Yi Mu 0001

dblp:m/YiMu · DBLP profile ↗
← Back
355ranked-venue papers
9as first author
45since 2021 · last 2026
0000-0002-1637-845XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 195 · 7 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 47 · 4 since 2021Databases, data management, data science and information retrieval · 26 · 5 since 2021Systems, architecture and hardware · 25 · 8 since 2021Computer networks · 21 · 1 first-author · 7 since 2021Theory of computation · 17 · 1 since 2021Software engineering, systems software and programming languages · 11 · 1 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 9 · 1 since 2021
YearPublicationVenuePosition
2026 Dynamic Hub Labeling for Shortest Distance Queries on Structured Encrypted Graphs
Mengdi Hu, Lanxiang Chen, Yi Mu 0001
VLDB J.3
2025 Laconic updatable private set intersection
Xiangqian Kong, Lanxiang Chen, Yizhao Zhu, Yi Mu 0001
J. Inf. Secur. Appl.4
2025 Leakage Reduced Searchable Symmetric Encryption for Multi-Keyword Queries
abstract
Conjunctive keyword queries on untrusted cloud servers represent one of the most common forms of search in encrypted environments. Extensive research has been devoted to developing efficient schemes that support multi-keyword queries. In particular, the Oblivious Cross-Tags (OXT) protocol has received significant attention and is widely regarded as a benchmark in this domain. However, existing schemes fail to simultaneously hide the Keyword-Pair Result Pattern (KPRP) and the conditional Intersection Pattern (IP), potentially leaking additional information to the server. In this work, we propose a novel searchable symmetric encryption (SSE) scheme, referred to asResult Hiding Search (RHS), which aims to minimize result pattern leakage and achieve query result hiding during the index retrieval phase by integrating Private Set Intersection (PSI) techniques. Our scheme enhances privacy by employing PSI for secure membership testing. To improve query efficiency, we shift the expensive complex computation to the offline phase, and utilize efficient pseudorandom functions and hash functions during the online phase. Moreover, we propose a variant of RHS, called vRHS, designed to reduce client-side storage overhead. A simulation-based security proof demonstrates that our scheme is robust against non-adaptive adversaries. Comprehensive experimental evaluation further shows that our approach achieves better security and efficiency trade-offs compared to existing SSE schemes.
Qinghua Deng, Lanxiang Chen, Yizhao Zhu, Yi Mu 0001
IEEE Trans. Cloud Comput.4
2025 Private Reachability Queries on Structured Encrypted Temporal Bipartite Graphs
abstract
A temporal bipartite graph is a graph model that incorporates time-related information into its edges, making it suitable for modeling real-world phenomena like disease outbreaks. However, this temporal information is often sensitive. To protect the privacy of graph data, researchers have explored various approaches to preserve privacy in graph queries, with reachability queries being popular and fundamental as they determine the possibility of reaching one node from others in a graph. While privacy-preserving reachability queries have been extensively studied, existing efforts often overlook the valuable attribute information present in both edges and nodes of the graphs. Moreover, reachability queries on temporal bipartite graphs have not received sufficient attention in the literature. To bridge this gap, we propose a novel approach to achieve various privatereachabilityqueries onstructured encryptedtemporalbipartitegraphs ($\mathsf{RQ}$-$\mathsf{STBG}$) through a real-world scenario. Specifically, we construct a minimal index using hierarchical 2-hop labels and integrate structured encryption, order-revealing encryption, and garbled Bloom filters to support reachability queries with different label constraints. The proposed scheme is flexible and can cater to the query requirements of diverse users. Security analysis and experimental evaluations demonstrate that the proposed scheme achieves both preferable security and efficiency.
Lanxiang Chen, Gaolin Chen, Yi Mu 0001, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.4
2025 Keyword-Pair Result Pattern Hiding Structured Encryption for Boolean Queries
abstract
Cash et al. [CRYPTO2013] proposed the oblivious cross-tags (OXT) protocol to enable highly scalable searchable symmetric encryption (SSE) with support for Boolean queries. More recently, Lai et al. [CCS2018] introduced the hidden cross-tags (HXT) protocol, an enhancement of OXT designed to eliminate “keyword-pair result pattern” (KPRP) leakage in conjunctive queries. However, while HXT prevents KPRP leakage in conjunctive queries, it suffers from low efficiency and remains vulnerable to KPRP leakage in disjunctive queries. In this paper, we propose the first efficient structured encryption scheme for Boolean queries (STE-BQ) that eliminates KPRP leakage for both disjunctive and conjunctive multi-keyword queries. Our approach introduces a novel index construction method based on prime number aggregation, which significantly reduces the number of comparisons required in multi-keyword searches, thereby improving efficiency. Security analysis confirms that STE-BQ satisfies CQA2-security. Experimental evaluations further demonstrate that STE-BQ achieves optimal performance in conjunctive query processing. While its disjunctive query time is slightly slower than that of OXT, STE-BQ is the only scheme that fully eliminates KPRP leakage for both conjunctive and disjunctive queries.
Lanxiang Chen, Yi Mu 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.2
2024 Practical and malicious private set intersection with improved efficiency
Yizhao Zhu, Lanxiang Chen, Yi Mu 0001
Theor. Comput. Sci.3
2024 Monero With Multi-Grained Redaction
abstract
Monero is a privacy-centric cryptocurrency that allows users to obscure their transactions with multiple input and output addresses. Current research on Monero mainly focuses on identifying design vulnerabilities or optimizing towards stronger privacy, security, etc. For example, improving the design of ring confidential transaction (RingCT) protocol proposed by Noether et al. As revealed by Ali et al. in USENIX 2016, new blockchains have inadequate nodes and network computing resources to resist powerful attack (e.g., 51% attack). Obviously, Monero blockchain is not an exception. Ateniese et al. proposed the notion of redactable blockchain in EuroS$ \& amp;$P 2017, which begins the trend of formalizing blockchain with extra cryptographic primitives. The motivation is to turn an immutable blockchain into a mutable ledger by adapting the blockchain design and integrating with new cryptographic schemes. In such a setting, users could use their private keys to perform the secure multi-party computation to reverse blockchain history. The idea of redactable blockchain has attracted many researchers to pursuit this topic. However, few works have considered the privacy-preserving setting. Even fewer have practised their designs in an actual cryptocurrency. In this paper, we seek to adapt the RingCT protocol with several building blocks. Our proposal achieves most of the desired properties for blockchain redaction. It allows multiple tracing authorities to collaboratively trace users’ identities, and a system manager to perform multi-grained (including block-level, transaction-level, accumulator-level and commitment-level) redaction on block contents. Our proposal can be seen as an extension of RingCT protocol. We give rigorous security requirements and comprehensive analysis of our scheme. The performance evaluation suggested that our scheme suffers from some unscalabilities in large-scale implementations. A more elegant design to achieve stronger security and ideal scalability is deemed as a challenging and interesting future work.
Ke Huang 0002, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaosong Zhang 0001, Xiong Li 0002
IEEE Trans. Dependable Secur. Comput.2
2024 A Pruned Pendant Vertex Based Index for Shortest Distance Query Under Structured Encrypted Graph
abstract
The shortest distance query is used to determine the shortest distance between two vertices. Various graph encryption schemes have been proposed to achieve accurate, efficient and secure shortest distance queries for encrypted graphs. However, the majority of these schemes are inefficient or lack scalability due to the time-consuming index construction and large index storage. Moreover, none of them consider the trade-off between query efficiency and accuracy. To better trade off the query efficiency and accuracy, we propose a Pruned Pendant Vertex based Index for Shortest Distance Query ($\mathsf { PPVI}$-$\mathsf { SDQ}$) under structured encryption. The proposed scheme utilizes the structured encryption technique to encrypt a graph and build indexes. The main idea is to use the recursive method to repeatedly prune the pendant vertex, and thereby reducing the index size and construction time by minimizing the redundant data storage and graph traversal. The proposed scheme achieves accurate, efficient and secure shortest distance query with privacy-preserving for encrypted graph. The security analysis demonstrates that the proposed scheme satisfies CQA2-security. Experimental results with real datasets show that the scheme achieves the optimal accuracy and efficiency.
Mengdi Hu, Lanxiang Chen, Gaolin Chen, Yi Mu 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.4
2024 Efficient Public-Key Searchable Encryption Scheme From PSI With Scalable Proxy Servers
abstract
Public-key Encryption with Keyword Search (PEKS) enables secure keyword searches within encrypted data. At the same time, Public-key Authenticated Encryption with Keyword Search (PAEKS) enhances security by permitting authorized users to search specific keyword sets, protecting against Internal Keyword Guessing Attacks (IKGA). However, to the best of our knowledge, existing PEKS and PAEKS schemes typically require to generate a distinct set of keyword ciphertext for each data user, leading to storage, computation, and communication costs and the lack of support for multiple-keyword search. In this article, we introduce a novel, efficient public-key searchable encryption scheme from the private set intersection (PSI) with scalable proxy servers, using a PSI protocol with multiple proxy server settings, which achieves sub-linear complexity. Our scheme is secure against IKGA and supports multiple keyword searches and sharing one encrypted keyword set by multiple users. We introduce an efficient system model with scalable proxy servers, significantly reducing computational overhead through a divide-and-conquer approach. Our proposed scheme supports multiple data users, and multiple keyword searches, utilizing a single set of keyword ciphertext for multiple data users. We formally define a security model and present a comprehensive security proof to demonstrate that our scheme maintains ciphertext-indistinguishability and trapdoor-indistinguishability.
Xiangqian Kong, Lanxiang Chen, Yizhao Zhu, Yi Mu 0001
IEEE Trans. Serv. Comput.4
2023 Identity-Based Encryption With Continuous Leakage-Resilient CCA Security From Static Complexity Assumption
abstract
Abstract Although a large number of provably secure cryptographic primitives have been proposed in the literature, many of these schemes might be broken in practice because of various leakage attacks. Therefore, the leakage resilience should be considered in designing these primitives. However, in identity-based cryptography, most of the existing leakage-resilient identity-based encryption (IBE) schemes suffer some limitations: they either resist the leakage attacks in the selective identity security model or achieve the chosen-ciphertext attack (CCA) security based on a non-static assumption. In this paper, an IBE scheme with adaptive leakage-resilient CCA security is proposed, and its security is rigorously proved in the random oracle model under a classic static complexity assumption, e.g. decisional bilinear Diffie–Hellman assumption. In our construction, all elements of ciphertext are randomly distributed in the adversary’s view. Hence, the adversary cannot obtain any useful information of the user’s private key from the given ciphertexts. Moreover, a unique property of our construction is that the leakage parameter is independent of the plaintext space, which contributes a better leakage rate.
Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Yi Mu 0001, Mingwu Zhang
Comput. J.6
2023 Leakage-resilient identity-based cryptography from minimal assumptions
Yanwei Zhou, Bo Yang 0003, Zirui Qiao, Zhe Xia, Mingwu Zhang, Yi Mu 0001
Des. Codes Cryptogr.6
2023 C-Wall: Conflict-Resistance in Privacy-Preserving Cloud Storage
abstract
Following the success of cloud computing, it has been shown its importance to realize various access control models in the cloud storage setting. Chinese Wall is a traditional access control model in business for solving the conflict of interest (CoI) problem, and it would be very interesting to achieve conflict-resistant in cloud storage system. However, the access control model does not ensure the privacy of users, and it may reveal the user's interest, investment tendency, etc. Therefore, it raises a big challenge to implement the Chinese Wall without compromising the user's privacy. In this paper, we focus on the Chinese Wall model and apply it to the cloud storage while protecting the access patterns of users. Specifically, we first formulate the tree-based Chinese Wall access control and then propose the Chinese Wall Protocol (called C-Wall). We prove that our C-Wall not only realizes the conflict-resistant but also protects the user's privacy with universally composable security. Besides, we also apply C-Wall to privacy-preserving cloud storage and propose the C2-Wall, which not only maintains C-Wall's features, but also ensures the sensitive files from being touched by "honest-but-curious" cloud servers. Furthermore, we evaluate our C2-Wall by theoretical analysis and experimental validation. Experimental results show its effectiveness and efficiency for practical deployment.
Xiaoguo Li, Tao Xiang 0001, Yi Mu 0001, Fuchun Guo, Zhongyuan Yao
IEEE Trans. Cloud Comput.3
2023 Toward Secure Data Computation and Outsource for Multi-User Cloud-Based IoT
abstract
Cloud computing has promoted the success of Internet of Things (IoT) with offering abundant storage and computation resources where the data from IoT sensors can be remotely outsourced to the cloud servers, whereas storing, exchanging and processing data collected through IoT sensors via centralised or decentralised cloud servers make cloud-based IoT systems prone to internal or external attacks. To protect IoT data against potential malicious users and adversaries, some cryptographic schemes have been applied to ensure confidentiality and integrity of IoT data. It is however a challenging task to perform any arithmetical computations once data items are encrypted. Fully-homomorphic encryption which is based on lattices can, in principle, provide a solution, but it is unfortunately inefficient in computation and hence cannot be applied to IoT. Fully-homomorphic encryption is feasible when we allow the involvement of a semi-trusted server. However, it is challenging to provide such a system in the situation of distributed environments for shared IoT data. We solve this problem and provide a fully-homomorphic encryption scheme for cloud-based IoT applications. We introduce a new method with the aid of a semi-trusted server that can help compute the homomorphic multiplications without gaining any useful information of the encrypted data. We show how our scheme is applied to multi-user IoT security and prove its semantic security. We also conduct experiments to justify its efficiency and applicability to multi-user cloud-based IoT systems.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang
IEEE Trans. Cloud Comput.2
2023 Authenticable Data Analytics Over Encrypted Data in the Cloud
abstract
Statistical analytics on encrypted data requires a fully-homomorphic encryption (FHE) scheme. However, heavy computation overheads make FHE impractical. In this paper we propose a novel approach to achieve privacy-preserving statistical analysis on an encrypted database. The main idea of this work is to construct a privacy-preserving calculator to calculate attributes’ count values for later statistical analysis. To authenticate these encrypted count values, we adopt an authenticable additive homomorphic encryption scheme to construct the calculator. We formalize the notion of an authenticable privacy-preserving calculator that has properties of broadcasting and additive homomorphism. Further, we propose a cryptosystem based on binary vectors to achieve complex logic expressions for statistical analysis on encrypted data. With the aid of the proposed cryptographic calculator, we design several protocols for statistical analysis including conjunctive, disjunctive and complex logic expressions to achieve more complicated statistical functionalities. Experimental results show that the proposed scheme is feasible and practical.
Lanxiang Chen, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.2
2023 BE-TRDSS: Blockchain-Enabled Secure and Efficient Traceable-Revocable Data-Sharing Scheme in Industrial Internet of Things
abstract
As an important component of the Industrial Internet of Things (IIoT), the smart factory uses IIoT and equipment-monitoring technology to collect data to reasonably arrange the production. A large number of data is collected and uploaded to the IIoT cloud platform. However, the IIoT cloud platform is semitrusted and has structural limitations and vulnerability, which makes it necessary to realize data dynamic security sharing and malicious users' tracking. In this article, we show that the most recent work on this issue is still vulnerable to security threats at first. Then, a blockchain-enabled dynamic and traceable data-sharing scheme for a smart factory is proposed. Blockchain performs the user authentication and stores the ciphertext index and public keys to avoid tampering with shared data. The tracking algorithm tracks malicious users and adds them to a revocation list embedded in the ciphertext. And the authority can flexibly select domain or user revocation as required. The LSSS access policy is hidden to protect user privacy, and the cloud server uses the match test algorithm to detect whether users meet the hidden access policy. Additionally, online–offline encryption and outsourced decryption improve the efficiency of the scheme where the ciphertext and the pairing operations required for decryption achieve constant size. A performance analysis shows that the scheme can resist a variety of collusion attacks, and simulations show that it outperforms current schemes.
Ruonan Ma, Leyou Zhang, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
IEEE Trans. Ind. Informatics4
2023 Global Combination and Clustering Based Differential Privacy Mixed Data Publishing
abstract
With the rapid advancement of information technology, a large amount of high-value data have been generated. To exploit the potential value of big data and at the same time to protect individuals' sensitive information, a global combination and clustering based differential privacy (DP) mixed data publishing method is proposed in this paper. The main idea of the proposed method is to improve the truthfulness of the published data as well as to enhance the utility by shifting the sensitivity of query function from a single record to a group of records using$k$-median clustering algorithm. Specifically, to improve the accuracy and utility of categorical attributes, a global combination method is proposed to take the correlation among categorical attributes into account. The proposed combination method takes all categorical attributes as a unit and then applies the exponential mechanism to improve the data utility. Then we combine it with the$k$-median clustering with differential privacy to publish the mixed data. Theoretical analysis shows that the proposed method satisfies$\varepsilon$-differential privacy. Experimental results on real datasets illustrate that the proposed method has a much lower information loss and time overhead than the state-of-the-art approach for the same parameters.
Lanxiang Chen, Lingfang Zeng, Yi Mu 0001, Leilei Chen
IEEE Trans. Knowl. Data Eng.3
2023 CASE-SSE: Context-Aware Semantically Extensible Searchable Symmetric Encryption for Encrypted Cloud Data
abstract
Traditional searchable symmetric encryption (SSE) schemes rarely support context-aware semantic extension, and then lead to the searched results being incomplete or deviating from the user’s query intention. To address this problem, a new context-aware semantically extensible searchable symmetric encryption based on Word2vec model (CASE-SSE) is proposed to achieve context-aware semantic extension in this article. The proposed scheme utilizes outsourced datasets as corpora to extract all keywords for training the Word2vec model, and the trained results is the ontology knowledge base that can be used to extend the semantics of query keywords directly. Further, to facilitate multi-keyword search using the extended query vector, we use the$k$-means clustering algorithm to classify outsourced datasets. We then construct an AVL-tree index and an inverted index based on the classified results, thereby achieving efficient context-aware semantically extensible SSE. The security analysis indicates it is secure and effective. The experimental results show that our scheme is superior in both efficiency and accuracy.
Lanxiang Chen, Yujie Xue, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng
IEEE Trans. Serv. Comput.3
2023 Authenticable Additive Homomorphic Scheme and its Application for MEC-Based IoT
abstract
The integration of Internet of Things (IoT) and cloud computing are always seen as promising technologies to enhance streamlined data collection, share and exchange. Although the advances in edge computing, particularly mobile edge computing (MEC), could enhance the performance of data collection and computation via computing offloading, security and privacy impediments have made new challenges to data integrity and confidentiality, in particular when multiple edges or nodes at different locations collect IoT data. Homomorphic encryption therefore has shown promising advantages for cloud computing, offering arithmetic operations to be carried out on the encrypted data without revealing the secret key. While fully homomorphic encryption introduced by Gentry, in 2009, allows both additive and multiplicative operations, it has shown significant implementation drawbacks due to the parameters generation and memory consumption. In this work, we focus on partially homomorphic encryption, which can be efficiently computed. However, it is challenging to add authentication feature for the verification and aggregation capability. We propose a novel secure and privacy preserving authenticable homomorphic encryption (AHEC) scheme. We demonstrate an application of our AHEC scheme for MEC-based IoT systems and provide security analysis to prove that our scheme is secure against chosen plaintext attack (IND-CPA) and unforgeability (UNF) under DDH-ZN2 and Lift-DH-ZN2 assumptions. Experimental results show that our proposed scheme is efficient for practical applications.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang
IEEE Trans. Serv. Comput.2
2022 Blockchain-based random auditor committee for integrity verification
Lanxiang Chen, Qingxiao Fu, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Min-Shiang Hwang
Future Gener. Comput. Syst.3
2022 BA-RMKABSE: Blockchain-aided Ranked Multi-keyword Attribute-based Searchable Encryption with Hiding Policy for Smart Health System
Jian Su 0004, Leyou Zhang, Yi Mu 0001
Future Gener. Comput. Syst.3
2022 Blockchain-based deduplication with arbitration and incentives
abstract
Abstract Cloud storage is an ideal platform to accommodate massive data. However, with the increasing number of various devices and improved processing power, the amount of generated data is becoming gigantic. Therefore, this calls for a cost‐effective way to outsource massively generated data to a remote server. Cloud service providers utilise deduplication technique which deduplicates redundant data by aborting identical uploading requests and deleting redundant files. However, current deduplication mechanisms mainly focus on the storage saving of the server, and ignore the sustainable and long‐term financial interests of servers and users. This is not helpful to expand outsourcing and deduplication services. Blockchain is an ideal solution to achieve an economical and incentive‐driven deduplication system. Though some current research studiess have integrated deduplication with blockchain, they did not utilise blockchain as a financial tool. Meanwhile, it lacks an arbitration mechanism to settle disputes between the server and the user, especially in a Bitcoin payment where the payment is not confirmed immediately and a dispute may occur. This creates a burden to achieve fair and transparent incentive‐based deduplication service. In this work, we construct a deduplication system with financial incentives for the server and the user based on Bitcoin. The data owner will pay money via Bitcoin to the server for outsourcing the file, but this fee can be compensated by charging deduplication users with some fees to acquire the deduplication service. The server and the user can receive revenues using deduplication service. Disputes on the fair distribution of incentives can be settled by our arbitration protocol with chameleon hashes as arbitration tags. We give concrete construction and security requirements for our proposed . The security analysis shows that our is theoretically secure. The performance evaluation shows that our proposed is acceptably efficient for the deduplication. Meanwhile, we evaluate and conclude that 1% of outsourcing fee (or less) is a reasonable and preferable price for each deduplication user to pay as compensation for data owner.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Yongcheng Gong
IET Inf. Secur.3
2022 Secure Decentralized Attribute-Based Sharing of Personal Health Records With Blockchain
abstract
Personal health records (PHRs) are located in a patient-centered electronic health system in which users can store and share medical information. However, PHRs have recently been plagued by security issues, such as the leakage of personal health information, illegal access to patient data, and data tampering. Recent security developments, such as introducing an access control policy with attribute-based encryption (ABE) or utilizing blockchain, have only been partially successful in solving these issues. Ongoing challenges to PHR sharing include single points of failure, node cheating attacks, and fair keyword search issues. In this article, we tackle these challenges by introducing a distributed PHR-sharing scheme based on blockchain and ciphertext policy ABE (CP-ABE), which allows for fast and efficient encryption and decryption. Blockchain maintains the integrity and the tracing source of the data while also recording all operations on the data in the form of transactions. In addition, the blockchain nodes act as attribute authorities to construct the CP-ABE cryptosystem. The tracing of malicious blockchain nodes is realized by tracing cryptography algorithms. Furthermore, the fair retrieval of ciphertext is achieved by employing smart contracts. To overcome the limited storage capacity of blockchain, we adopt both the on-chain and off-chain storage modes in our new system. Security analysis indicates that our new scheme remains intact when threatened by an indistinguishable chosen plaintext attack (IND-CPA) and an indistinguishable chosen keywords attack (IND-CKA). As such, we conclude that our proposed approach is feasible and efficient.
Leyou Zhang, Tianshuai Zhang, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
IEEE Internet Things J.4
2022 A Secure and Efficient Decentralized Access Control Scheme Based on Blockchain for Vehicular Social Networks
abstract
The vehicular social network (VSN) is an emerging mobile communication system combining a vehicle ad hoc network (VANET) with a social network. It provides a new means of sharing, disseminating, and delivering data for passengers, drivers, and vehicles. However, a VSN may expose users’ private information, such as identities, location information, and trajectories, and tampering with shared data may lead to security and safety problems in vehicle systems. Considering the security and privacy preservation of shared data, we propose a lightweight decentralized multiauthority access control scheme based on ciphertext-policy attribute-based encryption (CP-ABE) and blockchain, by which a decentralized multiauthorization node supports vehicle users by performing lightweight calculations with the assistance of the vehicle cloud service provider (VCSP). We use blockchain to record storage and access transactions, achieving self-verification by users and tamper-resistance of ciphertexts. An improved smart contract reduces the workload of verification by users and achieves privacy preservation by hiding the policy. It supports user revocation and outsourced decryption, enabling more flexibility and better performance. A security and performance analysis shows that our scheme has clear advantages over existing schemes.
Leyou Zhang, Ye Zhang 0026, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
IEEE Internet Things J.4
2022 Structured encryption for knowledge graphs
Yujie Xue, Lanxiang Chen, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng
Inf. Sci.3
2022 Controllable software licensing system for sub-licensing
Manli Yuan, Yi Mu 0001, Fatemeh Rezaeibagha, Li Xu 0002, Xinyi Huang 0001
J. Inf. Secur. Appl.2
2022 Blockchain-enabled multi-authorization and multi-cloud attribute-based keyword search over encrypted data in the cloud
Qing Wu 0005, Taotao Lai, Leyou Zhang, Yi Mu 0001, Fatemeh Rezaeibagha
J. Syst. Archit.4
2022 A traceable and revocable multi-authority access control scheme with privacy preserving for mHealth
Leyou Zhang, Chuchu Zhao, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
J. Syst. Archit.4
2022 Publicly verifiable secure communication with user and data privacy
Zhongyuan Yao, Yi Mu 0001
Pers. Ubiquitous Comput.2
2022 Bidirectional and Malleable Proof-of-Ownership for Large File in Cloud Storage
abstract
Cloud storage is a cost-effective platform to accommodate massive data at low cost. However, advances of cloud services propel data generation, which pushes storage servers to its limit. Deduplication is a popular technique enjoyed by most current cloud servers, which detects and deletes redundant data to save storage and bandwidth. For security concerns, proof-of-ownership (PoW) can be used to guarantee ownership of data such that no malicious user could pass deduplication easily or utilize such mechanism for malicious purposes. Generally, PoW is implemented in static data archive where the data file is supposed to be read-only. However, to satisfy users’ needs for dynamical manipulation on data and support real-time data services, it is required to devise efficient PoW for dynamic archive. Inspired by malleable signature, which offers authentication even after its committed message changes, we propose the notion of bidirectional and malleable proof-of-ownership ($\sf {BM\mbox{-}PoW}$) for the above challenge. Our proposed$\sf {BM\mbox{-}PoW}$consists of bidirectional PoW (${\mbox{B-PoW}}$), malleable PoW (${\mbox{M-PoW}}$) and dispute arbitration protocol$\sf {DAP}$. While our${\mbox{B-PoW}}$is proposed for a static setting, the${\mbox{M-PoW}}$caters specifically for dynamic manipulation of data. In addition, our proposed arbitration protocol$\sf {DAP}$achieves accountable redaction which can arbitrate the originality of file ownership. We provide the security analysis of our proposal, and performance evaluation that suggests our proposed${\mbox{B-PoW}}$is secure and efficient for large file in static data archive. In addition, our proposed${\mbox{M-PoW}}$achieves acceptable performance under dynamic setting where data is supposed to be outsourced first and updated later in dynamic data archive.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du
IEEE Trans. Cloud Comput.3
2022 Authenticated Data Redaction With Accountability and Transparency
abstract
A common practice in data redaction is removing sensitive information prior to data publication or release. In data-driven applications, one must be convinced that the redacted data is still trustworthy. Meanwhile, the data redactor must be held accountable for (malicious) redaction, which could change/hide the meaning of the original data. Motivated by these concerns, we present a novel solution for authenticated data redaction based on a new Redactable Signature Scheme with Implicit Accountability ($\mathsf {RSS}$RSS-$\mathsf {IA}$IA). In the event of a dispute, not only the original data signer but also the redactor can generate an evidence tag to unequivocally identify the party who produced the data/signature pair. Without the evidence tag, the redaction operation is transparent. Furthermore, the redactor can independently prove the trustworthiness of the redacted data, without any interaction with the original data signer. Our design is built on a new approach which adds accountability to any transparent redactable signature schemes. We show that the proposed design satisfies all the security goals with affordable cost. As an extension, we show how to realize accountable, transparent and authenticated data redaction in the multi-redactor setting.
Jinhua Ma, Xinyi Huang 0001, Yi Mu 0001, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.3
2022 Cloud-Based Outsourcing for Enabling Privacy-Preserving Large-Scale Non-Negative Matrix Factorization
abstract
It is inevitable and evident that outsourcing complicated intensive tasks to public cloud vendors would be the primary option for resource-constrained clients in order to save cost. Unfortunately, the public cloud vendors are usually untrusted. They may inadvertently leak the data or misuse the user’s data, compromise user’s privacy or intentionally corrupt computational results to make the system unreliable. It is therefore important how to stop this happening whilst embracing the computational power of public cloud vendors. Non-negative matrix factorization (NMF) is a significant method for conducting data dimension reduction, which has been widely used in large-scale data processing. Nevertheless, due to its non-polynomial hardness, NMF cannot be conducted efficiently using local computation resources, especially when dealing with big data. Motivated by this issue, we address this by presenting a novel outsourced scheme for NMF (O-NMF), which aims to lessen clients’ computing burden and tackle secure problems faced by outsourcing NMF. Particularly, based on two non-collusion servers, O-NMF exploits Paillier homomorphism to preserve data privacy. Additionally, O-NMF allows a verification mechanism to assist clients in verifying returned results with high probability. Security analysis and experimental evaluation demonstrates that the validity and practicality of O-NMF is also provided in this work.
Anmin Fu, Zhenzhu Chen, Yi Mu 0001, Willy Susilo, Yinxia Sun
IEEE Trans. Serv. Comput.3
2022 Privacy-Preserving Reverse Nearest Neighbor Query Over Encrypted Spatial Data
abstract
With the advent of cloud computing, it has become more and more popular to outsource various services to the cloud for releasing the burden of local data storage and maintenance. However, it may cause serious privacy problems because the cloud may be untrusted. In this article, we study the privacy-preserving reverse nearest neighbor (PPRNN) query over encrypted spatial data. First, we introduce the concept of reference-locked order-preserving encryption (RL-OPE) with its construction and security proof, which reveals less information than traditional order-preserving encryption (OPE). Then, we present a novel PPRNN scheme in static setting based on structured encryption (SE) and the proposed RL-OPE, called sPPRNN. After that, we design a generic method that extends a PPRNN scheme in static setting to the counterpart in dynamic setting, called dPPRNN. Furthermore, we present a thorough privacy analysis of our proposal. Finally, we demonstrate its efficiency and effectiveness for practical deployment through extensive experiments.
Xiaoguo Li, Tao Xiang 0001, Shangwei Guo, Hongwei Li 0001, Yi Mu 0001
IEEE Trans. Serv. Comput.5
2022 Secure Outsourced Attribute-Based Sharing Framework for Lightweight Devices in Smart Health Systems
abstract
The rapid evolution of the Internet of Things has led to the development of smart health. As a form of medical care that uses advanced Internet technology to realize better diagnosis and treatment of patients, smart health transitions medical services move toward real intelligence and greatly helps users. And in smart health, the secure sharing of personal health records (PHRs) is one of the main concerns of patients and medical personnel. Many attribute-based sharing models have been proposed to secure the sharing of PHRs, but there are still two problems to resolve. One is the potential disclosure of the patient data. The attribute-based model achieves flexible access control, but the access policies contain sensitive information of patients. The disclosure of the policy will lead to the leakage of data of the users. The other is the high computational and storage overhead, particularly in smart health systems with limited computing power. In this article, we present a Smart Health-Lightweight Fine-Grained Sharing (SH-LFGS) framework based on attribute-based encryption (ABE). It achieves a fully hidden access policy by adopting Viéte's formula. SH-LFGS introduces an online/offline mechanism in the PHR encryption phase and the outsourced verifiable decryption mechanism. Because the decrypting test requires only one bilinear pair operation, the SH-LFGS can achieve the task of lightweight computation. Analysis of the performance and security of the proposed model confirm its efficiency and security.
Leyou Zhang, Wenting You, Yi Mu 0001
IEEE Trans. Serv. Comput.3
2021 Privacy-Aware Image Authentication from Cryptographic Primitives
abstract
Abstract Image authentication is the process of verifying image origin, integrity and authenticity. In many situations, image authentication should allow reasonable image editing, which does not introduce any wrong information against the original one. While it has been studied both extensively and intensively with considerable efforts, there is no satisfactory method supporting region extraction. This paper presents a solution to address the issue of privacy protection in authenticated images. Our scheme allows anyone to extract sub-image blocks from an original image (authenticated by the image producer) and generate a proof tag to prove the credibility of the extracted image blocks. The process of proof tag generation does not require any interaction with the image producer. In addition, the image producer is able to define must-be-preserved image blocks (e.g. producer logo) during the extraction. We define the security property for the authenticated sub-images and give a generic design with two core primitives: an ordinary digital signature scheme and a cryptographic accumulator. The security of our design can be reduced to the underlying cryptographic primitives and its practical performance is demonstrated by a bunch of evaluations. We believe the proposed design, together with other image authentication methods, will further facilitate image relevant services and applications.
Haixia Chen, Xinyi Huang 0001, Wei Wu 0001, Yi Mu 0001
Comput. J.4
2021 Unlinkable and Revocable Secret Handshake
abstract
Abstract In this paper, we introduce a new construction for unlinkable secret handshake that allows a group of users to perform handshakes anonymously. We define formal security models for the proposed construction and prove that it can achieve session key security, anonymity and affiliation hiding. In particular, the proposed construction ensures that (i) anonymity against protocol participants (including group authority) is achieved since a hierarchical identity-based signature is used in generating group user’s pseudonym-credential pairs and (ii) revocation is achieved using a secret sharing-based revocation mechanism.
Yangguang Tian, Yingjiu Li, Yi Mu 0001, Guomin Yang
Comput. J.3
2021 Novel generic construction of leakage-resilient PKE scheme with CCA security
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang, Yi Mu 0001
Des. Codes Cryptogr.5
2021 Enhanced bitcoin with two-factor authentication
abstract
Bitcoin transactions rely on digital signatures to prove the ownership of bitcoin. The private signing key of the bitcoin owner is the key component to enable a bitcoin transaction. If the signing key of a bitcoin is stolen, the theft who possesses the key can make a transaction of the bitcoin. In this paper, based on the distance-based encryption (DBE), we propose an enhanced version of bitcoin in order to protect the signing key. Our approach is based on our two-factor authentication, where the signing key cannot be retrieved without being identified via the password and biometric authentication scheme, and the user is only required to enter his password and fingerprint (or other biometric information such as a factual image) to retrieve the key. By doing this, we can effectively improve the bitcoin security and provide stronger authentication. An attractive feature of our scheme is that one of encryption schemes is asymmetric, in the sense that the decryption key (biometric information) is not stored in the device. We also provide the security model and proof to justify the security of our scheme.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Leyou Zhang
Int. J. Inf. Comput. Secur.2
2021 Secure and Efficient Data Aggregation for IoT Monitoring Systems
abstract
The proliferation of Internet of Things (IoT) as a promising paradigm has contributed enormously to modern technology design. The wireless body sensor network (WBSN) technology is an application of IoT in healthcare, whereas data security and privacy impediments have raised some concerns. The collected data via IoT wireless body sensors is vulnerable to a variety of internal and external attacks. One solution is to encrypt or sign the collected data to provide confidentiality and integrity, but the computational complexity hinders the application in the real IoT-based healthcare devices. Although there have been some attempts to provide secure and efficient IoT schemes, there is a lack of achieving secure data analysis in modern healthcare. The aggregated data statistics about the patient's medical status is useful to doctors and healthcare providers. However, the dynamic data continually updating over time is challenging. In this article, we present an efficient and provably secure scheme, which is the first step toward secure data analysis for handling the data collection and analysis for IoT wireless body sensors. The main contribution of our work is a novel cryptographic accumulator based on our novel authenticated additive homomorphic encryption which can collect and accumulate data from IoT wireless wearable devices. These encrypted data can be used for analysis in an encrypted form so that the information is not revealed. To validate security and efficiency, we present security analysis and performance evaluations of our proposed scheme for IoT wireless body sensors.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen
IEEE Internet Things J.2
2021 Secure and Privacy-Preserved Data Collection for IoT Wireless Sensors
abstract
The captured data from smart devices via Internet of Things (IoT) wireless sensors are vulnerable to numerous online and offline attacks and unauthorized accesses, hence, some digital signature and encryption solutions have been designed to ensure public verifiability, data integrity, and confidentiality. However, there are still some issues to be addressed. For example, the data source is revealed to the public due to the public verifiability of digital signatures, in which authentication is transferrable. Moreover, computation of these data can only be done after decryption, restricting outsourced computation, such as a computing facility from a cloud. The best approach of private computation, which supports outsourced computation, is based on homomorphic encryption. However, significant computational overhead is a concern. To deal with these issues, in this article, we propose an efficient and provably secure scheme based on designated-verifier proofs, deniable authentication and homomorphic encryption for secure and lightweight data collection, batch verification, and data analysis in the privacy-preserved IoT wireless sensors applications. The main contribution of our work is the privacy-preserved IoT wireless sensors system along with a novel deniable authenticated homomorphic encryption scheme that can securely aggregate data from IoT wireless sensors for secure outsourced applications. To prove the security and efficiency of our proposed scheme, we provide formal security analysis and performance comparisons for IoT wireless sensors.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Leyou Zhang, Xinyi Huang 0001
IEEE Internet Things J.2
2021 An Enhanced Certificateless Aggregate Signature Without Pairings for E-Healthcare System
abstract
Recently, Gayathri et al. introduced an efficient certificateless aggregate signature (CLAS) for e-healthcare system and claimed that it can achieve efficient aggregation to different signatures on different messages from different medical sensors. In this article, we analyze it and find that the CLAS scheme and the underlying certificateless signature (CLS) scheme in it are not secure. Anyone can forge a valid aggregate/individual signature replacing the legitimate medical sensor only based on the public parameters set in Gayathri et al.'s CLAS scheme. Moreover, the malicious medical sensors can deny a valid aggregate signature (AS) by offering false individual signatures aggregated into this AS. We also present a secure CLAS scheme by aggregating an existing lightweight CLS scheme. The aggregation algorithm adopted in our new scheme is proven sound against inside attacks.
Wenjie Yang 0001, Shangpeng Wang, Yi Mu 0001
IEEE Internet Things J.3
2021 Privacy-Preserving Flexible Access Control for Encrypted Data in Internet of Things
abstract
Along with the development of edge computing and the cloud, the Internet of Things (IoT) is affecting and changing people’s lives. Data sharing has played an important role in the IoT, but the leakage of private user information poses a new security threat to the users. Thus, flexible fine-grained access control for such shared data is proposed in this article as an effective and secure method of eliminating vulnerabilities. However, the disclosure of access policies will also expose users’ private information. Recently, Yanget al.attempted to solve this problem and proposed a framework based on attribute-based encryption for shared data onto IEEE IoT-J(DOI: 10.1109/JIOT.2016.2571718). They hide the access policies by using a bloom filter (BF) and attempt to address privacy preservation in IoT. However, we demonstrate several security weaknesses of their framework and point out its vulnerability to dictionary attacks and access policy guessing attacks. Then, an improved IoT solution is proposed. Under this proposal, the attribute values are stored in BF while the attribute names are embedded in the access policy. The proposed scheme can resist dictionary attacks and access policy guessing attacks. In addition, it simultaneously realizes large attribute sets, an efficient decryption algorithm, and adaptive security. Security analysis and performance evaluations show that the presented scheme achieves higher security and implementation simplicity in the IoT than other currently available schemes.
Leyou Zhang, Jun Wang 0109, Yi Mu 0001
IEEE Internet Things J.3
2021 Multiauthority Access Control With Anonymous Authentication for Personal Health Record
abstract
A personal health record (PHR) system is a smart health system that serves patients and doctors. A PHR is usually stored in a cloud and managed by a semitrusted cloud provider. However, there is still a possibility of the exposure of personal health information to semitrusted parties and unauthorized users. To protect the privacy of patients and ensure that patients can control their PHRs, a patient-centric PHR sharing framework is proposed in this article. In this framework, all PHRs are protected with multiauthority attribute-based encryption before outsourcing, which solves the key hosting problem and achieves fine-grained access control to PHRs. Furthermore, an anonymous authentication between the cloud and the user is proposed to ensure data integrity on the cloud while not exposing the user's identity during authentication. The proposed authentication is issued from a new online-offline attribute-based signature. It can make the encrypted PHRs resist collusion attacks and not be forged during the period of sharing, which enhances patients' control of their PHRs. Online-offline and outsourcing decryption also reduces calculation costs and improves operational efficiency. Finally, comparisons are given based on numerical experiments.
Leyou Zhang, Yadi Ye, Yi Mu 0001
IEEE Internet Things J.3
2021 Scalable and redactable blockchain with update and anonymity
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du
Inf. Sci.3
2021 Multicopy provable data possession scheme supporting data dynamics for cloud-based Electronic Medical Record system
Lei Zhou 0026, Anmin Fu, Yi Mu 0001, Huaqun Wang, Shui Yu 0001, Yinxia Sun
Inf. Sci.3
2021 Privacy-Preserving Proof of Storage for the Pay-As-You-Go Business Model
abstract
Proof of Storage (PoS) enables a cloud storage provider to prove that a client's data is intact. However, existing PoS protocols are not designed for the pay-as-you-go business model in which payment is made based on both storage volume and duration. In this paper, we propose two PoS protocols suitable for the pay-as-you-go storage business model. The first is a time encapsulated Proof of Retrievability (PoR) protocol that ensures retrievability of the original file upon successful auditing by a client. Considering the large size of outsourced data, we then extend the protocol to a privacy-preserving public auditing protocol which allows a third party auditor to audit outsourced data on behalf of its clients without sacrificing the privacy of the data or the timestamp (i.e., time of storage). We formalize the definition, system model and security model of the proposed PoS system and prove the security of the proposed protocols by a sequence of games in the algebraic group model with a random oracle. We analyze the performance of the protocols both theoretically and experimentally and show that the protocols are practical.
Tong Wu 0011, Guomin Yang, Yi Mu 0001, Fuchun Guo, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.3
2020 Improvement of Attribute-Based Encryption Using Blakley Secret Sharing
Zhe Xia, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang, Yi Mu 0001
ACISP5
2020 Efficient and secure image authentication with robustness and versatility
Haixia Chen, Xinyi Huang 0001, Wei Wu 0001, Yi Mu 0001
Sci. China Inf. Sci.4
2020 An improved Durandal signature scheme
Yongcheng Song, Xinyi Huang 0001, Yi Mu 0001, Wei Wu 0001
Sci. China Inf. Sci.3
2020 Black-Box Accountable Authority Identity-Based Revocation System
abstract
Abstract Identity-based revocation system (IBRS) generates the ciphertext with a revoked identity list such that only the non-revoked identities can use their private keys to decrypt this ciphertext. IBRS can be efficiently applied in some practical applications, such as the pay-TV systems when the number of revoked identities are much less than the non-revoked ones. However, since IBRS is based on identity-based cryptography, it also suffers from the inherent key escrow problem where the private key generator (PKG) has full control of each user’s private key. As a consequence, it is hard to judge whether a pirated private key is generated by the PKG or the suspected user. There is no study on IBRS fulfilling accountability in literature to date. In this paper, we introduce the notion of accountable authority IBRS (A-IBRS), which provides accountability in IBRS schemes. In an A-IBRS, the aforementioned problem can be alleviated and resolved. Furthermore, a full black-box A-IBRS can distinguish the creator of a black box between the PKG and the associated user and the dishonest PKG is allowed to access the decryption results of the user private key. We formalize the definition and security models of the full black-box A-IBRS schemes. Then, we present a concrete full black-box A-IBRS scheme with constant-size master public key and private key. Finally, we prove the security of our scheme under the defined security models without random oracle.
Zhen Zhao 0005, Ge Wu 0001, Fuchun Guo, Willy Susilo, Yi Mu 0001, Baocang Wang, Yupu Hu
Comput. J.5
2020 EVA: Efficient Versatile Auditing Scheme for IoT-Based Datamarket in Jointcloud
abstract
Cloud storage offers convenient outsourcing services to users, and it serves as a basic platform to drive Internet-of-Things (IoT) where massive devices are connected to the cloud storage and interact with each other. However, cloud storage is more than a data warehouse. In the literature, data market was proposed as a novel model to empower IoT, where data are circulated as merchandise in the digital marketplace with financial activities. When storing IoT data in cloud storage, security and efficiency rules should be applied. Meanwhile, data dynamics is counted as a critical factor to the feasibility of datamarket as data are supposed to be manipulated through circulation and exploitation for IoT. Another issue is the single-point-of-failure (SPoF) of cloud server in which the initiative of jointcloud was suggested. Since providing data security, efficiency, and dynamics simultaneously is challenging, in this article, we propose a versatile auditing scheme (EVA) as a solution to problems. Our proposal ensures that data are securely, efficiently, and dynamically stored in the jointcloud meanwhile supported by data trades via blockchain. We give a comprehensive security analysis based on our security definitions and experiments to support our claims. The evidence has shown that our EVA is efficient for processing large files when proper parameters are chosen.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Jingwei Li 0001, Qi Xia 0001, Jing Qin 0002
IEEE Internet Things J.3
2020 Privacy-enhanced remote data integrity checking with updatable timestamp
Tong Wu 0011, Guomin Yang, Yi Mu 0001, Rongmao Chen, Shengmin Xu
Inf. Sci.3
2020 A practical and communication-efficient deniable authentication with source-hiding and its application on Wi-Fi privacy
Shengke Zeng, Yi Mu 0001, Mingxing He
Inf. Sci.2
2020 HUCDO: A Hybrid User-centric Data Outsourcing Scheme
abstract
Outsourcing helps relocate data from the cyber-physical system (CPS) for efficient storage at low cost. Current server-based outsourcing mainly focuses on the benefits of servers. This cannot attract users well, as their security, efficiency, and economy are not guaranteed. To solve with this issue, a hybrid outsourcing model that exploits both cloud server and edge devices to store data is needed. Meanwhile, the requirements of security and efficiency are different under specific scenarios. There is a lack of a comprehensive solution that considers all of the above issues. In this work, we overcome the above issues by proposing the first hybrid user-centric data outsourcing (HUCDO) scheme. It allows users to outsource data securely, efficiently, and economically via different CPSs. Brielly, our contributions consist of theories, implementations, and evaluations. Our theories include the first homomorphic collision-resistant chameleon hash (HCCH) and homomorphic designated-receiver signcryption (HDRS). As implementations, we instantiate how to use our proposals to outsource small- or large-scale data through distinct CPS, respectively. Additionally, a blockchain with proof-of-discrete-logarithm (B-PoDL) is instantiated to help improve our performance. Last, as demonstrated by our evaluations, our proposals are secure, efficient, and economic for users to implement while outsourcing their data via CPSs.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Guangquan Xu, Hao Wang 0003, James Xi Zheng, Guomin Yang, Qi Xia 0001, Xiaojiang Du
ACM Trans. Cyber Phys. Syst.4
2020 A code-based signature scheme from the Lyubashevsky framework
Yongcheng Song, Xinyi Huang 0001, Yi Mu 0001, Wei Wu 0001, Huaxiong Wang
Theor. Comput. Sci.3
2020 Revocable identity-based encryption with server-aided ciphertext evolution
Yinxia Sun, Yi Mu 0001, Willy Susilo, Futai Zhang, Anmin Fu
Theor. Comput. Sci.2
2020 Novel updatable identity-based hash proof system and its applications
Yanwei Zhou, Bo Yang 0003, Tao Wang 0039, Yi Mu 0001
Theor. Comput. Sci.4
2020 Identity-based encryption with leakage-amplified chosen-ciphertext attacks security
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang, Yi Mu 0001
Theor. Comput. Sci.5
2020 Multi-User Verifiable Searchable Symmetric Encryption for Cloud Storage
abstract
In a cloud data storage system, symmetric key encryption is usually used to encrypt files due to its high efficiency. In order allow the untrusted/semi-trusted cloud storage server to perform searching over encrypted data while maintaining data confidentiality, searchable symmetric encryption (SSE) has been proposed. In a typical SSE scheme, a users stores encrypted files on a cloud storage server and later can retrieve the encrypted files containing specific keywords. The basic security requirement of SSE is that the cloud server learns no information about the files or the keywords during the searching process. Some SSE schemes also offer additional functionalities such as detecting cheating behavior of a malicious server (i.e., verifiability) and allowing update (e.g., modifying, deleting and adding) of documents on the server. However, the previous (verifiable) SSE schemes were designed for single users, which means the searching can only be done by the data owner, whereas in reality people often use cloud storage to share files with other users. In this paper we present a multi-user verifiable searchable symmetric encryption (MVSSE) scheme that achieves all the desirable features of a verifiable SSE and allows multiple users to perform searching. We then define an ideal functionality for MVSSE under the Universally Composable (UC-) security framework and prove that our ideal functionality implies the security requirements of a secure MVSSE, and our multi-user verifiable SSE scheme is UC-secure. We also implement our scheme to verify its high performance based on some real dataset.
Xueqiao Liu, Guomin Yang, Yi Mu 0001, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.3
2020 Achieving Intelligent Trust-Layer for Internet-of-Things via Self-Redactable Blockchain
abstract
The advances of artificial intelligence (AI) propels big data processing and transmission for Internet of Things (IoT), by capturing and structuring big data produced by heterogeneous devices. While applying blockchain to manage IoT devices and associated big data, the blockchain itself suffers from abuse of decentralization from anonymous users. Specifically, it has been utilized to facilitate black market trades and illegal activities. Ateniese et al. proposed using the chameleon hash (CH) to derive redactable blockchain (EuroS&P), which works by embedding a trapdoor in the basic hash function so that block content can be rewritten without causing major hard forks. In short, the redacted block hash remains unchanged. However, there is lacking intelligent design where any mistakes observed in the chain can be corrected universally and automatically. This creates disincentives to use redactable blockchain (RB) for managing big data or any data-driven business mainly due to ineffective chain redaction. To solve this problem, in this article, we propose the notion of the self-redactable blockchain (SRB) to support intelligent execution of chain redaction. Specifically, we propose the first revocable chameleon hash (RCH) to power RB. It enables an ephemeral trapdoor for finding collision without any co-operation. Periodical expiration is applied to committed hash and an ephemeral trapdoor to prevent any abuses of redaction power. We instantiate how to use our RCH to build SRB as an intelligent trust-layer for IoT. We also give a rigorous analysis as well as comprehensive experiments to validate our proposals. The evidence showed that our proposal is secure and acceptably efficient for IoT devices.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du, Nadra Guizani
IEEE Trans. Ind. Informatics3
2020 Policy-Driven Blockchain and Its Applications for Transport Systems
abstract
Blockchains offer opportunities for developing advanced digital services. While current research on this topic is still growing, various security concerns have been raised and the security of blockchains has been becoming the most important issue which must be well addressed. Blockchain transactions are based on digital signatures, where the public key is associated with the ownership of the digital coin. User management of public or permissionless blockchain is ad hoc, i.e., any user can join and leave the blockchain network and participate in the Proof of Work (PoW). However, in a private blockchain and a permissioned blockchain, there are usually some constraints for users. In this paper, we investigate a scenario which provides a blockchain network with a set of policies where every user's signing key is associated with a policy set. It is particularly interesting while users are working in different sectors. We call our scheme as “policy-driven”, since policies in our scheme restrict users' rights. Our system is featured with a novel and lightweight policy-driven signature (PDS) scheme whose security has been proven formally. To justify our scenario, we provide experimental results and an example for the railway management services.
Yi Mu 0001, Fatemeh Rezaeibagha, Ke Huang 0002
IEEE Trans. Serv. Comput.1
2019 Provably Secure Group Authentication in the Asynchronous Communication Model
Zhe Xia, Lein Harn, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001, Willy Susilo, Weizhi Meng 0001
ICICS5
2019 Provably Secure Proactive Secret Sharing Without the Adjacent Assumption
Zhe Xia, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang, Hua Shen 0002, Yi Mu 0001
ProvSec6
2019 Efficient Micropayment of Cryptocurrency from Blockchains
abstract
Cryptocurrencies based on blockchain infrastructures have shown their advantages such as double-spending resistance and decentralization. Each transaction of cryptocurrency requires a certain amount of computation and attracts transaction fees. Often, in practice, many transactions are small; therefore, they add computation and transmission overheads to the system. In this paper, we introduce a cost-saving approach, which significantly reduces transaction time and storage for small amount of payment, i.e. micropayment. In our approach, with the notion of ‘transaction commitment’, the computation of each transaction is much more efficient. Therefore, our approach has advantages in comparison of other cryptocurrency systems such as the bitcoin system. Our approach can be applied to other existing cryptocurrency systems.
Fatemeh Rezaeibagha, Yi Mu 0001
Comput. J.2
2019 Strongly leakage resilient authenticated key exchange, revisited
Guomin Yang, Rongmao Chen, Yi Mu 0001, Willy Susilo, Fuchun Guo, Jie Li 0041
Des. Codes Cryptogr.3
2019 Continuous leakage-resilient identity-based encryption with leakage amplification
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001
Des. Codes Cryptogr.3
2019 A secure IoT cloud storage system with fine-grained access control and decryption key exposure resistance
Shengmin Xu, Guomin Yang, Yi Mu 0001, Ximeng Liu
Future Gener. Comput. Syst.3
2019 Identity-based encryption resilient to continuous key leakage
abstract
Leakage of private information has become a threat to the security of computing systems. It has become a common security requirement that a cryptography scheme should withstand various leakage attacks, even the continuous leakage attacks. However, in the current constructions on the (continuous) leakage‐resilient identity‐based encryption (CLR‐IBE) scheme, the leakage parameter is a fixed value. Aiming to solve these problems, in this study, the authors show how to construct the CLR‐IBE scheme, and the adaptive chosen‐ciphertext attacks security of proposed construction can be proved in the standard model. To further improve the practicability of CLR‐IBE scheme, they design an improved IBE scheme with continuous leakage amplified property, and the leakage parameter has an arbitrary length.
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001, Tao Wang 0039, Xin Wang 0058
IET Inf. Secur.3
2019 Identity-based revocation system: Enhanced security model and scalable bounded IBRS construction with short parameters
Peng Jiang 0007, Jianchang Lai, Fuchun Guo, Willy Susilo, Man Ho Au, Guomin Yang, Yi Mu 0001, Rongmao Chen
Inf. Sci.7
2019 Revocable attribute-based encryption with decryption key exposure resistance and ciphertext delegation
Shengmin Xu, Guomin Yang, Yi Mu 0001
Inf. Sci.3
2019 DABKE: Secure deniable attribute-based key exchange framework
abstract
We introduce the first deniable attribute-based key exchange (DABKE) framework that is resilient to impersonation attacks. We define the formal security models for DABKE framework, and propose a generic compiler that converts any attribute-based key exchanges into deniable ones. We prove that it can achieve session key security and user privacy in the standard model, and strong deniability in the simulation-based paradigm. In particular, the proposed generic compiler ensures: 1) a dishonest user cannot impersonate other user’s session participation in conversations since implicit authentication is used among authorized users; 2) an authorized user can plausibly deny his/her participation after secure conversations with others; 3) the strongest form of deniability is achieved using one-round communication between two authorized users.
Yangguang Tian, Yingjiu Li, Guomin Yang, Willy Susilo, Yi Mu 0001, Hui Cui 0001, Yinghui Zhang 0002
J. Comput. Secur.5
2019 Efficient identity-based broadcast encryption with keyword search against insider attacks for database systems
Peng Jiang 0007, Fuchun Guo, Yi Mu 0001
Theor. Comput. Sci.3
2019 The generic construction of continuous leakage-resilient identity-based cryptosystems
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001
Theor. Comput. Sci.3
2019 Building Redactable Consortium Blockchain for Industrial Internet-of-Things
abstract
Applying consortium blockchain as a trust layer for heterogeneous industrial Internet-of-Things devices is cost-effective. However, with an increase in computing power, some powerful attacks (e.g., the 51% attack) are inevitable and will cause severe consequences. Recent studies also confirm that anonymity and immutability of blockchain have been abused to facilitate black market trades, etc. To operate controllable blockchain for IIoT devices, it is necessary to rewrite blockchain history back to a normal state once the chain is breached. Ateniese et al. proposed redactable blockchain by using chameleon hash (CH) to replace traditional hash function, it allows blockchain history to be written when needed (EuroS&P 2017). However, we cannot apply this idea directly to IIoT without solving the following problems: (1) achieve a decentralized design of CH; (2) update the signatures accordingly to authenticate the redacted contents; (3) satisfy the low-computing need of the individual IIoT device. In this paper, we overcome the above issues by proposing the first threshold chameleon hash (TCH) and accountable-and-sanitizable chameleon signature (ASCS) schemes. Based on them, we build a redactable consortium blockchain which is efficient for IIoT devices to operate. It allows a group of authorized sensors to write and rewrite blockchain without causing any hard forks. Basically, TCH is the first TCH and ASCS is a public-key signature supporting file-level and block-level modifications of signatures without impairing authentications. Additionally, ASCS achieves accountability to avoid abuse of redaction. While security analysis validates our proposals, the simulation results show that redaction is acceptably efficient if it is executed at a small scale or if we adopt a coarse-grained redaction while sacrificing some securities.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Guomin Yang, Xiaojiang Du, Fatemeh Rezaeibagha, Qi Xia 0001, Mohsen Guizani
IEEE Trans. Ind. Informatics3
2018 Efficient Traceable Oblivious Transfer and Its Applications
Weiwei Liu 0005, Yinghui Zhang 0002, Yi Mu 0001, Guomin Yang, Yangguang Tian
ISPEC3
2018 An Efficient and Provably Secure Private Polynomial Evaluation Scheme
Zhe Xia, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001
ISPEC4
2018 Efficient Attribute-Based Encryption with Blackbox Traceability
Shengmin Xu, Guomin Yang, Yi Mu 0001, Ximeng Liu
ProvSec3
2018 Continuous leakage-resilient access control for wireless sensor networks
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001, Zhe Xia
Ad Hoc Networks3
2018 Identity-Based Broadcast Encryption for Inner Products
abstract
In the identity-based broadcast encryption (IBBE), only these users whose identities are chosen in the ciphertext computing can decrypt the encrypted message. In this paper, we introduce an extension of IBBE, namely Identity-Based Broadcast Encryption for Inner Product (IBBE-IP), where message encryption is replaced by inner product encryption (IPE) introduced by Abdalla et al. (PKC 2015). Precisely, in the IBBE-IP, the private key is associated with a pair of an identity and a vector (ID,y→)⁠. The user with private key of (ID,y→) can decrypt the encrypted vector x→ for an identity set S selected by the encryptor and learn the inner product 〈x→,y→〉 if and only if ID∈S⁠. Differing from the IBBE, the decryption in the IBBE-IP yields the inner product associated with the encrypted vector without leaking any information of the vector. The encrypted vector is protected as long as the number of selected identities is less than their length. We present a construction of IBBE-IP with constant-size private keys and it supports unbounded private key queries, which was unachieved in the previous works of IPE in the public-key setting. The security of our proposed scheme is proved in the random oracle model.
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Peng Jiang 0007, Sha Ma
Comput. J.2
2018 Continuous Leakage-Resilient Identity-Based Encryption without Random Oracles
abstract
Provably secure identity-based encryption (IBE) schemes in the presence of key-leakage have attracted a lot of attention recently. However, most of them were designed in the bounded-leakage model, and might not be able to meet the claimed security under the continuous-leakage attacks. The main issue is that the most of previous leakage-resilient IBE schemes could not ensure the randomness of all elements in the ciphertext, because some elements can be written as a function on the private key of user; therefore, the adversary can obtain the leakage on the private key of user from the corresponding given ciphertext. In this paper, a new construction of CCA-secure IBE scheme tolerating continuous-leakage attacks in the standard model is proposed, and its security is proved in the selective-ID security model based on the hardness of decisional bilinear Diffie–Hellman assumption, which is a classical static assumption. In our construction, the adversary cannot obtain any leakage on the private key from the corresponding ciphertext, since all elements in the ciphertext are random in the adversary’s view. The striking advantage of our constructions is the key leakage ratio, which is the best one among the previous leakage-resilient IBE constructions.
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001
Comput. J.3
2018 Ciphertext-policy attribute-based encryption against key-delegation abuse in fog computing
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo
Future Gener. Comput. Syst.3
2018 CCN framework with privacy support
abstract
Content‐centric networking (CCN) used the name of an Interest to seek the target content, where the name was a plaintext and unprotected. Apart from the name, the content in one Data is also unprotected. If an unauthorised node intercepted an Interest , it could infer what kind of content is requested. If the node intercepted a response Data , it could illegally acquire the content. This study focused on the privacy issues of CCN and proposed a CCN framework with privacy support. In this framework, the concept of a privacy name was proposed and accordingly the forwarding information base (FIB) and pending Interest table (PIT) establishment algorithms based on privacy names were proposed. On the basis of the proposed FIB and PIT, the content communication algorithm based on privacy names was presented. In this algorithm, one authorised consumer could use a privacy name to seek, retrieve and share the ciphertext of the content, so the privacy was achieved. Finally, the privacy of this framework was analysed and the performance was evaluated to justify its advantages.
Xiaonan Wang 0001, Zhengxiong Dou, Yi Mu 0001
IET Inf. Secur.3
2018 Privacy-enhanced attribute-based private information retrieval
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Peng Jiang 0007, Willy Susilo
Inf. Sci.2
2018 A Generic Scheme of plaintext-checkable database encryption
Sha Ma, Yi Mu 0001, Willy Susilo
Inf. Sci.2
2018 Witness-based searchable encryption
Sha Ma, Yi Mu 0001, Willy Susilo, Bo Yang 0003
Inf. Sci.2
2018 Multirate DelPHI to secure multirate ad hoc networks against wormhole attacks
Shams Qazi, Raad Raad, Yi Mu 0001, Willy Susilo
J. Inf. Secur. Appl.3
2018 Practical and secure telemedicine systems for user mobility
Fatemeh Rezaeibagha, Yi Mu 0001
J. Biomed. Informatics2
2018 A New Revocable and Re-Delegable Proxy Signature and Its Application
Shengmin Xu, Guomin Yang, Yi Mu 0001
J. Comput. Sci. Technol.3
2018 Man-in-the-middle attacks on Secure Simple Pairing in Bluetooth standard V5.0 and its countermeasure
Da-Zhi Sun, Yi Mu 0001, Willy Susilo
Pers. Ubiquitous Comput.2
2018 Correction to: Man-in-the-middle attacks on Secure Simple Pairing in Bluetooth standard V5.0 and its countermeasure
Da-Zhi Sun, Yi Mu 0001, Willy Susilo
Pers. Ubiquitous Comput.2
2018 Efficient k-out-of-n oblivious transfer scheme with the ideal communication cost
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Rongmao Chen, Sha Ma
Theor. Comput. Sci.2
2018 Policy controlled system with anonymity
Pairat Thorncharoensri, Willy Susilo, Yi Mu 0001
Theor. Comput. Sci.3
2018 Secure Fine-Grained Access Control and Data Sharing for Dynamic Groups in the Cloud
abstract
Cloud computing is an emerging computing paradigm that enables users to store their data in a cloud server to enjoy scalable and on-demand services. Nevertheless, it also brings many security issues, since cloud service providers (CSPs) are not in the same trusted domain as users. To protect data privacy against untrusted CSPs, existing solutions apply cryptographic methods (e.g., encryption mechanisms) and provide decryption keys only to authorized users. However, sharing cloud data among authorized users at a fine-grained level is still a challenging issue, especially when dealing with dynamic user groups. In this paper, we propose a secure and efficient fine-grained access control and data sharing scheme for dynamic user groups by: 1) defining and enforcing access policies based on the attributes of the data; 2) permitting the key generation center to efficiently update user credentials for dynamic user groups; and 3) allowing some expensive computation tasks to be performed by untrusted CSPs without requiring any delegation key. Specifically, we first design an efficient revocable attribute-based encryption (ABE) scheme with the property of ciphertext delegation by exploiting and uniquely combining techniques of identity-based encryption, ABE, subset-cover framework, and ciphertext encoding mechanism. We then present a fine-grained access control and data sharing system for on-demand services with dynamic user groups in the cloud. The experimental data show that our proposed scheme is more efficient and scalable than the state-of-the-art solution.
Shengmin Xu, Guomin Yang, Yi Mu 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.3
2018 Strong Identity-Based Proxy Signature Schemes, Revisited
abstract
Proxy signature is a useful cryptographic primitive that has been widely used in many applications. It has attracted a lot of attention since it was introduced. There have been lots of works in constructing efficient and secure proxy signature schemes. In this paper, we identify a new attack that has been neglected by many existing proven secure proxy signature schemes. We demonstrate this attack by launching it against an identity‐based proxy signature scheme which is proven secure. We then propose one method that can effectively prevent this attack. The weakness in some other proxy signature schemes can also be fixed by applying the same method.
Weiwei Liu 0005, Yi Mu 0001, Guomin Yang, Yangguang Tian
Wirel. Commun. Mob. Comput.2
2017 Privacy-Preserving k-time Authenticated Secret Handshakes
Yangguang Tian, Shiwei Zhang 0003, Guomin Yang, Yi Mu 0001, Yong Yu 0002
ACISP (2)4
2017 ID-Based Encryption with Equality Test Against Insider Attack
Tong Wu 0011, Sha Ma, Yi Mu 0001, Shengke Zeng
ACISP (1)3
2017 Mergeable and Revocable Identity-Based Encryption
Shengmin Xu, Guomin Yang, Yi Mu 0001, Willy Susilo
ACISP (1)3
2017 Hierarchical Functional Encryption for Linear Transformations
Shiwei Zhang 0003, Yi Mu 0001, Guomin Yang
ACISP (1)2
2017 Optimal Security Reductions for Unique Signatures: Bypassing Impossibilities with a Counterexample
Fuchun Guo, Rongmao Chen, Willy Susilo, Jianchang Lai, Guomin Yang, Yi Mu 0001
CRYPTO (2)6
2017 Fuzzy Extractors for Biometric Identification
abstract
Fuzzy extractor provides key generation from biometrics and other noisy data. The generated key is seamlessly usable for any cryptographic applications because its information entropy is sufficient for security. Biometric authentication offers natural and passwordless user authentication in various systems where fuzzy extractors can be used for biometric information security. Typically, a biometric system operates in two modes: verification and identification. However, existing fuzzy extractors does not support efficient user identification. In this paper, we propose a succinct fuzzy extractor scheme which enables efficient biometric identification as well as verification that it satisfies the security requirements. We show that the proposed scheme can be easily used in both verification and identification modes. To the best of our knowledge, we propose the first fuzzy extractor based biometric identification protocol. The proposed protocol is able to identify a user with constant computational cost rather than linear-time computation required by other fuzzy extractor schemes. We also provide security analysis of proposed schemes to show their security levels. The implementation shows that the performance of proposed identification protocol is constant and it is close to that of verification protocols.
Nan Li 0007, Fuchun Guo, Yi Mu 0001, Willy Susilo, Surya Nepal
ICDCS3
2017 Group-Based Source-Destination Verifiable Encryption with Blacklist Checking
Zhongyuan Yao, Yi Mu 0001, Guomin Yang
ISPEC2
2017 Provably Secure Homomorphic Signcryption
Fatemeh Rezaeibagha, Yi Mu 0001, Shiwei Zhang 0003
ProvSec2
2017 Deniable Ring Authentication Based on Projective Hash Functions
Shengke Zeng, Yi Mu 0001, Guomin Yang, Mingxing He
ProvSec2
2017 Fully Privacy-Preserving ID-Based Broadcast Encryption with Authorization
abstract
A revocable ID-based broadcast encryption scheme allows an authorized third party to revoke any receiver (decryptor) from the initial receiver set S of the original broadcast ciphertext without the need of decryption. However, the existing revocable ID-based broadcast encryption schemes in the literature cannot fully preserve the receiver privacy and have a large size of ciphertext when the revoked user sets are large. To solve these problems, in this paper, we propose a novel scheme: fully privacy-preserving ID-based broadcast encryption with authorization. Our scheme allows an authorized party to dynamically handle the decryption rights of receivers via an authorized user set L without knowing the message and the identities of the initial receivers. Only those users who are both in S and L can decrypt the ciphertext successfully. The final ciphertext reveals nothing about the identity information of receivers and the authorized users. Our scheme achieves full collusion resistance and is applicable to anonymous data sharing where the receivers are decided by the authorized third party (or multiple authorized third parties) excluding the data owner. We show that our proposed scheme is provably secure under the defined security models in the random oracle model.
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Rongmao Chen
Comput. J.2
2017 Novel Leakage-Resilient Attribute-Based Encryption from Hash Proof System
abstract
As an important primitive, attribute-based encryption (ABE) has attracted much attention in the relative-leakage model. However, the leakage rate in almost all of the existing ABE schemes is restricted with a leakage parameter. It implicitly suggests that higher leakage rate results in larger ciphertexts and keys. Aiming at tackling the challenge, novel leakage-resilient ciphertext-policy attribute-based encryption (CP-ABE) and key-policy attribute-based encryption (KP-ABE) are designed in this paper. It achieves shorter secret key size and simultaneously does not suffer from the undesirable drawback above. To realize this, the concepts of CP-AB-HPS and KP-AB-HPS are introduced, which generalize the notion of hash proof system (HPS) to attribute-based setting. Under some static assumptions, the proposed schemes are proved adaptively secure in the standard model. In addition, the results in simulation experiments indicate that the proposed scheme is efficient and practical.
Leyou Zhang, Jingxia Zhang, Yi Mu 0001
Comput. J.3
2017 Secure-channel free keyword search with authorization in manager-centric databases
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen
Comput. Secur.2
2017 Privacy-preserving data search and sharing protocol for social networks through wireless applications
abstract
Summary Data search and sharing are two important functionalities in social networks. The social network users can form a peer‐to‐peer group and securely and flexibly search and share cloud data through wireless applications. When the number of users increases, the communication, storage, and computational overheads will be increased, and the quality of services such as searching and data sharing for clients could be affected. In order to solve these problems, we formalize an ID‐based multi‐user searchable encryption (IDB‐MUSE) and formally define its security model, where the security notions accommodate indistinguishability against insider's keyword guessing attack, indistinguishability against chosen keyword attack, and indistinguishability against insider's identity guessing attack. We present an IDB‐MUSE scheme, where the index and search trapdoor are of constant size. We formally prove its security properties. To improve the search efficiency, we divide the computation of the trapdoor into two phases, that is, the offline phase and the online phase. The computation cost for the online phase trapdoor remains constant with respect to the number of users. Based on the IDB‐MUSE scheme, a privacy‐preserving data search and sharing protocol is proposed, where only the authorized user can access the shared group data. It captures the properties of source authenticity, data and search pattern privacy‐preserving, anonymity, and request unlinkability. The experimental results show that the protocol is practical for wireless applications. Copyright © 2016 John Wiley & Sons, Ltd.
Yi Mu 0001, Rongmao Chen
Concurr. Comput. Pract. Exp.2
2017 Strong authenticated key exchange with auxiliary inputs
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo
Des. Codes Cryptogr.2
2017 A note on the strong authenticated key exchange with auxiliary inputs
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo, Zheng Yang 0001
Des. Codes Cryptogr.2
2017 Communication security and privacy support in 6LoWPAN
Xiaonan Wang 0001, Yi Mu 0001
J. Inf. Secur. Appl.2
2017 Private Keyword-Search for Database Systems Against Insider Attacks
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen
J. Comput. Sci. Technol.2
2017 Fully privacy-preserving and revocable ID-based broadcast encryption for data access control in smart city
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Willy Susilo, Rongmao Chen
Pers. Ubiquitous Comput.2
2017 A Generic Table Recomputation-Based Higher-Order Masking
abstract
Masking is a class of well-known countermeasure against side-channel attacks by employing the idea of secret sharing. In this paper, we propose a generic table recomputation-based masking scheme at any chosen order t, named divided S-box masking (DSM), and its security has been proved under the security framework from Crypto 2003. The table recomputation-based masking is suitable for software implementation and the masked table can be stored in memory, where it can be accessed fast. For any input, DSM scheme generates n output shares by two queries. DSM scheme requires two vectors L and R, and a matrix M of random numbers. Each element of L is the XOR result of the output of S-box and n - 1 random numbers. These n - 1 random numbers are stored in two lines of M and R which is a vector of indexes for the second query. Furthermore, we performed the attacks on the software implementation of DSM to evaluate its practical security, and compared the timing and space complexity with the existing table recomputation-based masking in the same platform to verify the advantage of the DSM.
Ming Tang 0002, Zhenlong Qiu, Zhipeng Guo 0002, Yi Mu 0001, Xinyi Huang 0001, Jean-Luc Danger
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2017 Optimized Identity-Based Encryption from Bilinear Pairing for Lightweight Devices
abstract
Lightweight devices such as smart cards and RFID tags have a very limited hardware resource, which could be too weak to cope with asymmetric-key cryptography. It would be desirable if the cryptographic algorithm could be optimized in order to better use hardware resources. In this paper, we demonstrate how identity-based encryption algorithms from bilinear pairing can be optimized so that hardware resources can be saved. We notice that the identity-based encryption algorithms from bilinear pairing in the literature must perform both elliptic curve group operations and multiplicative group operations, which consume a lot of hardware resources. We manage to eliminate the need of multiplicative group operations for encryption. This is a significant discovery since the hardware structure can be simplified for implementing pairing-based cryptography. Our experimental results show that our encryption algorithm saves up to 47 percent memory (27,239 RAM bits) in FPGA implementation.
Fuchun Guo, Yi Mu 0001, Willy Susilo, Homer Hsing, Duncan S. Wong, Vijay Varadharajan
IEEE Trans. Dependable Secur. Comput.2
2017 EACSIP: Extendable Access Control System With Integrity Protection for Enhancing Collaboration in the Cloud
abstract
It is widely acknowledged that the collaborations with more users increase productivity. Secure cloud storage is a promising tool to enhance such a collaboration. Access control system can be enabled with attribute-based encryption. In this system, a user encrypts and uploads his/her data to the cloud with an access policy, such that only people who satisfy that access policy can decrypt the data. When a recipient would like to enable another person who is originally unauthorized by the original access policy, this recipient will need to extend the access policy by adding a new policy that includes the new person hence, the notion of extendable access control system. Admitting new users to access the uploaded data is an important requirement in enhancing collaborations. The main issue is with regards to the integrity protection during the process of extending the access policy. When a new access policy is added, the cloud has to be sure that the extended access policy remains guarding the same encrypted data as the original access policy, even though the cloud cannot decrypt this ciphertext, which is a challenging problem to solve. In this paper, we answer the above problem affirmatively by introducing an extendable access control system with Integrity Protection (EACSIP), which is suitable to enhance collaboration in the cloud. The construction of EACSIP is built on top of a novel cryptographic primitive, namely functional key encapsulation with equality testing. The security proof and the performance evaluation of EACSIP are provided in this paper.
Willy Susilo, Peng Jiang 0007, Fuchun Guo, Guomin Yang, Yong Yu 0002, Yi Mu 0001
IEEE Trans. Inf. Forensics Secur.6
2017 Efficient Public Verification of Data Integrity for Cloud Storage Systems from Indistinguishability Obfuscation
abstract
Cloud storage services allow users to outsource their data to cloud servers to save local data storage costs. However, unlike using local storage devices, users do not physically manage the data stored on cloud servers; therefore, the data integrity of the outsourced data has become an issue. Many public verification schemes have been proposed to enable a third-party auditor to verify the data integrity for users. These schemes make an impractical assumption-the auditors have enough computation capability to bear expensive verification costs. In this paper, we propose a novel public verification scheme for the cloud storage using indistinguishability obfuscation, which requires a lightweight computation on the auditor and the delegate most computation to the cloud. We further extend our scheme to support batch verification and data dynamic operations, where multiple verification tasks from different users can be performed efficiently by the auditor and the cloud-stored data can be updated dynamically. Compared with other existing works, our scheme significantly reduces the auditor's computation overhead. Moreover, the batch verification overhead on the auditor side in our scheme is independent of the number of verification tasks. Our scheme could be practical in a scenario, where the data integrity verifications are executed frequently, and the number of verification tasks (i.e., the number of users) is numerous; even if the auditor is equipped with a low-power device, it can verify the data integrity efficiently. We prove the security of our scheme under the strongest security model proposed by Shi et al. (ACM CCS 2013). Finally, we conduct a performance analysis to demonstrate that our scheme is more efficient than other existing works in terms of the auditor's communication and computation efficiency.
Yuan Zhang 0006, Chunxiang Xu, Xiaohui Liang 0002, Hongwei Li 0001, Yi Mu 0001
IEEE Trans. Inf. Forensics Secur.5
2017 Computation-efficient key establishment in wireless group communications
Ching-Fang Hsu 0001, Lein Harn, Yi Mu 0001, Maoyuan Zhang
Wirel. Networks3
2016 One-Round Strong Oblivious Signature-Based Envelope
Rongmao Chen, Yi Mu 0001, Willy Susilo, Guomin Yang, Fuchun Guo, Mingwu Zhang
ACISP (2)2
2016 Public Key Encryption with Authorized Keyword Search
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen
ACISP (2)2
2016 Ciphertext-Policy Attribute-Based Encryption with Key-Delegation Abuse Resistance
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo
ACISP (1)3
2016 Anonymous Identity-Based Broadcast Encryption with Revocation for File Sharing
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Willy Susilo, Rongmao Chen
ACISP (2)2
2016 Content-Based Encryption
Yi Mu 0001
ACISP (2)2
2016 Proxy Signature with Revocation
Shengmin Xu, Guomin Yang, Yi Mu 0001, Sha Ma
ACISP (2)3
2016 Linear Encryption with Keyword Search
Shiwei Zhang 0003, Guomin Yang, Yi Mu 0001
ACISP (2)3
2016 Cryptographic Reverse Firewall via Malleable Smooth Projective Hash Functions
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo, Mingwu Zhang
ASIACRYPT (1)2
2016 Iterated Random Oracle: A Universal Approach for Finding Loss in Security Reduction
Fuchun Guo, Willy Susilo, Yi Mu 0001, Rongmao Chen, Jianchang Lai, Guomin Yang
ASIACRYPT (2)3
2016 Recipient Revocable Identity-Based Broadcast Encryption: How to Revoke Some Recipients in IBBE without Knowledge of the Plaintext
abstract
In this paper, we present the notion of recipient-revocable identity-based broadcast encryption scheme. In this notion, a content provider will produce encrypted content and send them to a third party (which is a broadcaster). This third party will be able to revoke some identities from the ciphertext. We present a security model to capture these requirements, as well as a concrete construction. The ciphertext consists of k+3 group elements, assuming that the maximum number of revocation identities is k. That is, the ciphertext size is linear in the maximal size of R, where R is the revocation identity set. However, we say that the additional elements compared to that from an IBBE scheme are only for the revocation but not for decryption. Therefore, the ciphertext sent to the users for decryption will be of constant size (i.e.,3 group elements). Finally, we present the proof of security of our construction.
Willy Susilo, Rongmao Chen, Fuchun Guo, Guomin Yang, Yi Mu 0001, Yang-Wai Chow
AsiaCCS5
2016 Bilateral-secure Signature by Key Evolving
abstract
In practice, the greatest threat against the security of a digital signature scheme is the exposure of signing key, since the forward security of past signatures and the backward security of future signatures could be compromised. There are some attempts in the literature, addressing forward-secure signature for preventing forgeries of signatures in the past time; however, few studies addressed the backward-security of signatures, which prevents forgeries in the future time. In this paper, we introduce the concept of key-evolving signature with bilateral security, i.e., both forward security and backward security. We first define the bilateral security formally for preventing the adversaries from forging a valid signature of the past and the future time periods in the case of key exposure. We then provide a novel construction based on hub-and-spoke updating structure and the random oracle model, and show that the construction achieves bilateral security and unbounded number of time periods. Finally, we compare our scheme with the existing work by rigorous analysis and experimental evaluation, and demonstrate that our construction is more secure and efficient for practical applications.
Tao Xiang 0001, Xiaoguo Li, Fei Chen 0003, Yi Mu 0001
AsiaCCS4
2016 Achieving IND-CCA Security for Functional Encryption for Inner Products
Shiwei Zhang 0003, Yi Mu 0001, Guomin Yang
Inscrypt2
2016 Strongly Leakage-Resilient Authenticated Key Exchange
Rongmao Chen, Yi Mu 0001, Guomin Yang, Willy Susilo, Fuchun Guo
CT-RSA2
2016 Preserving User Location Privacy for Location-Based Service
Yi Mu 0001
GPC2
2016 Privacy-Preserving Cloud Auditing with Multiple Uploaders
Ge Wu 0001, Yi Mu 0001, Willy Susilo, Fuchun Guo
ISPEC2
2016 A Privacy Preserving Source Verifiable Encryption Scheme
Zhongyuan Yao, Yi Mu 0001, Guomin Yang
ISPEC2
2016 Ciphertext-Policy Attribute Based Encryption Supporting Access Policy Update
Yinhao Jiang, Willy Susilo, Yi Mu 0001, Fuchun Guo
ProvSec3
2016 Updatable Lossy Trapdoor Functions and Its Application in Continuous Leakage
Sujuan Li, Yi Mu 0001, Mingwu Zhang, Futai Zhang
ProvSec2
2016 One-Round Attribute-Based Key Exchange in the Multi-party Setting
Yangguang Tian, Guomin Yang, Yi Mu 0001, Kaitai Liang, Yong Yu 0002
ProvSec3
2016 Online/Offline Ciphertext Retrieval on Resource Constrained Devices
abstract
The ciphertext retrieval is of paramount importance for data confidentiality and utilization in mobile cloud environment. The receiver, usually equipped with resource constrained devices, retrieves data stored in the cloud server by submitting a confidential request (or trapdoor) to the cloud. Previous schemes need at least one exponentiation operation in group |$\mathbb {G}$| for each keyword to generate the trapdoor, which is quite burdensome for mobile devices to support such computational cost. The computational cost of trapdoor generation limits the application of ciphertext retrieval, especially in a wireless environment. In this paper, we propose the first online/offline ciphertext retrieval (OOCR) scheme, where the trapdoor generation is split into two phases: offline phase and online phase . Most of the computation of the trapdoor could be performed in the offline phase prior to knowing the keyword. The generation of the real trapdoor with keyword can be done efficiently in the online phase. The most challenging task is to resist the so-called insider attacks, which is about keyword guessing attacks from the untrusted cloud server. We also build a novel framework to resist insider attacks and propose an OOCR scheme against insider attacks. Our semantic security proof and performance analysis demonstrate that the proposal is practical for mobile cloud applications.
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Qiaoyan Wen
Comput. J.2
2016 Anonymous Proxy Signature with Hierarchical Traceability
abstract
Anonymous proxy signatures are very useful in the construction of anonymous credential systems such as anonymous voting and anonymous authentication protocols. As a basic requirement, we should ensure an honest proxy signer is anonymous. However, in order to prevent the proxy signer from abusing the signing right, we should also allow dishonest signers to be traced. In this paper, we present three novel anonymous proxy signature schemes with different levels of (namely, public, internal and original signer) traceability. We define the formal definitions and security models for these three different settings, and prove the security of our proposed schemes under some standard assumptions.
Jiannan Wei, Guomin Yang, Yi Mu 0001, Kaitai Liang
Comput. J.3
2016 Token-Leakage Tolerant and Vector Obfuscated IPE and Application in Privacy-Preserving Two-Party Point/Polynomial Evaluations
abstract
In mobile environments, data stored in nodes are subject to side-channel attacks such as power analysis, emitted signal, detected radiation, etc. In this work, we propose a leakage-resilient inner-product encryption that the decryption will succeed if and only if the decryption attribute vector (generate the token) meets the orthogonal encryption attribute vector (obfuscated encryption policy), that is, the match holds that the inner product of two vectors is zero. Propose scheme supports the security of attribute-hiding and leakage-resilient in the standard model. The adversary cannot only issue any token reveal query on non-match vector, but also can request at most |$\ell $|-bit information on the token-leakage query even if the queried vector matches the challenge vector. We prove the security by the technique of dual system encryption in the orthogonal subgroups, to be strongly leakage-resilient and adaptively attribute-hiding. We also deploy our scheme as a building block to devise a secure two-party point/polynomial evaluation protocol in mobility environments, in which two parties cooperate to evaluate a polynomial in the sense that their sensitive inputs of both point and polynomial are fully preserved. Finally, we assess the performance of leakage resilience including the leakage bound and the leakage fraction (LF). Analysis shows that the leakage bound is approximate |$(n-1)\log {\pi _2}$| and the LF is about |${1}/{2(1+\omega _1+\omega _3)}$|⁠, where |$n$| is the length of vector, |$\pi _2$| is the order of subgroup |$\mathbb {G}_{\pi _2}$| and |$\omega _1,\omega _3$| are the constants. We can obtain optimized LF |$1/2-o(1)$| by varying the sizes of subgroups.
Mingwu Zhang, Yi Mu 0001
Comput. J.2
2016 Compact Anonymous Hierarchical Identity-Based Encryption with Constant Size Private Keys
abstract
We present a new construction of anonymous hierarchical identity-based encryption (HIBE) over prime order groups. The distinct feature of our proposed scheme is that both private key and ciphertext have a constant size, which has never been achieved in all other existing anonymous HIBE schemes. Moreover, we utilized a double exponent technique to generate the ciphertext in order to provide anonymity. This simple and efficient method allows us to construct a more compact anonymous HIBE in prime order groups. Under the decisional bilinear |$n+1$|-Diffie–Hellman exponent assumption and linear assumption, we show that the proposed scheme is secure and anonymous against chosen plaintext attacks in the standard model.
Leyou Zhang, Yi Mu 0001, Qing Wu 0005
Comput. J.2
2016 Recent advances in security and privacy in large-scale networks
abstract
We are pleased to present to you 13 technical papers dealing with cutting-edge research and technology related to this topic. These papers were selected out of the significantly extended versions of the 149 submissions from 18 countries in the 3rd IEEE International Workshop on Large-Scale Network Security (LSNS 2014) and a large number of open submissions. The selection has been very rigorous, and only the best papers were selected. In the first paper, ‘An Error-Tolerant Keyword Search Scheme Based on Public-Key Encryption in Secure Cloud Computing’ 1, Yang et al. first present a general framework for searching on error-tolerant keywords based on a public-key encryption scheme. Then a concrete scheme is proposed based on the Cramer–Shoup cryptosystem. The scheme is chosen ciphertext attack secure, and suitable for all similarity metrics including Hamming distance metric, edit distance metric, and set difference metric. Because it does not require the user to construct and store anything in advance, very different from those cryptosystems used to calculate the trapdoor of keywords and to encrypt data documents, the new scheme tremendously eases the users' burden. In the second paper, ‘A Lightweight Privacy-Preserving Scheme with Data Integrity for Smart Grid Communications’ 2, Bao and Chen propose a lightweight data report scheme for smart grid communications, which can achieve privacy preservation and data integrity simultaneously. Specifically, an efficient pseudonym identity-based privacy-preserving report approach is proposed for the control center to obtain the fine-grained usage data of all the users while protecting user's privacy. An online/offline hash tree-based mechanism is also designed to check and assure data integrity of communications. Furthermore, a topology-independent data report architecture is also structured, which is adaptable for dynamic residential users to spontaneously form clusters and efficiently report data in flocks. Extensive performance evaluation demonstrates that the proposed scheme can achieve less communication overhead and dramatically reduce computational cost in comparison with the existing schemes. Secure biometric authentication aims to replace an encryption key or an identity certificate with biometrics to complete authentication. In the third paper, ‘A Secure Biometric Authentication Based on PEKS’ 3, Zhang et al. present a generic transformation from searchable encryption to secure biometric authentication and construct a specific secure biometric authentication scheme based on public key encryption with keyword search. Compared with some existing authentication schemes, the proposed scheme is more efficient in the practical application. Furthermore, the transformation from searchable encryption to secure biometric authentication presents a new direction of constructing authentication scheme. Certificateless aggregate signature schemes are required to satisfy the applications in certificateless environment. In the fourth paper, ‘A New Certificateless Signature with Enhanced Security and Aggregation Version’ 4, Deng et al. present an improved certificateless signature scheme and use it to construct a new certificateless signature scheme with enhanced security and aggregation. Compared with other schemes, the proposed scheme is more suitable for realistic applications. In the fifth paper, ‘Worm Propagation Model in Mobile Network’ 5, Chen et al. focus on mobile worm propagation model that allows to control and detect potential worm threat, according to the characteristics of worm's outbreak. Chen et al. put forward a worm propagation model based on the mobile network environment. After analyzing the model, it gives the simulation for controlling factors affecting worm propagation. This model allows us to have a certain understanding for the spread on the size and speed of the mobile worm, providing effective methods to control the spread of the mobile worm. In the sixth paper, ‘Efficient Privacy-Preserving Temporal and Spacial Data Aggregation for Smart Grid Communications’ 6, Dong et al. propose an efficient privacy-preserving temporal and spacial data aggregation from one-way functions in smart grid communications, which also allows special data aggregation from multiple users. The proposed construction can guarantee the unconditional security of users' metering power data privacy from the community gateway and the operation center, and the adaptive chosen ciphertext attack security of the aggregation result that can only be accessed by the authorized operation center. Both temporal and spacial data aggregation only require computing the underlying one-way function once. The provable multiple-replication data-possession protocol with full dynamics aims to realize efficient integrity verification and full dynamic data updates for cloud storage. In the seventh paper, ‘Provable Multiple Replication Data Possession with Full Dynamics for Secure Cloud Storage’ 7, Zhang et al. present a new multiple replication data possession scheme with full dynamics, in which a novel multiple replication Merkle hash tree with rank is used. The proposed scheme improves the efficiency of verifying updates for cloud storage with multiple replicas, which satisfies robust security properties. The eighth paper, ‘Efficient Group Key Management for Secure Big Data in Predictable Large-scale Networks’ 8, by He et al. focuses on secure group communication in large-scale social networks in which the entire social network may have millions of users but a concrete group is usually small. The paper proposes a new dynamic group key agreement protocol by using a novel dual-ring approach in which two rings of nodes are established, one active and one dummy. When some nodes leave, the remaining nodes can replace these nodes with dummy nodes, minimizing the required communications and computations after the protocol is set up and thus provides significant advantage over existing group key management protocols. The thorough analysis by the authors demonstrates provable security of the protocol and the superiority of computation and communication overload. The ninth paper, ‘Delegation of Signing Rights for Emerging 5G Networks’ 9, Ge et al. address the issue of delegating authentication in 5G networks by proposing a new proxy signature scheme. In their proposal, the original signer delegates his or her signing right by signing an exposure-free chameleon hash value as a warrant, and the proxy signer can generate a proxy signature on a message only by finding a chameleon hash collision instead of calculating a new digital signature, which can dramatically reduce computation cost of the proxy signer. With the emergence of cloud storage, searchable encryption technique that enables cloud clients to securely search over ciphertext through keywords and selectively retrieve records of interest has been extensively studied in both industry and academia. Unfortunately, most of the existing searchable encryption schemes cannot preserve keyword privacy and user privacy in multi-user setting simultaneously. For this end, in the 10th paper, ‘Revocable and Anonymous Searchable Encryption in Multi-user Setting’ 10, Miao et al. designed a secure and scalable cryptographic primitive based on identity-based encryption. As a further contribution, this proposed scheme can effectively resist decryption key exposure threat and achieve anonymous-revocable-ID-chosen plaintext attack (CPA) secure in the standard model. The location-based service (LBS) privacy protection scheme aims to solve the user's location privacy disclosure issue when the user initiates an LBS request. In the 11th paper, ‘DALP: A Demand-aware Location Privacy Protection Scheme in Continuous Location-based Services’ 11, Li et al. present a new anonymity-based scheme for continuous LBS queries, which allows a user to customize not only location privacy but also QoS requirement. The proposed scheme can maximize the demands-aware query sequence and minimize the constructed cloaking regions, thereby reducing the query latency and the server's workload. In the 12th paper, ‘Security Analysis of a Privacy-preserving Decentralized Ciphertext-Policy Attribute-based Encryption Scheme’ 12, Wang et al. point out the security weakness of a privacy-preserving decentralized ciphertext-policy attribute-based encryption scheme proposed 13, by Han et al. in ESORICS 2014. They present a collusion attack on the underlying decentralized ciphertext policy attribute based encryption (CP-ABE) scheme and additionally show that the privacy protection of attributes in the privacy-preserving key extraction protocol cannot be provided. The 13th paper, ‘Partner Selection of Agricultural Products Supply Chain Based on Data Mining’ 14, puts forward supply chain partner selection model and partner evaluation index system. With BP neural network, the agricultural products' supply chain partner-selection example analysis is made. The results show that the established supply chain partner-selection model has better generalization ability and can be effectively used to supply chain partner selection. We sincerely hope that you will enjoy reading these papers in this special issue. We thank all the international reviewers for their professional services. We deeply thank Professor Geoffrey Fox, the Editor-in-Chief, for providing this opportunity to publish this special issue. With his continuous support, encouragement, and guidance throughout this publishing project, this special issue has been very successful.
Yong Yu 0002, Yi Mu 0001, Rongxing Lu, Jian Ren 0001
Concurr. Comput. Pract. Exp.2
2016 Generalized closest substring encryption
Fuchun Guo, Willy Susilo, Yi Mu 0001
Des. Codes Cryptogr.3
2016 Quantum private set intersection cardinality and its application to anonymous authentication
Yi Mu 0001, Hong Zhong 0001, Shun Zhang 0002, Jie Cui 0004
Inf. Sci.2
2016 Secure Channel Free ID-Based Searchable Encryption for Peer-to-Peer Group
Yi Mu 0001, Rongmao Chen, Xiaosong Zhang 0001
J. Comput. Sci. Technol.2
2016 Centralized keyword search on encrypted data for cloud applications
abstract
Abstract Centralized approaches are widely adopted to improve the qualities of outsourced services owing to its feature of efficient system management. Because the cloud is untrusted, data are usually encrypted before outsourcing. One of the interesting applications is searchable encrypted keywords, a well‐known cryptographic primitive that allows encryption while enabling search for keywords. However, achieving data retrieval without revealing privacy in a cloud‐based centralized system is still a challenging problem. In this paper, we introduce centralized approaches to searchable encryption and present a novel centralized system for retrieval services. In our system, the centralized manager can search and access all the encrypted data from authorized users, while each user can only search and access his or her own data. The system builds on a new cryptographic notion calledcentralized keyword search on encrypted data. We formalize its security model and propose a centralized keyword search on encrypted data construction that is featured by short ciphertext and search result verification. We further extend the construction for removing secure channel and enabling batch authentication on data legalities. The experiment demonstrates the performance of our proposals. Copyright © 2016 John Wiley & Sons, Ltd.
Peng Jiang 0007, Yi Mu 0001, Fuchun Guo, Jianchang Lai
Secur. Commun. Networks2
2016 Privacy-preserving grouping proof with key exchange in the multiple-party setting
abstract
Grouping proof is a very useful security primitive that can be used to prove the co-existence of multiple entities in an identification protocol. It can be incorporated into radio frequency identification protocols and used in many practical applications such as pharmaceutical distribution and manufacturing. However, the existing grouping proofs do not support secure key establishment, which is required in order to allow secure communication between the reader and the radio frequency identification tags after the identification process. In this paper, we propose a novel grouping proof with key exchange that allows the reader to establish a secure communication channel with the tags. We define the formal security models for grouping proof with key exchange and prove that the proposed generic protocol can achieve grouping proof soundness, session key security, contributiveness, and tag identity privacy.
Yangguang Tian, Guomin Yang, Yi Mu 0001
Secur. Commun. Networks3
2016 An efficient privacy-preserving aggregation and billing protocol for smart grid
abstract
Abstract Smart grid is an electrical grid that uses digital information and communication technology to gather information. Like other digital systems, security and privacy are crucial for smart grid. However, security and privacy protection will inevitably introduce computational complexity and overhead. As smart grid systems are usually operated in a large scale, computational efficiency is a challenging issue. In this paper, we propose an efficient and secure billing system for smart grid, featuring privacy‐preserving and data aggregation. We show that our system offers better privacy protection and computational efficiency, in comparison with an existing protocol. Our security analysis indicates that our protocol achieves privacy‐preserving on electricity reading aggregation and billing, perfect forward secrecy of system session keys, identity authentication, data integrity, and confidentiality. It also shows that even if we allow the collusion of server and gateways, user privacy can still be achieved. Copyright © 2016 John Wiley & Sons, Ltd.
Yi Mu 0001, Rongmao Chen
Secur. Commun. Networks2
2016 Strongly average-case secure obfuscation: achieving input privacy and circuit obscurity
abstract
Abstract A program obfuscator is a compiling algorithm that takes a program/circuit as input and generates a new garbled circuit to implement the same functionality as before while obtaining hard‐to‐understand in some sense, that is, infeasible to learn information from the garbled circuit. In order to obtain a practical application, an obfuscation should satisfy equivalent in functionality, polynomial slowdown in efficiency, and virtual black‐box in security. In this paper, we model a stronger cryptographic obfuscation that does not only achieves the obfuscated circuit obscurity but also supports input re‐key privacy. In order to implement the re‐encryption obfuscation, we at first propose a key‐privacy two‐level encryption mechanism that implicitly supports the transformation from level‐2 ciphertext into level‐1 one, which provides an efficient method to re‐encrypt the ciphertext without explicitly decryption procedure. Under the mechanism of two‐level encryption and function of re‐encryption, we construct an obfuscation of re‐encryption that takes as input a probabilistic (keys) circuit and outputs a transformed circuit. We also give the proof that the obfuscator achieves the average‐case security for the circuit family under the extended DBDH assumption and Decisional Linear assumption in the standard model. Copyright © 2016 John Wiley & Sons, Ltd.
Mingwu Zhang, Yi Mu 0001, Jian Shen 0001, Xinyi Huang 0001
Secur. Commun. Networks2
2016 CCA2 secure public-key encryption scheme tolerating continual leakage attacks
abstract
Abstract For a public‐key encryption scheme to be applied in practical applications, it should withstand various leakage attacks (e.g., side‐channel attacks and cold‐boot attacks). To this end, we present a way of construct the more practical CCA2 secure public‐key encryption scheme tolerating leakage attacks, and the scheme's security is based on the hardness of classical decisional Diffie–Hellman assumption and the target collision resistant of one‐way hash function. Additionally, our proposal enjoys better performance, for example, all of elements of ciphertext will be random from the adversary's view, and any probabilistic polynomial‐time adversary cannot obtain leakage on the secret key from the ciphertext, and so on. In the bounded‐leakage setting, for any leakage parameter λ⩽logq − ω(logk)(q is the prime order of the underlying group, and k denotes the security parameter.), our proposal is secure against leakage‐resilient chosen‐ciphertext attacks, where λ is independent of the plaintext space, and has the constant size. However, in the real world, an adversary can continuously learn information on the secret key through a variety of leakage attacks and can trivially break the security of public‐key encryption scheme under the continual leakage attacks. Thus, we will improve our method to resist the continual leakage attacks. Similarly, for any round leakage parameter λC⩽logq − ω(logk), we can prove the security of the improvement scheme based on the hardness of decisional Diffie–Hellman assuming and the target collision resistant of one‐way hash function. With this important performance, our proposal may have some significant value in the practical applications, such as our proposal can provide the leakage‐resilient security for outsourcing data in the cloud computing environment. Copyright © 2016 John Wiley & Sons, Ltd.
Yanwei Zhou, Bo Yang 0003, Wenzheng Zhang 0001, Yi Mu 0001
Secur. Commun. Networks4
2016 Relations between robustness and RKA security under public-key encryption
Hui Cui 0001, Yi Mu 0001, Man Ho Au
Theor. Comput. Sci.2
2016 Efficient dynamic threshold identity-based encryption with constant-size ciphertext
Willy Susilo, Fuchun Guo, Yi Mu 0001
Theor. Comput. Sci.3
2016 Server-Aided Public Key Encryption With Keyword Search
abstract
Public key encryption with keyword search (PEKS) is a well-known cryptographic primitive for secure searchable data encryption in cloud storage. Unfortunately, it is inherently subject to the (inside) offline keyword guessing attack (KGA), which is against the data privacy of users. Existing countermeasures for dealing with this security issue mainly suffer from low efficiency and are impractical for real applications. In this paper, we provide a practical and applicable treatment on this security vulnerability by formalizing a new PEKS system named server-aided public key encryption with keyword search (SA-PEKS). In SA-PEKS, to generate the keyword ciphertext/trapdoor, the user needs to query a semitrusted third-party called keyword server (KS) by running an authentication protocol, and hence, security against the offline KGA can be obtained. We then introduce a universal transformation from any PEKS scheme to a secure SA-PEKS scheme using the deterministic blind signature. To illustrate its feasibility, we present the first instantiation of SA-PEKS scheme by utilizing the Full Domain Hash RSA signature and the PEKS scheme proposed by Boneh et al. in Eurocrypt 2004. Finally, we describe how to securely implement the client-KS protocol with a rate-limiting mechanism against online KGA and evaluate the performance of our solutions in experiments.
Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo, Xinyi Huang 0001
IEEE Trans. Inf. Forensics Secur.2
2016 Dual-Server Public-Key Encryption With Keyword Search for Secure Cloud Storage
abstract
Searchable encryption is of increasing interest for protecting the data privacy in secure searchable cloud storage. In this paper, we investigate the security of a well-known cryptographic primitive, namely, public key encryption with keyword search (PEKS) which is very useful in many applications of cloud storage. Unfortunately, it has been shown that the traditional PEKS framework suffers from an inherent insecurity called inside keyword guessing attack (KGA) launched by the malicious server. To address this security vulnerability, we propose a new PEKS framework named dual-server PEKS (DS-PEKS). As another main contribution, we define a new variant of the smooth projective hash functions (SPHFs) referred to as linear and homomorphic SPHF (LH-SPHF). We then show a generic construction of secure DS-PEKS from LH-SPHF. To illustrate the feasibility of our new framework, we provide an efficient instantiation of the general framework from a Decision Diffie-Hellman-based LH-SPHF and show that it can achieve the strong security against inside the KGA.
Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo
IEEE Trans. Inf. Forensics Secur.2
2016 Distance-Based Encryption: How to Embed Fuzziness in Biometric-Based Encryption
abstract
We introduce a new encryption notion called distance-based encryption (DBE) to apply biometrics in identity-based encryption. In this notion, a ciphertext encrypted with a vector and a threshold value can be decrypted with a private key of another vector, if and only if the distance between these two vectors is less than or equal to the threshold value. The adopted distance measurement is called Mahalanobis distance, which is a generalization of Euclidean distance. This novel distance is a useful recognition approach in the pattern recognition and image processing community. The primary application of this new encryption notion is to incorporate biometric identities, such as face, as the public identity in an identity-based encryption. In such an application, usually the input biometric identity associated with a private key will not be exactly the same as the input biometric identity in the encryption phase, even though they are from the same user. The introduced DBE addresses this problem well as the decryption condition does not require identities to be identical but having small distance. The closest encryption notion to DBE is the fuzzy identity-based encryption, but it measures biometric identities using a different distance called an overlap distance (a variant of Hamming distance) that is not widely accepted by the pattern recognition community, due to its long binary representations. In this paper, we study this new encryption notion and its constructions. We show how to generically and efficiently construct such a DBE from an inner product encryption (IPE) with reasonable size of private keys and ciphertexts. We also propose a new IPE scheme with the shortest private key to build DBE, namely, the need for a short private key. Finally, we study the encryption efficiency of DBE by splitting our IPE encryption algorithm into offline and online algorithms.
Fuchun Guo, Willy Susilo, Yi Mu 0001
IEEE Trans. Inf. Forensics Secur.3
2016 One-Round Privacy-Preserving Meeting Location Determination for Smartphone Applications
abstract
With the widely adopted GPS technology in mobile devices, users enjoy many types of location services. As a recently proposed application, determining the optimal private meeting location with an aid of a location server has been an interesting research topic. The challenge in this paper is due to the requirements of security and privacy, because user locations should not be revealed to the honest-but-curious or semi-trusted location server. Adding the security and privacy protection to a location service will inevitably introduce computational complexity and communication overhead. In order to introduce robust location service and make this location service practical, we propose an efficient optimal private meeting location determination protocol, which needs only one round communication and light computation. Our proposed protocol satisfies the requirement of location privacy against outsiders, the semi-trusted meeting location determination server, and the semi-trusted group users. In order to study the performance of our protocol in a real deployment, we simulate our scheme on smartphones. The simulation results and the performance comparison with another scheme demonstrate its advantages in communication and computation efficiency.
Yi Mu 0001, Rongmao Chen
IEEE Trans. Inf. Forensics Secur.2
2016 Comments on "Public Integrity Auditing for Dynamic Data Sharing With Multiuser Modification"
abstract
Recently, a practical public integrity auditing scheme supporting multiuser data modification (IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, DOI 10.1109/TIFS.2015.2423264) was proposed. Although the protocol was claimed secure, in this paper, we show that the proposal fails to achievesoundness, the most essential property that an auditing scheme should provide. Specifically, we show that a cloud server can collude with a revoked user to deceive a third-party auditor (TPA) that a stored file keeps virgin even when the entire file has been deleted.
Yong Yu 0002, Yannan Li 0001, Jianbing Ni, Guomin Yang, Yi Mu 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.5
2016 Comments on "Accountable and Privacy-Enhanced Access Control in Wireless Sensor Networks"
abstract
In a recent paper (IEEE Trans. Wireless Commun., vol. 14, no. 1, 2015), Heet al.proposed an accountable and privacy-enhanced access control (APAC) protocol, which aimed to provide privacy for honest users against network owners and accountability against misbehaving users without the involvement of any trusted third party. However, the level of trust on the network owner has not been clearly defined in Heet al.’s paper, and we demonstrate in this letter that in the case where the network owners cannot be trusted to correctly generate the system parameters, then the APAC protocol cannot ensure user privacy.
Jiannan Wei, Guomin Yang, Yi Mu 0001
IEEE Trans. Wirel. Commun.3
2016 Trust-based group services selection in web-based service-oriented environments
Xing Su 0001, Minjie Zhang 0001, Yi Mu 0001
World Wide Web3
2015 A New General Framework for Secure Public Key Encryption with Keyword Search
Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo
ACISP2
2015 A New Public Remote Integrity Checking Scheme with User Privacy
Yiteng Feng, Yi Mu 0001, Guomin Yang, Joseph K. Liu
ACISP2
2015 Improved Identity-Based Online/Offline Encryption
Jianchang Lai, Yi Mu 0001, Fuchun Guo, Willy Susilo
ACISP2
2015 Anonymous Yoking-Group Proofs
abstract
Yoking-proofs show an interesting application in Radio Frequency Identification (RFID) that a verifier can check whether two tags are simultaneously scanned by a reader. We consider a scenario that multi-group of tags can be proved to be scanned simultaneously. Grouping-proof, which is an extension of yoking-proofs, allows multiple tags to be proved together, while existing protocols cannot support multiple groups. In this paper, we introduce a novel concept called "yoking-group proofs". Additionally, we propose an anonymous yoking-proof protocol and an anonymous yoking-group proof protocol and prove their security in Universal Composability framework.
Nan Li 0007, Yi Mu 0001, Willy Susilo, Vijay Varadharajan
AsiaCCS2
2015 Threshold Broadcast Encryption with Keyword Search
Shiwei Zhang 0003, Yi Mu 0001, Guomin Yang
Inscrypt2
2015 Provably Secure Identity Based Provable Data Possession
Yong Yu 0002, Yafang Zhang, Yi Mu 0001, Willy Susilo
ProvSec3
2015 Further ideal multipartite access structures from integer polymatroids
Qianhong Wu, Duncan S. Wong, Yi Mu 0001, Jianwei Liu 0001
Sci. China Inf. Sci.5
2015 On Indistinguishability in Remote Data Integrity Checking
abstract
With a rapid growth of data storage in the cloud, data integrity checking in a remote data storage system has become an important issue. A number of protocols, which allow remote integrity checking by a third party, have been proposed. Although those protocols are provably secure, the data privacy issues in those protocols have not been considered. We believe that these issues are equally important since the communication flows of integrity proofs from the cloud server should not reveal any useful information of the stored data. In this paper, we introduce a new definition of data privacy called ‘IND-Privacy’ by an indistinguishability game. It is found that many existing remote integrity proofs are insecure under an IND-Privacy game. It is also found that by adopting witness indistinguishable proofs, the IND-Privacy is achievable. We provide an instantiation that captures data integrity, soundness and IND-privacy.
Guomin Yang, Yi Mu 0001, Yong Yu 0002
Comput. J.3
2015 Secure Delegation of Signing Power from Factorization
abstract
Delegation of signing is a working way common in office automation work, and is also an important approach to establish trust. Proxy signature is an important cryptographic primitive for delegating signing powers and it has found many real-world applications. The existing proxy signature schemes from factorization assumption are either insecure or inefficient. In this paper, we propose a novel, efficient and provably secure proxy signature scheme from factorization. Our construction makes use of a factorization-based key exposure-free chameleon hash function in the delegation phase and the proxy signer needs only to find a collision to a chameleon hash value to generate a valid proxy signature. As a result, our scheme is highly efficient in terms of the computation of a proxy signature. We also provide a formal security proof by classifying the adversaries into three categories. Comparisons demonstrate that the new scheme outperforms the known ones in terms of security, computational efficiency and the length of the public key.
Yong Yu 0002, Man Ho Au, Yi Mu 0001, Willy Susilo, Huai Wu
Comput. J.3
2015 Functional Encryption Resilient to Hard-to-Invert Leakage
abstract
Functional encryption (FE) systems provide a flexible and expressive encryption mechanism that private keys and ciphertexts are associated with attributes and predicate formulae Γ and decryption are possible whenever keys and ciphertexts are related, i.e. ⁠. In this work, we put forward a leakage-resilient FE scheme against the amount of leakage output over a hard-to-invert function family. In our scheme, the encryption policy is specified as an arbitrary monotonic formula, and the adversary can learn the arbitrary length output of the master key and the private key from any computationally irreversible function with the input (master) keys. To improve the efficiency, we employ the set of minimal sets to describe the predicate formula or access structure, and initiate the formal model of leakage-resilient FE, which is a generic extension of identity-based encryption and attribute-based encryption in the presence of key leakage with auxiliary inputs. We provide the concrete construction in bilinear groups of composite order, and prove the adaptively leakage-resilient security in the standard model based on static assumptions. Our hard-to-invert leakage resilience employs the Goldreich–Levin theorem and its extension as a hard-core value over large fields. We also give an extensional construction in the case of obtaining the hard-to-invert randomness leakage of the encryption, which uses a strong extractor to prevent leakage of randomness and a hard-to-invert encryption to prevent the leakage of the key. Finally, we analyze and discuss the stepped-up security on master leakage and continual leakage, and the lower bound of the irreversible leakage function.
Mingwu Zhang, Tsuyoshi Takagi, Yi Mu 0001
Comput. J.4
2015 A reliable recommendation and privacy-preserving based cross-layer reputation mechanism for mobile cloud computing
Hui Lin 0007, Li Xu 0002, Yi Mu 0001, Wei Wu 0001
Future Gener. Comput. Syst.3
2015 Proof of retrievability with public verifiability resilient against related-key attacks
abstract
Modern technologies such as cloud computing, grid computing and software as a service all require data to be stored by the third parties. A specific problem encountered in this context is to convince a verifier that a user's data are kept intact at the storage servers. An important approach to achieve this goal is called proof of retrievability, by which a storage server can assure a verifier via a concise proof that a user's file is available. However, for most publicly verifiable systems, existing proof of retrievability solutions do not take physical attacks into consideration, where an adversary can observe the outcome of the computation with methods like fault injection techniques. In fact, the authors find that giving the adversary the ability to obtain the information about the relations between the private keys, those systems are not secure anymore. Motivated by the need of preventing this kind of attacks, they present the security model for related‐key attacks in publicly verifiable proofs of retrievability, where the adversary can subsequently observe the outcome of the publicly verifiable proof of retrievability under the modified key. After pointing out a linear related‐key attack on an existing proof of retrievability system with public verifiability, they present a secure and efficient proof of retrievability with public verifiability, against related‐key attacks.
Hui Cui 0001, Yi Mu 0001, Man Ho Au
IET Inf. Secur.2
2015 Identity-based quotable ring signature
Kefeng Wang, Yi Mu 0001, Willy Susilo
Inf. Sci.2
2015 A resilient identity-based authenticated key exchange protocol
abstract
This paper presents a new security notion for key exchange (KE) protocols called resiliency. That is, if a shared secret between a group of parties is compromised or leaked, they can generate another completely new shared secret without the need to set up a new KE session. We present an identity-based authenticated KE protocol that satisfies the resiliency security property. We prove that if an l-bit shared secret key (SSK) is leaked, then two parties P1 and P2 can safely generate another shared secret SSK1 without the need to establish a new session. We adjust the unauthenticated adversarial model of the Canetti–Krawczyk to meet this security property and prove the security of the proposed protocol using the Canetti–Krawczyk model based on the quadratic residuosity assumption. Copyright © 2015 John Wiley & Sons, Ltd.
Ibrahim F. Elashry, Yi Mu 0001, Willy Susilo
Secur. Commun. Networks2
2015 Vulnerabilities of an ECC-based RFID authentication scheme
abstract
Radio frequency identification (RFID) authentication is an indispensable part of RFID applications, which allows a reader to identify objects in an authenticated manner. Recently, Liao and Hsiao proposed a very interesting elliptic curve cryptography-based RFID authentication scheme with ID-verifier transfer protocol. They claimed that the proposed protocol is secure against many attacks and satisfies essential security requirements of RFID systems. However, in this paper, we demonstrate that the protocol suffers from several attacks, in contrast to their original claims in the paper. Furthermore, we also propose a repaired version of the authentication protocol against identified attacks, and we provide formal security proofs.
Nan Li 0007, Yi Mu 0001, Willy Susilo, Fuchun Guo, Vijay Varadharajan
Secur. Commun. Networks2
2015 Loss-Tolerant Bundle Fragment Authentication for Space-Based DTNs
abstract
Bundle authentication, which ensures the authenticity and integrity of bundles, is critical in space Delay/disruption-Tolerant Networks (DTNs). When bundle fragment services are needed, the previous solutions directly using digital signatures suffer from heavy computational costs and bandwidth overheads. This paper addresses the issue of fragment authentication for Bundle Protocol by exploiting erasure codes and the batch transmission characteristic of DTNs. Erasure codes are adopted to allow all the fragments of a bundle to equally share only one signature, to tolerate high delays as well as unexpected loss of connectivity. Following this generic idea, we present two approaches, both of which are effective in filtering inauthentic fragments as early as possible. The first one takes a surprisingly low bandwidth overhead, while it makes all received fragments of a bundle to be removed when there is an inauthentic one, because of its failure in locating the inauthentic fragments. Considering this defect, we present an improved scheme which is able to detect inauthentic fragments thanks to a special hash chain and then only remove these inauthentic ones. The performance simulation demonstrates that both our schemes significantly reduce bandwidth overheads and computational costs as compared to the prior works.
Xixiang Lv, Yi Mu 0001, Hui Li 0006
IEEE Trans. Dependable Secur. Comput.2
2015 BL-MLE: Block-Level Message-Locked Encryption for Secure Large File Deduplication
abstract
Deduplication is a popular technique widely used to save storage spaces in the cloud. To achieve secure deduplication of encrypted files, Bellare et al. formalized a new cryptographic primitive named message-locked encryption (MLE) in Eurocrypt 2013. Although an MLE scheme can be extended to obtain secure deduplication for large files, it requires a lot of metadata maintained by the end user and the cloud server. In this paper, we propose a new approach to achieve more efficient deduplication for (encrypted) large files. Our approach, named block-level message-locked encryption (BL-MLE), can achieve file-level and block-level deduplication, block key management, and proof of ownership simultaneously using a small set of metadata. We also show that our BL-MLE scheme can be easily extended to support proof of storage, which makes it multi-purpose for secure cloud storage.
Rongmao Chen, Yi Mu 0001, Guomin Yang, Fuchun Guo
IEEE Trans. Inf. Forensics Secur.2
2015 AAC-OT: Accountable Oblivious Transfer With Access Control
abstract
To prevent illegal users accessing the database and protect users' privacy, oblivious transfer with access control (AC-OT) was proposed. In an AC-OT scheme, the database provider can encrypt the records and publish corresponding access control lists (ACLs). Prior to accessing the records, a user needs to obtain anonymous credentials from the issuer. Subsequently, an authorized user can obtain the intended records without the database provider knowing its choices. Although AC-OT schemes have shown a lot of merits, there are some practical issues: 1) one of the inherited problems in anonymous credentials is timely revocation and 2) how to prevent malicious users overusing the records. In this paper, we propose an accountable AC-OT scheme to address these issues. In our scheme, an authorized user can access the protected records without the database provider knowing his personal information and choices if: 1) he has obtained the required credentials listed in the ACLs and 2) the number of the access times for each record is no more than the specified bound. Notably, the database provider can trace and revoke the user who overused the records even in the lifetime of his credentials. To the best of our knowledge, it is the first AC-OT scheme where timely revocation and overuse detection are considered.
Jinguang Han, Willy Susilo, Yi Mu 0001, Man Ho Au, Jie Cao 0001
IEEE Trans. Inf. Forensics Secur.3
2015 Improving Privacy and Security in Decentralized Ciphertext-Policy Attribute-Based Encryption
abstract
In previous privacy-preserving multiauthority attribute-based encryption (PPMA-ABE) schemes, a user can acquire secret keys from multiple authorities with them knowing his/her attributes and furthermore, a central authority is required. Notably, a user's identity information can be extracted from his/her some sensitive attributes. Hence, existing PPMA-ABE schemes cannot fully protect users' privacy as multiple authorities can collaborate to identify a user by collecting and analyzing his attributes. Moreover, ciphertext-policy ABE (CP-ABE) is a more efficient public-key encryption, where the encryptor can select flexible access structures to encrypt messages. Therefore, a challenging and important work is to construct a PPMA-ABE scheme where there is no necessity of having the central authority and furthermore, both the identifiers and the attributes can be protected to be known by the authorities. In this paper, a privacy-preserving decentralized CP-ABE (PPDCP-ABE) is proposed to reduce the trust on the central authority and protect users' privacy. In our PPDCP-ABE scheme, each authority can work independently without any collaboration to initial the system and issue secret keys to users. Furthermore, a user can obtain secret keys from multiple authorities without them knowing anything about his global identifier and attributes.
Jinguang Han, Willy Susilo, Yi Mu 0001, Jianying Zhou 0001, Man Ho Au
IEEE Trans. Inf. Forensics Secur.3
2015 Comments on a Public Auditing Mechanism for Shared Cloud Data Service
abstract
Recently, a public auditing protocol for shared data called Panda (IEEE Transactions on Services Computing, doi: 10.1109/TSC.2013.2295611) was proposed to ensure the correctness of the outsourced data. A distinctive feature of Panda is the support of data sharing and user revocation. Unfortunately, in this letter, we show that Panda is insecure in the sense that a cloud server can hide data loss without being detected. Specifically, we show that even some stored file blocks have been lost, the server is able to generate a valid proof by replacing a pair of lost data block and its signature with another block and signature pair. We also provide a solution to the problem while preserving all the desirable features of the original protocol.
Yong Yu 0002, Jianbing Ni, Man Ho Au, Yi Mu 0001, Boyang Wang 0001, Hui Li 0006
IEEE Trans. Serv. Comput.4
2014 POSTER: Euclidean Distance Based Encryption: How to Embed Fuzziness in Biometric Based Encryption
abstract
We introduce a new encryption notion called Euclidean Distance based Encryption (EDE). In this notion, a ciphertext encrypted with a vector and a threshold value can be decrypted with a private key of another vector, if and only if the Euclidean distance between these two vectors is less than or equal to the threshold value. Euclidean distance is the underlying technique in the pattern recognition and image processing community for image recognition. The primary application of this encryption notion is to enable an identity-based encryption that incorporates biometric identifiers, such as fingerprint, face, hand geometry, vein and iris. In that application, usually the input biometric will not be exactly the same during the enrollment and encryption phases. In this poster, we propose this new encryption notion and study its construction. We show how to generically and efficiently construct an EDE from an inner-product encryption (IPE) with reasonable size of private keys and ciphertexts. We also propose a new IPE scheme that is equipped with a specific characteristic to build EDE, namely the need for short private key. Our IPE scheme achieves the shortest private key compared to existing IPE schemes in the literature, where our private key is composed of two group elements only.
Fuchun Guo, Willy Susilo, Yi Mu 0001
CCS3
2014 An Efficient Privacy-Preserving E-coupon System
Weiwei Liu 0005, Yi Mu 0001, Guomin Yang
Inscrypt2
2014 PPDCP-ABE: Privacy-Preserving Decentralized Ciphertext-Policy Attribute-Based Encryption
Jinguang Han, Willy Susilo, Yi Mu 0001, Jianying Zhou 0001, Man Ho Au
ESORICS (2)3
2014 Attribute-Based Signature with Message Recovery
Kefeng Wang, Yi Mu 0001, Willy Susilo, Fuchun Guo
ISPEC2
2014 Jhanwar-Barua's Identity-Based Encryption Revisited
Ibrahim F. Elashry, Yi Mu 0001, Willy Susilo
NSS2
2014 Attribute-Based Signing Right Delegation
Weiwei Liu 0005, Yi Mu 0001, Guomin Yang
NSS2
2014 Identity Privacy-Preserving Public Auditing with Dynamic Group for Secure Mobile Cloud Storage
Yong Yu 0002, Yi Mu 0001, Jianbing Ni, Jiang Deng, Ke Huang 0002
NSS2
2014 Complete Robustness in Identity-Based Encryption
Hui Cui 0001, Yi Mu 0001, Man Ho Au
ProvSec2
2014 Public-Key Encryption Resilient against Linear Related-Key Attacks Revisited
abstract
Wee (PKC'12) proposed a generic public-key encryption scheme in the setting of related-key attacks. Bellare, Paterson and Thomson (Asiacrypt'12) provided a framework enabling related-key attack (RKA) secure cryptographic primitives for a class of non-linear related-key derivation functions. However, in both of their constructions, the instantiations to achieve the full (not weak) RKA security are given under the scenario regarding the private key composed of single element. In other words, each element of the private key shares the same modification. However, this is impractical in real world. In this paper, we concentrate on the security of public-key encryption schemes under linear related-key attacks in the setting of multielement private keys (that is, the private key is composed of more than one element), where an adversary is allowed to tamper any part of this private key stored in a hardware device, and subsequently observes the outcome of a public key encryption system under this targeted modified private key. We define the security model for RKA secure public-key encryption schemes as chosen-cipher text and related-key attack (CC-RKA) security, which means that a public-key encryption scheme remains secure even when an adversary is allowed to issue the decryption oracle on linear shifts of any component of the private key. After that, we present a detailed public key encryption schemes with the private key formed of several elements, of which the CC-RKA security is under the decisional BDH assumption in the standard model.
Hui Cui 0001, Yi Mu 0001, Man Ho Au
TrustCom2
2014 Anonymous Proxy Signature with Restricted Traceability
abstract
Signer anonymity is an important security requirement for many digital signature schemes due to the need of user privacy in many applications. In this paper, we study signer anonymity for proxy signature which allows a signer to delegate his/her signing right to another user (or proxy). Since the proxy signer is the actual singer in a proxy signature scheme, we are interested in protecting the proxy signer's identity in this paper. However, one potential problem in an anonymous proxy signature scheme is that the proxy signer may abuse the delegated signing right due to the anonymity property of a proxy signature. In this paper, we propose a novel anonymous proxy signature scheme with restricted traceability, which allows the original singer to trace dishonest proxy signers. However, if the proxy signer is honest, then his/her identity is well protected against any user (including the original signer). Our scheme will be useful in many applications such as anonymous authentication protocols and anonymous voting schemes.
Jiannan Wei, Guomin Yang, Yi Mu 0001
TrustCom3
2014 Toward reverse engineering on secret S-boxes in block ciphers
Ming Tang 0002, Zhenlong Qiu, Hongbo Peng, Yi Mu 0001, Huanguo Zhang
Sci. China Inf. Sci.5
2014 Signcryption Secure Against Linear Related-Key Attacks
abstract
A related-key attack (RKA) occurs when an adversary tampers the private key stored in a cryptographic hardware device, and observes the result of the cryptographic primitive under this modified private key. In this paper, we consider the security of signcryption schemes under linear RKAs, where an adversary is allowed to tamper the private keys of the receiver and the sender, and subsequently observe the outcome of a signcryption system under these modified private keys of both parties. We define two security notions for RKA-secure signcryption schemes: chosen ciphertext RKA and chosen message RKA. We require that a signcryption scheme remains secure even when an adversary is allowed to access the designcryption oracle and the signcryption oracle on linear shifts of the private keys of the receiver and the sender, respectively. After reviewing some basic definitions related to our construction, we give a specific signcryption scheme from bilinear Diffie-Hellman which is secure against RKAs. Furthermore, we extend the security model of signcryption with anonymity, where the ciphertext is anonymous to others except the real receiver given the honest sender and the honest receiver. Fortunately, with a trivial modification to the original signcryption scheme, our proposed signcryption scheme can protect the privacy of both the sender and the receiver.
Hui Cui 0001, Yi Mu 0001, Man Ho Au
Comput. J.2
2014 Server-Aided Signature Verification for Lightweight Devices
abstract
Server-aided verification (SAV) has potential applicability in lightweight devices for improving signature verification, where the verifier possesses a computationally weak hardware. We observe that lightweight devices run all algorithms through hardware implementation with logic circuits. Existing SAV protocols indeed improve computational efficiency for lightweight devices, however, few of them take the hardware cost into consideration. The hardware implementation of SAV protocols could be still costly and expensive for lightweight devices. Currently, the most secure SAV protocols in the literature for pairing-based (𝔾1 × 𝔾2 → 𝔾T) signatures can securely delegate pairing computations to the server; however, verifiers are still required to perform group operations over two completely different groups 𝔾1 and 𝔾T, which heavily contribute to the cost of hardware implementation. In this work, we propose several collusion-resistant SAV protocols for pairing-based signatures to improve their applicability for lightweight devices. In our SAV protocols, verifiers are only required to perform group operations in 𝔾1. In comparison with existing SAV protocols, our protocols save the unnecessary hardware cost for implementing group operations in 𝔾T and therefore are more applicable to lightweight applications.
Fuchun Guo, Yi Mu 0001, Willy Susilo, Vijay Varadharajan
Comput. J.2
2014 Attribute-Based Data Transfer with Filtering Scheme in Cloud Computing
abstract
Data transfer is a transmission of data over a point-to-point or point-to-multipoint communication channel. To protect the confidentiality of the transferred data, public-key cryptography has been introduced in data transfer schemes (DTSs). Data transfer is a transmission of data over a point-to-point or point-to-multipoint communication channel. To protect the confidentiality of the transferred data, public-key cryptography has been introduced in data transfer schemes (DTSs). Unfortunately, there exist some drawbacks in the current DTSs. First, the sender must know who the real receivers are. This is undesirable in a system where the number of the users is very large, such as cloud computing. In practice, the sender only knows some descriptive attributes of the receivers. Secondly, the receiver cannot be guaranteed to only receive messages from the legal senders. Therefore, it remains an elusive and challenging research problem on how to design a DTS scheme where the sender can send messages to the unknown receivers and the receiver can filter out false messages according to the described attributes. In this paper, we propose an attribute-based data transfer with filtering (ABDTF) scheme to address these problems. In our proposed scheme, the receiver can publish an access structure so that only the users whose attributes satisfy this access structure can send messages to him. Furthermore, the sender can encrypt a message under a set of attributes such that only the users who hold these attributes can obtain the message. In particular, we provide an efficient filtering algorithm for the receiver to resist the denial-of-service attacks. Notably, we propose the formal definition and security models for ABDTF schemes. To the best of our knowledge, it is the first time that a provable ABDTF scheme is proposed. Hence, this work provides a new research approach to ABDTF schemes. must know who are the real receivers. This is undesirable in a system where the number of the users is very large, such as cloud computing. In practice, the sender only knows some descriptive attributes of the receivers. Second, the receiver cannot be guaranteed to only receive messages from the legal senders. Therefore, it remains an elusive and challenging research problem on how to design a DTS scheme where the sender can send messages to the unknown receivers and the receiver can filter out false messages according to the described attributes. In this paper, we propose an attribute-based data transfer with filtering (ABDTF) scheme to address these problems. In our proposed scheme, the receiver can publish an access structure so that only the users whose attributes satisfy this access structure can send messages to him. Furthermore, the sender can encrypt a message under a set of attributes such that only the users who hold these attributes can obtain the message. In particular, we provide an efficient filtering algorithm for the receiver to resist the denial-of-service (DoS) attacks. Notably, we propose the formal definition and security models for ABDTF schemes. To the best of our knowledge, it is the first time that a provable ABDTF scheme is proposed. Hence, this work provides a new research approach to ABDTF schemes.
Jinguang Han, Willy Susilo, Yi Mu 0001, Jun Yan 0005
Comput. J.3
2014 Affiliation-Hiding Authenticated Asymmetric Group Key Agreement Based on Short Signature
abstract
The notion of Affiliation-Hiding Authenticated Group Key Agreement (AH-AGKA) protocols was first introduced by Jarecki et al. in CT-RSA 2007, where they presented two concrete AH-AGKA protocols. In this paper, we show that Jarecki et al.'s second protocol has some drawbacks. We propose a new affiliation-hiding protocol. Differing from Jarecki et al.'s protocol, our protocol is asymmetric. Compared with existing AH-AGKA protocols, our scheme not only exhibits the affiliation-hiding property, but also holds the properties of detectability and perfect forward secrecy.
Chang Xu 0004, Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001
Comput. J.4
2014 Trust-oriented QoS-aware composite service selection based on genetic algorithms
abstract
SUMMARY Service selection in service‐oriented computing has emerged to be an increasingly important research area. From the client's point of view, in addition to the QoS of a service or a service composition, the trust level becomes an important part. As the complexity of invocation in service composition has been greatly increased, a comprehensive mechanism, which could evaluate both the subjective aspect as trust expression and the objective aspect as QoS, is needed. In this paper, we provide a formal service composition architecture for service selection. In addition, we propose a trust evaluation method for the service composition plan based on the subjective probability theory, based on them, our trust‐oriented genetic algorithm (TOGA) is proposed to find a near‐optimal service composition plan with QoS constraints. Experimental results have illustrated that our proposed approach can discover the near‐optimal solution efficiently. Copyright © 2013 John Wiley & Sons, Ltd.
Jun Yan 0005, Yi Mu 0001
Concurr. Comput. Pract. Exp.3
2014 Security of new generation computing systems
abstract
Modern computing systems have become more easy-to-use, sophisticated and powerful, and have dramatically changed the way we live. However, the same systems add complexity and also introduce new interdependencies, vulnerabilities and privacy issues. There will be more ways to disrupt our life through cyber attacks. It is thus of great importance to consider and develop methods to mitigate those security risks. This special issue presents the recent advances on the security of new generation computing systems including distributed, cloud, and grid systems. We are pleased to present to you nine technical papers dealing with cutting-edge research and technology related to this topic. These papers were selected out of the significantly extended versions of the 173 submissions from 28 countries in the 6th International Conference on Network and System Security (NSS 2012) and a large number of open submissions. The selection has been very rigorous, and only the best papers were selected.
Li Xu 0002, Elisa Bertino, Yi Mu 0001
Concurr. Comput. Pract. Exp.3
2014 Key continual-leakage resilient broadcast cryptosystem from dual system in broadcast networks
Mingwu Zhang, Yi Mu 0001
Frontiers Comput. Sci.2
2014 SA3: Self-adaptive anonymous authentication for dynamic authentication policies
Yanling Lian, Xinyi Huang 0001, Yi Mu 0001
Future Gener. Comput. Syst.3
2014 On the security of auditing mechanisms for secure cloud storage
Yong Yu 0002, Lei Niu, Guomin Yang, Yi Mu 0001, Willy Susilo
Future Gener. Comput. Syst.4
2014 Security pitfalls of an efficient threshold proxy signature scheme for mobile agents
Yong Yu 0002, Yi Mu 0001, Willy Susilo, Man Ho Au
Inf. Process. Lett.2
2014 Towards a cryptographic treatment of publish/subscribe systems
abstract
Publish/subscribe mechanism is a typical many-to-many messaging paradigm when multiple applications want to receive the same message or when a group of applications would like to notify each other. Nonetheless, there exist only a few works that address the security issues for content-based publish/subscribe systems formally. Although the security requirements have been partially addressed by Wang et al., there is no formal definition for all of these security requirements in the literature. As a result, most of the existing schemes do not have any security proof and it is difficult to justify whether those schemes are really secure in practice. Furthermore, there is no comprehensive scheme that satisfies the most essential security requirements at the same time. In this paper, we introduce the first security model for important security requirements of content-based publish/subscribe systems. We also give a new security requirement for publisher authenticity, which means that the publisher is authenticated to publish certain types of notification only, and cannot publish other types of notification. We then exhibit a new scheme which fulfills most of the security requirements. Furthermore, we also provide a comprehensive proof for our concrete construction according to the new model.
Tsz Hon Yuen, Willy Susilo, Yi Mu 0001
J. Comput. Secur.3
2014 Loss-tolerant authentication with digital signatures
abstract
ABSTRACT Consider a signed file that cannot be verified because of some fraction loss or noise, which might not affect the business of users. It would be desirable for the verifier to locate the damaged fractions so that the authenticity of other components of the file can be ensured. Thereafter, the verifier can decide whether or not to accept it. To address this issue, in this paper, we present a loss‐tolerant authentication scheme, which allows the verifier to locate the damaged elements in the signed file stream. Our idea is to allow the signed file to be fragmented, and each fragment is appended a short authentication tag, which enables the verifier to find the modified fragments in the signed file and verify the signature even if some fragments are lost. The proposed scheme adopts a combination of Reed–Solomon error correction and erasure codes, aiming to allow verifiers to locate the modified fractions and thereafter reconstruct the signature when sufficient original fractions of the file are obtained. Our scheme offers many potential applications such as loss‐tolerant transmission and storage. Copyright © 2013 John Wiley & Sons, Ltd.
Xixiang Lv, Yi Mu 0001, Hui Li 0006
Secur. Commun. Networks2
2014 A secure mobility support scheme for 6LoWPAN wireless sensor networks
abstract
ABSTRACT This paper proposes a secure mobility support scheme for 6LoWPAN wireless sensor networks. The paper first presents the IPv6 over Low power Wireless Personal Area Networks (6LoWPAN) architecture where the routing can be automatically performed. With the architecture, both the hierarchical Internet protocol version 6 address structure and the secure address configuration algorithm for a 6LoWPAN wireless sensor network are proposed. With the architecture and the address structure, the secure intranetwork and internetwork mobility handover algorithms are presented, and they utilize the encryption and authentication to achieve the security. During the mobility process, a mobile node does not need a care‐of address, so the mobility handover process includes neither the care‐of address configuration operation nor the address‐binding operation. As a result, the mobility handover cost and delay are reduced. Moreover, mobile nodes do not need to be involved in the mobility handover process, so the packet loss caused by mobile nodes' failure is avoided. During the intranetwork mobility handover process, a link address is used to identify a mobile node, so the size of a control message is reduced substantially. As a result, the transmission cost and delay are reduced. The paper analyzes the performance parameters of the proposed scheme, including mobility handover cost, delay, and packet loss rate. Compared with the existing scheme without security, the proposed scheme has relatively good mobility handover performance. Copyright © 2013 John Wiley & Sons, Ltd.
Xiaonan Wang 0001, Yi Mu 0001
Secur. Commun. Networks2
2014 Efficient public key encryption with revocable keyword search
abstract
ABSTRACT Public key encryption with keyword search is a novel cryptographic primitive enabling one to search on the encrypted data directly. In the known schemes, once getting a trapdoor, the server can search associated data without any restrictions. However, in reality, it is sometimes essential to prevent the server from searching the data all the time because the server is not fully trusted. In this paper, we propose the notion of public key encryption with revocable keyword search to address the issue. We also develop a concrete construction by dividing the whole life of the system into distinct times to achieve our goals. The proposed scheme achieves the properties of the indistinguishability of ciphertexts against an adaptive chosen keywords attack security under the co‐decisional bilinear Diffie–Hellman assumption in our security model. Compared with two somewhat schemes, ours offers much better performance in terms of computational cost. Copyright © 2013 John Wiley & Sons, Ltd.
Yong Yu 0002, Jianbing Ni, Haomiao Yang, Yi Mu 0001, Willy Susilo
Secur. Commun. Networks4
2014 Identity-Based Secure DistributedData Storage Schemes
abstract
Secure distributed data storage can shift the burden of maintaining a large number of files from the owner to proxy servers. Proxy servers can convert encrypted files for the owner to encrypted files for the receiver without the necessity of knowing the content of the original files. In practice, the original files will be removed by the owner for the sake of space efficiency. Hence, the issues on confidentiality and integrity of the outsourced data must be addressed carefully. In this paper, we propose two identity-based secure distributed data storage (IBSDDS) schemes. Our schemes can capture the following properties: (1) The file owner can decide the access permission independently without the help of the private key generator (PKG); (2) For one query, a receiver can only access one file, instead of all files of the owner; (3) Our schemes are secure against the collusion attacks, namely even if the receiver can compromise the proxy servers, he cannot obtain the owner’s secret key. Although the first scheme is only secure against the chosen plaintext attacks (CPA), the second scheme is secure against the chosen ciphertext attacks (CCA). To the best of our knowledge, it is the first IBSDDS schemes where an access permission is made by the owner for an exact file and collusion attacks can be protected in the standard model.
Jinguang Han, Willy Susilo, Yi Mu 0001
IEEE Trans. Computers3
2014 Identity based identification from algebraic coding theory
Guomin Yang, Chik How Tan, Yi Mu 0001, Willy Susilo, Duncan S. Wong
Theor. Comput. Sci.3
2014 Subset Membership Encryption and Its Applications to Oblivious Transfer
abstract
In this paper, we propose a novel cryptographic notion called subset membership encryption (SME), and provide a very efficient SME scheme. Given a system parameter generated by an encryptor (Alice), a decryptor (Bob) generates a randomized privacy-preserved attribute token P(G) from a set of attributes G. A message is encrypted using an attribute set A chosen by Alice and P(G) provided by Bob. It requires that A is a subset of G for Bob to decrypt the message. We propose a very efficient SME scheme, where both the size of P(G) and ciphertext are short and independent of G and A. In particular, it has three useful and practical applications to oblivious transfer as follows. 1) k-Out-of-n Oblivious Transfer (OT): SME can be naturally applied to a two-round OT, which features a great communication efficiency especially for the receiver, where the receiver only sends two group elements to the message sender. 2) Priced Oblivious Transfer (POT): Our POT protocol allows a buyer to purchase any number of items in each transaction and hide selected items, price and balance from the vendor. In comparison with previous POT protocols, our protocol is more flexible and eliminates the restriction that a buyer can only purchase one item in a transaction. Our POT scheme is very efficient since it does not require any zero-knowledge proof or homomorphic encryption. 3) Restricted Priced Oblivious Transfer (RPOT): We introduce a novel POT named RPOT where a vendor can set restrictions on items or prices in POT. For example, a seller could offer a discounted price to those buyers who have purchased some specific items previously from the same seller.
Fuchun Guo, Yi Mu 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.2
2014 CP-ABE With Constant-Size Keys for Lightweight Devices
abstract
Lightweight devices, such as radio frequency identification tags, have a limited storage capacity, which has become a bottleneck for many applications, especially for security applications. Ciphertext-policy attribute-based encryption (CP-ABE) is a promising cryptographic tool, where the encryptor can decide the access structure that will be used to protect the sensitive data. However, current CP-ABE schemes suffer from the issue of having long decryption keys, in which the size is linear to and dependent on the number of attributes. This drawback prevents the use of lightweight devices in practice as a storage of the decryption keys of the CP-ABE for users. In this paper, we provide an affirmative answer to the above long standing issue, which will make the CP-ABE very practical. We propose a novel CP-ABE scheme with constant-size decryption keys independent of the number of attributes. We found that the size can be as small as 672 bits. In comparison with other schemes in the literature, the proposed scheme is the only CP-ABE with expressive access structures, which is suitable for CP-ABE key storage in lightweight devices.
Fuchun Guo, Yi Mu 0001, Willy Susilo, Duncan S. Wong, Vijay Varadharajan
IEEE Trans. Inf. Forensics Secur.2
2014 Non-Interactive Key Establishment for Bundle Security Protocol of Space DTNs
abstract
To ensure the authenticity, integrity, and confidentiality of bundles, the in-transit Protocol Data Units of bundle protocol (BP) in space delay/disruption tolerant networks (DTNs), the Consultative Committee for Space Data Systems bundle security protocol (BSP) specification suggests four IPsec style security headers to provide four aspects of security services. However, this specification leaves key management as an open problem. Aiming to address the key establishment issue for BP, in this paper, we utilize a time-evolving topology model and two-channel cryptography to design efficient and noninteractive key exchange protocol. A time-evolving model is used to formally model the periodic and predetermined behavior patterns of space DTNs, and therefore, a node can schedule when and to whom it should send its public key. Meanwhile, the application of two-channel cryptography enables DTN nodes to exchange their public keys or revocation status information, with authentication assurance and in a noninteractive manner. The proposed scheme helps to establish a secure context to support for BSP, tolerating high delays, and unexpected loss of connectivity of space DTNs.
Xixiang Lv, Yi Mu 0001, Hui Li 0006
IEEE Trans. Inf. Forensics Secur.2
2014 An Efficient Generic Framework for Three-Factor Authentication With Provably Secure Instantiation
abstract
Remote authentication has been widely studied and adapted in distributed systems. The security of remote authentication mechanisms mostly relies on one of or the combination of three factors: 1) something users know—password; 2) something users have—smart card; and 3) something users are—biometric characteristics. This paper introduces an efficient generic framework for three-factor authentication. The proposed generic framework enhances the security of existing two-factor authentication schemes by upgrading them to three-factor authentication schemes, without exposing user privacy. In addition, we present a case study by upgrading a secure two-factor authentication scheme to a secure three-factor authentication scheme. Furthermore, implementation analysis, formal proof, and privacy discussion are provided to show that the derived scheme is practical, secure, and privacy preserving.
Jiangshan Yu, Guilin Wang, Yi Mu 0001, Wei Gao 0007
IEEE Trans. Inf. Forensics Secur.3
2014 On the Security of an Efficient Dynamic Auditing Protocol in Cloud Storage
abstract
Using cloud storage, data owners can remotely store their data and enjoy the on-demand high quality cloud services without the burden of local data storage and maintenance. However, this new paradigm does trigger many security concerns. A major concern is how to ensure the integrity of the outsourced data. To address this issue, recently, a highly efficient dynamic auditing protocol (IEEE Transactions on Parallel and Distributed Systems, doi:10.1109/TPDS.2013.199) for cloud storage was proposed which enjoys many desirable features. Unfortunately, in this letter, we demonstrate that the protocol is insecure when an active adversary is involved in the cloud environment. We show that the adversary is able to arbitrarily modify the cloud data without being detected by the auditor in the auditing process. We also suggest a solution to fix the problem while preserving all the properties of the original protocol.
Jianbing Ni, Yong Yu 0002, Yi Mu 0001, Qi Xia 0001
IEEE Trans. Parallel Distributed Syst.3
2013 Membership Encryption and Its Applications
Fuchun Guo, Yi Mu 0001, Willy Susilo, Vijay Varadharajan
ACISP2
2013 Secure RFID Ownership Transfer Protocols
Nan Li 0007, Yi Mu 0001, Willy Susilo, Vijay Varadharajan
ISPEC2
2013 Identity-Based Multisignature with Message Recovery
Kefeng Wang, Yi Mu 0001, Willy Susilo
ISPEC2
2013 Leakage Resilient Authenticated Key Exchange Secure in the Auxiliary Input Model
Guomin Yang, Yi Mu 0001, Willy Susilo, Duncan S. Wong
ISPEC2
2013 Leakage-Resilient Attribute-Based Encryption with Fast Decryption: Models, Analysis and Constructions
Mingwu Zhang, Zhenhua Chen 0001, Yi Mu 0001
ISPEC5
2013 Anonymous Signcryption against Linear Related-Key Attacks
Hui Cui 0001, Yi Mu 0001, Man Ho Au
ProvSec2
2013 k-time Proxy Signature: Formal Definition and Efficient Construction
Weiwei Liu 0005, Guomin Yang, Yi Mu 0001, Jiannan Wei
ProvSec3
2013 Public-Key Encryption Resilient to Linear Related-Key Attacks
Hui Cui 0001, Yi Mu 0001, Man Ho Au
SecureComm2
2013 Generic Mediated Encryption
Ibrahim F. Elashry, Yi Mu 0001, Willy Susilo
SecureComm2
2013 Identity-based data storage in cloud computing
Jinguang Han, Willy Susilo, Yi Mu 0001
Future Gener. Comput. Syst.3
2013 Efficient and dynamic key management for multiple identities in identity-based systems
Hua Guo 0001, Chang Xu 0004, Zhoujun Li 0001, Yi Mu 0001
Inf. Sci.5
2013 On security of a certificateless signcryption scheme
Songqin Miao, Futai Zhang, Sujuan Li, Yi Mu 0001
Inf. Sci.4
2013 A robust trust model for service-oriented systems
Xing Su 0001, Minjie Zhang 0001, Yi Mu 0001, Quan Bai 0001
J. Comput. Syst. Sci.3
2013 Securing DSR against wormhole attacks in multirate ad hoc networks
Shams Qazi, Raad Raad, Yi Mu 0001, Willy Susilo
J. Netw. Comput. Appl.3
2013 A secure IPv6 address configuration scheme for a MANET
abstract
ABSTRACT We propose a secure Internet Protocol version 6 (IPv6) address configuration scheme for a Mobile Ad Hoc Network. The scheme presents the architecture for a Mobile Ad Hoc Network and the hierarchical IPv6 address structure. In the architecture, a new node can acquire a unique IPv6 address from a proxy node within one‐hop scope without performing a duplicate address detection process, and the IP addresses occupied by failed nodes can be recovered automatically for reuse. On the basis of the hierarchical IPv6 address structure, each proxy node can acquire a unique address scope for assignment and assign a unique IP address for new nodes, so the address configuration task is distributed around proxy nodes. In addition, the transmission scope of the control packets for address configuration is controlled within one‐hop scope, so the address configuration cost is reduced, and the delay is shortened. The security of the proposed address configuration scheme is achieved through authentication. The paper analyzes the performance parameters of the proposed scheme and the existing schemes, and the analytical results show that the address configuration cost of the proposed scheme is lower and the delay is shorter. Copyright © 2012 John Wiley & Sons, Ltd.
Xiaonan Wang 0001, Yi Mu 0001
Secur. Commun. Networks2
2013 New construction of affiliation-hiding authenticated group key agreement
abstract
ABSTRACT In CT‐RSA 2007, Jarecki, Kim, and Tsudik introduced the notion of affiliation‐hiding authenticated group key agreement (AH‐AGKA) protocols and presented two concrete AH‐AGKA protocols. In this paper, we will show that these protocols have some drawbacks. We will also introduce the notion of affiliation‐hiding authenticated asymmetric group key agreement (AH‐AAGKA) and present an AH‐AAGKA protocol. AH‐AAGKA protocols allow the participants of a group to establish a common encryption key associated with several decryption keys; each of which can only be computed by the corresponding legitimate participant. Meanwhile, any party is assured that its affiliation is revealed to the participants that belong to the same group only. Compared with previous AH‐AGKA protocols, if invalid players participate in our protocol, legitimate participants can identify these invalid players. In contrast to existing AH‐AGKA protocols, our protocol holds perfect forward secrecy, which is proven in a novel security model we proposed. Additionally, we present a new privacy model to prove that our protocol achieves linkable affiliation‐hiding property. Copyright © 2012 John Wiley & Sons, Ltd.
Chang Xu 0004, Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001
Secur. Commun. Networks4
2012 Identity-Based Traitor Tracing with Short Private Key and Short Ciphertext
Fuchun Guo, Yi Mu 0001, Willy Susilo
ESORICS2
2012 A Pre-computable Signature Scheme with Efficient Verification for RFID
Fuchun Guo, Yi Mu 0001, Willy Susilo, Vijay Varadharajan
ISPEC2
2012 Provably Secure Single Sign-on Scheme in Distributed Systems and Networks
abstract
Distributed systems and networks have been adopted by telecommunications, remote educations, businesses, armies and governments. A widely applied technique for distributed systems and networks is the single sign-on (SSO) which enables a user to use a unitary secure credential (or token) to access multiple computers and systems where he/she has access permissions. However, most existing SSO schemes have not been formally proved to satisfy credential privacy and soundness of credential based authentication. To overcome this drawback, we formalise the security model of single sign-on scheme with authenticated key exchange. Specially, we point out the difference between soundness and credential privacy, and define them together in one definition. Also, we propose a provably secure single sign-on authentication scheme, which satisfies soundness, preserves credential privacy, meets user anonymity, and supports session key exchange. The proposed scheme is very efficient so that it suits for mobile devices in distributed systems and networks.
Jiangshan Yu, Guilin Wang, Yi Mu 0001
TrustCom3
2012 Polar differential power attacks and evaluation
Ming Tang 0002, Zhenlong Qiu, Yi Mu 0001, Huanguo Zhang, Yingzhen Jin
Sci. China Inf. Sci.4
2012 Attribute-Based Oblivious Access Control
abstract
In an attribute-based system (ABS), users are identified by various attributes, instead of their identities. Since its seminal introduction, the attribute-based mechanism has attracted a lot of attention. However, current ABS schemes have a number of drawbacks: (i) the communication cost is linear in the number of the required attributes; (ii) the computation cost is linear in the number of the required attributes and (iii) there are no efficient verification algorithms for the secret keys. These drawbacks limit the use of ABS in practice. In this paper, we propose an attribute-based oblivious access control (ABOAC) scheme to address these problems, where only the receiver whose attributes satisfy the access policies can obtain services obliviously. As a result, the receiver does not release anything about the contents of the selected services and his attributes to the sender, and even the number and supersets of his attributes are protected. The sender only knows the number of the services selected by the authorized receiver. Notably, the costs of computation and communication are constant and independent of the number of required attributes. While, in the prior comparable schemes, both the costs of computation and communication are linear in the required attributes. Therefore, our ABOAC scheme provides a novel and elegant solution to protect user's privacy in the systems where both the bandwidth and the computing capability are limited, such as wireless sensor and actor networks, mobile ad hoc networks, etc..
Jinguang Han, Willy Susilo, Yi Mu 0001, Jun Yan 0005
Comput. J.3
2012 Certificateless Signatures: New Schemes and Security Models
abstract
We present a study of security in certificateless signatures. We divide potential adversaries according to their attack power, and for the first time, three new kinds of adversaries are introduced into certificateless signatures. They are Normal Adversary, Strong Adversary and Super Adversary (ordered by their attack power). Combined with the known Type I Adversary and Type II Adversary in certificateless cryptography, we then define the security of certificateless signatures in different attack scenarios. Our new security models, together with others in the literature, provide a clear definition of the security in certificateless signatures. Two concrete schemes with different security levels are also proposed in this paper. The first scheme, which is proven secure (in the random oracle model) against Normal Type I and Super Type II adversaries, has the shortest signature length among all known certificateless signature schemes. The second scheme is secure (in the random oracle model) against Super Type I and Type II adversaries. Compared with another scheme that has a similar security level, our second scheme requires less operational cost but a little longer signature length. Two server-aided verification protocols are also proposed to reduce the verification cost on the verifier.
Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Duncan S. Wong, Wei Wu 0001
Comput. J.2
2012 A Provably Secure Construction of Certificate-Based Encryption from Certificateless Encryption
abstract
Certificate-based encryption (CBE) and certificateless encryption (CLE) are proposed to lessen the certificate management problem in a traditional public-key encryption setting. Although they are two different notions, CBE and CLE are closely related and possess several common features. The encryption in CBE and CLE does not require authenticity verification of the recipient public key. The decryption in both notions requires two secrets that are generated by the third party and the public key owner, respectively. Recently a generic conversion from CLE to CBE was given, but unfortunately its security proof is flawed. This paper provides an elaborate security model of CBE, based on which a provably secure generic construction of CBE from CLE is proposed. A concrete instantiation is also presented to demonstrate the application of our generic construction.
Wei Wu 0001, Yi Mu 0001, Willy Susilo, Xinyi Huang 0001, Li Xu 0002
Comput. J.2
2012 Affiliation-Hiding Authenticated Asymmetric Group Key Agreement
abstract
We introduce the concept of Affiliation-Hiding Authenticated Asymmetric Group Key Agreement (AH-AAGKA) and construct a concrete one-round AH-AAGKA protocol. An AH-AAGKA protocol allows the participants of a group to establish a common encryption key associated with several decryption keys; each of which can only be computed by the corresponding legitimate group member. An AH-AAGKA protocol has the following privacy feature. For a member 𝒰i of a group G, if 𝒰i participates in an AH-AAGKA protocol, any protocol participant 𝒰j cannot learn whether 𝒰i is a member of G, unless 𝒰j himself is a member of group G. Our scheme demonstrates new features in comparison with other existing AH-AGKA protocols. If non-group members participate in our protocol, honest parties can identify these non-group members. Our scheme also captures Unlinkability and Perfect Forward Secrecy (PFS), which are missing in other existing schemes. We propose a novel security model to prove that our protocol holds PFS and present a new privacy model to prove that our scheme meets Affiliation-Hiding property.
Chang Xu 0004, Zhoujun Li 0001, Yi Mu 0001, Hua Guo 0001
Comput. J.3
2012 Improved certificateless signature scheme provably secure in the standard model
abstract
Certificateless cryptography shares many features of identity-based cryptography and partially solves the problem of key escrow. Three certificateless signature schemes without random oracles were found in the literature. However, all the schemes suffer from some common drawbacks. First, by obtaining a signature on a message and replacing the public key of a signer, an adversary can forge valid signatures on the same message under the replaced public key. Secondly, all the schemes require a relatively large size of public parameters. The authors propose a new certificateless signature scheme, which exhibits an improvement on the existing schemes. Compared with the previous schemes, the proposed scheme offers stronger security, shorter system parameters and higher computational efficiency.
Yong Yu 0002, Yi Mu 0001, Guilin Wang, Qi Xia 0001, Bo Yang 0003
IET Inf. Secur.2
2012 Privacy enhanced data outsourcing in the cloud
Miao Zhou, Yi Mu 0001, Willy Susilo, Jun Yan 0005, Liju Dong
J. Netw. Comput. Appl.2
2012 Privacy preserving protocol for service aggregation in cloud computing
abstract
SUMMARY Cloud computing has increasingly become a new model in the world of computing, and more businesses are moving to the cloud. As a cost‐effective and time‐efficient way to develop new applications and services, service aggregation in cloud computing empowers all service providers and consumers and creates tremendous opportunities in various industry sectors. However, it also poses various challenges to the privacy of personal information as well as the confidentiality of business and governmental information. The full benefits of service aggregation in cloud computing would only be enjoyed if the privacy concerns are addressed properly. In this paper, we investigate the privacy issues in service aggregation in a cloudenvironment and propose a privacy preserving protocol that is suitable for this environment. To demonstrate the security of our system, we construct a security game called IND‐P3SAC‐CPA and prove the security of the protocol accordingly. Our protocol has a distinct property that allows any service provider to obtain only the queried data under its conspiracy with the cloud. Additionally, the efficiency and various extensions are also discussed. Copyright © 2011 John Wiley & Sons, Ltd.
Peishun Wang, Yi Mu 0001, Willy Susilo, Jun Yan 0005
Softw. Pract. Exp.2
2012 Privacy-Preserving Decentralized Key-Policy Attribute-Based Encryption
abstract
Decentralized attribute-based encryption (ABE) is a variant of a multiauthority ABE scheme where each authority can issue secret keys to the user independently without any cooperation and a central authority. This is in contrast to the previous constructions, where multiple authorities must be online and setup the system interactively, which is impractical. Hence, it is clear that a decentralized ABE scheme eliminates the heavy communication cost and the need for collaborative computation in the setup stage. Furthermore, every authority can join or leave the system freely without the necessity of reinitializing the system. In contemporary multiauthority ABE schemes, a user's secret keys from different authorities must be tied to his global identifier (GID) to resist the collusion attack. However, this will compromise the user's privacy. Multiple authorities can collaborate to trace the user by his GID, collect his attributes, then impersonate him. Therefore, constructing a decentralized ABE scheme with privacy-preserving remains a challenging research problem. In this paper, we propose a privacy-preserving decentralized key-policy ABE scheme where each authority can issue secret keys to a user independently without knowing anything about his GID. Therefore, even if multiple authorities are corrupted, they cannot collect the user's attributes by tracing his GID. Notably, our scheme only requires standard complexity assumptions (e.g., decisional bilinear Diffie-Hellman) and does not require any cooperation between the multiple authorities, in contrast to the previous comparable scheme that requires nonstandard complexity assumptions (e.g., q-decisional Diffie-Hellman inversion) and interactions among multiple authorities. To the best of our knowledge, it is the first decentralized ABE scheme with privacy-preserving based on standard complexity assumptions.
Jinguang Han, Willy Susilo, Yi Mu 0001, Jun Yan 0005
IEEE Trans. Parallel Distributed Syst.3
2011 Electronic Cash with Anonymous User Suspension
Man Ho Au, Willy Susilo, Yi Mu 0001
ACISP3
2011 Self-certified ring signatures
abstract
We present a new notion, Self-certified Ring Signature (SCRS), to provide an alternative solution to the certificate management problem in ring signatures and eliminate private key escrow problem in identity based ring signatures. Our scheme captures all features of ring signatures and exhibits the advantages such as low storage, communication and computation cost. The main contribution of this paper is a precise definition of self-certified ring signatures along with a concrete construction. We also provide a security model of SCRS and a security proof of our scheme.
Nan Li 0007, Yi Mu 0001, Willy Susilo, Fuchun Guo
AsiaCCS2
2011 Efficient Self-certified Signatures with Batch Verification
Nan Li 0007, Yi Mu 0001, Willy Susilo
Inscrypt2
2011 Policy-Based Authentication for Mobile Agents
Yi Mu 0001, Minjie Zhang 0001
ISPEC2
2011 Optimistic Fair Exchange of Ring Signatures
Lie Qu, Guilin Wang, Yi Mu 0001
SecureComm3
2011 Case-Based Trust Evaluation from Provenance Information
abstract
Trust is a crucial aspect for open distributed systems. Especially as users may rely on the shared services to make important decisions, it is essential to let them know services' trustworthiness. Provenance describes the origins and processes that are related to the generation of services. It can greatly enhance transparency and accountability of shared services. In this paper, we focus on how to derive trust information from huge amount of provenance data, and proposed a case-based approach which can estimate services' trustworthiness from provenance. This approach can greatly utilise the value of provenance, and provide more objective and reasonable trust estimation to users.
Quan Bai 0001, Xing Su 0001, Qing Liu 0001, Andrew Terhorst, Minjie Zhang 0001, Yi Mu 0001
TrustCom6
2011 Privacy-Preserved Access Control for Cloud Computing
abstract
The problem of access control on outsourced data to "honest but curious" cloud servers has received considerable attention, especially in scenarios involving potentially huge sets of data files, where re-encryption and re-transmission by the data owner may not be acceptable. Considering the user privacy and data security in cloud environment, in this paper, we propose a solution to achieve flexible and fine-grained access control on outsourced data files. In particular, we look at the problem of defining and assigning keys to users based on different attribute sets, and hiding access policies as well as users information to the third-party cloud servers. Our proposed scheme is partially based on our observation that, in practical application scenarios each user can be associated with a set of attributes which are meaningful in the access policy and data file context. The access policy can thus be defined as a logical expression formula over different attribute sets to reflect the scope of data file that the kind of users is allowed to access. As any access policy can be represented as such a logical expression formula, fine-grained access control can be accomplished.
Miao Zhou, Yi Mu 0001, Willy Susilo, Man Ho Au, Jun Yan 0005
TrustCom2
2011 GTrust: An Innovated Trust Model for Group Services Selection in Web-Based Service-Oriented Environments
Xing Su 0001, Minjie Zhang 0001, Yi Mu 0001, Quan Bai 0001
WISE3
2011 Short Signatures with a Tighter Security Reduction Without Random Oracles
abstract
The recent work by Hofheinz and Kiltz (Crypto 2008) has demonstrated that it is feasible to generate a short signature with <320 bits and 80-bit security without the need of random oracles. The authors also showed that the signature length can be reduced to 230 bits if no more than 230 signatures are generated. In this paper, we present three novel short signature schemes with a comparable signature length. Although our schemes can be considered as variants of Hofheinz and Kiltz's schemes, ours can be proved with a much tighter security reduction without random oracles. Our first scheme offers a 270-bit short signature length for 80-bit security without using random oracles and can be tightly reduced to the q-strong Diffie–Hellman problem. Using a stateful signing approach in our second scheme, we show how to further shorten the signature length to 191 bits. Our idea can also be applied to construct short RSA-based signatures with a tight security reduction to the strong RSA problem without random oracles. We note that the 80-bit security defined in all short signature schemes without random oracles is associated with loose reductions or strong assumptions. We compare our schemes with the Boneh–Boyen short signature scheme (Eurocrypt 2004) and the Hofheinz–Kiltz short signature scheme by taking security reductions into account. We show that with the same assumptions, our schemes offer the shortest signatures and achieve the same concrete security.
Fuchun Guo, Yi Mu 0001, Willy Susilo
Comput. J.2
2011 Cryptanalysis of an Off-Line Electronic Cash Scheme Based on Proxy Blind Signature
abstract
Proxy blind signature is an important cryptographic primitive and plays an essential role in construction of the electronic cash (e-cash). Recently, Tan (2001, An offline electronic cash scheme based on proxy blind signature. Comput. J., 54, 505–512) proposed a new proxy blind signature scheme and applied it to electronic cash. The scheme was claimed as being provably secure under the Discrete Log assumption, DBDH assumption and Chosen–Target CDH assumption in the random oracle model. In this paper, we show that Tan's proxy blind signature scheme is insecure by demonstrating several attacks in which a malicious original signer can forge both valid proxy signature keys of arbitrary proxy signers and a proxy blind signature on an arbitrary message with respect to any proxy signer directly. We also discuss some weaknesses in the e-cash scheme proposed by Tan.
Yong Yu 0002, Yi Mu 0001, Guilin Wang
Comput. J.2
2011 Secure Image Retrieval Based on Visual Content and Watermarking Protocol
abstract
As an interesting application on cloud computing, content-based image retrieval (CBIR) has attracted a lot of attention, but the focus of previous research work was mainly on improving the retrieval performance rather than addressing security issues such as copyrights and user privacy. With an increase of security attacks in the computer networks, these security issues become critical for CBIR systems. In this paper, we propose a novel two-party watermarking protocol that can resolve the issues regarding user rights and privacy. Unlike the previously published protocols, our protocol does not require the existence of a trusted party. It exhibits three useful features: security against partial watermark removal, security in watermark verification and non-repudiation. In addition, we report an empirical research of CBIR with the security mechanism. The experimental results show that the proposed protocol is practicable and the retrieval performance will not be affected by watermarking query images.
Jun Zhang 0010, Yang Xiang 0001, Wanlei Zhou 0001, Lei Ye 0002, Yi Mu 0001
Comput. J.5
2011 Attribute-based authentication for multi-agent systems with dynamic groups
Yi Mu 0001, Minjie Zhang 0001
Comput. Commun.2
2011 An efficient and non-interactive hierarchical key agreement protocol
Hua Guo 0001, Yi Mu 0001, Zhoujun Li 0001, Xiyong Zhang
Comput. Secur.2
2011 Secure mobile agents with controlled resources
abstract
Abstract Mobile agents often travel in a hostile environment where their security and privacy could be compromised by any party including remote hosts in which agents visit and get services. It is believed that the host visited by an agent should jointly sign a service agreement with the agent's owner; hence a proxy‐signing model was proposed in the literature, allowing every host in the agent system to sign a service agreement. We observe that this actually poses a serious problem whereby a host that should be excluded from an underlying agent network could also send a signed service agreement. In order to solve this problem, we propose two schemes achieving host authentication with controlled resources, where only selected hosts can be included in the agent network. We provide two schemes in this paper. The second scheme offers a smaller data size. We also define security models and provide rigorous security proofs to our schemes. Copyright © 2010 John Wiley & Sons, Ltd.
Yi Mu 0001, Minjie Zhang 0001, Robert H. Deng
Concurr. Comput. Pract. Exp.2
2011 Provably secure identity-based authenticated key agreement protocols with malicious private key generators
Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001, Xiyong Zhang
Inf. Sci.3
2011 Practical RFID ownership transfer scheme
abstract
When an RFID tag changes hand, it is not as simply as handing over the tag secret to the new owner. Privacy is a concern if there is no secure ownership transfer scheme to aid the transfer. After sales service and temporary tag delegation are also features commonly seen in such applications. In thi s paper, we proposed a new RFID ownership transfer scheme that achieves the most security protections and properties in comparison to most of the previous schemes. We also introduced four new security properties that have not been considered before. This opens up new research directions for further development of RFID ownership transfer.
Ching Yu Ng, Willy Susilo, Yi Mu 0001, Reihaneh Safavi-Naini
J. Comput. Secur.3
2011 Optimistic Fair Exchange with Strong Resolution-Ambiguity
abstract
Optimistic fair exchange (OFE) allows two parties to exchange their digital items in a fair way. As one of the fundamental problems in secure electronic business and digital rights management, OFE has been studied intensively since its introduction. This paper introduces and defines a new property for OFE: Strong Resolution-Ambiguity. We show that many existing OFE protocols have the new property, but its formal investigation has been missing in those protocols. We prove that in the certified-key model, an OFE protocol is secure in the multi-user setting if it is secure in the single-user setting and has the property of strong resolution-ambiguity. Our result not only simplifies the security analysis of OFE protocols in the multi-user setting but also provides a new approach for the design of multi-user secure OFE protocols. Following this approach, a new OFE protocol with strong resolution-ambiguity is proposed. Our analysis shows that the protocol is setup-free, stand-alone and multi-user secure without random oracles.
Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Wei Wu 0001, Yang Xiang 0001
IEEE J. Sel. Areas Commun.2
2011 Improving security of q-SDH based digital signatures
Fuchun Guo, Yi Mu 0001, Willy Susilo
J. Syst. Softw.2
2011 Strongly unforgeable proxy signature scheme secure in the standard model
Chunxiang Xu, Yong Yu 0002, Yi Mu 0001
J. Syst. Softw.4
2011 Preserving Transparency and Accountability in Optimistic Fair Exchange of Digital Signatures
abstract
Optimistic fair exchange (OFE) protocols are useful tools for two participants to fairly exchange items with the aid of a third party who is only involved if needed. A widely accepted requirement is that the third party's involvement in the exchange must be transparent, to protect privacy and avoid bad publicity. At the same time, a dishonest third party would compromise the fairness of the exchange and the third party thus must be responsible for its behaviors. This is achieved in OFE protocols with another property called accountability. It is unfortunate that the accountability has never been formally studied in OFE since its introduction ten years ago. In this paper, we fill these gaps by giving the first complete definition of accountability in OFE where one of the exchanged items is a digital signature and a generic (also the first) design of OFE where transparency and accountability coexist.
Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Wei Wu 0001, Jianying Zhou 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.2
2011 Authenticated key exchange protocol with selectable identities
abstract
Abstract In the traditional identity‐based cryptography, a user, who holds multiple identities, has to manage multiple private keys, where each private key is associated with an identity. In this paper, we present a key agreement protocol, which allows a single private key to map multiple public keys (identities) that are selectable by the user. That is, the established session key is associated with an arbitrary subset of identities held by the user, while the unselected identities remain secret to other participants. As a bonus, our scheme can be considered as a credential‐based key agreement, where the unique private key can be treated as a credential of the user and the user only proves that his credential is associated with some selected identities. We prove that our scheme is secure in the random oracle model. Copyright © 2010 John Wiley & Sons, Ltd.
Hua Guo 0001, Yi Mu 0001, Xiyong Zhang, Zhoujun Li 0001
Wirel. Commun. Mob. Comput.2
2010 Proof-of-Knowledge of Representation of Committed Value and Its Applications
Man Ho Au, Willy Susilo, Yi Mu 0001
ACISP3
2010 Towards a Cryptographic Treatment of Publish/Subscribe Systems
Tsz Hon Yuen, Willy Susilo, Yi Mu 0001
CANS3
2010 Efficient Online/Offline Signatures with Computational Leakage Resilience in Online Phase
Fuchun Guo, Yi Mu 0001, Willy Susilo
Inscrypt2
2010 A framework for privacy policy management in service aggregation
abstract
With a rapid growth of the Internet, exploring cost-effective and time-efficient methods for creating Internet services has become critical. As an emerging technology, service aggregation has been regarded as a promising candidate. However, it also raises serious issues on privacy management, as a service is usually provided by multiple providers that are usually transparent to its users. We observe that these issues have not been formally studied in the literature. In this paper, we propose a formal model for the privacy management in service aggregation and present a negotiation strategy on different privacy policies between two organizations.
Peishun Wang, Liju Dong, Yi Mu 0001, Willy Susilo, Jun Yan 0005
CSCWD3
2010 Efficient RFID Authentication Scheme for Supply Chain Applications
abstract
Radio Frequency Identification (RFID) technology has been widely used in supply chains to track and manage shipments. By tagging shipments with RFID tags, which can be remotely accessed by RFID readers, shipments can be identified and tracked in a supply chain. Security issues in RFID have been major concerns, since passive RFID tags have very weak computational power to support authentication. Sound authentication between tag and reader remains a challenging problem. In this paper, we provide a novel authentication scheme to protect tags from being tracked and identified by unauthorized readers and protect authorized readers against bogus tags. Our scheme can be applied to supply chain security. It also exhibits an additional feature that a supply chain can be dynamically updated.
Fei Bi, Yi Mu 0001
EUC2
2010 PBTrust: A Priority-Based Trust Model for Service Selection in General Service-Oriented Environments
abstract
How to choose the best service provider (agent), which a service consumer can trust in terms of the quality and success rate of the service in an open and dynamic environment, is a challenging problem in many service-oriented applications such as Internet-based grid systems, e-trading systems, as well as service-oriented computing systems. This paper presents a Priority-Based Trust (PBTrust) model for service selection in general service-oriented environments. The PBTrust is robust and novel from several perspectives. (1) The reputation of a service provider is derived from referees who are third parties and had interactions with the provider in a rich context format, including attributes of the service, the priority distribution on attributes and a rating value for each attribute from a third party, (2) The concept of 'Similarity' is introduced to measure the difference in terms of distributions of priorities on attributes between requested service and a refereed service in order to precisely predict the performance of a potential provider on the requested service, (3) The concept of general performance of a service provider on a service in history is also introduced to improve the success rate on the requested service. The experimental results can prove that PBtrust has a better performance than that of the CR model in a service-oriented environment.
Xing Su 0001, Minjie Zhang 0001, Yi Mu 0001, Kwang Mong Sim 0001
EUC3
2010 Enhanced Security Notions for Dedicated-Key Hash Functions: Definitions and Relationships
Reza Reyhanitabar, Willy Susilo, Yi Mu 0001
FSE3
2010 Dynamic Trust Model for Federated Identity Management
abstract
The goal of federated identity management is to allow principals, such as identities and attributes, to be shared across trust boundaries based on established policies. Since current Single Sign-On (SSO) mechanism excessively relies on the specifications of Circle of Trust (CoT), the need for service collaboration from different domains is being addressed on CoT. For the motivating issue of the cross-domain SSO mechanism, we need an emergent dynamic trust list for calculating the trust parties, thus, the CoT specifications require an initial effort on enrolling members automatically to adapt to the dynamic open environment. In this paper, we propose a Dynamic Trust Policy Language to support trust negotiation. The formal syntax of this language is presented in Backus Naur Form (BNF) based on the concept of role membership. We also systematically develop the Dynamic Trust Model (DTM) to allow Untrusted SP to join the existing CoT by trust negotiation. Finally, we identify the process and algorithm for communication between negotiation entities.
Jun Yan 0005, Yi Mu 0001
NSS3
2010 A Generic Construction of Dynamic Single Sign-on with Strong Security
Jinguang Han, Yi Mu 0001, Willy Susilo, Jun Yan 0005
SecureComm2
2010 Certificateless threshold signature scheme from bilinear maps
Futai Zhang, Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Lei Zhang 0009
Inf. Sci.4
2010 Constructions of certificate-based signature secure against key replacement attacks
abstract
In Eurocrypt 2003, Gentry introduced the notion of certificate-based encryption. The merit of certificate-based encryption lies in the following features: (1) providing more efficient public-key infrastructure (PKI) that requires less infrastructure, (2) solving the certificate revocation problem, and (3) eliminating third-party queries in the traditional PKI. Additionally, it also offers the solution to the inherent key escrow problem in the identity-based cryptography. The contributions of this paper are threefold. Firstly, we introduce a new attack called the “Key Replacement Attack” into the certificate-based signature system and refine the security model of certificate-based signature. Secondly, we show that the certificate-based signature scheme presented by Kang, Park and Hahn in CT-RSA 2004 is insecure against key replacement attacks. Thirdly, we present two new certificate-based signature schemes secure against key replacement attacks. Our first scheme is existentially unforgeable against adaptive chosen message attacks under the computational Diffie–Hellman assumption in the random oracle model. Compared with the certificate-based signature scheme in CT-RSA 2004, our first scheme enjoys shorter signature length and less operation cost. Our second scheme is inspired by Waters signature and is the first construction of certificate-based signature secure against key replacement attacks in the standard model.
Jiguo Li 0001, Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Qianhong Wu
J. Comput. Secur.3
2009 Analysis of Property-Preservation Capabilities of the ROX and ESh Hash Domain Extenders
Reza Reyhanitabar, Willy Susilo, Yi Mu 0001
ACISP3
2009 Efficient Non-interactive Range Proof
Tsz Hon Yuen, Qiong Huang 0001, Yi Mu 0001, Willy Susilo, Duncan S. Wong, Guomin Yang
COCOON3
2009 Dynamic Universal Accumulators for DDH Groups and Their Application to Attribute-Based Anonymous Credential Systems
Man Ho Au, Patrick P. Tsang, Willy Susilo, Yi Mu 0001
CT-RSA4
2009 New Privacy Results on Synchronized RFID Authentication Protocols against Tag Tracing
Ching Yu Ng, Willy Susilo, Yi Mu 0001, Reihaneh Safavi-Naini
ESORICS3
2009 Asymmetric Group Key Agreement
Qianhong Wu, Yi Mu 0001, Willy Susilo, Josep Domingo-Ferrer
EUROCRYPT2
2009 Enhanced Target Collision Resistant Hash Functions Revisited
Reza Reyhanitabar, Willy Susilo, Yi Mu 0001
FSE3
2009 Policy-Controlled Signatures
Pairat Thorncharoensri, Willy Susilo, Yi Mu 0001
ICICS3
2009 An Efficient Certificateless Encryption Scheme in the Standard Model
abstract
We propose an efficient certificateless public key encryption (CL-PKE) scheme which is provably secure against chosen ciphertext attacks without random oracles. Our scheme is more computationally efficient than the existing schemes and provides the shortest public key length compared to other existing CL-PKEs with random oracles. We also propose a practical self-generated-certificate encryption (SGC-PKE) scheme based on our CL-PKE scheme. One of merits of such cryptographic systems is that it can be applied to countermeasure "Denial-of-Decryption (DoD) Attacks" that is inherent in CL-PKE.
Hua Guo 0001, Xiyong Zhang, Yi Mu 0001, Zhoujun Li 0001
NSS3
2009 Secure Mobile Agents with Designated Hosts
abstract
Mobile agents often travel in a hostile environment where their security and privacy could be compromised by any party including remote hosts in which agents visit and get services. It was proposed in the literature that the host visited by an agent should jointly sign a service agreement with the agent's home, where a proxy-signing model was deployed and every host in the agent system can sign. We observe that this actually poses a serious problem in that a host that should be excluded from an underlying agent network could also send a signed service agreement. In order to solve this problem, we propose a secure mobile agent scheme achieving host authentication with designated hosts, where only selected hosts can be included in the agent network. We also present a security model and provide a rigorous security proof to our scheme.
Yi Mu 0001, Minjie Zhang 0001, Robert H. Deng
NSS2
2009 Is the Notion of Divisible On-Line/Off-Line Signatures Stronger than On-Line/Off-Line Signatures?
Man Ho Au, Willy Susilo, Yi Mu 0001
ProvSec3
2009 How to Prove Security of a Signature with a Tighter Security Reduction
Fuchun Guo, Yi Mu 0001, Willy Susilo
ProvSec2
2009 Server-Controlled Identity-Based Authenticated Key Exchange
Hua Guo 0001, Yi Mu 0001, Xiyong Zhang, Zhoujun Li 0001
ProvSec2
2009 Novel and Efficient Identity-Based Authenticated Key Agreement Protocols from Weil Pairings
Hua Guo 0001, Yi Mu 0001, Xiyong Zhang, Zhoujun Li 0001
UIC2
2009 Certificateless Threshold Ring Signature
Shuang Chang, Duncan S. Wong, Yi Mu 0001, Zhenfeng Zhang
Inf. Sci.3
2008 Sanitizable Signatures Revisited
Tsz Hon Yuen, Willy Susilo, Joseph K. Liu, Yi Mu 0001
CANS4
2008 Publicly Verifiable Privacy-Preserving Group Decryption
Qianhong Wu, Willy Susilo, Yi Mu 0001
Inscrypt4
2008 Privacy for Private Key in Signatures
Qianhong Wu, Yi Mu 0001, Willy Susilo
Inscrypt3
2008 RFID Privacy Models Revisited
Ching Yu Ng, Willy Susilo, Yi Mu 0001, Reihaneh Safavi-Naini
ESORICS3
2008 A Generic Construction of Identity-Based Online/Offline Signcryption
abstract
Signcryption has clear advantage over traditional sign-then-encrypt schemes. However, the computational overhead for signcryption is still too heavy when it is applied to resource-constraint systems. In this paper, we propose a generic construction of the identity-based online/offline signcryption, where most of computations are carried out when the associated message is still unavailable and the online part of our scheme does not require any exponent computations and therefore is very efficient. Our scheme isgeneric and identity-based, in the sense it is independent of the selection of signature and encryption algorithms. Our scheme possesses the properties of ciphertext indistinguishability (IND-gCCA2) and existentially unforgeability (UF-CMA).
Dongdong Sun, Yi Mu 0001, Willy Susilo
ISPA2
2008 Optimal Online/Offline Signature: How to Sign a Message without Online Computation
Fuchun Guo, Yi Mu 0001
ProvSec2
2008 Server-Aided Verification Signatures: Definitions and New Constructions
Wei Wu 0001, Yi Mu 0001, Willy Susilo, Xinyi Huang 0001
ProvSec2
2008 Cryptanalysis of simple three-party key exchange protocol
Hua Guo 0001, Zhoujun Li 0001, Yi Mu 0001, Xiyong Zhang
Comput. Secur.3
2008 Efficient generic on-line/off-line (threshold) signatures without key exposure
Xiaofeng Chen 0001, Fangguo Zhang, Haibo Tian, Baodian Wei, Willy Susilo, Yi Mu 0001, Hyunrok Lee, Kwangjo Kim
Inf. Sci.6
2007 Practical Compact E-Cash
Man Ho Au, Willy Susilo, Yi Mu 0001
ACISP3
2007 Certificateless Signature Revisited
Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Duncan S. Wong, Wei Wu 0001
ACISP2
2007 Efficient Generic On-Line/Off-Line Signatures Without Key Exposure
Xiaofeng Chen 0001, Fangguo Zhang, Willy Susilo, Yi Mu 0001
ACNS4
2007 Identity-Based Proxy Signature from Pairings
Wei Wu 0001, Yi Mu 0001, Willy Susilo, Jennifer Seberry, Xinyi Huang 0001
ATC2
2007 Cryptanalysis of BGW Broadcast Encryption Schemes for DVD Content Protection
Qianhong Wu, Willy Susilo, Yi Mu 0001
ATC3
2007 Mutative Identity-Based Signatures or Dynamic Credentials Without Random Oracles
Fuchun Guo, Yi Mu 0001, Zhide Chen
CANS2
2007 A Generic Construction for Universally-Convertible Undeniable Signatures
Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Wei Wu 0001
CANS2
2007 Multi-Identity Single-Key Decryption without Random Oracles
Fuchun Guo, Yi Mu 0001, Zhide Chen, Li Xu 0002
Inscrypt2
2007 Provably Secure Identity-Based Undeniable Signatures with Selective and Universal Convertibility
Wei Wu 0001, Yi Mu 0001, Willy Susilo, Xinyi Huang 0001
Inscrypt2
2007 Compact E-Cash from Bounded Accumulator
Man Ho Au, Qianhong Wu, Willy Susilo, Yi Mu 0001
CT-RSA4
2007 Efficient Partially Blind Signatures with Provable Security
Qianhong Wu, Willy Susilo, Yi Mu 0001, Fangguo Zhang
ICCSA (3)3
2007 Formal Definition and Construction of Nominative Signature
Dennis Y. W. Liu, Duncan S. Wong, Xinyi Huang 0001, Guilin Wang, Qiong Huang 0001, Yi Mu 0001, Willy Susilo
ICICS6
2007 New Construction of Group Secret Handshakes Based on Pairings
Willy Susilo, Yi Mu 0001
ICICS3
2007 First price sealed bid auction without auctioneers
abstract
We propose two protocol variants for a first price sealed-bid auction, without using intermediatory auctioneers. One version achieves full privacy for the bidders and their bids, the other provides a form of verifiability, at the cost of some privacy. Full privacy protects all bids. In particular the winner's identity and price are only known by the seller. Lesser privacy allows the winner to be known and verified publicly. Both versions provide non-repudiation. We demonstrate correctness and show how computational and communication costs vary with different privacy levels.
Luke McAven, Yi Mu 0001
IWCMC3
2007 Identity-Based Encryption: How to Decrypt Multiple Ciphertexts Using a Single Decryption Key
Fuchun Guo, Yi Mu 0001, Zhide Chen
Pairing2
2007 Provably Secure Pairing-Based Convertible Undeniable Signature with Short Signature Length
Xinyi Huang 0001, Yi Mu 0001, Willy Susilo, Wei Wu 0001
Pairing2
2007 Designated Verifier Signature: Definition, Framework and New Constructions
Yong Li 0002, Willy Susilo, Yi Mu 0001, Dingyi Pei
UIC3
2007 Breaking and Repairing Trapdoor-Free Group Signature Schemes from Asiacrypt'2004
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang
J. Comput. Sci. Technol.3
2007 Revocable Ring Signature
Dennis Y. W. Liu, Joseph K. Liu, Yi Mu 0001, Willy Susilo, Duncan S. Wong
J. Comput. Sci. Technol.3
2007 Short Group Signatures Without Random Oracles
Qianhong Wu, Willy Susilo, Yi Mu 0001, Yumin Wang, Zhengtao Jiang
J. Comput. Sci. Technol.4
2006 Online/Offline Signatures and Multisignatures for AODV and DSR Routing Security
Shidi Xu, Yi Mu 0001, Willy Susilo
ACISP2
2006 Certificateless Designated Verifier Signature Schemes
abstract
Designated verifier signature schemes allow a signer to convince a designated verifier, in such a way that only the designated verifier will believe with the authenticity of such a signature. The previous constructions of designated verifier signature rely on the underlying public key Infrastructure, that requires both signer and verifier to verify the authenticity of the public keys, and hence, the certificates are required. In contrast to the previous constructions, in this paper, we propose the first notion and construction of the certificateless designated verifier signature scheme. In our new notion, the necessity of certificates are eliminated. We show that our scheme satisfies all the requirements of the designated verifier signature schemes in the certificateless system. We also provide complete security proofs for our scheme and prove that our scheme is unforgeable under the assumption of the gap bilinear Diffie-Hellman problem in the random oracle model
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang
AINA (2)3
2006 Zero-Knowledge Proof of Generalized Compact Knapsacks (or A Novel Identification/Signature Scheme)
Qianhong Wu, Willy Susilo, Yi Mu 0001, Yumin Wang
ATC4
2006 Efficient Signcryption Without Random Oracles
Qianhong Wu, Yi Mu 0001, Willy Susilo, Fangguo Zhang
ATC2
2006 Designated group credentials
abstract
Consider a situation where a secret agent wants to authenticate herself to the other secret agents. This secret agent must be able to convince the others of her identity. She cannot convince any other people other than those predetermined secret agents. This is to avoid problems that might occur if this secret agent would like to ‘betray’ her group. On the whole we would like to allow the agent to convince a predetermined group of people by showing that she holds a credential and so she is a member of the group. However we would like to prohibit this agent from convincing any other people outside the group. We also need to ensure that the party who has been convinced by the credential cannot use this information to convince any third party. We call this type of scheme as Designated Group Credential. In this paper, we first show a model of designated group credential systems followed by an efficient construction based on pairing-based cryptography. We also provide security proof of our scheme based on the random oracle model.
Ching Yu Ng, Willy Susilo, Yi Mu 0001
AsiaCCS3
2006 Efficient Partially Blind Signatures with Provable Security
Qianhong Wu, Willy Susilo, Yi Mu 0001, Fangguo Zhang
ICCSA (3)3
2006 Universal Designated Verifier Signature Without Delegatability
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Wei Wu 0001
ICICS3
2006 Short (Identity-Based) Strong Designated Verifier Signature Schemes
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang
ISPEC3
2006 Privately Retrieve Data from Large Databases
Qianhong Wu, Yi Mu 0001, Willy Susilo, Fangguo Zhang
ISPEC2
2006 Three-Round Secret Handshakes Based on ElGamal and DSA
Willy Susilo, Yi Mu 0001
ISPEC3
2006 Identity-based anonymous designated ring signatures
abstract
In this paper, we propose the concept of identity-based anonymous designated ring signature. This concept extends the existing notion of ring signatures in two ways: firstly, it allows a member from the ring to sign a message directed to a designated verifier, but secondly, we would like to have an anonymous designated verifier. At a glance, these two additional properties seem contradictory, but we shall show an example of situation where this kind of primitive is required. We present a formal model of such a scheme, and proceed with a construction based on bilinear pairings. Our scheme is provably secure under the random oracle model.
Willy Susilo, Yi Mu 0001
IWCMC3
2006 Proxy Signature Without Random Oracles
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Wei Wu 0001
MSN3
2006 Efficient ID-Based Authenticated Group Key Agreement from Bilinear Pairings
Willy Susilo, Yi Mu 0001
MSN3
2006 Restricted Universal Designated Verifier Signature
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang
UIC3
2005 On the Security of Nominative Signatures
Willy Susilo, Yi Mu 0001
ACISP2
2005 Identity-Based Ring Signcryption Schemes: Cryptographic Primitives for Preserving Privacy and Authenticity in the Ubiquitous World
abstract
In this paper, we present a new concept called an identity based ring signcryption scheme (IDRSC,). We argue that this is an important cryptographic primitive that must be used to protect privacy and authenticity of a collection of users who are connected through an ad-hoc network, such as Bluetooth. We also present an efficient IDRSC scheme based on bilinear pairing. As a regular signcryption scheme, our scheme combines the functionality of signature and encryption schemes. However, the idea is to have an identity based system. In our scheme, a user can anonymously sign-crypts a message on behalf of the group. We show that our scheme outperforms a traditional identity based scheme, that is obtained by a standard sign-then-encrypt mechanism, in terms of the length of the ciphertext. We also provide a formal proof of our scheme with the chosen cipher-text security under the decisional bilinear Diffie-Hellman assumption, which is believed to be intractable.
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang
AINA3
2005 Privacy-Enhanced Internet Storage
abstract
One of the main important uses of Internet is its ability to connect people through the use of email or Internet storage. However, it is often desirable to limit the use of email or Internet storage clue to organization's restriction, avoiding spams, etc. In this paper, we propose cryptographic schemes that can be used to stop unwanted messages to be stored in the Internet server. We refer this technique as privacy enhancement for Internet storage, since the Internet server will not learn any information directed to its users, other than performing its task to deliver or stop the messages. Firstly, we describe a notion of non-interactive publicly verifiable 1-out-of-n encryption by proposing a model together with its security requirements. Then, we extend this notion to a publicly verifiable ring-to-1-out-of-n encryption, that provides sender anonymity. We note that the previously known interactive versions of the publicly verifiable 1-out-of-n encryption cannot be used to construct publicly verifiable ring-to-1-out-of-n encryption.
Willy Susilo, Fangguo Zhang, Yi Mu 0001
AINA3
2005 Reducing Security Overhead for Mobile Networks
abstract
Security of mobile communications comes with the cost of computational overhead. Reducing the overhead in security computations is critical to ensure the overall performance of a mobile network. In this paper, we present the notion of online/offline signcryption, where most of computations are carried out offline and the online part of our scheme does not require any exponent computations and therefore is very efficient. Our scheme allows any third party to verify the encryption without compromising confidentiality. We also show that our scheme is secure against existential forgery under chosen message attacks and adaptively chosen ciphertext attacks under the notion of indistinguishability of ciphertext.
Fangguo Zhang, Yi Mu 0001, Willy Susilo
AINA2
2005 On the Security of Certificateless Signature Schemes from Asiacrypt 2003
Xinyi Huang 0001, Willy Susilo, Yi Mu 0001, Futai Zhang
CANS3
2005 Secure AODV Routing Protocol Using One-Time Signature
Shidi Xu, Yi Mu 0001, Willy Susilo
MSN2
2005 Tripartite Concurrent Signatures
Willy Susilo, Yi Mu 0001
SEC2
2004 Identity-Based Strong Designated Verifier Signature Schemes
Willy Susilo, Fangguo Zhang, Yi Mu 0001
ACISP3
2004 Deniable Ring Authentication Revisited
Willy Susilo, Yi Mu 0001
ACNS2
2004 Securing XML Document Sources and Their Distribution
abstract
XML has been becoming popular for data store, document representation and exchange over the Web. Security mechanisms for the protection of XML document sources and their distribution are essential. Author-X is a Java based system specifically conceived for the protection of XML documents. It supports a range of protection granularity levels and subject credentials, but also supports push distribution for documents broadcast. However, the proposed system has certain disadvantages in terms of both security and dynamic key management. For example, a sender has to distribute the secret keys to all correspondent users for different XML documents. Also, if one of the users leave or a credential is changed, then the sender has to re-encrypt all related documents and redistribute the secret keys to all correspondent users. In this paper, we present a scheme for securing XML documents and their distribution. Our scheme has several advantages over Author-X such as: (a) one user needs only one private key; (b) even when the user leaves or a credential is changed, all the other users will be unaffected; (c) there is no need to establish a secure channel for key distribution; and (d) there is no need for checking the XML documents for access control policies applied. These make the security model more efficient and robust as well as simplifying the programming and the generation of the encrypted document base.
Vijay Varadharajan, Yi Mu 0001
AINA (1)3
2004 Perfect Concurrent Signature Schemes
Willy Susilo, Yi Mu 0001, Fangguo Zhang
ICICS2
2004 On the Design of a New Trust Model for Mobile Agent Security
Ching Lin, Vijay Varadharajan, Yan Wang 0002, Yi Mu 0001
TrustBus4
2002 m out of n Oblivious Transfer
Yi Mu 0001, Vijay Varadharajan
ACISP1
2002 A Secure Object Sharing Scheme for Java Card
Vijay Varadharajan, Yi Mu 0001
ICICS3
2000 Fail-Stop Confirmer Signatures
Yi Mu 0001, Vijay Varadharajan
ACISP1
2000 Fair On-line Gambling
abstract
This paper proposes a fair electronic gambling scheme for the Internet. The proposed scheme provides a unique link between payment and gambling outcome so that the winner can be ensured to get the payment. Since an optimal fair exchange method is used in gambling message exchange the proposed system guarantees that no one can successfully cheat during a gambling process. Our system requires an off-line Trusted Third Party (TTP). If a cheating occurs, the TTP can resolve the problem and make the gambling process fair.
Weiliang Zhao, Vijay Varadharajan, Yi Mu 0001
ACSAC3
1999 Divertible Zero-Knowledge Proof of Polynominal Relations and Blind Group Signature
Khanh Quoc Nguyen, Yi Mu 0001, Vijay Varadharajan
ACISP2
1999 Zero-Knowledge Proofs of Possession of Digital Signatures and Its Applications
Khanh Quoc Nguyen, Feng Bao 0001, Yi Mu 0001, Vijay Varadharajan
ICICS3
1999 Delegated Decryption
Yi Mu 0001, Vijay Varadharajan, Khanh Quoc Nguyen
IMACC1
1999 On the Design of Efficient RSA-based Off-line Electronic Cash Schemes
Vijay Varadharajan, Khanh Quoc Nguyen, Yi Mu 0001
Theor. Comput. Sci.3
1998 Anonymous Secure E-Voting Over a Network
abstract
We propose two new anonymous secure electronic voting schemes that protect the privacy of the voters and prevent double voting. These schemes do not require any special voting channel and the communications can occur entirely over existing networks such as the Internet. The proposed schemes are based on the ElGamal digital signature algorithm and can be applied to elections in a variety of situations ranging from an election in a small organization to a country.
Yi Mu 0001, Vijay Varadharajan
ACSAC1
1998 A New Scheme of Credit based Payment for Electronic Commerce
abstract
The paper describes a new credit card system, which presents a promise for us to develop a new method of protecting secret information, such as credit card number, PIN and identification. Our credit cards are anonymous. That is, the identity of a card holder and credit card information are not revealed during a payment process. One important feature of our system lies in the fact that, unlike normal electronic credit based systems such as SET, iKP and NetCard, the involvement of the online financial institution that runs the payment system is reduced to a minimum.
Yi Mu 0001, Vijay Varadharajan
LCN1
1997 New Micropayment Schemes Based on PayWords
Yi Mu 0001, Vijay Varadharajan, Yan-Xia Lin
ACISP1
1997 Micro-Digital Money for Electronic Commerce
abstract
Proposes two novel cash-based micropayment schemes based on a new technique referred to as the double-locked hash chain technique. Both schemes support the divisibility and transferability of digital coins in a simpler way compared to the existing solutions. The basic scheme allows full or partial use of a coin chain in a transaction; if only part of a coin chain has been used with one vendor, the rest of the chain can be used, for instance in a subsequent transaction with another vendor. The modified scheme extends this to multiple chains, making the scheme particularly suitable for a large number of micropayment transactions.
Khanh Quoc Nguyen, Yi Mu 0001, Vijay Varadharajan
ACSAC2
1997 Secure and Efficient Digital Coins
abstract
Current off-line electronic cash systems require a great number of complex online computations by clients during the payment phase. In this paper, we propose a new off-line anonymous cash scheme that greatly reduces the number of online computations that need to be done by the clients for each payment transaction. In particular, except for the first coin in a transaction, the client only needs to perform minimal computations for the remaining coins in the transaction. Our scheme also provides unconditional client anonymity and is able to detect double-spending and is resistant to coin forgery and framing attacks.
Khanh Quoc Nguyen, Yi Mu 0001, Vijay Varadharajan
ACSAC2
1997 A New Efficient Off-line Anonymous Cash Scheme
Khanh Quoc Nguyen, Vijay Varadharajan, Yi Mu 0001
ISAAC3
1996 On the design of security protocols for mobile communications
Yi Mu 0001, Vijay Varadharajan
ACISP1
1996 An alternative model of quantum key agreement via photon coupling
Yi Mu 0001, Yuliang Zheng 0001
ACISP1
1996 On The Design Of Secure Electronic Payment Schemes For Internet
abstract
Considers the design of secure electronic credit card based payment schemes for the Internet, and reveals some of the issues that have not been adequately addressed in the proposed protocols to date. This paper proposes additional mechanisms that need to be incorporated as part of the design phase of the scheme to deal efficiently with the disputes that can arise. The design methods described in this paper are applicable to a range of protocols, including iKP (Internet Kaufmannisch Protokoll), STT (Secure Transaction Technology) and SEPP (Secure Electronic Payment Protocol). Based on this discussion, the paper goes on to propose an improved payment scheme and protocol. The new protocol, referred to as the permission-based payment (PBP) protocol, provides a fair treatment of both the client and the merchant involved in the transaction. It separates the purchase request phase from the payment phase, thereby increasing the ability to handle certain class of disputes more efficiently. It removes the need to store the secret private key at the client's machine or the need for a smart card device. This is important as one cannot assume that all the clients connected to the Internet have smart card readers attached to them. The new protocol makes simpler assumptions about the environment, thereby making the scheme practical for securing commercial electronic credit card transactions.
Vijay Varadharajan, Yi Mu 0001
ACSAC2