong Wu 0011, Guomin Yang, Yi Mu 0001, Fuchun Guo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Improvement of Attribute-Based Encryption Using Blakley Secret Sharing
Zhe Xia, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang, Yi Mu 0001 |
ACISP | 5 |
| 2020 | Efficient and secure image authentication with robustness and versatility
Haixia Chen, Xinyi Huang 0001, Wei Wu 0001, Yi Mu 0001 |
Sci. China Inf. Sci. | 4 |
| 2020 | An improved Durandal signature scheme
Yongcheng Song, Xinyi Huang 0001, Yi Mu 0001, Wei Wu 0001 |
Sci. China Inf. Sci. | 3 |
| 2020 | Black-Box Accountable Authority Identity-Based Revocation SystemabstractAbstract Identity-based revocation system (IBRS) generates the ciphertext with a revoked identity list such that only the non-revoked identities can use their private keys to decrypt this ciphertext. IBRS can be efficiently applied in some practical applications, such as the pay-TV systems when the number of revoked identities are much less than the non-revoked ones. However, since IBRS is based on identity-based cryptography, it also suffers from the inherent key escrow problem where the private key generator (PKG) has full control of each user’s private key. As a consequence, it is hard to judge whether a pirated private key is generated by the PKG or the suspected user. There is no study on IBRS fulfilling accountability in literature to date. In this paper, we introduce the notion of accountable authority IBRS (A-IBRS), which provides accountability in IBRS schemes. In an A-IBRS, the aforementioned problem can be alleviated and resolved. Furthermore, a full black-box A-IBRS can distinguish the creator of a black box between the PKG and the associated user and the dishonest PKG is allowed to access the decryption results of the user private key. We formalize the definition and security models of the full black-box A-IBRS schemes. Then, we present a concrete full black-box A-IBRS scheme with constant-size master public key and private key. Finally, we prove the security of our scheme under the defined security models without random oracle. Zhen Zhao 0005, Ge Wu 0001, Fuchun Guo, Willy Susilo, Yi Mu 0001, Baocang Wang, Yupu Hu |
Comput. J. | 5 |
| 2020 | EVA: Efficient Versatile Auditing Scheme for IoT-Based Datamarket in JointcloudabstractCloud storage offers convenient outsourcing services to users, and it serves as a basic platform to drive Internet-of-Things (IoT) where massive devices are connected to the cloud storage and interact with each other. However, cloud storage is more than a data warehouse. In the literature, data market was proposed as a novel model to empower IoT, where data are circulated as merchandise in the digital marketplace with financial activities. When storing IoT data in cloud storage, security and efficiency rules should be applied. Meanwhile, data dynamics is counted as a critical factor to the feasibility of datamarket as data are supposed to be manipulated through circulation and exploitation for IoT. Another issue is the single-point-of-failure (SPoF) of cloud server in which the initiative of jointcloud was suggested. Since providing data security, efficiency, and dynamics simultaneously is challenging, in this article, we propose a versatile auditing scheme (EVA) as a solution to problems. Our proposal ensures that data are securely, efficiently, and dynamically stored in the jointcloud meanwhile supported by data trades via blockchain. We give a comprehensive security analysis based on our security definitions and experiments to support our claims. The evidence has shown that our EVA is efficient for processing large files when proper parameters are chosen. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Jingwei Li 0001, Qi Xia 0001, Jing Qin 0002 |
IEEE Internet Things J. | 3 |
| 2020 | Privacy-enhanced remote data integrity checking with updatable timestamp
Tong Wu 0011, Guomin Yang, Yi Mu 0001, Rongmao Chen, Shengmin Xu |
Inf. Sci. | 3 |
| 2020 | A practical and communication-efficient deniable authentication with source-hiding and its application on Wi-Fi privacy
Shengke Zeng, Yi Mu 0001, Mingxing He |
Inf. Sci. | 2 |
| 2020 | HUCDO: A Hybrid User-centric Data Outsourcing SchemeabstractOutsourcing helps relocate data from the cyber-physical system (CPS) for efficient storage at low cost. Current server-based outsourcing mainly focuses on the benefits of servers. This cannot attract users well, as their security, efficiency, and economy are not guaranteed. To solve with this issue, a hybrid outsourcing model that exploits both cloud server and edge devices to store data is needed. Meanwhile, the requirements of security and efficiency are different under specific scenarios. There is a lack of a comprehensive solution that considers all of the above issues. In this work, we overcome the above issues by proposing the first hybrid user-centric data outsourcing (HUCDO) scheme. It allows users to outsource data securely, efficiently, and economically via different CPSs. Brielly, our contributions consist of theories, implementations, and evaluations. Our theories include the first homomorphic collision-resistant chameleon hash (HCCH) and homomorphic designated-receiver signcryption (HDRS). As implementations, we instantiate how to use our proposals to outsource small- or large-scale data through distinct CPS, respectively. Additionally, a blockchain with proof-of-discrete-logarithm (B-PoDL) is instantiated to help improve our performance. Last, as demonstrated by our evaluations, our proposals are secure, efficient, and economic for users to implement while outsourcing their data via CPSs. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Guangquan Xu, Hao Wang 0003, James Xi Zheng, Guomin Yang, Qi Xia 0001, Xiaojiang Du |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2020 | A code-based signature scheme from the Lyubashevsky framework
Yongcheng Song, Xinyi Huang 0001, Yi Mu 0001, Wei Wu 0001, Huaxiong Wang |
Theor. Comput. Sci. | 3 |
| 2020 | Revocable identity-based encryption with server-aided ciphertext evolution
Yinxia Sun, Yi Mu 0001, Willy Susilo, Futai Zhang, Anmin Fu |
Theor. Comput. Sci. | 2 |
| 2020 | Novel updatable identity-based hash proof system and its applications
Yanwei Zhou, Bo Yang 0003, Tao Wang 0039, Yi Mu 0001 |
Theor. Comput. Sci. | 4 |
| 2020 | Identity-based encryption with leakage-amplified chosen-ciphertext attacks security
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang, Yi Mu 0001 |
Theor. Comput. Sci. | 5 |
| 2020 | Multi-User Verifiable Searchable Symmetric Encryption for Cloud StorageabstractIn a cloud data storage system, symmetric key encryption is usually used to encrypt files due to its high efficiency. In order allow the untrusted/semi-trusted cloud storage server to perform searching over encrypted data while maintaining data confidentiality, searchable symmetric encryption (SSE) has been proposed. In a typical SSE scheme, a users stores encrypted files on a cloud storage server and later can retrieve the encrypted files containing specific keywords. The basic security requirement of SSE is that the cloud server learns no information about the files or the keywords during the searching process. Some SSE schemes also offer additional functionalities such as detecting cheating behavior of a malicious server (i.e., verifiability) and allowing update (e.g., modifying, deleting and adding) of documents on the server. However, the previous (verifiable) SSE schemes were designed for single users, which means the searching can only be done by the data owner, whereas in reality people often use cloud storage to share files with other users. In this paper we present a multi-user verifiable searchable symmetric encryption (MVSSE) scheme that achieves all the desirable features of a verifiable SSE and allows multiple users to perform searching. We then define an ideal functionality for MVSSE under the Universally Composable (UC-) security framework and prove that our ideal functionality implies the security requirements of a secure MVSSE, and our multi-user verifiable SSE scheme is UC-secure. We also implement our scheme to verify its high performance based on some real dataset. Xueqiao Liu, Guomin Yang, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Achieving Intelligent Trust-Layer for Internet-of-Things via Self-Redactable BlockchainabstractThe advances of artificial intelligence (AI) propels big data processing and transmission for Internet of Things (IoT), by capturing and structuring big data produced by heterogeneous devices. While applying blockchain to manage IoT devices and associated big data, the blockchain itself suffers from abuse of decentralization from anonymous users. Specifically, it has been utilized to facilitate black market trades and illegal activities. Ateniese et al. proposed using the chameleon hash (CH) to derive redactable blockchain (EuroS&P), which works by embedding a trapdoor in the basic hash function so that block content can be rewritten without causing major hard forks. In short, the redacted block hash remains unchanged. However, there is lacking intelligent design where any mistakes observed in the chain can be corrected universally and automatically. This creates disincentives to use redactable blockchain (RB) for managing big data or any data-driven business mainly due to ineffective chain redaction. To solve this problem, in this article, we propose the notion of the self-redactable blockchain (SRB) to support intelligent execution of chain redaction. Specifically, we propose the first revocable chameleon hash (RCH) to power RB. It enables an ephemeral trapdoor for finding collision without any co-operation. Periodical expiration is applied to committed hash and an ephemeral trapdoor to prevent any abuses of redaction power. We instantiate how to use our RCH to build SRB as an intelligent trust-layer for IoT. We also give a rigorous analysis as well as comprehensive experiments to validate our proposals. The evidence showed that our proposal is secure and acceptably efficient for IoT devices. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du, Nadra Guizani |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | Policy-Driven Blockchain and Its Applications for Transport SystemsabstractBlockchains offer opportunities for developing advanced digital services. While current research on this topic is still growing, various security concerns have been raised and the security of blockchains has been becoming the most important issue which must be well addressed. Blockchain transactions are based on digital signatures, where the public key is associated with the ownership of the digital coin. User management of public or permissionless blockchain is ad hoc, i.e., any user can join and leave the blockchain network and participate in the Proof of Work (PoW). However, in a private blockchain and a permissioned blockchain, there are usually some constraints for users. In this paper, we investigate a scenario which provides a blockchain network with a set of policies where every user's signing key is associated with a policy set. It is particularly interesting while users are working in different sectors. We call our scheme as “policy-driven”, since policies in our scheme restrict users' rights. Our system is featured with a novel and lightweight policy-driven signature (PDS) scheme whose security has been proven formally. To justify our scenario, we provide experimental results and an example for the railway management services. Yi Mu 0001, Fatemeh Rezaeibagha, Ke Huang 0002 |
IEEE Trans. Serv. Comput. | 1 |
| 2019 | Provably Secure Group Authentication in the Asynchronous Communication Model
Zhe Xia, Lein Harn, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001, Willy Susilo, Weizhi Meng 0001 |
ICICS | 5 |
| 2019 | Provably Secure Proactive Secret Sharing Without the Adjacent Assumption
Zhe Xia, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang, Hua Shen 0002, Yi Mu 0001 |
ProvSec | 6 |
| 2019 | Efficient Micropayment of Cryptocurrency from BlockchainsabstractCryptocurrencies based on blockchain infrastructures have shown their advantages such as double-spending resistance and decentralization. Each transaction of cryptocurrency requires a certain amount of computation and attracts transaction fees. Often, in practice, many transactions are small; therefore, they add computation and transmission overheads to the system. In this paper, we introduce a cost-saving approach, which significantly reduces transaction time and storage for small amount of payment, i.e. micropayment. In our approach, with the notion of ‘transaction commitment’, the computation of each transaction is much more efficient. Therefore, our approach has advantages in comparison of other cryptocurrency systems such as the bitcoin system. Our approach can be applied to other existing cryptocurrency systems. Fatemeh Rezaeibagha, Yi Mu 0001 |
Comput. J. | 2 |
| 2019 | Strongly leakage resilient authenticated key exchange, revisited
Guomin Yang, Rongmao Chen, Yi Mu 0001, Willy Susilo, Fuchun Guo, Jie Li 0041 |
Des. Codes Cryptogr. | 3 |
| 2019 | Continuous leakage-resilient identity-based encryption with leakage amplification
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001 |
Des. Codes Cryptogr. | 3 |
| 2019 | A secure IoT cloud storage system with fine-grained access control and decryption key exposure resistance
Shengmin Xu, Guomin Yang, Yi Mu 0001, Ximeng Liu |
Future Gener. Comput. Syst. | 3 |
| 2019 | Identity-based encryption resilient to continuous key leakageabstractLeakage of private information has become a threat to the security of computing systems. It has become a common security requirement that a cryptography scheme should withstand various leakage attacks, even the continuous leakage attacks. However, in the current constructions on the (continuous) leakage‐resilient identity‐based encryption (CLR‐IBE) scheme, the leakage parameter is a fixed value. Aiming to solve these problems, in this study, the authors show how to construct the CLR‐IBE scheme, and the adaptive chosen‐ciphertext attacks security of proposed construction can be proved in the standard model. To further improve the practicability of CLR‐IBE scheme, they design an improved IBE scheme with continuous leakage amplified property, and the leakage parameter has an arbitrary length. Yanwei Zhou, Bo Yang 0003, Yi Mu 0001, Tao Wang 0039, Xin Wang 0058 |
IET Inf. Secur. | 3 |
| 2019 | Identity-based revocation system: Enhanced security model and scalable bounded IBRS construction with short parameters
Peng Jiang 0007, Jianchang Lai, Fuchun Guo, Willy Susilo, Man Ho Au, Guomin Yang, Yi Mu 0001, Rongmao Chen |
Inf. Sci. | 7 |
| 2019 | Revocable attribute-based encryption with decryption key exposure resistance and ciphertext delegation
Shengmin Xu, Guomin Yang, Yi Mu 0001 |
Inf. Sci. | 3 |
| 2019 | DABKE: Secure deniable attribute-based key exchange frameworkabstractWe introduce the first deniable attribute-based key exchange (DABKE) framework that is resilient to impersonation attacks. We define the formal security models for DABKE framework, and propose a generic compiler that converts any attribute-based key exchanges into deniable ones. We prove that it can achieve session key security and user privacy in the standard model, and strong deniability in the simulation-based paradigm. In particular, the proposed generic compiler ensures: 1) a dishonest user cannot impersonate other user’s session participation in conversations since implicit authentication is used among authorized users; 2) an authorized user can plausibly deny his/her participation after secure conversations with others; 3) the strongest form of deniability is achieved using one-round communication between two authorized users. Yangguang Tian, Yingjiu Li, Guomin Yang, Willy Susilo, Yi Mu 0001, Hui Cui 0001, Yinghui Zhang 0002 |
J. Comput. Secur. | 5 |
| 2019 | Efficient identity-based broadcast encryption with keyword search against insider attacks for database systems
Peng Jiang 0007, Fuchun Guo, Yi Mu 0001 |
Theor. Comput. Sci. | 3 |
| 2019 | The generic construction of continuous leakage-resilient identity-based cryptosystems
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001 |
Theor. Comput. Sci. | 3 |
| 2019 | Building Redactable Consortium Blockchain for Industrial Internet-of-ThingsabstractApplying consortium blockchain as a trust layer for heterogeneous industrial Internet-of-Things devices is cost-effective. However, with an increase in computing power, some powerful attacks (e.g., the 51% attack) are inevitable and will cause severe consequences. Recent studies also confirm that anonymity and immutability of blockchain have been abused to facilitate black market trades, etc. To operate controllable blockchain for IIoT devices, it is necessary to rewrite blockchain history back to a normal state once the chain is breached. Ateniese et al. proposed redactable blockchain by using chameleon hash (CH) to replace traditional hash function, it allows blockchain history to be written when needed (EuroS&P 2017). However, we cannot apply this idea directly to IIoT without solving the following problems: (1) achieve a decentralized design of CH; (2) update the signatures accordingly to authenticate the redacted contents; (3) satisfy the low-computing need of the individual IIoT device. In this paper, we overcome the above issues by proposing the first threshold chameleon hash (TCH) and accountable-and-sanitizable chameleon signature (ASCS) schemes. Based on them, we build a redactable consortium blockchain which is efficient for IIoT devices to operate. It allows a group of authorized sensors to write and rewrite blockchain without causing any hard forks. Basically, TCH is the first TCH and ASCS is a public-key signature supporting file-level and block-level modifications of signatures without impairing authentications. Additionally, ASCS achieves accountability to avoid abuse of redaction. While security analysis validates our proposals, the simulation results show that redaction is acceptably efficient if it is executed at a small scale or if we adopt a coarse-grained redaction while sacrificing some securities. Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Guomin Yang, Xiaojiang Du, Fatemeh Rezaeibagha, Qi Xia 0001, Mohsen Guizani |
IEEE Trans. Ind. Informatics | 3 |
| 2018 | Efficient Traceable Oblivious Transfer and Its Applications
Weiwei Liu 0005, Yinghui Zhang 0002, Yi Mu 0001, Guomin Yang, Yangguang Tian |
ISPEC | 3 |
| 2018 | An Efficient and Provably Secure Private Polynomial Evaluation Scheme
Zhe Xia, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001 |
ISPEC | 4 |
| 2018 | Efficient Attribute-Based Encryption with Blackbox Traceability
Shengmin Xu, Guomin Yang, Yi Mu 0001, Ximeng Liu |
ProvSec | 3 |
| 2018 | Continuous leakage-resilient access control for wireless sensor networks
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001, Zhe Xia |
Ad Hoc Networks | 3 |
| 2018 | Identity-Based Broadcast Encryption for Inner ProductsabstractIn the identity-based broadcast encryption (IBBE), only these users whose identities are chosen in the ciphertext computing can decrypt the encrypted message. In this paper, we introduce an extension of IBBE, namely Identity-Based Broadcast Encryption for Inner Product (IBBE-IP), where message encryption is replaced by inner product encryption (IPE) introduced by Abdalla et al. (PKC 2015). Precisely, in the IBBE-IP, the private key is associated with a pair of an identity and a vector (ID,y→). The user with private key of (ID,y→) can decrypt the encrypted vector x→ for an identity set S selected by the encryptor and learn the inner product 〈x→,y→〉 if and only if ID∈S. Differing from the IBBE, the decryption in the IBBE-IP yields the inner product associated with the encrypted vector without leaking any information of the vector. The encrypted vector is protected as long as the number of selected identities is less than their length. We present a construction of IBBE-IP with constant-size private keys and it supports unbounded private key queries, which was unachieved in the previous works of IPE in the public-key setting. The security of our proposed scheme is proved in the random oracle model. Jianchang Lai, Yi Mu 0001, Fuchun Guo, Peng Jiang 0007, Sha Ma |
Comput. J. | 2 |
| 2018 | Continuous Leakage-Resilient Identity-Based Encryption without Random OraclesabstractProvably secure identity-based encryption (IBE) schemes in the presence of key-leakage have attracted a lot of attention recently. However, most of them were designed in the bounded-leakage model, and might not be able to meet the claimed security under the continuous-leakage attacks. The main issue is that the most of previous leakage-resilient IBE schemes could not ensure the randomness of all elements in the ciphertext, because some elements can be written as a function on the private key of user; therefore, the adversary can obtain the leakage on the private key of user from the corresponding given ciphertext. In this paper, a new construction of CCA-secure IBE scheme tolerating continuous-leakage attacks in the standard model is proposed, and its security is proved in the selective-ID security model based on the hardness of decisional bilinear Diffie–Hellman assumption, which is a classical static assumption. In our construction, the adversary cannot obtain any leakage on the private key from the corresponding ciphertext, since all elements in the ciphertext are random in the adversary’s view. The striking advantage of our constructions is the key leakage ratio, which is the best one among the previous leakage-resilient IBE constructions. Yanwei Zhou, Bo Yang 0003, Yi Mu 0001 |
Comput. J. | 3 |
| 2018 | Ciphertext-policy attribute-based encryption against key-delegation abuse in fog computing
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo |
Future Gener. Comput. Syst. | 3 |
| 2018 | CCN framework with privacy supportabstractContent‐centric networking (CCN) used the name of an Interest to seek the target content, where the name was a plaintext and unprotected. Apart from the name, the content in one Data is also unprotected. If an unauthorised node intercepted an Interest , it could infer what kind of content is requested. If the node intercepted a response Data , it could illegally acquire the content. This study focused on the privacy issues of CCN and proposed a CCN framework with privacy support. In this framework, the concept of a privacy name was proposed and accordingly the forwarding information base (FIB) and pending Interest table (PIT) establishment algorithms based on privacy names were proposed. On the basis of the proposed FIB and PIT, the content communication algorithm based on privacy names was presented. In this algorithm, one authorised consumer could use a privacy name to seek, retrieve and share the ciphertext of the content, so the privacy was achieved. Finally, the privacy of this framework was analysed and the performance was evaluated to justify its advantages. Xiaonan Wang 0001, Zhengxiong Dou, Yi Mu 0001 |
IET Inf. Secur. | 3 |
| 2018 | Privacy-enhanced attribute-based private information retrieval
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Peng Jiang 0007, Willy Susilo |
Inf. Sci. | 2 |
| 2018 | A Generic Scheme of plaintext-checkable database encryption
Sha Ma, Yi Mu 0001, Willy Susilo |
Inf. Sci. | 2 |
| 2018 | Witness-based searchable encryption
Sha Ma, Yi Mu 0001, Willy Susilo, Bo Yang 0003 |
Inf. Sci. | 2 |
| 2018 | Multirate DelPHI to secure multirate ad hoc networks against wormhole attacks
Shams Qazi, Raad Raad, Yi Mu 0001, Willy Susilo |
J. Inf. Secur. Appl. | 3 |
| 2018 | Practical and secure telemedicine systems for user mobility
Fatemeh Rezaeibagha, Yi Mu 0001 |
J. Biomed. Informatics | 2 |
| 2018 | A New Revocable and Re-Delegable Proxy Signature and Its Application
Shengmin Xu, Guomin Yang, Yi Mu 0001 |
J. Comput. Sci. Technol. | 3 |
| 2018 | Man-in-the-middle attacks on Secure Simple Pairing in Bluetooth standard V5.0 and its countermeasure
Da-Zhi Sun, Yi Mu 0001, Willy Susilo |
Pers. Ubiquitous Comput. | 2 |
| 2018 | Correction to: Man-in-the-middle attacks on Secure Simple Pairing in Bluetooth standard V5.0 and its countermeasure
Da-Zhi Sun, Yi Mu 0001, Willy Susilo |
Pers. Ubiquitous Comput. | 2 |
| 2018 | Efficient k-out-of-n oblivious transfer scheme with the ideal communication cost
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Rongmao Chen, Sha Ma |
Theor. Comput. Sci. | 2 |
| 2018 | Policy controlled system with anonymity
Pairat Thorncharoensri, Willy Susilo, Yi Mu 0001 |
Theor. Comput. Sci. | 3 |
| 2018 | Secure Fine-Grained Access Control and Data Sharing for Dynamic Groups in the CloudabstractCloud computing is an emerging computing paradigm that enables users to store their data in a cloud server to enjoy scalable and on-demand services. Nevertheless, it also brings many security issues, since cloud service providers (CSPs) are not in the same trusted domain as users. To protect data privacy against untrusted CSPs, existing solutions apply cryptographic methods (e.g., encryption mechanisms) and provide decryption keys only to authorized users. However, sharing cloud data among authorized users at a fine-grained level is still a challenging issue, especially when dealing with dynamic user groups. In this paper, we propose a secure and efficient fine-grained access control and data sharing scheme for dynamic user groups by: 1) defining and enforcing access policies based on the attributes of the data; 2) permitting the key generation center to efficiently update user credentials for dynamic user groups; and 3) allowing some expensive computation tasks to be performed by untrusted CSPs without requiring any delegation key. Specifically, we first design an efficient revocable attribute-based encryption (ABE) scheme with the property of ciphertext delegation by exploiting and uniquely combining techniques of identity-based encryption, ABE, subset-cover framework, and ciphertext encoding mechanism. We then present a fine-grained access control and data sharing system for on-demand services with dynamic user groups in the cloud. The experimental data show that our proposed scheme is more efficient and scalable than the state-of-the-art solution. Shengmin Xu, Guomin Yang, Yi Mu 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Strong Identity-Based Proxy Signature Schemes, RevisitedabstractProxy signature is a useful cryptographic primitive that has been widely used in many applications. It has attracted a lot of attention since it was introduced. There have been lots of works in constructing efficient and secure proxy signature schemes. In this paper, we identify a new attack that has been neglected by many existing proven secure proxy signature schemes. We demonstrate this attack by launching it against an identity‐based proxy signature scheme which is proven secure. We then propose one method that can effectively prevent this attack. The weakness in some other proxy signature schemes can also be fixed by applying the same method. Weiwei Liu 0005, Yi Mu 0001, Guomin Yang, Yangguang Tian |
Wirel. Commun. Mob. Comput. | 2 |
| 2017 | Privacy-Preserving k-time Authenticated Secret Handshakes
Yangguang Tian, Shiwei Zhang 0003, Guomin Yang, Yi Mu 0001, Yong Yu 0002 |
ACISP (2) | 4 |
| 2017 | ID-Based Encryption with Equality Test Against Insider Attack
Tong Wu 0011, Sha Ma, Yi Mu 0001, Shengke Zeng |
ACISP (1) | 3 |
| 2017 | Mergeable and Revocable Identity-Based Encryption
Shengmin Xu, Guomin Yang, Yi Mu 0001, Willy Susilo |
ACISP (1) | 3 |
| 2017 | Hierarchical Functional Encryption for Linear Transformations
Shiwei Zhang 0003, Yi Mu 0001, Guomin Yang |
ACISP (1) | 2 |
| 2017 | Optimal Security Reductions for Unique Signatures: Bypassing Impossibilities with a Counterexample
Fuchun Guo, Rongmao Chen, Willy Susilo, Jianchang Lai, Guomin Yang, Yi Mu 0001 |
CRYPTO (2) | 6 |
| 2017 | Fuzzy Extractors for Biometric IdentificationabstractFuzzy extractor provides key generation from biometrics and other noisy data. The generated key is seamlessly usable for any cryptographic applications because its information entropy is sufficient for security. Biometric authentication offers natural and passwordless user authentication in various systems where fuzzy extractors can be used for biometric information security. Typically, a biometric system operates in two modes: verification and identification. However, existing fuzzy extractors does not support efficient user identification. In this paper, we propose a succinct fuzzy extractor scheme which enables efficient biometric identification as well as verification that it satisfies the security requirements. We show that the proposed scheme can be easily used in both verification and identification modes. To the best of our knowledge, we propose the first fuzzy extractor based biometric identification protocol. The proposed protocol is able to identify a user with constant computational cost rather than linear-time computation required by other fuzzy extractor schemes. We also provide security analysis of proposed schemes to show their security levels. The implementation shows that the performance of proposed identification protocol is constant and it is close to that of verification protocols. Nan Li 0007, Fuchun Guo, Yi Mu 0001, Willy Susilo, Surya Nepal |
ICDCS | 3 |
| 2017 | Group-Based Source-Destination Verifiable Encryption with Blacklist Checking
Zhongyuan Yao, Yi Mu 0001, Guomin Yang |
ISPEC | 2 |
| 2017 | Provably Secure Homomorphic Signcryption
Fatemeh Rezaeibagha, Yi Mu 0001, Shiwei Zhang 0003 |
ProvSec | 2 |
| 2017 | Deniable Ring Authentication Based on Projective Hash Functions
Shengke Zeng, Yi Mu 0001, Guomin Yang, Mingxing He |
ProvSec | 2 |
| 2017 | Fully Privacy-Preserving ID-Based Broadcast Encryption with AuthorizationabstractA revocable ID-based broadcast encryption scheme allows an authorized third party to revoke any receiver (decryptor) from the initial receiver set S of the original broadcast ciphertext without the need of decryption. However, the existing revocable ID-based broadcast encryption schemes in the literature cannot fully preserve the receiver privacy and have a large size of ciphertext when the revoked user sets are large. To solve these problems, in this paper, we propose a novel scheme: fully privacy-preserving ID-based broadcast encryption with authorization. Our scheme allows an authorized party to dynamically handle the decryption rights of receivers via an authorized user set L without knowing the message and the identities of the initial receivers. Only those users who are both in S and L can decrypt the ciphertext successfully. The final ciphertext reveals nothing about the identity information of receivers and the authorized users. Our scheme achieves full collusion resistance and is applicable to anonymous data sharing where the receivers are decided by the authorized third party (or multiple authorized third parties) excluding the data owner. We show that our proposed scheme is provably secure under the defined security models in the random oracle model. Jianchang Lai, Yi Mu 0001, Fuchun Guo, Rongmao Chen |
Comput. J. | 2 |
| 2017 | Novel Leakage-Resilient Attribute-Based Encryption from Hash Proof SystemabstractAs an important primitive, attribute-based encryption (ABE) has attracted much attention in the relative-leakage model. However, the leakage rate in almost all of the existing ABE schemes is restricted with a leakage parameter. It implicitly suggests that higher leakage rate results in larger ciphertexts and keys. Aiming at tackling the challenge, novel leakage-resilient ciphertext-policy attribute-based encryption (CP-ABE) and key-policy attribute-based encryption (KP-ABE) are designed in this paper. It achieves shorter secret key size and simultaneously does not suffer from the undesirable drawback above. To realize this, the concepts of CP-AB-HPS and KP-AB-HPS are introduced, which generalize the notion of hash proof system (HPS) to attribute-based setting. Under some static assumptions, the proposed schemes are proved adaptively secure in the standard model. In addition, the results in simulation experiments indicate that the proposed scheme is efficient and practical. Leyou Zhang, Jingxia Zhang, Yi Mu 0001 |
Comput. J. | 3 |
| 2017 | Secure-channel free keyword search with authorization in manager-centric databases
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen |
Comput. Secur. | 2 |
| 2017 | Privacy-preserving data search and sharing protocol for social networks through wireless applicationsabstractSummary Data search and sharing are two important functionalities in social networks. The social network users can form a peer‐to‐peer group and securely and flexibly search and share cloud data through wireless applications. When the number of users increases, the communication, storage, and computational overheads will be increased, and the quality of services such as searching and data sharing for clients could be affected. In order to solve these problems, we formalize an ID‐based multi‐user searchable encryption (IDB‐MUSE) and formally define its security model, where the security notions accommodate indistinguishability against insider's keyword guessing attack, indistinguishability against chosen keyword attack, and indistinguishability against insider's identity guessing attack. We present an IDB‐MUSE scheme, where the index and search trapdoor are of constant size. We formally prove its security properties. To improve the search efficiency, we divide the computation of the trapdoor into two phases, that is, the offline phase and the online phase. The computation cost for the online phase trapdoor remains constant with respect to the number of users. Based on the IDB‐MUSE scheme, a privacy‐preserving data search and sharing protocol is proposed, where only the authorized user can access the shared group data. It captures the properties of source authenticity, data and search pattern privacy‐preserving, anonymity, and request unlinkability. The experimental results show that the protocol is practical for wireless applications. Copyright © 2016 John Wiley & Sons, Ltd. Yi Mu 0001, Rongmao Chen |
Concurr. Comput. Pract. Exp. | 2 |
| 2017 | Strong authenticated key exchange with auxiliary inputs
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo |
Des. Codes Cryptogr. | 2 |
| 2017 | A note on the strong authenticated key exchange with auxiliary inputs
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo, Zheng Yang 0001 |
Des. Codes Cryptogr. | 2 |
| 2017 | Communication security and privacy support in 6LoWPAN
Xiaonan Wang 0001, Yi Mu 0001 |
J. Inf. Secur. Appl. | 2 |
| 2017 | Private Keyword-Search for Database Systems Against Insider Attacks
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen |
J. Comput. Sci. Technol. | 2 |
| 2017 | Fully privacy-preserving and revocable ID-based broadcast encryption for data access control in smart city
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Willy Susilo, Rongmao Chen |
Pers. Ubiquitous Comput. | 2 |
| 2017 | A Generic Table Recomputation-Based Higher-Order MaskingabstractMasking is a class of well-known countermeasure against side-channel attacks by employing the idea of secret sharing. In this paper, we propose a generic table recomputation-based masking scheme at any chosen order t, named divided S-box masking (DSM), and its security has been proved under the security framework from Crypto 2003. The table recomputation-based masking is suitable for software implementation and the masked table can be stored in memory, where it can be accessed fast. For any input, DSM scheme generates n output shares by two queries. DSM scheme requires two vectors L and R, and a matrix M of random numbers. Each element of L is the XOR result of the output of S-box and n - 1 random numbers. These n - 1 random numbers are stored in two lines of M and R which is a vector of indexes for the second query. Furthermore, we performed the attacks on the software implementation of DSM to evaluate its practical security, and compared the timing and space complexity with the existing table recomputation-based masking in the same platform to verify the advantage of the DSM. Ming Tang 0002, Zhenlong Qiu, Zhipeng Guo 0002, Yi Mu 0001, Xinyi Huang 0001, Jean-Luc Danger |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 4 |
| 2017 | Optimized Identity-Based Encryption from Bilinear Pairing for Lightweight DevicesabstractLightweight devices such as smart cards and RFID tags have a very limited hardware resource, which could be too weak to cope with asymmetric-key cryptography. It would be desirable if the cryptographic algorithm could be optimized in order to better use hardware resources. In this paper, we demonstrate how identity-based encryption algorithms from bilinear pairing can be optimized so that hardware resources can be saved. We notice that the identity-based encryption algorithms from bilinear pairing in the literature must perform both elliptic curve group operations and multiplicative group operations, which consume a lot of hardware resources. We manage to eliminate the need of multiplicative group operations for encryption. This is a significant discovery since the hardware structure can be simplified for implementing pairing-based cryptography. Our experimental results show that our encryption algorithm saves up to 47 percent memory (27,239 RAM bits) in FPGA implementation. Fuchun Guo, Yi Mu 0001, Willy Susilo, Homer Hsing, Duncan S. Wong, Vijay Varadharajan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2017 | EACSIP: Extendable Access Control System With Integrity Protection for Enhancing Collaboration in the CloudabstractIt is widely acknowledged that the collaborations with more users increase productivity. Secure cloud storage is a promising tool to enhance such a collaboration. Access control system can be enabled with attribute-based encryption. In this system, a user encrypts and uploads his/her data to the cloud with an access policy, such that only people who satisfy that access policy can decrypt the data. When a recipient would like to enable another person who is originally unauthorized by the original access policy, this recipient will need to extend the access policy by adding a new policy that includes the new person hence, the notion of extendable access control system. Admitting new users to access the uploaded data is an important requirement in enhancing collaborations. The main issue is with regards to the integrity protection during the process of extending the access policy. When a new access policy is added, the cloud has to be sure that the extended access policy remains guarding the same encrypted data as the original access policy, even though the cloud cannot decrypt this ciphertext, which is a challenging problem to solve. In this paper, we answer the above problem affirmatively by introducing an extendable access control system with Integrity Protection (EACSIP), which is suitable to enhance collaboration in the cloud. The construction of EACSIP is built on top of a novel cryptographic primitive, namely functional key encapsulation with equality testing. The security proof and the performance evaluation of EACSIP are provided in this paper. Willy Susilo, Peng Jiang 0007, Fuchun Guo, Guomin Yang, Yong Yu 0002, Yi Mu 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2017 | Efficient Public Verification of Data Integrity for Cloud Storage Systems from Indistinguishability ObfuscationabstractCloud storage services allow users to outsource their data to cloud servers to save local data storage costs. However, unlike using local storage devices, users do not physically manage the data stored on cloud servers; therefore, the data integrity of the outsourced data has become an issue. Many public verification schemes have been proposed to enable a third-party auditor to verify the data integrity for users. These schemes make an impractical assumption-the auditors have enough computation capability to bear expensive verification costs. In this paper, we propose a novel public verification scheme for the cloud storage using indistinguishability obfuscation, which requires a lightweight computation on the auditor and the delegate most computation to the cloud. We further extend our scheme to support batch verification and data dynamic operations, where multiple verification tasks from different users can be performed efficiently by the auditor and the cloud-stored data can be updated dynamically. Compared with other existing works, our scheme significantly reduces the auditor's computation overhead. Moreover, the batch verification overhead on the auditor side in our scheme is independent of the number of verification tasks. Our scheme could be practical in a scenario, where the data integrity verifications are executed frequently, and the number of verification tasks (i.e., the number of users) is numerous; even if the auditor is equipped with a low-power device, it can verify the data integrity efficiently. We prove the security of our scheme under the strongest security model proposed by Shi et al. (ACM CCS 2013). Finally, we conduct a performance analysis to demonstrate that our scheme is more efficient than other existing works in terms of the auditor's communication and computation efficiency. Yuan Zhang 0006, Chunxiang Xu, Xiaohui Liang 0002, Hongwei Li 0001, Yi Mu 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2017 | Computation-efficient key establishment in wireless group communications
Ching-Fang Hsu 0001, Lein Harn, Yi Mu 0001, Maoyuan Zhang |
Wirel. Networks | 3 |
| 2016 | One-Round Strong Oblivious Signature-Based Envelope
Rongmao Chen, Yi Mu 0001, Willy Susilo, Guomin Yang, Fuchun Guo, Mingwu Zhang |
ACISP (2) | 2 |
| 2016 | Public Key Encryption with Authorized Keyword Search
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen |
ACISP (2) | 2 |
| 2016 | Ciphertext-Policy Attribute-Based Encryption with Key-Delegation Abuse Resistance
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo |
ACISP (1) | 3 |
| 2016 | Anonymous Identity-Based Broadcast Encryption with Revocation for File Sharing
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Willy Susilo, Rongmao Chen |
ACISP (2) | 2 |
| 2016 | Content-Based Encryption
Yi Mu 0001 |
ACISP (2) | 2 |
| 2016 | Proxy Signature with Revocation
Shengmin Xu, Guomin Yang, Yi Mu 0001, Sha Ma |
ACISP (2) | 3 |
| 2016 | Linear Encryption with Keyword Search
Shiwei Zhang 0003, Guomin Yang, Yi Mu 0001 |
ACISP (2) | 3 |
| 2016 | Cryptographic Reverse Firewall via Malleable Smooth Projective Hash Functions
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo, Mingwu Zhang |
ASIACRYPT (1) | 2 |
| 2016 | Iterated Random Oracle: A Universal Approach for Finding Loss in Security Reduction
Fuchun Guo, Willy Susilo, Yi Mu 0001, Rongmao Chen, Jianchang Lai, Guomin Yang |
ASIACRYPT (2) | 3 |
| 2016 | Recipient Revocable Identity-Based Broadcast Encryption: How to Revoke Some Recipients in IBBE without Knowledge of the PlaintextabstractIn this paper, we present the notion of recipient-revocable identity-based broadcast encryption scheme. In this notion, a content provider will produce encrypted content and send them to a third party (which is a broadcaster). This third party will be able to revoke some identities from the ciphertext. We present a security model to capture these requirements, as well as a concrete construction. The ciphertext consists of k+3 group elements, assuming that the maximum number of revocation identities is k. That is, the ciphertext size is linear in the maximal size of R, where R is the revocation identity set. However, we say that the additional elements compared to that from an IBBE scheme are only for the revocation but not for decryption. Therefore, the ciphertext sent to the users for decryption will be of constant size (i.e.,3 group elements). Finally, we present the proof of security of our construction. Willy Susilo, Rongmao Chen, Fuchun Guo, Guomin Yang, Yi Mu 0001, Yang-Wai Chow |
AsiaCCS | 5 |
| 2016 | Bilateral-secure Signature by Key EvolvingabstractIn practice, the greatest threat against the security of a digital signature scheme is the exposure of signing key, since the forward security of past signatures and the backward security of future signatures could be compromised. There are some attempts in the literature, addressing forward-secure signature for preventing forgeries of signatures in the past time; however, few studies addressed the backward-security of signatures, which prevents forgeries in the future time. In this paper, we introduce the concept of key-evolving signature with bilateral security, i.e., both forward security and backward security. We first define the bilateral security formally for preventing the adversaries from forging a valid signature of the past and the future time periods in the case of key exposure. We then provide a novel construction based on hub-and-spoke updating structure and the random oracle model, and show that the construction achieves bilateral security and unbounded number of time periods. Finally, we compare our scheme with the existing work by rigorous analysis and experimental evaluation, and demonstrate that our construction is more secure and efficient for practical applications. Tao Xiang 0001, Xiaoguo Li, Fei Chen 0003, Yi Mu 0001 |
AsiaCCS | 4 |
| 2016 | Achieving IND-CCA Security for Functional Encryption for Inner Products
Shiwei Zhang 0003, Yi Mu 0001, Guomin Yang |
Inscrypt | 2 |
| 2016 | Strongly Leakage-Resilient Authenticated Key Exchange
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo |
CT-RSA | 2 |
| 2016 | Preserving User Location Privacy for Location-Based Service
Yi Mu 0001 |
GPC | 2 |
| 2016 | Privacy-Preserving Cloud Auditing with Multiple Uploaders
Ge Wu 0001, Yi Mu 0001, Willy Susilo, Fuchun Guo |
ISPEC | 2 |
| 2016 | A Privacy Preserving Source Verifiable Encryption Scheme
Zhongyuan Yao, Yi Mu 0001, Guomin Yang |
ISPEC | 2 |
| 2016 | Ciphertext-Policy Attribute Based Encryption Supporting Access Policy Update
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo |
ProvSec | 3 |
| 2016 | Updatable Lossy Trapdoor Functions and Its Application in Continuous Leakage
Sujuan Li, Yi Mu 0001, Mingwu Zhang, Futai Zhang |
ProvSec | 2 |
| 2016 | One-Round Attribute-Based Key Exchange in the Multi-party Setting
Yangguang Tian, Guomin Yang, Yi Mu 0001, Kaitai Liang, Yong Yu 0002 |
ProvSec | 3 |
| 2016 | Online/Offline Ciphertext Retrieval on Resource Constrained DevicesabstractThe ciphertext retrieval is of paramount importance for data confidentiality and utilization in mobile cloud environment. The receiver, usually equipped with resource constrained devices, retrieves data stored in the cloud server by submitting a confidential request (or trapdoor) to the cloud. Previous schemes need at least one exponentiation operation in group |$\mathbb {G}$| for each keyword to generate the trapdoor, which is quite burdensome for mobile devices to support such computational cost. The computational cost of trapdoor generation limits the application of ciphertext retrieval, especially in a wireless environment. In this paper, we propose the first online/offline ciphertext retrieval (OOCR) scheme, where the trapdoor generation is split into two phases: offline phase and online phase . Most of the computation of the trapdoor could be performed in the offline phase prior to knowing the keyword. The generation of the real trapdoor with keyword can be done efficiently in the online phase. The most challenging task is to resist the so-called insider attacks, which is about keyword guessing attacks from the untrusted cloud server. We also build a novel framework to resist insider attacks and propose an OOCR scheme against insider attacks. Our semantic security proof and performance analysis demonstrate that the proposal is practical for mobile cloud applications. Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen |
Comput. J. | 2 |
| 2016 | Anonymous Proxy Signature with Hierarchical TraceabilityabstractAnonymous proxy signatures are very useful in the construction of anonymous credential systems such as anonymous voting and anonymous authentication protocols. As a basic requirement, we should ensure an honest proxy signer is anonymous. However, in order to prevent the proxy signer from abusing the signing right, we should also allow dishonest signers to be traced. In this paper, we present three novel anonymous proxy signature schemes with different levels of (namely, public, internal and original signer) traceability. We define the formal definitions and security models for these three different settings, and prove the security of our proposed schemes under some standard assumptions. Jiannan Wei, Guomin Yang, Yi Mu 0001, Kaitai Liang |
Comput. J. | 3 |
| 2016 | Token-Leakage Tolerant and Vector Obfuscated IPE and Application in Privacy-Preserving Two-Party Point/Polynomial EvaluationsabstractIn mobile environments, data stored in nodes are subject to side-channel attacks such as power analysis, emitted signal, detected radiation, etc. In this work, we propose a leakage-resilient inner-product encryption that the decryption will succeed if and only if the decryption attribute vector (generate the token) meets the orthogonal encryption attribute vector (obfuscated encryption policy), that is, the match holds that the inner product of two vectors is zero. Propose scheme supports the security of attribute-hiding and leakage-resilient in the standard model. The adversary cannot only issue any token reveal query on non-match vector, but also can request at most |$\ell $|-bit information on the token-leakage query even if the queried vector matches the challenge vector. We prove the security by the technique of dual system encryption in the orthogonal subgroups, to be strongly leakage-resilient and adaptively attribute-hiding. We also deploy our scheme as a building block to devise a secure two-party point/polynomial evaluation protocol in mobility environments, in which two parties cooperate to evaluate a polynomial in the sense that their sensitive inputs of both point and polynomial are fully preserved. Finally, we assess the performance of leakage resilience including the leakage bound and the leakage fraction (LF). Analysis shows that the leakage bound is approximate |$(n-1)\log {\pi _2}$| and the LF is about |${1}/{2(1+\omega _1+\omega _3)}$|, where |$n$| is the length of vector, |$\pi _2$| is the order of subgroup |$\mathbb {G}_{\pi _2}$| and |$\omega _1,\omega _3$| are the constants. We can obtain optimized LF |$1/2-o(1)$| by varying the sizes of subgroups. Mingwu Zhang, Yi Mu 0001 |
Comput. J. | 2 |
| 2016 | Compact Anonymous Hierarchical Identity-Based Encryption with Constant Size Private KeysabstractWe present a new construction of anonymous hierarchical identity-based encryption (HIBE) over prime order groups. The distinct feature of our proposed scheme is that both private key and ciphertext have a constant size, which has never been achieved in all other existing anonymous HIBE schemes. Moreover, we utilized a double exponent technique to generate the ciphertext in order to provide anonymity. This simple and efficient method allows us to construct a more compact anonymous HIBE in prime order groups. Under the decisional bilinear |$n+1$|-Diffie–Hellman exponent assumption and linear assumption, we show that the proposed scheme is secure and anonymous against chosen plaintext attacks in the standard model. Leyou Zhang, Yi Mu 0001, Qing Wu 0005 |
Comput. J. | 2 |
| 2016 | Recent advances in security and privacy in large-scale networksabstractWe are pleased to present to you 13 technical papers dealing with cutting-edge research and technology related to this topic. These papers were selected out of the significantly extended versions of the 149 submissions from 18 countries in the 3rd IEEE International Workshop on Large-Scale Network Security (LSNS 2014) and a large number of open submissions. The selection has been very rigorous, and only the best papers were selected. In the first paper, ‘An Error-Tolerant Keyword Search Scheme Based on Public-Key Encryption in Secure Cloud Computing’ 1, Yang et al. first present a general framework for searching on error-tolerant keywords based on a public-key encryption scheme. Then a concrete scheme is proposed based on the Cramer–Shoup cryptosystem. The scheme is chosen ciphertext attack secure, and suitable for all similarity metrics including Hamming distance metric, edit distance metric, and set difference metric. Because it does not require the user to construct and store anything in advance, very different from those cryptosystems used to calculate the trapdoor of keywords and to encrypt data documents, the new scheme tremendously eases the users' burden. In the second paper, ‘A Lightweight Privacy-Preserving Scheme with Data Integrity for Smart Grid Communications’ 2, Bao and Chen propose a lightweight data report scheme for smart grid communications, which can achieve privacy preservation and data integrity simultaneously. Specifically, an efficient pseudonym identity-based privacy-preserving report approach is proposed for the control center to obtain the fine-grained usage data of all the users while protecting user's privacy. An online/offline hash tree-based mechanism is also designed to check and assure data integrity of communications. Furthermore, a topology-independent data report architecture is also structured, which is adaptable for dynamic residential users to spontaneously form clusters and efficiently report data in flocks. Extensive performance evaluation demonstrates that the proposed scheme can achieve less communication overhead and dramatically reduce computational cost in comparison with the existing schemes. Secure biometric authentication aims to replace an encryption key or an identity certificate with biometrics to complete authentication. In the third paper, ‘A Secure Biometric Authentication Based on PEKS’ 3, Zhang et al. present a generic transformation from searchable encryption to secure biometric authentication and construct a specific secure biometric authentication scheme based on public key encryption with keyword search. Compared with some existing authentication schemes, the proposed scheme is more efficient in the practical application. Furthermore, the transformation from searchable encryption to secure biometric authentication presents a new direction of constructing authentication scheme. Certificateless aggregate signature schemes are required to satisfy the applications in certificateless environment. In the fourth paper, ‘A New Certificateless Signature with Enhanced Security and Aggregation Version’ 4, Deng et al. present an improved certificateless signature scheme and use it to construct a new certificateless signature scheme with enhanced security and aggregation. Compared with other schemes, the proposed scheme is more suitable for realistic applications. In the fifth paper, ‘Worm Propagation Model in Mobile Network’ 5, Chen et al. focus on mobile worm propagation model that allows to control and detect potential worm threat, according to the characteristics of worm's outbreak. Chen et al. put forward a worm propagation model based on the mobile network environment. After analyzing the model, it gives the simulation for controlling factors affecting worm propagation. This model allows us to have a certain understanding for the spread on the size and speed of the mobile worm, providing effective methods to control the spread of the mobile worm. In the sixth paper, ‘Efficient Privacy-Preserving Temporal and Spacial Data Aggregation for Smart Grid Communications’ 6, Dong et al. propose an efficient privacy-preserving temporal and spacial data aggregation from one-way functions in smart grid communications, which also allows special data aggregation from multiple users. The proposed construction can guarantee the unconditional security of users' metering power data privacy from the community gateway and the operation center, and the adaptive chosen ciphertext attack security of the aggregation result that can only be accessed by the authorized operation center. Both temporal and spacial data aggregation only require computing the underlying one-way function once. The provable multiple-replication data-possession protocol with full dynamics aims to realize efficient integrity verification and full dynamic data updates for cloud storage. In the seventh paper, ‘Provable Multiple Replication Data Possession with Full Dynamics for Secure Cloud Storage’ 7, Zhang et al. present a new multiple replication data possession scheme with full dynamics, in which a novel multiple replication Merkle hash tree with rank is used. The proposed scheme improves the efficiency of verifying updates for cloud storage with multiple replicas, which satisfies robust security properties. The eighth paper, ‘Efficient Group Key Management for Secure Big Data in Predictable Large-scale Networks’ 8, by He et al. focuses on secure group communication in large-scale social networks in which the entire social network may have millions of users but a concrete group is usually small. The paper proposes a new dynamic group key agreement protocol by using a novel dual-ring approach in which two rings of nodes are established, one active and one dummy. When some nodes leave, the remaining nodes can replace these nodes with dummy nodes, minimizing the required communications and computations after the protocol is set up and thus provides significant advantage over existing group key management protocols. The thorough analysis by the authors demonstrates provable security of the protocol and the superiority of computation and communication overload. The ninth paper, ‘Delegation of Signing Rights for Emerging 5G Networks’ 9, Ge et al. address the issue of delegating authentication in 5G networks by proposing a new proxy signature scheme. In their proposal, the original signer delegates his or her signing right by signing an exposure-free chameleon hash value as a warrant, and the proxy signer can generate a proxy signature on a message only by finding a chameleon hash collision instead of calculating a new digital signature, which can dramatically reduce computation cost of the proxy signer. With the emergence of cloud storage, searchable encryption technique that enables cloud clients to securely search over ciphertext through keywords and selectively retrieve records of interest has been extensively studied in both industry and academia. Unfortunately, most of the existing searchable encryption schemes cannot preserve keyword privacy and user privacy in multi-user setting simultaneously. For this end, in the 10th paper, ‘Revocable and Anonymous Searchable Encryption in Multi-user Setting’ 10, Miao et al. designed a secure and scalable cryptographic primitive based on identity-based encryption. As a further contribution, this proposed scheme can effectively resist decryption key exposure threat and achieve anonymous-revocable-ID-chosen plaintext attack (CPA) secure in the standard model. The location-based service (LBS) privacy protection scheme aims to solve the user's location privacy disclosure issue when the user initiates an LBS request. In the 11th paper, ‘DALP: A Demand-aware Location Privacy Protection Scheme in Continuous Location-based Services’ 11, Li et al. present a new anonymity-based scheme for continuous LBS queries, which allows a user to customize not only location privacy but also QoS requirement. The proposed scheme can maximize the demands-aware query sequence and minimize the constructed cloaking regions, thereby reducing the query latency and the server's workload. In the 12th paper, ‘Security Analysis of a Privacy-preserving Decentralized Ciphertext-Policy Attribute-based Encryption Scheme’ 12, Wang et al. point out the security weakness of a privacy-preserving decentralized ciphertext-policy attribute-based encryption scheme proposed 13, by Han et al. in ESORICS 2014. They present a collusion attack on the underlying decentralized ciphertext policy attribute based encryption (CP-ABE) scheme and additionally show that the privacy protection of attributes in the privacy-preserving key extraction protocol cannot be provided. The 13th paper, ‘Partner Selection of Agricultural Products Supply Chain Based on Data Mining’ 14, puts forward supply chain partner selection model and partner evaluation index system. With BP neural network, the agricultural products' supply chain partner-selection example analysis is made. The results show that the established supply chain partner-selection model has better generalization ability and can be effectively used to supply chain partner selection. We sincerely hope that you will enjoy reading these papers in this special issue. We thank all the international reviewers for their professional services. We deeply thank Professor Geoffrey Fox, the Editor-in-Chief, for providing this opportunity to publish this special issue. With his continuous support, encouragement, and guidance throughout this publishing project, this special issue has been very successful. Yong Yu 0002, Yi Mu 0001, Rongxing Lu, Jian Ren 0001 |
Concurr. Comput. Pract. Exp. | 2 |
| 2016 | Generalized closest substring encryption
Fuchun Guo, Willy Susilo, Yi Mu 0001 |
Des. Codes Cryptogr. | 3 |
| 2016 | Quantum private set intersection cardinality and its application to anonymous authentication
Yi Mu 0001, Hong Zhong 0001, Shun Zhang 0002, Jie Cui 0004 |
Inf. Sci. | 2 |
| 2016 | Secure Channel Free ID-Based Searchable Encryption for Peer-to-Peer Group
Yi Mu 0001, Rongmao Chen, Xiaosong Zhang 0001 |
J. Comput. Sci. Technol. | 2 |
| 2016 | Centralized keyword search on encrypted data for cloud applicationsabstractAbstract Centralized approaches are widely adopted to improve the qualities of outsourced services owing to its feature of efficient system management. Because the cloud is untrusted, data are usually encrypted before outsourcing. One of the interesting applications is searchable encrypted keywords, a well‐known cryptographic primitive that allows encryption while enabling search for keywords. However, achieving data retrieval without revealing privacy in a cloud‐based centralized system is still a challenging problem. In this paper, we introduce centralized approaches to searchable encryption and present a novel centralized system for retrieval services. In our system, the centralized manager can search and access all the encrypted data from authorized users, while each user can only search and access his or her own data. The system builds on a new cryptographic notion calledcentralized keyword search on encrypted data. We formalize its security model and propose a centralized keyword search on encrypted data construction that is featured by short ciphertext and search result verification. We further extend the construction for removing secure channel and enabling batch authentication on data legalities. The experiment demonstrates the performance of our proposals. Copyright © 2016 John Wiley & Sons, Ltd. Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Jianchang Lai |
Secur. Commun. Networks | 2 |
| 2016 | Privacy-preserving grouping proof with key exchange in the multiple-party settingabstractGrouping proof is a very useful security primitive that can be used to prove the co-existence of multiple entities in an identification protocol. It can be incorporated into radio frequency identification protocols and used in many practical applications such as pharmaceutical distribution and manufacturing. However, the existing grouping proofs do not support secure key establishment, which is required in order to allow secure communication between the reader and the radio frequency identification tags after the identification process. In this paper, we propose a novel grouping proof with key exchange that allows the reader to establish a secure communication channel with the tags. We define the formal security models for grouping proof with key exchange and prove that the proposed generic protocol can achieve grouping proof soundness, session key security, contributiveness, and tag identity privacy. Yangguang Tian, Guomin Yang, Yi Mu 0001 |
Secur. Commun. Networks | 3 |
| 2016 | An efficient privacy-preserving aggregation and billing protocol for smart gridabstractAbstract Smart grid is an electrical grid that uses digital information and communication technology to gather information. Like other digital systems, security and privacy are crucial for smart grid. However, security and privacy protection will inevitably introduce computational complexity and overhead. As smart grid systems are usually operated in a large scale, computational efficiency is a challenging issue. In this paper, we propose an efficient and secure billing system for smart grid, featuring privacy‐preserving and data aggregation. We show that our system offers better privacy protection and computational efficiency, in comparison with an existing protocol. Our security analysis indicates that our protocol achieves privacy‐preserving on electricity reading aggregation and billing, perfect forward secrecy of system session keys, identity authentication, data integrity, and confidentiality. It also shows that even if we allow the collusion of server and gateways, user privacy can still be achieved. Copyright © 2016 John Wiley & Sons, Ltd. Yi Mu 0001, Rongmao Chen |
Secur. Commun. Networks | 2 |
| 2016 | Strongly average-case secure obfuscation: achieving input privacy and circuit obscurityabstractAbstract A program obfuscator is a compiling algorithm that takes a program/circuit as input and generates a new garbled circuit to implement the same functionality as before while obtaining hard‐to‐understand in some sense, that is, infeasible to learn information from the garbled circuit. In order to obtain a practical application, an obfuscation should satisfy equivalent in functionality, polynomial slowdown in efficiency, and virtual black‐box in security. In this paper, we model a stronger cryptographic obfuscation that does not only achieves the obfuscated circuit obscurity but also supports input re‐key privacy. In order to implement the re‐encryption obfuscation, we at first propose a key‐privacy two‐level encryption mechanism that implicitly supports the transformation from level‐2 ciphertext into level‐1 one, which provides an efficient method to re‐encrypt the ciphertext without explicitly decryption procedure. Under the mechanism of two‐level encryption and function of re‐encryption, we construct an obfuscation of re‐encryption that takes as input a probabilistic (keys) circuit and outputs a transformed circuit. We also give the proof that the obfuscator achieves the average‐case security for the circuit family under the extended DBDH assumption and Decisional Linear assumption in the standard model. Copyright © 2016 John Wiley & Sons, Ltd. Mingwu Zhang, Yi Mu 0001, Jian Shen 0001, Xinyi Huang 0001 |
Secur. Commun. Networks | 2 |
| 2016 | CCA2 secure public-key encryption scheme tolerating continual leakage attacksabstractAbstract For a public‐key encryption scheme to be applied in practical applications, it should withstand various leakage attacks (e.g., side‐channel attacks and cold‐boot attacks). To this end, we present a way of construct the more practical CCA2 secure public‐key encryption scheme tolerating leakage attacks, and the scheme's security is based on the hardness of classical decisional Diffie–Hellman assumption and the target collision resistant of one‐way hash function. Additionally, our proposal enjoys better performance, for example, all of elements of ciphertext will be random from the adversary's view, and any probabilistic polynomial‐time adversary cannot obtain leakage on the secret key from the ciphertext, and so on. In the bounded‐leakage setting, for any leakage parameter λ⩽logq − ω(logk)(q is the prime order of the underlying group, and k denotes the security parameter.), our proposal is secure against leakage‐resilient chosen‐ciphertext attacks, where λ is independent of the plaintext space, and has the constant size. However, in the real world, an adversary can continuously learn information on the secret key through a variety of leakage attacks and can trivially break the security of public‐key encryption scheme under the continual leakage attacks. Thus, we will improve our method to resist the continual leakage attacks. Similarly, for any round leakage parameter λC⩽logq − ω(logk), we can prove the security of the improvement scheme based on the hardness of decisional Diffie–Hellman assuming and the target collision resistant of one‐way hash function. With this important performance, our proposal may have some significant value in the practical applications, such as our proposal can provide the leakage‐resilient security for outsourcing data in the cloud computing environment. Copyright © 2016 John Wiley & Sons, Ltd. Yanwei Zhou, Bo Yang 0003, Wenzheng Zhang 0001, Yi Mu 0001 |
Secur. Commun. Networks | 4 |
| 2016 | Relations between robustness and RKA security under public-key encryption
Hui Cui 0001, Yi Mu 0001, Man Ho Au |
Theor. Comput. Sci. | 2 |
| 2016 | Efficient dynamic threshold identity-based encryption with constant-size ciphertext
Willy Susilo, Fuchun Guo, Yi Mu 0001 |
Theor. Comput. Sci. | 3 |
| 2016 | Server-Aided Public Key Encryption With Keyword SearchabstractPublic key encryption with keyword search (PEKS) is a well-known cryptographic primitive for secure searchable data encryption in cloud storage. Unfortunately, it is inherently subject to the (inside) offline keyword guessing attack (KGA), which is against the data privacy of users. Existing countermeasures for dealing with this security issue mainly suffer from low efficiency and are impractical for real applications. In this paper, we provide a practical and applicable treatment on this security vulnerability by formalizing a new PEKS system named server-aided public key encryption with keyword search (SA-PEKS). In SA-PEKS, to generate the keyword ciphertext/trapdoor, the user needs to query a semitrusted third-party called keyword server (KS) by running an authentication protocol, and hence, security against the offline KGA can be obtained. We then introduce a universal transformation from any PEKS scheme to a secure SA-PEKS scheme using the deterministic blind signature. To illustrate its feasibility, we present the first instantiation of SA-PEKS scheme by utilizing the Full Domain Hash RSA signature and the PEKS scheme proposed by Boneh et al. in Eurocrypt 2004. Finally, we describe how to securely implement the client-KS protocol with a rate-limiting mechanism against online KGA and evaluate the performance of our solutions in experiments. Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Dual-Server Public-Key Encryption With Keyword Search for Secure Cloud StorageabstractSearchable encryption is of increasing interest for protecting the data privacy in secure searchable cloud storage. In this paper, we investigate the security of a well-known cryptographic primitive, namely, public key encryption with keyword search (PEKS) which is very useful in many applications of cloud storage. Unfortunately, it has been shown that the traditional PEKS framework suffers from an inherent insecurity called inside keyword guessing attack (KGA) launched by the malicious server. To address this security vulnerability, we propose a new PEKS framework named dual-server PEKS (DS-PEKS). As another main contribution, we define a new variant of the smooth projective hash functions (SPHFs) referred to as linear and homomorphic SPHF (LH-SPHF). We then show a generic construction of secure DS-PEKS from LH-SPHF. To illustrate the feasibility of our new framework, we provide an efficient instantiation of the general framework from a Decision Diffie-Hellman-based LH-SPHF and show that it can achieve the strong security against inside the KGA. Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Distance-Based Encryption: How to Embed Fuzziness in Biometric-Based EncryptionabstractWe introduce a new encryption notion called distance-based encryption (DBE) to apply biometrics in identity-based encryption. In this notion, a ciphertext encrypted with a vector and a threshold value can be decrypted with a private key of another vector, if and only if the distance between these two vectors is less than or equal to the threshold value. The adopted distance measurement is called Mahalanobis distance, which is a generalization of Euclidean distance. This novel distance is a useful recognition approach in the pattern recognition and image processing community. The primary application of this new encryption notion is to incorporate biometric identities, such as face, as the public identity in an identity-based encryption. In such an application, usually the input biometric identity associated with a private key will not be exactly the same as the input biometric identity in the encryption phase, even though they are from the same user. The introduced DBE addresses this problem well as the decryption condition does not require identities to be identical but having small distance. The closest encryption notion to DBE is the fuzzy identity-based encryption, but it measures biometric identities using a different distance called an overlap distance (a variant of Hamming distance) that is not widely accepted by the pattern recognition community, due to its long binary representations. In this paper, we study this new encryption notion and its constructions. We show how to generically and efficiently construct such a DBE from an inner product encryption (IPE) with reasonable size of private keys and ciphertexts. We also propose a new IPE scheme with the shortest private key to build DBE, namely, the need for a short private key. Finally, we study the encryption efficiency of DBE by splitting our IPE encryption algorithm into offline and online algorithms. Fuchun Guo, Willy Susilo, Yi Mu 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | One-Round Privacy-Preserving Meeting Location Determination for Smartphone ApplicationsabstractWith the widely adopted GPS technology in mobile devices, users enjoy many types of location services. As a recently proposed application, determining the optimal private meeting location with an aid of a location server has been an interesting research topic. The challenge in this paper is due to the requirements of security and privacy, because user locations should not be revealed to the honest-but-curious or semi-trusted location server. Adding the security and privacy protection to a location service will inevitably introduce computational complexity and communication overhead. In order to introduce robust location service and make this location service practical, we propose an efficient optimal private meeting location determination protocol, which needs only one round communication and light computation. Our proposed protocol satisfies the requirement of location privacy against outsiders, the semi-trusted meeting location determination server, and the semi-trusted group users. In order to study the performance of our protocol in a real deployment, we simulate our scheme on smartphones. The simulation results and the performance comparison with another scheme demonstrate its advantages in communication and computation efficiency. Yi Mu 0001, Rongmao Chen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Comments on "Public Integrity Auditing for Dynamic Data Sharing With Multiuser Modification"abstractRecently, a practical public integrity auditing scheme supporting multiuser data modification (IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, DOI 10.1109/TIFS.2015.2423264) was proposed. Although the protocol was claimed secure, in this paper, we show that the proposal fails to achievesoundness, the most essential property that an auditing scheme should provide. Specifically, we show that a cloud server can collude with a revoked user to deceive a third-party auditor (TPA) that a stored file keeps virgin even when the entire file has been deleted. Yong Yu 0002, Yannan Li 0001, Jianbing Ni, Guomin Yang, Yi Mu 0001, Willy Susilo |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2016 | Comments on "Accountable and Privacy-Enhanced Access Control in Wireless Sensor Networks"abstractIn a recent paper (IEEE Trans. Wireless Commun., vol. 14, no. 1, 2015), Heet al.proposed an accountable and privacy-enhanced access control (APAC) protocol, which aimed to provide privacy for honest users against network owners and accountability against misbehaving users without the involvement of any trusted third party. However, the level of trust on the network owner has not been clearly defined in Heet al.’s paper, and we demonstrate in this letter that in the case where the network owners cannot be trusted to correctly generate the system parameters, then the APAC protocol cannot ensure user privacy. Jiannan Wei, Guomin Yang, Yi Mu 0001 |
IEEE Trans. Wirel. Commun. | 3 |
| 2016 | Trust-based group services selection in web-based service-oriented environments
Xing Su 0001, Minjie Zhang 0001, Yi Mu 0001 |
World Wide Web | 3 |
| 2015 | A New General Framework for Secure Public Key Encryption with Keyword Search
Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo |
ACISP | 2 |
| 2015 | A New Public Remote Integrity Checking Scheme with User Privacy
Yiteng Feng, Yi Mu 0001, Guomin Yang, Joseph K. Liu |
ACISP | 2 |
| 2015 | Improved Identity-Based Online/Offline Encryption
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Willy Susilo |
ACISP | 2 |
| 2015 | Anonymous Yoking-Group ProofsabstractYoking-proofs show an interesting application in Radio Frequency Identification (RFID) that a verifier can check whether two tags are simultaneously scanned by a reader. We consider a scenario that multi-group of tags can be proved to be scanned simultaneously. Grouping-proof, which is an extension of yoking-proofs, allows multiple tags to be proved together, while existing protocols cannot support multiple groups. In this paper, we introduce a novel concept called "yoking-group proofs". Additionally, we propose an anonymous yoking-proof protocol and an anonymous yoking-group proof protocol and prove their security in Universal Composability framework. Nan Li 0007, Yi Mu 0001, Willy Susilo, Vijay Varadharajan |
AsiaCCS | 2 |
| 2015 | Threshold Broadcast Encryption with Keyword Search
Shiwei Zhang 0003, Yi Mu 0001, Guomin Yang |
Inscrypt | 2 |
| 2015 | Provably Secure Identity Based Provable Data Possession
Yong Yu 0002, Yafang Zhang, Yi Mu 0001, Willy Susilo |
ProvSec | 3 |
| 2015 | Further ideal multipartite access structures from integer polymatroids
Qianhong Wu, Duncan S. Wong, Yi Mu 0001, Jianwei Liu 0001 |
Sci. China Inf. Sci. | 5 |
| 2015 | On Indistinguishability in Remote Data Integrity CheckingabstractWith a rapid growth of data storage in the cloud, data integrity checking in a remote data storage system has become an important issue. A number of protocols, which allow remote integrity checking by a third party, have been proposed. Although those protocols are provably secure, the data privacy issues in those protocols have not been considered. We believe that these issues are equally important since the communication flows of integrity proofs from the cloud server should not reveal any useful information of the stored data. In this paper, we introduce a new definition of data privacy called ‘IND-Privacy’ by an indistinguishability game. It is found that many existing remote integrity proofs are insecure under an IND-Privacy game. It is also found that by adopting witness indistinguishable proofs, the IND-Privacy is achievable. We provide an instantiation that captures data integrity, soundness and IND-privacy. Guomin Yang, Yi Mu 0001, Yong Yu 0002 |
Comput. J. | 3 |
| 2015 | Secure Delegation of Signing Power from FactorizationabstractDelegation of signing is a working way common in office automation work, and is also an important approach to establish trust. Proxy signature is an important cryptographic primitive for delegating signing powers and it has found many real-world applications. The existing proxy signature schemes from factorization assumption are either insecure or inefficient. In this paper, we propose a novel, efficient and provably secure proxy signature scheme from factorization. Our construction makes use of a factorization-based key exposure-free chameleon hash function in the delegation phase and the proxy signer needs only to find a collision to a chameleon hash value to generate a valid proxy signature. As a result, our scheme is highly efficient in terms of the computation of a proxy signature. We also provide a formal security proof by classifying the adversaries into three categories. Comparisons demonstrate that the new scheme outperforms the known ones in terms of security, computational efficiency and the length of the public key. Yong Yu 0002, Man Ho Au, Yi Mu 0001, Willy Susilo, Huai Wu |
Comput. J. | 3 |
| 2015 | Functional Encryption Resilient to Hard-to-Invert LeakageabstractFunctional encryption (FE) systems provide a flexible and expressive encryption mechanism that private keys and ciphertexts are associated with attributes and predicate formulae Γ and decryption are possible whenever keys and ciphertexts are related, i.e. . In this work, we put forward a leakage-resilient FE scheme against the amount of leakage output over a hard-to-invert function family. In our scheme, the encryption policy is specified as an arbitrary monotonic formula, and the adversary can learn the arbitrary length output of the master key and the private key from any computationally irreversible function with the input (master) keys. To improve the efficiency, we employ the set of minimal sets to describe the predicate formula or access structure, and initiate the formal model of leakage-resilient FE, which is a generic extension of identity-based encryption and attribute-based encryption in the presence of key leakage with auxiliary inputs. We provide the concrete construction in bilinear groups of composite order, and prove the adaptively leakage-resilient security in the standard model based on static assumptions. Our hard-to-invert leakage resilience employs the Goldreich–Levin theorem and its extension as a hard-core value over large fields. We also give an extensional construction in the case of obtaining the hard-to-invert randomness leakage of the encryption, which uses a strong extractor to prevent leakage of randomness and a hard-to-invert encryption to prevent the leakage of the key. Finally, we analyze and discuss the stepped-up security on master leakage and continual leakage, and the lower bound of the irreversible leakage function. Mingwu Zhang, Tsuyoshi Takagi, Yi Mu 0001 |
Comput. J. | 4 |
| 2015 | A reliable recommendation and privacy-preserving based cross-layer reputation mechanism for mobile cloud computing
Hui Lin 0007, Li Xu 0002, Yi Mu 0001, Wei Wu 0001 |
Future Gener. Comput. Syst. | 3 |
| 2015 | Proof of retrievability with public verifiability resilient against related-key attacksabstractModern technologies such as cloud computing, grid computing and software as a service all require data to be stored by the third parties. A specific problem encountered in this context is to convince a verifier that a user's data are kept intact at the storage servers. An important approach to achieve this goal is called proof of retrievability, by which a storage server can assure a verifier via a concise proof that a user's file is available. However, for most publicly verifiable systems, existing proof of retrievability solutions do not take physical attacks into consideration, where an adversary can observe the outcome of the computation with methods like fault injection techniques. In fact, the authors find that giving the adversary the ability to obtain the information about the relations between the private keys, those systems are not secure anymore. Motivated by the need of preventing this kind of attacks, they present the security model for related‐key attacks in publicly verifiable proofs of retrievability, where the adversary can subsequently observe the outcome of the publicly verifiable proof of retrievability under the modified key. After pointing out a linear related‐key attack on an existing proof of retrievability system with public verifiability, they present a secure and efficient proof of retrievability with public verifiability, against related‐key attacks. Hui Cui 0001, Yi Mu 0001, Man Ho Au |
IET Inf. Secur. | 2 |
| 2015 | Identity-based quotable ring signature
Kefeng Wang, Yi Mu 0001, Willy Susilo |
Inf. Sci. | 2 |
| 2015 | A resilient identity-based authenticated key exchange protocolabstractThis paper presents a new security notion for key exchange (KE) protocols called resiliency. That is, if a shared secret between a group of parties is compromised or leaked, they can generate another completely new shared secret without the need to set up a new KE session. We present an identity-based authenticated KE protocol that satisfies the resiliency security property. We prove that if an l-bit shared secret key (SSK) is leaked, then two parties P1 and P2 can safely generate another shared secret SSK1 without the need to establish a new session. We adjust the unauthenticated adversarial model of the Canetti–Krawczyk to meet this security property and prove the security of the proposed protocol using the Canetti–Krawczyk model based on the quadratic residuosity assumption. Copyright © 2015 John Wiley & Sons, Ltd. Ibrahim F. Elashry, Yi Mu 0001, Willy Susilo |
Secur. Commun. Networks | 2 |
| 2015 | Vulnerabilities of an ECC-based RFID authentication schemeabstractRadio frequency identification (RFID) authentication is an indispensable part of RFID applications, which allows a reader to identify objects in an authenticated manner. Recently, Liao and Hsiao proposed a very interesting elliptic curve cryptography-based RFID authentication scheme with ID-verifier transfer protocol. They claimed that the proposed protocol is secure against many attacks and satisfies essential security requirements of RFID systems. However, in this paper, we demonstrate that the protocol suffers from several attacks, in contrast to their original claims in the paper. Furthermore, we also propose a repaired version of the authentication protocol against identified attacks, and we provide formal security proofs. Nan Li 0007, Yi Mu 0001, Willy Susilo, Fuchun Guo, Vijay Varadharajan |
Secur. Commun. Networks | 2 |
| 2015 | Loss-Tolerant Bundle Fragment Authentication for Space-Based DTNsabstractBundle authentication, which ensures the authenticity and integrity of bundles, is critical in space Delay/disruption-Tolerant Networks (DTNs). When bundle fragment services are needed, the previous solutions directly using digital signatures suffer from heavy computational costs and bandwidth overheads. This paper addresses the issue of fragment authentication for Bundle Protocol by exploiting erasure codes and the batch transmission characteristic of DTNs. Erasure codes are adopted to allow all the fragments of a bundle to equally share only one signature, to tolerate high delays as well as unexpected loss of connectivity. Following this generic idea, we present two approaches, both of which are effective in filtering inauthentic fragments as early as possible. The first one takes a surprisingly low bandwidth overhead, while it makes all received fragments of a bundle to be removed when there is an inauthentic one, because of its failure in locating the inauthentic fragments. Considering this defect, we present an improved scheme which is able to detect inauthentic fragments thanks to a special hash chain and then only remove these inauthentic ones. The performance simulation demonstrates that both our schemes significantly reduce bandwidth overheads and computational costs as compared to the prior works. Xixiang Lv, Yi Mu 0001, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2015 | BL-MLE: Block-Level Message-Locked Encryption for Secure Large File DeduplicationabstractDeduplication is a popular technique widely used to save storage spaces in the cloud. To achieve secure deduplication of encrypted files, Bellare et al. formalized a new cryptographic primitive named message-locked encryption (MLE) in Eurocrypt 2013. Although an MLE scheme can be extended to obtain secure deduplication for large files, it requires a lot of metadata maintained by the end user and the cloud server. In this paper, we propose a new approach to achieve more efficient deduplication for (encrypted) large files. Our approach, named block-level message-locked encryption (BL-MLE), can achieve file-level and block-level deduplication, block key management, and proof of ownership simultaneously using a small set of metadata. We also show that our BL-MLE scheme can be easily extended to support proof of storage, which makes it multi-purpose for secure cloud storage. Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | AAC-OT: Accountable Oblivious Transfer With Access ControlabstractTo prevent illegal users accessing the database and protect users' privacy, oblivious transfer with access control (AC-OT) was proposed. In an AC-OT scheme, the database provider can encrypt the records and publish corresponding access control lists (ACLs). Prior to accessing the records, a user needs to obtain anonymous credentials from the issuer. Subsequently, an authorized user can obtain the intended records without the database provider knowing its choices. Although AC-OT schemes have shown a lot of merits, there are some practical issues: 1) one of the inherited problems in anonymous credentials is timely revocation and 2) how to prevent malicious users overusing the records. In this paper, we propose an accountable AC-OT scheme to address these issues. In our scheme, an authorized user can access the protected records without the database provider knowing his personal information and choices if: 1) he has obtained the required credentials listed in the ACLs and 2) the number of the access times for each record is no more than the specified bound. Notably, the database provider can trace and revoke the user who overused the records even in the lifetime of his credentials. To the best of our knowledge, it is the first AC-OT scheme where timely revocation and overuse detection are considered. Jinguang Han, Willy Susilo, Yi Mu 0001, Man Ho Au, Jie Cao 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2015 | Improving Privacy and Security in Decentralized Ciphertext-Policy Attribute-Based EncryptionabstractIn previous privacy-preserving multiauthority attribute-based encryption (PPMA-ABE) schemes, a user can acquire secret keys from multiple authorities with them knowing his/her attributes and furthermore, a central authority is required. Notably, a user's identity information can be extracted from his/her some sensitive attributes. Hence, existing PPMA-ABE schemes cannot fully protect users' privacy as multiple authorities can collaborate to identify a user by collecting and analyzing his attributes. Moreover, ciphertext-policy ABE (CP-ABE) is a more efficient public-key encryption, where the encryptor can select flexible access structures to encrypt messages. Therefore, a challenging and important work is to construct a PPMA-ABE scheme where there is no necessity of having the central authority and furthermore, both the identifiers and the attributes can be protected to be known by the authorities. In this paper, a privacy-preserving decentralized CP-ABE (PPDCP-ABE) is proposed to reduce the trust on the central authority and protect users' privacy. In our PPDCP-ABE scheme, each authority can work independently without any collaboration to initial the system and issue secret keys to users. Furthermore, a user can obtain secret keys from multiple authorities without them knowing anything about his global identifier and attributes. Jinguang Han, Willy Susilo, Yi Mu 0001, Jianying Zhou 0001, Man Ho Au |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2015 | Comments on a Public Auditing Mechanism for Shared Cloud Data ServiceabstractRecently, a public auditing protocol for shared data called Panda (IEEE Transactions on Services Computing, doi: 10.1109/TSC.2013.2295611) was proposed to ensure the correctness of the outsourced data. A distinctive feature of Panda is the support of data sharing and user revocation. Unfortunately, in this letter, we show that Panda is insecure in the sense that a cloud server can hide data loss without being detected. Specifically, we show that even some stored file blocks have been lost, the server is able to generate a valid proof by replacing a pair of lost data block and its signature with another block and signature pair. We also provide a solution to the problem while preserving all the desirable features of the original protocol. Yong Yu 0002, Jianbing Ni, Man Ho Au, Yi Mu 0001, Boyang Wang 0001, Hui Li 0006 |
IEEE Trans. Serv. Comput. | 4 |
| 2014 | POSTER: Euclidean Distance Based Encryption: How to Embed Fuzziness in Biometric Based EncryptionabstractWe introduce a new encryption notion called Euclidean Distance based Encryption (EDE). In this notion, a ciphertext encrypted with a vector and a threshold value can be decrypted with a private key of another vector, if and only if the Euclidean distance between these two vectors is less than or equal to the threshold value. Euclidean distance is the underlying technique in the pattern recognition and image processing community for image recognition. The primary application of this encryption notion is to enable an identity-based encryption that incorporates biometric identifiers, such as fingerprint, face, hand geometry, vein and iris. In that application, usually the input biometric will not be exactly the same during the enrollment and encryption phases. In this poster, we propose this new encryption notion and study its construction. We show how to generically and efficiently construct an EDE from an inner-product encryption (IPE) with reasonable size of private keys and ciphertexts. We also propose a new IPE scheme that is equipped with a specific characteristic to build EDE, namely the need for short private key. Our IPE scheme achieves the shortest private key compared to existing IPE schemes in the literature, where our private key is composed of two group elements only. Fuchun Guo, Willy Susilo, Yi Mu 0001 |
CCS | 3 |
| 2014 | An Efficient Privacy-Preserving E-coupon System
Weiwei Liu 0005, Yi Mu 0001, Guomin Yang |
Inscrypt | 2 |
| 2014 | PPDCP-ABE: Privacy-Preserving Decentralized Ciphertext-Policy Attribute-Based Encryption
Jinguang Han, Willy Susilo, Yi Mu 0001, Jianying Zhou 0001, Man Ho Au |
ESORICS (2) | 3 |
| 2014 | Attribute-Based Signature with Message Recovery
Kefeng Wang, Yi Mu 0001, Willy Susilo, Fuchun Guo |
ISPEC | 2 |
| 2014 | Jhanwar-Barua's Identity-Based Encryption Revisited
Ibrahim F. Elashry, Yi Mu 0001, Willy Susilo |
NSS | 2 |
| 2014 | Attribute-Based Signing Right Delegation
Weiwei Liu 0005, Yi Mu 0001, Guomin Yang |
NSS | 2 |
| 2014 | Identity Privacy-Preserving Public Auditing with Dynamic Group for Secure Mobile Cloud Storage
Yong Yu 0002, Yi Mu 0001, Jianbing Ni, Jiang Deng, Ke Huang 0002 |
NSS | 2 |
| 2014 | Complete Robustness in Identity-Based Encryption
Hui Cui 0001, Yi Mu 0001, Man Ho Au |
ProvSec | 2 |
| 2014 | Public-Key Encryption Resilient against Linear Related-Key Attacks RevisitedabstractWee (PKC'12) proposed a generic public-key encryption scheme in the setting of related-key attacks. Bellare, Paterson and Thomson (Asiacrypt'12) provided a framework enabling related-key attack (RKA) secure cryptographic primitives for a class of non-linear related-key derivation functions. However, in both of their constructions, the instantiations to achieve the full (not weak) RKA security are given under the scenario regarding the private key composed of single element. In other words, each element of the private key shares the same modification. However, this is impractical in real world. In this paper, we concentrate on the security of public-key encryption schemes under linear related-key attacks in the setting of multielement private keys (that is, the private key is composed of more than one element), where an adversary is allowed to tamper any part of this private key stored in a hardware device, and subsequently observes the outcome of a public key encryption system under this targeted modified private key. We define the security model for RKA secure public-key encryption schemes as chosen-cipher text and related-key attack (CC-RKA) security, which means that a public-key encryption scheme remains secure even when an adversary is allowed to issue the decryption oracle on linear shifts of any component of the private key. After that, we present a detailed public key encryption schemes with the private key formed of several elements, of which the CC-RKA security is under the decisional BDH assumption in the standard model. Hui Cui 0001, Yi Mu 0001, Man Ho Au |
TrustCom | 2 |
| 2014 | Anonymous Proxy Signature with Restricted TraceabilityabstractSigner anonymity is an important security requirement for many digital signature schemes due to the need of user privacy in many applications. In this paper, we study signer anonymity for proxy signature which allows a signer to delegate his/her signing right to another user (or proxy). Since the proxy signer is the actual singer in a proxy signature scheme, we are interested in protecting the proxy signer's identity in this paper. However, one potential problem in an anonymous proxy signature scheme is that the proxy signer may abuse the delegated signing right due to the anonymity property of a proxy signature. In this paper, we propose a novel anonymous proxy signature scheme with restricted traceability, which allows the original singer to trace dishonest proxy signers. However, if the proxy signer is honest, then his/her identity is well protected against any user (including the original signer). Our scheme will be useful in many applications such as anonymous authentication protocols and anonymous voting schemes. Jiannan Wei, Guomin Yang, Yi Mu 0001 |
TrustCom | 3 |
| 2014 | Toward reverse engineering on secret S-boxes in block ciphers
Ming Tang 0002, Zhenlong Qiu, Hongbo Peng, Yi Mu 0001, Huanguo Zhang |
Sci. China Inf. Sci. | 5 |
| 2014 | Signcryption Secure Against Linear Related-Key AttacksabstractA related-key attack (RKA) occurs when an adversary tampers the private key stored in a cryptographic hardware device, and observes the result of the cryptographic primitive under this modified private key. In this paper, we consider the security of signcryption schemes under linear RKAs, where an adversary is allowed to tamper the private keys of the receiver and the sender, and subsequently observe the outcome of a signcryption system under these modified private keys of both parties. We define two security notions for RKA-secure signcryption schemes: chosen ciphertext RKA and chosen message RKA. We require that a signcryption scheme remains secure even when an adversary is allowed to access the designcryption oracle and the signcryption oracle on linear shifts of the private keys of the receiver and the sender, respectively. After reviewing some basic definitions related to our construction, we give a specific signcryption scheme from bilinear Diffie-Hellman which is secure against RKAs. Furthermore, we extend the security model of signcryption with anonymity, where the ciphertext is anonymous to others except the real receiver given the honest sender and the honest receiver. Fortunately, with a trivial modification to the original signcryption scheme, our proposed signcryption scheme can protect the privacy of both the sender and the receiver. Hui Cui 0001, Yi Mu 0001, Man Ho Au |
Comput. J. | 2 |
| 2014 | Server-Aided Signature Verification for Lightweight DevicesabstractServer-aided verification (SAV) has potential applicability in lightweight devices for improving signature verification, where the verifier possesses a computationally weak hardware. We observe that lightweight devices run all algorithms through hardware implementation with logic circuits. Existing SAV protocols indeed improve computational efficiency for lightweight devices, however, few of them take the hardware cost into consideration. The hardware implementation of SAV protocols could be still costly and expensive for lightweight devices. Currently, the most secure SAV protocols in the literature for pairing-based (𝔾1 × 𝔾2 → 𝔾T) signatures can securely delegate pairing computations to the server; however, verifiers are still required to perform group operations over two completely different groups 𝔾1 and 𝔾T, which heavily contribute to the cost of hardware implementation. In this work, we propose several collusion-resistant SAV protocols for pairing-based signatures to improve their applicability for lightweight devices. In our SAV protocols, verifiers are only required to perform group operations in 𝔾1. In comparison with existing SAV protocols, our protocols save the unnecessary hardware cost for implementing group operations in 𝔾T and therefore are more applicable to lightweight applications. Fuchun Guo, Yi Mu 0001, Willy Susilo, Vijay Varadharajan |
Comput. J. | 2 |
| 2014 | Attribute-Based Data Transfer with Filtering Scheme in Cloud ComputingabstractData transfer is a transmission of data over a point-to-point or point-to-multipoint communication channel. To protect the confidentiality of the transferred data, public-key cryptography has been introduced in data transfer schemes (DTSs). Data transfer is a transmission of data over a point-to-point or point-to-multipoint communication channel. To protect the confidentiality of the transferred data, public-key cryptography has been introduced in data transfer schemes (DTSs). Unfortunately, there exist some drawbacks in the current DTSs. First, the sender must know who the real receivers are. This is undesirable in a system where the number of the users is very large, such as cloud computing. In practice, the sender only knows some descriptive attributes of the receivers. Secondly, the receiver cannot be guaranteed to only receive messages from the legal senders. Therefore, it remains an elusive and challenging research problem on how to design a DTS scheme where the sender can send messages to the unknown receivers and the receiver can filter out false messages according to the described attributes. In this paper, we propose an attribute-based data transfer with filtering (ABDTF) scheme to address these problems. In our proposed scheme, the receiver can publish an access structure so that only the users whose attributes satisfy this access structure can send messages to him. Furthermore, the sender can encrypt a message under a set of attributes such that only the users who hold these attributes can obtain the message. In particular, we provide an efficient filtering algorithm for the receiver to resist the denial-of-service attacks. Notably, we propose the formal definition and security models for ABDTF schemes. To the best of our knowledge, it is the first time that a provable ABDTF scheme is proposed. Hence, this work provides a new research approach to ABDTF schemes. must know who are the real receivers. This is undesirable in a system where the number of the users is very large, such as cloud computing. In practice, the sender only knows some descriptive attributes of the receivers. Second, the receiver cannot be guaranteed to only receive messages from the legal senders. Therefore, it remains an elusive and challenging research problem on how to design a DTS scheme where the sender can send messages to the unknown receivers and the receiver can filter out false messages according to the described attributes. In this paper, we propose an attribute-based data transfer with filtering (ABDTF) scheme to address these problems. In our proposed scheme, the receiver can publish an access structure so that only the users whose attributes satisfy this access structure can send messages to him. Furthermore, the sender can encrypt a message under a set of attributes such that only the users who hold these attributes can obtain the message. In particular, we provide an efficient filtering algorithm for the receiver to resist the denial-of-service (DoS) attacks. Notably, we propose the formal definition and security models for ABDTF schemes. To the best of our knowledge, it is the first time that a provable ABDTF scheme is proposed. Hence, this work provides a new research approach to ABDTF schemes. Jinguang Han, Willy Susilo, Yi Mu 0001, Jun Yan 0005 |
Comput. J. | 3 |
| 2014 | Affiliation-Hiding Authenticated Asymmetric Group Key Agreement Based on Short SignatureabstractThe notion of Affiliation-Hiding Authenticated Group Key Agreement (AH-AGKA) protocols was first introduced by Jarecki et al. in CT-RSA 2007, where they presented two concrete AH-AGKA protocols. In this paper, we show that Jarecki et al.'s second protocol has some drawbacks. We propose a new affiliation-hiding protocol. Differing from Jarecki et al.'s protocol, our protocol is asymmetric. Compared with existing AH-AGKA protocols, our scheme not only exhibits the affiliation-hiding property, but also holds the properties of detectability and perfect forward secrecy. Chang Xu 0004, Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001 |
Comput. J. | 4 |
| 2014 | Trust-oriented QoS-aware composite service selection based on genetic algorithmsabstractSUMMARY Service selection in service‐oriented computing has emerged to be an increasingly important research area. From the client's point of view, in addition to the QoS of a service or a service composition, the trust level becomes an important part. As the complexity of invocation in service composition has been greatly increased, a comprehensive mechanism, which could evaluate both the subjective aspect as trust expression and the objective aspect as QoS, is needed. In this paper, we provide a formal service composition architecture for service selection. In addition, we propose a trust evaluation method for the service composition plan based on the subjective probability theory, based on them, our trust‐oriented genetic algorithm (TOGA) is proposed to find a near‐optimal service composition plan with QoS constraints. Experimental results have illustrated that our proposed approach can discover the near‐optimal solution efficiently. Copyright © 2013 John Wiley & Sons, Ltd. Jun Yan 0005, Yi Mu 0001 |
Concurr. Comput. Pract. Exp. | 3 |
| 2014 | Security of new generation computing systemsabstractModern computing systems have become more easy-to-use, sophisticated and powerful, and have dramatically changed the way we live. However, the same systems add complexity and also introduce new interdependencies, vulnerabilities and privacy issues. There will be more ways to disrupt our life through cyber attacks. It is thus of great importance to consider and develop methods to mitigate those security risks. This special issue presents the recent advances on the security of new generation computing systems including distributed, cloud, and grid systems. We are pleased to present to you nine technical papers dealing with cutting-edge research and technology related to this topic. These papers were selected out of the significantly extended versions of the 173 submissions from 28 countries in the 6th International Conference on Network and System Security (NSS 2012) and a large number of open submissions. The selection has been very rigorous, and only the best papers were selected. Li Xu 0002, Elisa Bertino, Yi Mu 0001 |
Concurr. Comput. Pract. Exp. | 3 |
| 2014 | Key continual-leakage resilient broadcast cryptosystem from dual system in broadcast networks
Mingwu Zhang, Yi Mu 0001 |
Frontiers Comput. Sci. | 2 |
| 2014 | SA3: Self-adaptive anonymous authentication for dynamic authentication policies
Yanling Lian, Xinyi Huang 0001, Yi Mu 0001 |
Future Gener. Comput. Syst. | 3 |
| 2014 | On the security of auditing mechanisms for secure cloud storage
Yong Yu 0002, Lei Niu, Guomin Yang, Yi Mu 0001, Willy Susilo |
Future Gener. Comput. Syst. | 4 |
| 2014 | Security pitfalls of an efficient threshold proxy signature scheme for mobile agents
Yong Yu 0002, Yi Mu 0001, Willy Susilo, Man Ho Au |
Inf. Process. Lett. | 2 |
| 2014 | Towards a cryptographic treatment of publish/subscribe systemsabstractPublish/subscribe mechanism is a typical many-to-many messaging paradigm when multiple applications want to receive the same message or when a group of applications would like to notify each other. Nonetheless, there exist only a few works that address the security issues for content-based publish/subscribe systems formally. Although the security requirements have been partially addressed by Wang et al., there is no formal definition for all of these security requirements in the literature. As a result, most of the existing schemes do not have any security proof and it is difficult to justify whether those schemes are really secure in practice. Furthermore, there is no comprehensive scheme that satisfies the most essential security requirements at the same time. In this paper, we introduce the first security model for important security requirements of content-based publish/subscribe systems. We also give a new security requirement for publisher authenticity, which means that the publisher is authenticated to publish certain types of notification only, and cannot publish other types of notification. We then exhibit a new scheme which fulfills most of the security requirements. Furthermore, we also provide a comprehensive proof for our concrete construction according to the new model. Tsz Hon Yuen, Willy Susilo, Yi Mu 0001 |
J. Comput. Secur. | 3 |
| 2014 | Loss-tolerant authentication with digital signaturesabstractABSTRACT Consider a signed file that cannot be verified because of some fraction loss or noise, which might not affect the business of users. It would be desirable for the verifier to locate the damaged fractions so that the authenticity of other components of the file can be ensured. Thereafter, the verifier can decide whether or not to accept it. To address this issue, in this paper, we present a loss‐tolerant authentication scheme, which allows the verifier to locate the damaged elements in the signed file stream. Our idea is to allow the signed file to be fragmented, and each fragment is appended a short authentication tag, which enables the verifier to find the modified fragments in the signed file and verify the signature even if some fragments are lost. The proposed scheme adopts a combination of Reed–Solomon error correction and erasure codes, aiming to allow verifiers to locate the modified fractions and thereafter reconstruct the signature when sufficient original fractions of the file are obtained. Our scheme offers many potential applications such as loss‐tolerant transmission and storage. Copyright © 2013 John Wiley & Sons, Ltd. Xixiang Lv, Yi Mu 0001, Hui Li 0006 |
Secur. Commun. Networks | 2 |
| 2014 | A secure mobility support scheme for 6LoWPAN wireless sensor networksabstractABSTRACT This paper proposes a secure mobility support scheme for 6LoWPAN wireless sensor networks. The paper first presents the IPv6 over Low power Wireless Personal Area Networks (6LoWPAN) architecture where the routing can be automatically performed. With the architecture, both the hierarchical Internet protocol version 6 address structure and the secure address configuration algorithm for a 6LoWPAN wireless sensor network are proposed. With the architecture and the address structure, the secure intranetwork and internetwork mobility handover algorithms are presented, and they utilize the encryption and authentication to achieve the security. During the mobility process, a mobile node does not need a care‐of address, so the mobility handover process includes neither the care‐of address configuration operation nor the address‐binding operation. As a result, the mobility handover cost and delay are reduced. Moreover, mobile nodes do not need to be involved in the mobility handover process, so the packet loss caused by mobile nodes' failure is avoided. During the intranetwork mobility handover process, a link address is used to identify a mobile node, so the size of a control message is reduced substantially. As a result, the transmission cost and delay are reduced. The paper analyzes the performance parameters of the proposed scheme, including mobility handover cost, delay, and packet loss rate. Compared with the existing scheme without security, the proposed scheme has relatively good mobility handover performance. Copyright © 2013 John Wiley & Sons, Ltd. Xiaonan Wang 0001, Yi Mu 0001 |
Secur. Commun. Networks | 2 |
| 2014 | Efficient public key encryption with revocable keyword searchabstractABSTRACT Public key encryption with keyword search is a novel cryptographic primitive enabling one to search on the encrypted data directly. In the known schemes, once getting a trapdoor, the server can search associated data without any restrictions. However, in reality, it is sometimes essential to prevent the server from searching the data all the time because the server is not fully trusted. In this paper, we propose the notion of public key encryption with revocable keyword search to address the issue. We also develop a concrete construction by dividing the whole life of the system into distinct times to achieve our goals. The proposed scheme achieves the properties of the indistinguishability of ciphertexts against an adaptive chosen keywords attack security under the co‐decisional bilinear Diffie–Hellman assumption in our security model. Compared with two somewhat schemes, ours offers much better performance in terms of computational cost. Copyright © 2013 John Wiley & Sons, Ltd. Yong Yu 0002, Jianbing Ni, Haomiao Yang, Yi Mu 0001, Willy Susilo |
Secur. Commun. Networks | 4 |
| 2014 | Identity-Based Secure DistributedData Storage SchemesabstractSecure distributed data storage can shift the burden of maintaining a large number of files from the owner to proxy servers. Proxy servers can convert encrypted files for the owner to encrypted files for the receiver without the necessity of knowing the content of the original files. In practice, the original files will be removed by the owner for the sake of space efficiency. Hence, the issues on confidentiality and integrity of the outsourced data must be addressed carefully. In this paper, we propose two identity-based secure distributed data storage (IBSDDS) schemes. Our schemes can capture the following properties: (1) The file owner can decide the access permission independently without the help of the private key generator (PKG); (2) For one query, a receiver can only access one file, instead of all files of the owner; (3) Our schemes are secure against the collusion attacks, namely even if the receiver can compromise the proxy servers, he cannot obtain the owner’s secret key. Although the first scheme is only secure against the chosen plaintext attacks (CPA), the second scheme is secure against the chosen ciphertext attacks (CCA). To the best of our knowledge, it is the first IBSDDS schemes where an access permission is made by the owner for an exact file and collusion attacks can be protected in the standard model. Jinguang Han, Willy Susilo, Yi Mu 0001 |
IEEE Trans. Computers | 3 |
| 2014 | Identity based identification from algebraic coding theory
Guomin Yang, Chik How Tan, Yi Mu 0001, Willy Susilo, Duncan S. Wong |
Theor. Comput. Sci. | 3 |
| 2014 | Subset Membership Encryption and Its Applications to Oblivious TransferabstractIn this paper, we propose a novel cryptographic notion called subset membership encryption (SME), and provide a very efficient SME scheme. Given a system parameter generated by an encryptor (Alice), a decryptor (Bob) generates a randomized privacy-preserved attribute token P(G) from a set of attributes G. A message is encrypted using an attribute set A chosen by Alice and P(G) provided by Bob. It requires that A is a subset of G for Bob to decrypt the message. We propose a very efficient SME scheme, where both the size of P(G) and ciphertext are short and independent of G and A. In particular, it has three useful and practical applications to oblivious transfer as follows. 1) k-Out-of-n Oblivious Transfer (OT): SME can be naturally applied to a two-round OT, which features a great communication efficiency especially for the receiver, where the receiver only sends two group elements to the message sender. 2) Priced Oblivious Transfer (POT): Our POT protocol allows a buyer to purchase any number of items in each transaction and hide selected items, price and balance from the vendor. In comparison with previous POT protocols, our protocol is more flexible and eliminates the restriction that a buyer can only purchase one item in a transaction. Our POT scheme is very efficient since it does not require any zero-knowledge proof or homomorphic encryption. 3) Restricted Priced Oblivious Transfer (RPOT): We introduce a novel POT named RPOT where a vendor can set restrictions on items or prices in POT. For example, a seller could offer a discounted price to those buyers who have purchased some specific items previously from the same seller. Fuchun Guo, Yi Mu 0001, Willy Susilo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | CP-ABE With Constant-Size Keys for Lightweight DevicesabstractLightweight devices, such as radio frequency identification tags, have a limited storage capacity, which has become a bottleneck for many applications, especially for security applications. Ciphertext-policy attribute-based encryption (CP-ABE) is a promising cryptographic tool, where the encryptor can decide the access structure that will be used to protect the sensitive data. However, current CP-ABE schemes suffer from the issue of having long decryption keys, in which the size is linear to and dependent on the number of attributes. This drawback prevents the use of lightweight devices in practice as a storage of the decryption keys of the CP-ABE for users. In this paper, we provide an affirmative answer to the above long standing issue, which will make the CP-ABE very practical. We propose a novel CP-ABE scheme with constant-size decryption keys independent of the number of attributes. We found that the size can be as small as 672 bits. In comparison with other schemes in the literature, the proposed scheme is the only CP-ABE with expressive access structures, which is suitable for CP-ABE key storage in lightweight devices. Fuchun Guo, Yi Mu 0001, Willy Susilo, Duncan S. Wong, Vijay Varadharajan |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | Non-Interactive Key Establishment for Bundle Security Protocol of Space DTNsabstractTo ensure the authenticity, integrity, and confidentiality of bundles, the in-transit Protocol Data Units of bundle protocol (BP) in space delay/disruption tolerant networks (DTNs), the Consultative Committee for Space Data Systems bundle security protocol (BSP) specification suggests four IPsec style security headers to provide four aspects of security services. However, this specification leaves key management as an open problem. Aiming to address the key establishment issue for BP, in this paper, we utilize a time-evolving topology model and two-channel cryptography to design efficient and noninteractive key exchange protocol. A time-evolving model is used to formally model the periodic and predetermined behavior patterns of space DTNs, and therefore, a node can schedule when and to whom it should send its public key. Meanwhile, the application of two-channel cryptography enables DTN nodes to exchange their public keys or revocation status information, with authentication assurance and in a noninteractive manner. The proposed scheme helps to establish a secure context to support for BSP, tolerating high delays, and unexpected loss of connectivity of space DTNs. Xixiang Lv, Yi Mu 0001, Hui Li 0006 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | An Efficient Generic Framework for Three-Factor Authentication With Provably Secure InstantiationabstractRemote authentication has been widely studied and adapted in distributed systems. The security of remote authentication mechanisms mostly relies on one of or the combination of three factors: 1) something users know—password; 2) something users have—smart card; and 3) something users are—biometric characteristics. This paper introduces an efficient generic framework for three-factor authentication. The proposed generic framework enhances the security of existing two-factor authentication schemes by upgrading them to three-factor authentication schemes, without exposing user privacy. In addition, we present a case study by upgrading a secure two-factor authentication scheme to a secure three-factor authentication scheme. Furthermore, implementation analysis, formal proof, and privacy discussion are provided to show that the derived scheme is practical, secure, and privacy preserving. Jiangshan Yu, Guilin Wang, Yi Mu 0001, Wei Gao 0007 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | On the Security of an Efficient Dynamic Auditing Protocol in Cloud StorageabstractUsing cloud storage, data owners can remotely store their data and enjoy the on-demand high quality cloud services without the burden of local data storage and maintenance. However, this new paradigm does trigger many security concerns. A major concern is how to ensure the integrity of the outsourced data. To address this issue, recently, a highly efficient dynamic auditing protocol (IEEE Transactions on Parallel and Distributed Systems, doi:10.1109/TPDS.2013.199) for cloud storage was proposed which enjoys many desirable features. Unfortunately, in this letter, we demonstrate that the protocol is insecure when an active adversary is involved in the cloud environment. We show that the adversary is able to arbitrarily modify the cloud data without being detected by the auditor in the auditing process. We also suggest a solution to fix the problem while preserving all the properties of the original protocol. Jianbing Ni, Yong Yu 0002, Yi Mu 0001, Qi Xia 0001 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2013 | Membership Encryption and Its Applications
Fuchun Guo, Yi Mu 0001, Willy Susilo, Vijay Varadharajan |
ACISP | 2 |
| 2013 | Secure RFID Ownership Transfer Protocols
Nan Li 0007, Yi Mu 0001, Willy Susilo, Vijay Varadharajan |
ISPEC | 2 |
| 2013 | Identity-Based Multisignature with Message Recovery
Kefeng Wang, Yi Mu 0001, Willy Susilo |
ISPEC | 2 |
| 2013 | Leakage Resilient Authenticated Key Exchange Secure in the Auxiliary Input Model
Guomin Yang, Yi Mu 0001, Willy Susilo, Duncan S. Wong |
ISPEC | 2 |
| 2013 | Leakage-Resilient Attribute-Based Encryption with Fast Decryption: Models, Analysis and Constructions
Mingwu Zhang, Zhenhua Chen 0001, Yi Mu 0001 |
ISPEC | 5 |
| 2013 | Anonymous Signcryption against Linear Related-Key Attacks
Hui Cui 0001, Yi Mu 0001, Man Ho Au |
ProvSec | 2 |
| 2013 | k-time Proxy Signature: Formal Definition and Efficient Construction
Weiwei Liu 0005, Guomin Yang, Yi Mu 0001, Jiannan Wei |
ProvSec | 3 |
| 2013 | Public-Key Encryption Resilient to Linear Related-Key Attacks
Hui Cui 0001, Yi Mu 0001, Man Ho Au |
SecureComm | 2 |
| 2013 | Generic Mediated Encryption
Ibrahim F. Elashry, Yi Mu 0001, Willy Susilo |
SecureComm | 2 |
| 2013 | Identity-based data storage in cloud computing
Jinguang Han, Willy Susilo, Yi Mu 0001 |
Future Gener. Comput. Syst. | 3 |
| 2013 | Efficient and dynamic key management for multiple identities in identity-based systems
Hua Guo 0001, Chang Xu 0004, Zhoujun Li 0001, Yi Mu 0001 |
Inf. Sci. | 5 |
| 2013 | On security of a certificateless signcryption scheme
Songqin Miao, Futai Zhang, Sujuan Li, Yi Mu 0001 |
Inf. Sci. | 4 |
| 2013 | A robust trust model for service-oriented systems
Xing Su 0001, Minjie Zhang 0001, Yi Mu 0001, Quan Bai 0001 |
J. Comput. Syst. Sci. | 3 |
| 2013 | Securing DSR against wormhole attacks in multirate ad hoc networks
Shams Qazi, Raad Raad, Yi Mu 0001, Willy Susilo |
J. Netw. Comput. Appl. | 3 |
| 2013 | A secure IPv6 address configuration scheme for a MANETabstractABSTRACT We propose a secure Internet Protocol version 6 (IPv6) address configuration scheme for a Mobile Ad Hoc Network. The scheme presents the architecture for a Mobile Ad Hoc Network and the hierarchical IPv6 address structure. In the architecture, a new node can acquire a unique IPv6 address from a proxy node within one‐hop scope without performing a duplicate address detection process, and the IP addresses occupied by failed nodes can be recovered automatically for reuse. On the basis of the hierarchical IPv6 address structure, each proxy node can acquire a unique address scope for assignment and assign a unique IP address for new nodes, so the address configuration task is distributed around proxy nodes. In addition, the transmission scope of the control packets for address configuration is controlled within one‐hop scope, so the address configuration cost is reduced, and the delay is shortened. The security of the proposed address configuration scheme is achieved through authentication. The paper analyzes the performance parameters of the proposed scheme and the existing schemes, and the analytical results show that the address configuration cost of the proposed scheme is lower and the delay is shorter. Copyright © 2012 John Wiley & Sons, Ltd. Xiaonan Wang 0001, Yi Mu 0001 |
Secur. Commun. Networks | 2 |
| 2013 | New construction of affiliation-hiding authenticated group key agreementabstractABSTRACT In CT‐RSA 2007, Jarecki, Kim, and Tsudik introduced the notion of affiliation‐hiding authenticated group key agreement (AH‐AGKA) protocols and presented two concrete AH‐AGKA protocols. In this paper, we will show that these protocols have some drawbacks. We will also introduce the notion of affiliation‐hiding authenticated asymmetric group key agreement (AH‐AAGKA) and present an AH‐AAGKA protocol. AH‐AAGKA protocols allow the participants of a group to establish a common encryption key associated with several decryption keys; each of which can only be computed by the corresponding legitimate participant. Meanwhile, any party is assured that its affiliation is revealed to the participants that belong to the same group only. Compared with previous AH‐AGKA protocols, if invalid players participate in our protocol, legitimate participants can identify these invalid players. In contrast to existing AH‐AGKA protocols, our protocol holds perfect forward secrecy, which is proven in a novel security model we proposed. Additionally, we present a new privacy model to prove that our protocol achieves linkable affiliation‐hiding property. Copyright © 2012 John Wiley & Sons, Ltd. Chang Xu 0004, Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001 |
Secur. Commun. Networks | 4 |
| 2012 | Identity-Based Traitor Tracing with Short Private Key and Short Ciphertext
Fuchun Guo, Yi Mu 0001, Willy Susilo |
ESORICS | 2 |
| 2012 | A Pre-computable Signature Scheme with Efficient Verification for RFID
Fuchun Guo, Yi Mu 0001, Willy Susilo, Vijay Varadharajan |
ISPEC | 2 |
| 2012 | Provably Secure Single Sign-on Scheme in Distributed Systems and NetworksabstractDistributed systems and networks have been adopted by telecommunications, remote educations, businesses, armies and governments. A widely applied technique for distributed systems and networks is the single sign-on (SSO) which enables a user to use a unitary secure credential (or token) to access multiple computers and systems where he/she has access permissions. However, most existing SSO schemes have not been formally proved to satisfy credential privacy and soundness of credential based authentication. To overcome this drawback, we formalise the security model of single sign-on scheme with authenticated key exchange. Specially, we point out the difference between soundness and credential privacy, and define them together in one definition. Also, we propose a provably secure single sign-on authentication scheme, which satisfies soundness, preserves credential privacy, meets user anonymity, and supports session key exchange. The proposed scheme is very efficient so that it suits for mobile devices in distributed systems and networks. Jiangshan Yu, Guilin Wang, Yi Mu 0001 |
TrustCom | 3 |
| 2012 | Polar differential power attacks and evaluation
Ming Tang 0002, Zhenlong Qiu, Yi Mu 0001, Huanguo Zhang, Yingzhen Jin |
Sci. China Inf. Sci. | 4 |
| 2012 | Attribute-Based Oblivious Access ControlabstractIn an attribute-based system (ABS), users are identified by various attributes, instead of their identities. Since its seminal introduction, the attribute-based mechanism has attracted a lot of attention. However, current ABS schemes have a number of drawbacks: (i) the communication cost is linear in the number of the required attributes; (ii) the computation cost is linear in the number of the required attributes and (iii) there are no efficient verification algorithms for the secret keys. These drawbacks limit the use of ABS in practice. In this paper, we propose an attribute-based oblivious access control (ABOAC) scheme to address these problems, where only the receiver whose attributes satisfy the access policies can obtain services obliviously. As a result, the receiver does not release anything about the contents of the selected services and his attributes to the sender, and even the number and supersets of his attributes are protected. The sender only knows the number of the services selected by the authorized receiver. Notably, the costs of computation and communication are constant and independent of the number of required attributes. While, in the prior comparable schemes, both the costs of computation and communication are linear in the required attributes. Therefore, our ABOAC scheme provides a novel and elegant solution to protect user's privacy in the systems where both the bandwidth and the computing capability are limited, such as wireless sensor and actor networks, mobile ad hoc networks, etc.. Jinguang Han, Willy Susilo, Yi Mu 0001, Jun Yan 0005 |
Comput. J. | 3 |
| 2012 | Certificateless Signatures: New Schemes and Security ModelsabstractWe present a study of security in certificateless signatures. We divide potential adversaries according to their attack power, and for the first time, three new kinds of adversaries are introduced into certificateless signatures. They are Normal Adversary, Strong Adversary and Super Adversary (ordered by their attack power). Combined with the known Type I Adversary and Type II Adversary in certificateless cryptography, we then define the security of certificateless signatures in different attack scenarios. Our new security models, together with others in the literature, provide a clear definition of the security in certificateless signatures. Two concrete schemes with different security levels are also proposed in this paper. The first scheme, which is proven secure (in the random oracle model) against Normal Type I and Super Type II adversaries, has the shortest signature length among all known certificateless signature schemes. The second scheme is secure (in the random oracle model) against Super Type I and Type II adversaries. Compared with another scheme that has a similar security level, our second scheme requires less operational cost but a little longer signature length. Two server-aided verification protocols are also proposed to reduce the verification cost on the verifier. Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Duncan S. Wong, Wei Wu 0001 |
Comput. J. | 2 |
| 2012 | A Provably Secure Construction of Certificate-Based Encryption from Certificateless EncryptionabstractCertificate-based encryption (CBE) and certificateless encryption (CLE) are proposed to lessen the certificate management problem in a traditional public-key encryption setting. Although they are two different notions, CBE and CLE are closely related and possess several common features. The encryption in CBE and CLE does not require authenticity verification of the recipient public key. The decryption in both notions requires two secrets that are generated by the third party and the public key owner, respectively. Recently a generic conversion from CLE to CBE was given, but unfortunately its security proof is flawed. This paper provides an elaborate security model of CBE, based on which a provably secure generic construction of CBE from CLE is proposed. A concrete instantiation is also presented to demonstrate the application of our generic construction. Wei Wu 0001, Yi Mu 0001, Willy Susilo, Xinyi Huang 0001, Li Xu 0002 |
Comput. J. | 2 |
| 2012 | Affiliation-Hiding Authenticated Asymmetric Group Key AgreementabstractWe introduce the concept of Affiliation-Hiding Authenticated Asymmetric Group Key Agreement (AH-AAGKA) and construct a concrete one-round AH-AAGKA protocol. An AH-AAGKA protocol allows the participants of a group to establish a common encryption key associated with several decryption keys; each of which can only be computed by the corresponding legitimate group member. An AH-AAGKA protocol has the following privacy feature. For a member 𝒰i of a group G, if 𝒰i participates in an AH-AAGKA protocol, any protocol participant 𝒰j cannot learn whether 𝒰i is a member of G, unless 𝒰j himself is a member of group G. Our scheme demonstrates new features in comparison with other existing AH-AGKA protocols. If non-group members participate in our protocol, honest parties can identify these non-group members. Our scheme also captures Unlinkability and Perfect Forward Secrecy (PFS), which are missing in other existing schemes. We propose a novel security model to prove that our protocol holds PFS and present a new privacy model to prove that our scheme meets Affiliation-Hiding property. Chang Xu 0004, Zhoujun Li 0001, Yi Mu 0001, Hua Guo 0001 |
Comput. J. | 3 |
| 2012 | Improved certificateless signature scheme provably secure in the standard modelabstractCertificateless cryptography shares many features of identity-based cryptography and partially solves the problem of key escrow. Three certificateless signature schemes without random oracles were found in the literature. However, all the schemes suffer from some common drawbacks. First, by obtaining a signature on a message and replacing the public key of a signer, an adversary can forge valid signatures on the same message under the replaced public key. Secondly, all the schemes require a relatively large size of public parameters. The authors propose a new certificateless signature scheme, which exhibits an improvement on the existing schemes. Compared with the previous schemes, the proposed scheme offers stronger security, shorter system parameters and higher computational efficiency. Yong Yu 0002, Yi Mu 0001, Guilin Wang, Qi Xia 0001, Bo Yang 0003 |
IET Inf. Secur. | 2 |
| 2012 | Privacy enhanced data outsourcing in the cloud
Miao Zhou, Yi Mu 0001, Willy Susilo, Jun Yan 0005, Liju Dong |
J. Netw. Comput. Appl. | 2 |
| 2012 | Privacy preserving protocol for service aggregation in cloud computingabstractSUMMARY Cloud computing has increasingly become a new model in the world of computing, and more businesses are moving to the cloud. As a cost‐effective and time‐efficient way to develop new applications and services, service aggregation in cloud computing empowers all service providers and consumers and creates tremendous opportunities in various industry sectors. However, it also poses various challenges to the privacy of personal information as well as the confidentiality of business and governmental information. The full benefits of service aggregation in cloud computing would only be enjoyed if the privacy concerns are addressed properly. In this paper, we investigate the privacy issues in service aggregation in a cloudenvironment and propose a privacy preserving protocol that is suitable for this environment. To demonstrate the security of our system, we construct a security game called IND‐P3SAC‐CPA and prove the security of the protocol accordingly. Our protocol has a distinct property that allows any service provider to obtain only the queried data under its conspiracy with the cloud. Additionally, the efficiency and various extensions are also discussed. Copyright © 2011 John Wiley & Sons, Ltd. Peishun Wang, Yi Mu 0001, Willy Susilo, Jun Yan 0005 |
Softw. Pract. Exp. | 2 |
| 2012 | Privacy-Preserving Decentralized Key-Policy Attribute-Based EncryptionabstractDecentralized attribute-based encryption (ABE) is a variant of a multiauthority ABE scheme where each authority can issue secret keys to the user independently without any cooperation and a central authority. This is in contrast to the previous constructions, where multiple authorities must be online and setup the system interactively, which is impractical. Hence, it is clear that a decentralized ABE scheme eliminates the heavy communication cost and the need for collaborative computation in the setup stage. Furthermore, every authority can join or leave the system freely without the necessity of reinitializing the system. In contemporary multiauthority ABE schemes, a user's secret keys from different authorities must be tied to his global identifier (GID) to resist the collusion attack. However, this will compromise the user's privacy. Multiple authorities can collaborate to trace the user by his GID, collect his attributes, then impersonate him. Therefore, constructing a decentralized ABE scheme with privacy-preserving remains a challenging research problem. In this paper, we propose a privacy-preserving decentralized key-policy ABE scheme where each authority can issue secret keys to a user independently without knowing anything about his GID. Therefore, even if multiple authorities are corrupted, they cannot collect the user's attributes by tracing his GID. Notably, our scheme only requires standard complexity assumptions (e.g., decisional bilinear Diffie-Hellman) and does not require any cooperation between the multiple authorities, in contrast to the previous comparable scheme that requires nonstandard complexity assumptions (e.g., q-decisional Diffie-Hellman inversion) and interactions among multiple authorities. To the best of our knowledge, it is the first decentralized ABE scheme with privacy-preserving based on standard complexity assumptions. Jinguang Han, Willy Susilo, Yi Mu 0001, Jun Yan 0005 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2011 | Electronic Cash with Anonymous User Suspension
Man Ho Au, Willy Susilo, Yi Mu 0001 |
ACISP | 3 |
| 2011 | Self-certified ring signaturesabstractWe present a new notion, Self-certified Ring Signature (SCRS), to provide an alternative solution to the certificate management problem in ring signatures and eliminate private key escrow problem in identity based ring signatures. Our scheme captures all features of ring signatures and exhibits the advantages such as low storage, communication and computation cost. The main contribution of this paper is a precise definition of self-certified ring signatures along with a concrete construction. We also provide a security model of SCRS and a security proof of our scheme. Nan Li 0007, Yi Mu 0001, Willy Susilo, Fuchun Guo |
AsiaCCS | 2 |
| 2011 | Efficient Self-certified Signatures with Batch Verification
Nan Li 0007, Yi Mu 0001, Willy Susilo |
Inscrypt | 2 |
| 2011 | Policy-Based Authentication for Mobile Agents
Yi Mu 0001, Minjie Zhang 0001 |
ISPEC | 2 |
| 2011 | Optimistic Fair Exchange of Ring Signatures
Lie Qu, Guilin Wang, Yi Mu 0001 |
SecureComm | 3 |
| 2011 | Case-Based Trust Evaluation from Provenance InformationabstractTrust is a crucial aspect for open distributed systems. Especially as users may rely on the shared services to make important decisions, it is essential to let them know services' trustworthiness. Provenance describes the origins and processes that are related to the generation of services. It can greatly enhance transparency and accountability of shared services. In this paper, we focus on how to derive trust information from huge amount of provenance data, and proposed a case-based approach which can estimate services' trustworthiness from provenance. This approach can greatly utilise the value of provenance, and provide more objective and reasonable trust estimation to users. Quan Bai 0001, Xing Su 0001, Qing Liu 0001, Andrew Terhorst, Minjie Zhang 0001, Yi Mu 0001 |
TrustCom | 6 |
| 2011 | Privacy-Preserved Access Control for Cloud ComputingabstractThe problem of access control on outsourced data to "honest but curious" cloud servers has received considerable attention, especially in scenarios involving potentially huge sets of data files, where re-encryption and re-transmission by the data owner may not be acceptable. Considering the user privacy and data security in cloud environment, in this paper, we propose a solution to achieve flexible and fine-grained access control on outsourced data files. In particular, we look at the problem of defining and assigning keys to users based on different attribute sets, and hiding access policies as well as users information to the third-party cloud servers. Our proposed scheme is partially based on our observation that, in practical application scenarios each user can be associated with a set of attributes which are meaningful in the access policy and data file context. The access policy can thus be defined as a logical expression formula over different attribute sets to reflect the scope of data file that the kind of users is allowed to access. As any access policy can be represented as such a logical expression formula, fine-grained access control can be accomplished. Miao Zhou, Yi Mu 0001, Willy Susilo, Man Ho Au, Jun Yan 0005 |
TrustCom | 2 |
| 2011 | GTrust: An Innovated Trust Model for Group Services Selection in Web-Based Service-Oriented Environments
Xing Su 0001, Minjie Zhang 0001, Yi Mu 0001, Quan Bai 0001 |
WISE | 3 |
| 2011 | Short Signatures with a Tighter Security Reduction Without Random OraclesabstractThe recent work by Hofheinz and Kiltz (Crypto 2008) has demonstrated that it is feasible to generate a short signature with <320 bits and 80-bit security without the need of random oracles. The authors also showed that the signature length can be reduced to 230 bits if no more than 230 signatures are generated. In this paper, we present three novel short signature schemes with a comparable signature length. Although our schemes can be considered as variants of Hofheinz and Kiltz's schemes, ours can be proved with a much tighter security reduction without random oracles. Our first scheme offers a 270-bit short signature length for 80-bit security without using random oracles and can be tightly reduced to the q-strong Diffie–Hellman problem. Using a stateful signing approach in our second scheme, we show how to further shorten the signature length to 191 bits. Our idea can also be applied to construct short RSA-based signatures with a tight security reduction to the strong RSA problem without random oracles. We note that the 80-bit security defined in all short signature schemes without random oracles is associated with loose reductions or strong assumptions. We compare our schemes with the Boneh–Boyen short signature scheme (Eurocrypt 2004) and the Hofheinz–Kiltz short signature scheme by taking security reductions into account. We show that with the same assumptions, our schemes offer the shortest signatures and achieve the same concrete security. Fuchun Guo, Yi Mu 0001, Willy Susilo |
Comput. J. | 2 |
| 2011 | Cryptanalysis of an Off-Line Electronic Cash Scheme Based on Proxy Blind SignatureabstractProxy blind signature is an important cryptographic primitive and plays an essential role in construction of the electronic cash (e-cash). Recently, Tan (2001, An offline electronic cash scheme based on proxy blind signature. Comput. J., 54, 505–512) proposed a new proxy blind signature scheme and applied it to electronic cash. The scheme was claimed as being provably secure under the Discrete Log assumption, DBDH assumption and Chosen–Target CDH assumption in the random oracle model. In this paper, we show that Tan's proxy blind signature scheme is insecure by demonstrating several attacks in which a malicious original signer can forge both valid proxy signature keys of arbitrary proxy signers and a proxy blind signature on an arbitrary message with respect to any proxy signer directly. We also discuss some weaknesses in the e-cash scheme proposed by Tan. Yong Yu 0002, Yi Mu 0001, Guilin Wang |
Comput. J. | 2 |
| 2011 | Secure Image Retrieval Based on Visual Content and Watermarking ProtocolabstractAs an interesting application on cloud computing, content-based image retrieval (CBIR) has attracted a lot of attention, but the focus of previous research work was mainly on improving the retrieval performance rather than addressing security issues such as copyrights and user privacy. With an increase of security attacks in the computer networks, these security issues become critical for CBIR systems. In this paper, we propose a novel two-party watermarking protocol that can resolve the issues regarding user rights and privacy. Unlike the previously published protocols, our protocol does not require the existence of a trusted party. It exhibits three useful features: security against partial watermark removal, security in watermark verification and non-repudiation. In addition, we report an empirical research of CBIR with the security mechanism. The experimental results show that the proposed protocol is practicable and the retrieval performance will not be affected by watermarking query images. Jun Zhang 0010, Yang Xiang 0001, Wanlei Zhou 0001, Lei Ye 0002, Yi Mu 0001 |
Comput. J. | 5 |
| 2011 | Attribute-based authentication for multi-agent systems with dynamic groups
Yi Mu 0001, Minjie Zhang 0001 |
Comput. Commun. | 2 |
| 2011 | An efficient and non-interactive hierarchical key agreement protocol
Hua Guo 0001, Yi Mu 0001, Zhoujun Li 0001, Xiyong Zhang |
Comput. Secur. | 2 |
| 2011 | Secure mobile agents with controlled resourcesabstractAbstract Mobile agents often travel in a hostile environment where their security and privacy could be compromised by any party including remote hosts in which agents visit and get services. It is believed that the host visited by an agent should jointly sign a service agreement with the agent's owner; hence a proxy‐signing model was proposed in the literature, allowing every host in the agent system to sign a service agreement. We observe that this actually poses a serious problem whereby a host that should be excluded from an underlying agent network could also send a signed service agreement. In order to solve this problem, we propose two schemes achieving host authentication with controlled resources, where only selected hosts can be included in the agent network. We provide two schemes in this paper. The second scheme offers a smaller data size. We also define security models and provide rigorous security proofs to our schemes. Copyright © 2010 John Wiley & Sons, Ltd. Yi Mu 0001, Minjie Zhang 0001, Robert H. Deng |
Concurr. Comput. Pract. Exp. | 2 |
| 2011 | Provably secure identity-based authenticated key agreement protocols with malicious private key generators
Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001, Xiyong Zhang |
Inf. Sci. | 3 |
| 2011 | Practical RFID ownership transfer schemeabstractWhen an RFID tag changes hand, it is not as simply as handing over the tag secret to the new owner. Privacy is a concern if there is no secure ownership transfer scheme to aid the transfer. After sales service and temporary tag delegation are also features commonly seen in such applications. In thi s paper, we proposed a new RFID ownership transfer scheme that achieves the most security protections and properties in comparison to most of the previous schemes. We also introduced four new security properties that have not been considered before. This opens up new research directions for further development of RFID ownership transfer. Ching Yu Ng, Willy Susilo, Yi Mu 0001, Reihaneh Safavi-Naini |
J. Comput. Secur. | 3 |
| 2011 | Optimistic Fair Exchange with Strong Resolution-AmbiguityabstractOptimistic fair exchange (OFE) allows two parties to exchange their digital items in a fair way. As one of the fundamental problems in secure electronic business and digital rights management, OFE has been studied intensively since its introduction. This paper introduces and defines a new property for OFE: Strong Resolution-Ambiguity. We show that many existing OFE protocols have the new property, but its formal investigation has been missing in those protocols. We prove that in the certified-key model, an OFE protocol is secure in the multi-user setting if it is secure in the single-user setting and has the property of strong resolution-ambiguity. Our result not only simplifies the security analysis of OFE protocols in the multi-user setting but also provides a new approach for the design of multi-user secure OFE protocols. Following this approach, a new OFE protocol with strong resolution-ambiguity is proposed. Our analysis shows that the protocol is setup-free, stand-alone and multi-user secure without random oracles. Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Wei Wu 0001, Yang Xiang 0001 |
IEEE J. Sel. Areas Commun. | 2 |
| 2011 | Improving security of q-SDH based digital signatures
Fuchun Guo, Yi Mu 0001, Willy Susilo |
J. Syst. Softw. | 2 |
| 2011 | Strongly unforgeable proxy signature scheme secure in the standard model
Chunxiang Xu, Yong Yu 0002, Yi Mu 0001 |
J. Syst. Softw. | 4 |
| 2011 | Preserving Transparency and Accountability in Optimistic Fair Exchange of Digital SignaturesabstractOptimistic fair exchange (OFE) protocols are useful tools for two participants to fairly exchange items with the aid of a third party who is only involved if needed. A widely accepted requirement is that the third party's involvement in the exchange must be transparent, to protect privacy and avoid bad publicity. At the same time, a dishonest third party would compromise the fairness of the exchange and the third party thus must be responsible for its behaviors. This is achieved in OFE protocols with another property called accountability. It is unfortunate that the accountability has never been formally studied in OFE since its introduction ten years ago. In this paper, we fill these gaps by giving the first complete definition of accountability in OFE where one of the exchanged items is a digital signature and a generic (also the first) design of OFE where transparency and accountability coexist. Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Wei Wu 0001, Jianying Zhou 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2011 | Authenticated key exchange protocol with selectable identitiesabstractAbstract In the traditional identity‐based cryptography, a user, who holds multiple identities, has to manage multiple private keys, where each private key is associated with an identity. In this paper, we present a key agreement protocol, which allows a single private key to map multiple public keys (identities) that are selectable by the user. That is, the established session key is associated with an arbitrary subset of identities held by the user, while the unselected identities remain secret to other participants. As a bonus, our scheme can be considered as a credential‐based key agreement, where the unique private key can be treated as a credential of the user and the user only proves that his credential is associated with some selected identities. We prove that our scheme is secure in the random oracle model. Copyright © 2010 John Wiley & Sons, Ltd. Hua Guo 0001, Yi Mu 0001, Xiyong Zhang, Zhoujun Li 0001 |
Wirel. Commun. Mob. Comput. | 2 |
| 2010 | Proof-of-Knowledge of Representation of Committed Value and Its Applications
Man Ho Au, Willy Susilo, Yi Mu 0001 |
ACISP | 3 |
| 2010 | Towards a Cryptographic Treatment of Publish/Subscribe Systems
Tsz Hon Yuen, Willy Susilo, Yi Mu 0001 |
CANS | 3 |
| 2010 | Efficient Online/Offline Signatures with Computational Leakage Resilience in Online Phase
Fuchun Guo, Yi Mu 0001, Willy Susilo |
Inscrypt | 2 |
| 2010 | A framework for privacy policy management in service aggregationabstractWith a rapid growth of the Internet, exploring cost-effective and time-efficient methods for creating Internet services has become critical. As an emerging technology, service aggregation has been regarded as a promising candidate. However, it also raises serious issues on privacy management, as a service is usually provided by multiple providers that are usually transparent to its users. We observe that these issues have not been formally studied in the literature. In this paper, we propose a formal model for the privacy management in service aggregation and present a negotiation strategy on different privacy policies between two organizations. Peishun Wang, Liju Dong, Yi Mu 0001, Willy Susilo, Jun Yan 0005 |
CSCWD | 3 |
| 2010 | Efficient RFID Authentication Scheme for Supply Chain ApplicationsabstractRadio Frequency Identification (RFID) technology has been widely used in supply chains to track and manage shipments. By tagging shipments with RFID tags, which can be remotely accessed by RFID readers, shipments can be identified and tracked in a supply chain. Security issues in RFID have been major concerns, since passive RFID tags have very weak computational power to support authentication. Sound authentication between tag and reader remains a challenging problem. In this paper, we provide a novel authentication scheme to protect tags from being tracked and identified by unauthorized readers and protect authorized readers against bogus tags. Our scheme can be applied to supply chain security. It also exhibits an additional feature that a supply chain can be dynamically updated. Fei Bi, Yi Mu 0001 |
EUC | 2 |
| 2010 | PBTrust: A Priority-Based Trust Model for Service Selection in General Service-Oriented EnvironmentsabstractHow to choose the best service provider (agent), which a service consumer can trust in terms of the quality and success rate of the service in an open and dynamic environment, is a challenging problem in many service-oriented applications such as Internet-based grid systems, e-trading systems, as well as service-oriented computing systems. This paper presents a Priority-Based Trust (PBTrust) model for service selection in general service-oriented environments. The PBTrust is robust and novel from several perspectives. (1) The reputation of a service provider is derived from referees who are third parties and had interactions with the provider in a rich context format, including attributes of the service, the priority distribution on attributes and a rating value for each attribute from a third party, (2) The concept of 'Similarity' is introduced to measure the difference in terms of distributions of priorities on attributes between requested service and a refereed service in order to precisely predict the performance of a potential provider on the requested service, (3) The concept of general performance of a service provider on a service in history is also introduced to improve the success rate on the requested service. The experimental results can prove that PBtrust has a better performance than that of the CR model in a service-oriented environment. Xing Su 0001, Minjie Zhang 0001, Yi Mu 0001, Kwang Mong Sim 0001 |
EUC | 3 |
| 2010 | Enhanced Security Notions for Dedicated-Key Hash Functions: Definitions and Relationships
Reza Reyhanitabar, Willy Susilo, Yi Mu 0001 |
FSE | 3 |
| 2010 | Dynamic Trust Model for Federated Identity ManagementabstractThe goal of federated identity management is to allow principals, such as identities and attributes, to be shared across trust boundaries based on established policies. Since current Single Sign-On (SSO) mechanism excessively relies on the specifications of Circle of Trust (CoT), the need for service collaboration from different domains is being addressed on CoT. For the motivating issue of the cross-domain SSO mechanism, we need an emergent dynamic trust list for calculating the trust parties, thus, the CoT specifications require an initial effort on enrolling members automatically to adapt to the dynamic open environment. In this paper, we propose a Dynamic Trust Policy Language to support trust negotiation. The formal syntax of this language is presented in Backus Naur Form (BNF) based on the concept of role membership. We also systematically develop the Dynamic Trust Model (DTM) to allow Untrusted SP to join the existing CoT by trust negotiation. Finally, we identify the process and algorithm for communication between negotiation entities. Jun Yan 0005, Yi Mu 0001 |
NSS | 3 |
| 2010 | A Generic Construction of Dynamic Single Sign-on with Strong Security
Jinguang Han, Yi Mu 0001, Willy Susilo, Jun Yan 0005 |
SecureComm | 2 |
| 2010 | Certificateless threshold signature scheme from bilinear maps
Futai Zhang, Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Lei Zhang 0009 |
Inf. Sci. | 4 |
| 2010 | Constructions of certificate-based signature secure against key replacement attacksabstractIn Eurocrypt 2003, Gentry introduced the notion of certificate-based encryption. The merit of certificate-based encryption lies in the following features: (1) providing more efficient public-key infrastructure (PKI) that requires less infrastructure, (2) solving the certificate revocation problem, and (3) eliminating third-party queries in the traditional PKI. Additionally, it also offers the solution to the inherent key escrow problem in the identity-based cryptography. The contributions of this paper are threefold. Firstly, we introduce a new attack called the “Key Replacement Attack” into the certificate-based signature system and refine the security model of certificate-based signature. Secondly, we show that the certificate-based signature scheme presented by Kang, Park and Hahn in CT-RSA 2004 is insecure against key replacement attacks. Thirdly, we present two new certificate-based signature schemes secure against key replacement attacks. Our first scheme is existentially unforgeable against adaptive chosen message attacks under the computational Diffie–Hellman assumption in the random oracle model. Compared with the certificate-based signature scheme in CT-RSA 2004, our first scheme enjoys shorter signature length and less operation cost. Our second scheme is inspired by Waters signature and is the first construction of certificate-based signature secure against key replacement attacks in the standard model. Jiguo Li 0001, Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Qianhong Wu |
J. Comput. Secur. | 3 |
| 2009 | Analysis of Property-Preservation Capabilities of the ROX and ESh Hash Domain Extenders
Reza Reyhanitabar, Willy Susilo, Yi Mu 0001 |
ACISP | 3 |
| 2009 | Efficient Non-interactive Range Proof
Tsz Hon Yuen, Qiong Huang 0001, Yi Mu 0001, Willy Susilo, Duncan S. Wong, Guomin Yang |
COCOON | 3 |
| 2009 | Dynamic Universal Accumulators for DDH Groups and Their Application to Attribute-Based Anonymous Credential Systems
Man Ho Au, Patrick P. Tsang, Willy Susilo, Yi Mu 0001 |
CT-RSA | 4 |
| 2009 | New Privacy Results on Synchronized RFID Authentication Protocols against Tag Tracing
Ching Yu Ng, Willy Susilo, Yi Mu 0001, Reihaneh Safavi-Naini |
ESORICS | 3 |
| 2009 | Asymmetric Group Key Agreement
Qianhong Wu, Yi Mu 0001, Willy Susilo, Josep Domingo-Ferrer |
EUROCRYPT | 2 |
| 2009 | Enhanced Target Collision Resistant Hash Functions Revisited
Reza Reyhanitabar, Willy Susilo, Yi Mu 0001 |
FSE | 3 |
| 2009 | Policy-Controlled Signatures
Pairat Thorncharoensri, Willy Susilo, Yi Mu 0001 |
ICICS | 3 |
| 2009 | An Efficient Certificateless Encryption Scheme in the Standard ModelabstractWe propose an efficient certificateless public key encryption (CL-PKE) scheme which is provably secure against chosen ciphertext attacks without random oracles. Our scheme is more computationally efficient than the existing schemes and provides the shortest public key length compared to other existing CL-PKEs with random oracles. We also propose a practical self-generated-certificate encryption (SGC-PKE) scheme based on our CL-PKE scheme. One of merits of such cryptographic systems is that it can be applied to countermeasure "Denial-of-Decryption (DoD) Attacks" that is inherent in CL-PKE. Hua Guo 0001, Xiyong Zhang, Yi Mu 0001, Zhoujun Li 0001 |
NSS | 3 |
| 2009 | Secure Mobile Agents with Designated HostsabstractMobile agents often travel in a hostile environment where their security and privacy could be compromised by any party including remote hosts in which agents visit and get services. It was proposed in the literature that the host visited by an agent should jointly sign a service agreement with the agent's home, where a proxy-signing model was deployed and every host in the agent system can sign. We observe that this actually poses a serious problem in that a host that should be excluded from an underlying agent network could also send a signed service agreement. In order to solve this problem, we propose a secure mobile agent scheme achieving host authentication with designated hosts, where only selected hosts can be included in the agent network. We also present a security model and provide a rigorous security proof to our scheme. Yi Mu 0001, Minjie Zhang 0001, Robert H. Deng |
NSS | 2 |
| 2009 | Is the Notion of Divisible On-Line/Off-Line Signatures Stronger than On-Line/Off-Line Signatures?
Man Ho Au, Willy Susilo, Yi Mu 0001 |
ProvSec | 3 |
| 2009 | How to Prove Security of a Signature with a Tighter Security Reduction
Fuchun Guo, Yi Mu 0001, Willy Susilo |
ProvSec | 2 |
| 2009 | Server-Controlled Identity-Based Authenticated Key Exchange
Hua Guo 0001, Yi Mu 0001, Xiyong Zhang, Zhoujun Li 0001 |
ProvSec | 2 |
| 2009 | Novel and Efficient Identity-Based Authenticated Key Agreement Protocols from Weil Pairings
Hua Guo 0001, Yi Mu 0001, Xiyong Zhang, Zhoujun Li 0001 |
UIC | 2 |
| 2009 | Certificateless Threshold Ring Signature
Shuang Chang, Duncan S. Wong, Yi Mu 0001, Zhenfeng Zhang |
Inf. Sci. | 3 |
| 2008 | Sanitizable Signatures Revisited
Tsz Hon Yuen, Willy Susilo, Joseph K. Liu, Yi Mu 0001 |
CANS | 4 |
| 2008 | Publicly Verifiable Privacy-Preserving Group Decryption
Qianhong Wu, Willy Susilo, Yi Mu 0001 |
Inscrypt | 4 |
| 2008 | Privacy for Private Key in Signatures
Qianhong Wu, Yi Mu 0001, Willy Susilo |
Inscrypt | 3 |
| 2008 | RFID Privacy Models Revisited
Ching Yu Ng, Willy Susilo, Yi Mu 0001, Reihaneh Safavi-Naini |
ESORICS | 3 |
| 2008 | A Generic Construction of Identity-Based Online/Offline SigncryptionabstractSigncryption has clear advantage over traditional sign-then-encrypt schemes. However, the computational overhead for signcryption is still too heavy when it is applied to resource-constraint systems. In this paper, we propose a generic construction of the identity-based online/offline signcryption, where most of computations are carried out when the associated message is still unavailable and the online part of our scheme does not require any exponent computations and therefore is very efficient. Our scheme isgeneric and identity-based, in the sense it is independent of the selection of signature and encryption algorithms. Our scheme possesses the properties of ciphertext indistinguishability (IND-gCCA2) and existentially unforgeability (UF-CMA). Dongdong Sun, Yi Mu 0001, Willy Susilo |
ISPA | 2 |
| 2008 | Optimal Online/Offline Signature: How to Sign a Message without Online Computation
Fuchun Guo, Yi Mu 0001 |
ProvSec | 2 |
| 2008 | Server-Aided Verification Signatures: Definitions and New Constructions
Wei Wu 0001, Yi Mu 0001, Willy Susilo, Xinyi Huang 0001 |
ProvSec | 2 |
| 2008 | Cryptanalysis of simple three-party key exchange protocol
Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001, Xiyong Zhang |
Comput. Secur. | 3 |
| 2008 | Efficient generic on-line/off-line (threshold) signatures without key exposure
Xiaofeng Chen 0001, Fangguo Zhang, Haibo Tian, Baodian Wei, Willy Susilo, Yi Mu 0001, Hyunrok Lee, Kwangjo Kim |
Inf. Sci. | 6 |
| 2007 | Practical Compact E-Cash
Man Ho Au, Willy Susilo, Yi Mu 0001 |
ACISP | 3 |
| 2007 | Certificateless Signature Revisited
Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Duncan S. Wong, Wei Wu 0001 |
ACISP | 2 |
| 2007 | Efficient Generic On-Line/Off-Line Signatures Without Key Exposure
Xiaofeng Chen 0001, Fangguo Zhang, Willy Susilo, Yi Mu 0001 |
ACNS | 4 |
| 2007 | Identity-Based Proxy Signature from Pairings
Wei Wu 0001, Yi Mu 0001, Willy Susilo, Jennifer Seberry, Xinyi Huang 0001 |
ATC | 2 |
| 2007 | Cryptanalysis of BGW Broadcast Encryption Schemes for DVD Content Protection
Qianhong Wu, Willy Susilo, Yi Mu 0001 |
ATC | 3 |
| 2007 | Mutative Identity-Based Signatures or Dynamic Credentials Without Random Oracles
Fuchun Guo, Yi Mu 0001, Zhide Chen |
CANS | 2 |
| 2007 | A Generic Construction for Universally-Convertible Undeniable Signatures
Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Wei Wu 0001 |
CANS | 2 |
| 2007 | Multi-Identity Single-Key Decryption without Random Oracles
Fuchun Guo, Yi Mu 0001, Zhide Chen, Li Xu 0002 |
Inscrypt | 2 |
| 2007 | Provably Secure Identity-Based Undeniable Signatures with Selective and Universal Convertibility
Wei Wu 0001, Yi Mu 0001, Willy Susilo, Xinyi Huang 0001 |
Inscrypt | 2 |
| 2007 | Compact E-Cash from Bounded Accumulator
Man Ho Au, Qianhong Wu, Willy Susilo, Yi Mu 0001 |
CT-RSA | 4 |
| 2007 | Efficient Partially Blind Signatures with Provable Security
Qianhong Wu, Willy Susilo, Yi Mu 0001, Fangguo Zhang |
ICCSA (3) | 3 |
| 2007 | Formal Definition and Construction of Nominative Signature
Dennis Y. W. Liu, Duncan S. Wong, Xinyi Huang 0001, Guilin Wang, Qiong Huang 0001, Yi Mu 0001, Willy Susilo |
ICICS | 6 |
| 2007 | New Construction of Group Secret Handshakes Based on Pairings
Willy Susilo, Yi Mu 0001 |
ICICS | 3 |
| 2007 | First price sealed bid auction without auctioneersabstractWe propose two protocol variants for a first price sealed-bid auction, without using intermediatory auctioneers. One version achieves full privacy for the bidders and their bids, the other provides a form of verifiability, at the cost of some privacy. Full privacy protects all bids. In particular the winner's identity and price are only known by the seller. Lesser privacy allows the winner to be known and verified publicly. Both versions provide non-repudiation. We demonstrate correctness and show how computational and communication costs vary with different privacy levels. Luke McAven, Yi Mu 0001 |
IWCMC | 3 |
| 2007 | Identity-Based Encryption: How to Decrypt Multiple Ciphertexts Using a Single Decryption Key
Fuchun Guo, Yi Mu 0001, Zhide Chen |
Pairing | 2 |
| 2007 | Provably Secure Pairing-Based Convertible Undeniable Signature with Short Signature Length
Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Wei Wu 0001 |
Pairing | 2 |
| 2007 | Designated Verifier Signature: Definition, Framework and New Constructions
Yong Li 0002, Willy Susilo, Yi Mu 0001, Dingyi Pei |
UIC | 3 |
| 2007 | Breaking and Repairing Trapdoor-Free Group Signature Schemes from Asiacrypt'2004
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
J. Comput. Sci. Technol. | 3 |
| 2007 | Revocable Ring Signature
Dennis Y. W. Liu, Joseph K. Liu, Yi Mu 0001, Willy Susilo, Duncan S. Wong |
J. Comput. Sci. Technol. | 3 |
| 2007 | Short Group Signatures Without Random Oracles
Qianhong Wu, Willy Susilo, Yi Mu 0001, Yumin Wang, Zhengtao Jiang |
J. Comput. Sci. Technol. | 4 |
| 2006 | Online/Offline Signatures and Multisignatures for AODV and DSR Routing Security
Shidi Xu, Yi Mu 0001, Willy Susilo |
ACISP | 2 |
| 2006 | Certificateless Designated Verifier Signature SchemesabstractDesignated verifier signature schemes allow a signer to convince a designated verifier, in such a way that only the designated verifier will believe with the authenticity of such a signature. The previous constructions of designated verifier signature rely on the underlying public key Infrastructure, that requires both signer and verifier to verify the authenticity of the public keys, and hence, the certificates are required. In contrast to the previous constructions, in this paper, we propose the first notion and construction of the certificateless designated verifier signature scheme. In our new notion, the necessity of certificates are eliminated. We show that our scheme satisfies all the requirements of the designated verifier signature schemes in the certificateless system. We also provide complete security proofs for our scheme and prove that our scheme is unforgeable under the assumption of the gap bilinear Diffie-Hellman problem in the random oracle model Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
AINA (2) | 3 |
| 2006 | Zero-Knowledge Proof of Generalized Compact Knapsacks (or A Novel Identification/Signature Scheme)
Qianhong Wu, Willy Susilo, Yi Mu 0001, Yumin Wang |
ATC | 4 |
| 2006 | Efficient Signcryption Without Random Oracles
Qianhong Wu, Yi Mu 0001, Willy Susilo, Fangguo Zhang |
ATC | 2 |
| 2006 | Designated group credentialsabstractConsider a situation where a secret agent wants to authenticate herself to the other secret agents. This secret agent must be able to convince the others of her identity. She cannot convince any other people other than those predetermined secret agents. This is to avoid problems that might occur if this secret agent would like to ‘betray’ her group. On the whole we would like to allow the agent to convince a predetermined group of people by showing that she holds a credential and so she is a member of the group. However we would like to prohibit this agent from convincing any other people outside the group. We also need to ensure that the party who has been convinced by the credential cannot use this information to convince any third party. We call this type of scheme as Designated Group Credential. In this paper, we first show a model of designated group credential systems followed by an efficient construction based on pairing-based cryptography. We also provide security proof of our scheme based on the random oracle model. Ching Yu Ng, Willy Susilo, Yi Mu 0001 |
AsiaCCS | 3 |
| 2006 | Efficient Partially Blind Signatures with Provable Security
Qianhong Wu, Willy Susilo, Yi Mu 0001, Fangguo Zhang |
ICCSA (3) | 3 |
| 2006 | Universal Designated Verifier Signature Without Delegatability
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Wei Wu 0001 |
ICICS | 3 |
| 2006 | Short (Identity-Based) Strong Designated Verifier Signature Schemes
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
ISPEC | 3 |
| 2006 | Privately Retrieve Data from Large Databases
Qianhong Wu, Yi Mu 0001, Willy Susilo, Fangguo Zhang |
ISPEC | 2 |
| 2006 | Three-Round Secret Handshakes Based on ElGamal and DSA
Willy Susilo, Yi Mu 0001 |
ISPEC | 3 |
| 2006 | Identity-based anonymous designated ring signaturesabstractIn this paper, we propose the concept of identity-based anonymous designated ring signature. This concept extends the existing notion of ring signatures in two ways: firstly, it allows a member from the ring to sign a message directed to a designated verifier, but secondly, we would like to have an anonymous designated verifier. At a glance, these two additional properties seem contradictory, but we shall show an example of situation where this kind of primitive is required. We present a formal model of such a scheme, and proceed with a construction based on bilinear pairings. Our scheme is provably secure under the random oracle model. Willy Susilo, Yi Mu 0001 |
IWCMC | 3 |
| 2006 | Proxy Signature Without Random Oracles
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Wei Wu 0001 |
MSN | 3 |
| 2006 | Efficient ID-Based Authenticated Group Key Agreement from Bilinear Pairings
Willy Susilo, Yi Mu 0001 |
MSN | 3 |
| 2006 | Restricted Universal Designated Verifier Signature
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
UIC | 3 |
| 2005 | On the Security of Nominative Signatures
Willy Susilo, Yi Mu 0001 |
ACISP | 2 |
| 2005 | Identity-Based Ring Signcryption Schemes: Cryptographic Primitives for Preserving Privacy and Authenticity in the Ubiquitous WorldabstractIn this paper, we present a new concept called an identity based ring signcryption scheme (IDRSC,). We argue that this is an important cryptographic primitive that must be used to protect privacy and authenticity of a collection of users who are connected through an ad-hoc network, such as Bluetooth. We also present an efficient IDRSC scheme based on bilinear pairing. As a regular signcryption scheme, our scheme combines the functionality of signature and encryption schemes. However, the idea is to have an identity based system. In our scheme, a user can anonymously sign-crypts a message on behalf of the group. We show that our scheme outperforms a traditional identity based scheme, that is obtained by a standard sign-then-encrypt mechanism, in terms of the length of the ciphertext. We also provide a formal proof of our scheme with the chosen cipher-text security under the decisional bilinear Diffie-Hellman assumption, which is believed to be intractable. Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
AINA | 3 |
| 2005 | Privacy-Enhanced Internet StorageabstractOne of the main important uses of Internet is its ability to connect people through the use of email or Internet storage. However, it is often desirable to limit the use of email or Internet storage clue to organization's restriction, avoiding spams, etc. In this paper, we propose cryptographic schemes that can be used to stop unwanted messages to be stored in the Internet server. We refer this technique as privacy enhancement for Internet storage, since the Internet server will not learn any information directed to its users, other than performing its task to deliver or stop the messages. Firstly, we describe a notion of non-interactive publicly verifiable 1-out-of-n encryption by proposing a model together with its security requirements. Then, we extend this notion to a publicly verifiable ring-to-1-out-of-n encryption, that provides sender anonymity. We note that the previously known interactive versions of the publicly verifiable 1-out-of-n encryption cannot be used to construct publicly verifiable ring-to-1-out-of-n encryption. Willy Susilo, Fangguo Zhang, Yi Mu 0001 |
AINA | 3 |
| 2005 | Reducing Security Overhead for Mobile NetworksabstractSecurity of mobile communications comes with the cost of computational overhead. Reducing the overhead in security computations is critical to ensure the overall performance of a mobile network. In this paper, we present the notion of online/offline signcryption, where most of computations are carried out offline and the online part of our scheme does not require any exponent computations and therefore is very efficient. Our scheme allows any third party to verify the encryption without compromising confidentiality. We also show that our scheme is secure against existential forgery under chosen message attacks and adaptively chosen ciphertext attacks under the notion of indistinguishability of ciphertext. Fangguo Zhang, Yi Mu 0001, Willy Susilo |
AINA | 2 |
| 2005 | On the Security of Certificateless Signature Schemes from Asiacrypt 2003
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang |
CANS | 3 |
| 2005 | Secure AODV Routing Protocol Using One-Time Signature
Shidi Xu, Yi Mu 0001, Willy Susilo |
MSN | 2 |
| 2005 | Tripartite Concurrent Signatures
Willy Susilo, Yi Mu 0001 |
SEC | 2 |
| 2004 | Identity-Based Strong Designated Verifier Signature Schemes
Willy Susilo, Fangguo Zhang, Yi Mu 0001 |
ACISP | 3 |
| 2004 | Deniable Ring Authentication Revisited
Willy Susilo, Yi Mu 0001 |
ACNS | 2 |
| 2004 | Securing XML Document Sources and Their DistributionabstractXML has been becoming popular for data store, document representation and exchange over the Web. Security mechanisms for the protection of XML document sources and their distribution are essential. Author-X is a Java based system specifically conceived for the protection of XML documents. It supports a range of protection granularity levels and subject credentials, but also supports push distribution for documents broadcast. However, the proposed system has certain disadvantages in terms of both security and dynamic key management. For example, a sender has to distribute the secret keys to all correspondent users for different XML documents. Also, if one of the users leave or a credential is changed, then the sender has to re-encrypt all related documents and redistribute the secret keys to all correspondent users. In this paper, we present a scheme for securing XML documents and their distribution. Our scheme has several advantages over Author-X such as: (a) one user needs only one private key; (b) even when the user leaves or a credential is changed, all the other users will be unaffected; (c) there is no need to establish a secure channel for key distribution; and (d) there is no need for checking the XML documents for access control policies applied. These make the security model more efficient and robust as well as simplifying the programming and the generation of the encrypted document base. Vijay Varadharajan, Yi Mu 0001 |
AINA (1) | 3 |
| 2004 | Perfect Concurrent Signature Schemes
Willy Susilo, Yi Mu 0001, Fangguo Zhang |
ICICS | 2 |
| 2004 | On the Design of a New Trust Model for Mobile Agent Security
Ching Lin, Vijay Varadharajan, Yan Wang 0002, Yi Mu 0001 |
TrustBus | 4 |
| 2002 | m out of n Oblivious Transfer
Yi Mu 0001, Vijay Varadharajan |
ACISP | 1 |
| 2002 | A Secure Object Sharing Scheme for Java Card
Vijay Varadharajan, Yi Mu 0001 |
ICICS | 3 |
| 2000 | Fail-Stop Confirmer Signatures
Yi Mu 0001, Vijay Varadharajan |
ACISP | 1 |
| 2000 | Fair On-line GamblingabstractThis paper proposes a fair electronic gambling scheme for the Internet. The proposed scheme provides a unique link between payment and gambling outcome so that the winner can be ensured to get the payment. Since an optimal fair exchange method is used in gambling message exchange the proposed system guarantees that no one can successfully cheat during a gambling process. Our system requires an off-line Trusted Third Party (TTP). If a cheating occurs, the TTP can resolve the problem and make the gambling process fair. Weiliang Zhao, Vijay Varadharajan, Yi Mu 0001 |
ACSAC | 3 |
| 1999 | Divertible Zero-Knowledge Proof of Polynominal Relations and Blind Group Signature
Khanh Quoc Nguyen, Yi Mu 0001, Vijay Varadharajan |
ACISP | 2 |
| 1999 | Zero-Knowledge Proofs of Possession of Digital Signatures and Its Applications
Khanh Quoc Nguyen, Feng Bao 0001, Yi Mu 0001, Vijay Varadharajan |
ICICS | 3 |
| 1999 | Delegated Decryption
Yi Mu 0001, Vijay Varadharajan, Khanh Quoc Nguyen |
IMACC | 1 |
| 1999 | On the Design of Efficient RSA-based Off-line Electronic Cash Schemes
Vijay Varadharajan, Khanh Quoc Nguyen, Yi Mu 0001 |
Theor. Comput. Sci. | 3 |
| 1998 | Anonymous Secure E-Voting Over a NetworkabstractWe propose two new anonymous secure electronic voting schemes that protect the privacy of the voters and prevent double voting. These schemes do not require any special voting channel and the communications can occur entirely over existing networks such as the Internet. The proposed schemes are based on the ElGamal digital signature algorithm and can be applied to elections in a variety of situations ranging from an election in a small organization to a country. Yi Mu 0001, Vijay Varadharajan |
ACSAC | 1 |
| 1998 | A New Scheme of Credit based Payment for Electronic CommerceabstractThe paper describes a new credit card system, which presents a promise for us to develop a new method of protecting secret information, such as credit card number, PIN and identification. Our credit cards are anonymous. That is, the identity of a card holder and credit card information are not revealed during a payment process. One important feature of our system lies in the fact that, unlike normal electronic credit based systems such as SET, iKP and NetCard, the involvement of the online financial institution that runs the payment system is reduced to a minimum. Yi Mu 0001, Vijay Varadharajan |
LCN | 1 |
| 1997 | New Micropayment Schemes Based on PayWords
Yi Mu 0001, Vijay Varadharajan, Yan-Xia Lin |
ACISP | 1 |
| 1997 | Micro-Digital Money for Electronic CommerceabstractProposes two novel cash-based micropayment schemes based on a new technique referred to as the double-locked hash chain technique. Both schemes support the divisibility and transferability of digital coins in a simpler way compared to the existing solutions. The basic scheme allows full or partial use of a coin chain in a transaction; if only part of a coin chain has been used with one vendor, the rest of the chain can be used, for instance in a subsequent transaction with another vendor. The modified scheme extends this to multiple chains, making the scheme particularly suitable for a large number of micropayment transactions. Khanh Quoc Nguyen, Yi Mu 0001, Vijay Varadharajan |
ACSAC | 2 |
| 1997 | Secure and Efficient Digital CoinsabstractCurrent off-line electronic cash systems require a great number of complex online computations by clients during the payment phase. In this paper, we propose a new off-line anonymous cash scheme that greatly reduces the number of online computations that need to be done by the clients for each payment transaction. In particular, except for the first coin in a transaction, the client only needs to perform minimal computations for the remaining coins in the transaction. Our scheme also provides unconditional client anonymity and is able to detect double-spending and is resistant to coin forgery and framing attacks. Khanh Quoc Nguyen, Yi Mu 0001, Vijay Varadharajan |
ACSAC | 2 |
| 1997 | A New Efficient Off-line Anonymous Cash Scheme
Khanh Quoc Nguyen, Vijay Varadharajan, Yi Mu 0001 |
ISAAC | 3 |
| 1996 | On the design of security protocols for mobile communications
Yi Mu 0001, Vijay Varadharajan |
ACISP | 1 |
| 1996 | An alternative model of quantum key agreement via photon coupling
Yi Mu 0001, Yuliang Zheng 0001 |
ACISP | 1 |
| 1996 | On The Design Of Secure Electronic Payment Schemes For InternetabstractConsiders the design of secure electronic credit card based payment schemes for the Internet, and reveals some of the issues that have not been adequately addressed in the proposed protocols to date. This paper proposes additional mechanisms that need to be incorporated as part of the design phase of the scheme to deal efficiently with the disputes that can arise. The design methods described in this paper are applicable to a range of protocols, including iKP (Internet Kaufmannisch Protokoll), STT (Secure Transaction Technology) and SEPP (Secure Electronic Payment Protocol). Based on this discussion, the paper goes on to propose an improved payment scheme and protocol. The new protocol, referred to as the permission-based payment (PBP) protocol, provides a fair treatment of both the client and the merchant involved in the transaction. It separates the purchase request phase from the payment phase, thereby increasing the ability to handle certain class of disputes more efficiently. It removes the need to store the secret private key at the client's machine or the need for a smart card device. This is important as one cannot assume that all the clients connected to the Internet have smart card readers attached to them. The new protocol makes simpler assumptions about the environment, thereby making the scheme practical for securing commercial electronic credit card transactions. Vijay Varadharajan, Yi Mu 0001 |
ACSAC | 2 |