Yan Xu 0007

dblp:03/4702-7 · DBLP profile ↗
← Back
41ranked-venue papers
6as first author
19since 2021 · last 2026
0000-0001-7723-8250ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 1 first-author · 4 since 2021Systems, architecture and hardware · 9 · 2 first-author · 7 since 2021Security and privacy · 6 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CAAS-DMSK: A Certificateless Anonymous Authentication Scheme with Dynamic Master Secret Keys in VANETs
Yan Xu 0007, Huilan Zhang, Jie Cui 0004, Hong Zhong 0001
J. Syst. Archit.1
2025 A novel federal learning-based framework defending server-level privacy leakage
Qingren Wang, Chuankai Feng, Yan Xu 0007, Jinqin Zhong, Victor S. Sheng
Expert Syst. Appl.4
2023 LPPA-RCM: A lightweight privacy-preserving authentication scheme for road condition monitoring in fog-based VANETs
Yan Xu 0007, ChongYue Yao, Jie Cui 0004, Hong Zhong 0001
J. Syst. Archit.1
2023 An Efficient Integrity Checking Scheme With Full Identity Anonymity for Cloud Data Sharing
abstract
Cloud storage services can support data sharing for a group of users. However, the cloud server may lose some of the shared data when attacked. The integrity of stored data is a key issue for cloud storage. However, identity anonymity, an important problem in data integrity, has not been fully investigated yet. Furthermore, the existing schemes of data integrity checking are usually based on public key infrastructure and thus have to perform complex certificate management. In this paper, we propose an efficient integrity checking scheme to achieve full identity anonymity. Additionally, the proposed scheme can reduce the workloads of certificate management and simplify key management. Inspired by the idea of attribute-based signature, we devise a common predicate to manage the identities of legitimate users and disable illegal users from joining the data sharing. By adopting the technique of the monotone span program, the legitimate user can compute the valid authenticators of shared data for all attributes in the common predicate without the need of binding his attribute set to the shared data. Whereupon, the user's identity remains anonymous to all parties in the data sharing because he can share the data and authenticators without revealing his attribute set to other parties. The extensive experimental results demonstrate that the proposed scheme has less computational and communication overhead compared with the existing schemes while achieving full identity anonymity.
Yan Xu 0007, Hong Zhong 0001, Jie Cui 0004, Geyong Min
IEEE Trans. Cloud Comput.2
2023 Differentially Private Combinatorial Cloud Auction
abstract
Cloud service providers typically provide different types of virtual machines (VMs) to cloud users with various requirements. Thanks to its effectiveness and fairness,auctionhas been widely applied in this heterogeneous resource allocation. Recently, several strategy-proof combinatorial cloud auction mechanisms have been proposed. However, they fail to protect the bid privacy of users from being inferred from the auction results. In this article, we design adifferentially privatecombinatorial cloud auction mechanism (DPCA) to address this privacy issue. Technically, we employ the exponential mechanism to compute a clearing unit price vector with a probability proportional to the corresponding revenue. We further improve the mechanism to reduce the running time while maintaining high revenues, by computing a single clearing unit price, or a subgroup of clearing unit prices at a time, resulting in the improved mechanisms DPCA-S and its generalized version DPCA-M, respectively. We theoretically prove that our mechanisms can guarantee differential privacy, approximate truthfulness and high revenue. Extensive experimental results demonstrate that DPCA can generate near-optimal revenues at the price of relatively high time complexity, while the improved mechanisms achieve a tunable trade-off between auction revenue and running time.
Tianjiao Ni, Lin Chen 0002, Shun Zhang 0002, Yan Xu 0007, Hong Zhong 0001
IEEE Trans. Cloud Comput.5
2023 Achieving Revocable Attribute Group-Based Encryption for Mobile Cloud Data: A Multi-Proxy Assisted Approach
abstract
Although proxy-assisted revocable attribute-based encryption provides fine-grained privacy protection and reduces the decryption cost of data users, it inherits several disadvantages in outsourcing decryption. The decryption capability in outsourcing decryption is divided into two parts: the outsourcing transformation key and the user decryption key. The proxy server utilizes transformation keys to transform the ciphertext which can only be decrypted by the users who generated the transformation key. When multiple users with the same attributes request outsourcing transformation, the proxy server must do numerous transformation operations, increasing the computing overhead of the proxy server and the user request response time. To address the aforementioned issues, we propose a multi-proxy assisted revocable attribute group-based encryption (MP-RAGBE) scheme. We form a user group out of users who have the same attributes and send the transformation keys directly to the proxy server. Users in the same group can decrypt the transformed ciphertext, and only a small number of transformation keys need to be updated when revocation occurs. The security and experimental analyses show that the proposed scheme meets the defined security requirements while significantly reducing user request response time, the overhead of transformation key generation, transmission, and ciphertext transformation.
Jie Cui 0004, Hong Zhong 0001, Yan Xu 0007, Lu Liu 0001
IEEE Trans. Dependable Secur. Comput.4
2023 Towards Fully Anonymous Integrity Checking and Reliability Authentication for Cloud Data Sharing
abstract
Cloud storage services improve the efficiency and popularity of data sharing. These services allow groups of participants to jointly maintain the shared data. As important security properties of cloud data sharing, the integrity and the reliability of the shared data have been studied recently. However, the existing research cannot sufficiently solve the issue of participant identity anonymity in the scenario of data modification. In this paper, we propose a novel approach to achieve fully anonymous integrity checking and reliability authentication for cloud data sharing. We design a predicate for the shared data, and construct the Lagrange interpolation polynomials for all participants to compute the secret keys based on the designed predicate. When modifying the shared data, the participants compute the authenticators of the modified data using the secret key associated with the designed predicate instead of their identities. In this way, the integrity checking and reliability authentication of the shared data modified by different participants can be performed while the identities of the corresponding participants remain fully anonymous. In addition, the traceability and revocation of participant identity are considered. The performance analysis demonstrates the efficiency of the proposed approach, and the security analysis shows that the proposed approach satisfies the desired properties.
Yan Xu 0007, Hong Zhong 0001, Jie Cui 0004, Kewei Sha
IEEE Trans. Serv. Comput.2
2022 Forward and backward secure searchable encryption with multi-keyword search and result verification
Jie Cui 0004, Yan Xu 0007, Miaomiao Tian 0001, Hong Zhong 0001
Sci. China Inf. Sci.3
2022 Authentication and Key Agreement Based on Anonymous Identity for Peer-to-Peer Cloud
abstract
Cross-cloud data migration is one of the prevailing challenges faced by mobile users, which is an essential process when users change their mobile phones to a different provider. However, due to the insufficient local storage and computational capabilities of the smart phones, it is often very difficult for users to backup all data from the original cloud servers to their mobile phones in order to further upload the downloaded data to the new cloud provider. To solve this problem, we propose an efficient data migration model between cloud providers and construct a mutual authentication and key agreement scheme based on elliptic curve certificate-free cryptography for peer-to-peer cloud. The proposed scheme helps to develop trust between different cloud providers and lays a foundation for the realization of cross-cloud data migration. Mathematical verification and security correctness of our scheme is evaluated against notable existing schemes of data migration, which demonstrate that our proposed scheme exhibits a better performance than other state-of-the-art scheme in terms of the achieved reduction in both the computational and communication cost.
Hong Zhong 0001, Chuanwang Zhang, Jie Cui 0004, Yan Xu 0007, Lu Liu 0001
IEEE Trans. Cloud Comput.4
2022 Proven Secure Tree-Based Authenticated Key Agreement for Securing V2V and V2I Communications in VANETs
abstract
Vehicular ad hoc networks (VANETs) are vulnerable to many kinds of security attacks, so it is necessary to design an authenticated key agreement (AKA) scheme for securing communication channels in VANETs. Existing AKA schemes in VANETs have not provided an efficient and secure method to secure V2V and V2I communications simultaneously while meeting the necessary security and privacy requirements. Further, few key updating mechanisms, which are secure, conditional privacy-preserving, practical, and lightweight, exist in current VANETs AKA schemes. In this paper, we propose a proven secure AKA scheme for securing V2V and V2I communications in VANETs, which can be divided into two parts. The first part is a three-party authentication process in which vehicles, road side unit (RSU), and trust authority (TA) authenticate each other. The second part is the key agreement process, which is used in the key generation and updating processes. For this phase, we design a tree-based key agreement algorithm that considers two scenarios, i.e., the joining of an authenticated vehicle and the leaving of the vehicle. The formal security proof and the security analysis show that our proposed scheme satisfies session key security and the necessary security requirements in VANETs, respectively. The performance analysis demonstrates that our proposed scheme has an advantage over several representative AKA schemes in VANETs.
Lu Wei 0003, Jie Cui 0004, Hong Zhong 0001, Yan Xu 0007, Lu Liu 0001
IEEE Trans. Mob. Comput.4
2022 A Practical and Efficient Bidirectional Access Control Scheme for Cloud-Edge Data Sharing
abstract
The cloud computing paradigm provides numerous tempting advantages, enabling users to store and share their data conveniently. However, users are naturally resistant to directly outsourcing their data to the cloud since the data often contain sensitive information. Although several fine-grained access control schemes for cloud-data sharing have been proposed, most of them focus on the access control of the encrypted data (e.g., restricting the decryption capabilities of the receivers). Distinct from the existing work, this article aims to address this challenging problem by developing a more practical bidirectional fine-grained access control scheme that can restrict the capabilities of both senders and receivers. To this end, we systematically investigate the access control for cloud data sharing. Inspired by the access control encryption (ACE), we propose a novel data sharing framework that combines the cloud side and the edge side. The edge server is located in the middle of all the communications, checking and preventing illegal communications according to the predefined access policy. Next, we develop an efficient access control algorithm by exploiting the attribute-based encryption and proxy re-encryption for the proposed framework. The experimental results show that our scheme exhibits superior performance in the encryption and decryption compared to the prior work.
Jie Cui 0004, Hong Zhong 0001, Geyong Min, Yan Xu 0007, Lu Liu 0001
IEEE Trans. Parallel Distributed Syst.5
2021 Assessing Profit of Prediction for SDN controllers load balancing
Hong Zhong 0001, Jinpeng Fan, Jie Cui 0004, Yan Xu 0007, Lu Liu 0001
Comput. Networks4
2021 Fair auctioning and trading framework for cloud virtual machines based on blockchain
Yan Xu 0007, Miaomiao Tian 0001, Hong Zhong 0001
Comput. Commun.3
2021 IBEET-AOK: ID-based encryption with equality test against off-line KGAs for cloud medical services
Yan Xu 0007, Hong Zhong 0001, Sheng Zhong 0002
Frontiers Comput. Sci.1
2021 An efficient and outsourcing-supported attribute-based access control scheme for edge-enabled smart healthcare
Hong Zhong 0001, Yiyuan Zhou, Qingyang Zhang 0001, Yan Xu 0007, Jie Cui 0004
Future Gener. Comput. Syst.4
2021 Leveraging Semisupervised Hierarchical Stacking Temporal Convolutional Network for Anomaly Detection in IoT Communication
abstract
The rapid development of the Internet of Things (IoT) accumulates a large number of communication records, which are utilized for anomaly detection in IoT communication. However, only a small part of these records can be labeled, which increases the difficulty in anomaly detection. This article proposes a semisupervised hierarchical stacking temporal convolutional network (HS-TCN), which is the first semisupervised model for anomaly detection in IoT communication, and it can train unlabeled data based on a small number of labeled data. Furthermore, HS-TCN fully considers the features of streaming data in IoT communication and can weed out uncertain records. Finally, the experimental results demonstrate that HS-TCN promotes the performance of anomaly detection and attains better efficiency.
Yongliang Cheng, Yan Xu 0007, Hong Zhong 0001
IEEE Internet Things J.2
2021 Secure and Lightweight Conditional Privacy-Preserving Authentication for Securing Traffic Emergency Messages in VANETs
abstract
Owing to the development of wireless communication technology and the increasing number of automobiles, vehicular ad hoc networks (VANETs) have become essential tools to secure traffic safety and enhance driving convenience. It is necessary to design a conditional privacy-preserving authentication (CPPA) scheme for VANETs because of their vulnerability and security requirements. Traditional CPPA schemes have two deficiencies. One is that the communication or storage overhead is not sufficiently low, but the traffic emergency message requires an ultra-low transmission delay. The other is that traditional CPPA schemes do not consider updating the system secret key (SSK), which is stored in an unhackable Tamper Proof Device (TPD), whereas side-channel attack methods and the wide usage of the SSK increase the probability of breaking the SSK. To solve the first issue, we propose a CPPA signature scheme based on elliptic curve cryptography, which can achieve message recovery and be reduced to elliptic curve discrete logarithm assumption, so that traffic emergency messages are secured with ultra-low communication overhead. To solve the second issue, we design an SSK updating algorithm, which is constructed on Shamir's secret sharing algorithm and secure pseudo random function, so that the TPDs of unrevoked vehicles can update SSK securely. Formal security proof and analysis show that our proposed scheme satisfies the security and privacy requirements of VANETs. Performance analysis demonstrates that our proposed scheme requires less storage size and has a lower transmission delay compared with related schemes.
Lu Wei 0003, Jie Cui 0004, Yan Xu 0007, Jiujun Cheng, Hong Zhong 0001
IEEE Trans. Inf. Forensics Secur.3
2021 SMAKA: Secure Many-to-Many Authentication and Key Agreement Scheme for Vehicular Networks
abstract
With the rising popularity of the Internet and communication technology, vehicles can analyze and judge the real-time data collected by various cloud service providers (CSPs) in a vehicular network. However, in a vehicular network environment, real-time data are transmitted via wireless channels, which can lead to security and privacy issues. To avoid illegal access by adversaries, vehicle authentication and key agreement mechanism has been considered as one of the promising security measures in vehicular network environments. Besides, most of the solutions focus on authentication between one vehicle and one CSP. In such strategies, the implementation of efficient authentication for multiple vehicles and CSPs simultaneously is usually challenging. Further, they are also subjected to performance limitations due to the overhead incurred. To solve these issues, we propose a many-to-many authentication and key agreement scheme for secure authentication between multiple vehicles and CSPs. The proposed scheme can prevent unauthorized access and provide SK-security even if temporary information is leaked. To improve the service, the CSP only needs to broadcast an anonymous message periodically instead of having to generate a unique anonymous message for each of vehicles. Similarly, when a vehicle wants to request the services of m CSPs, it only needs to send one request message instead of m. Therefore, the proposed scheme not only implements many-to-many communication but also significantly reduces the computation and communication overhead. Moreover, a thorough security analysis shows that the proposed scheme provides better security compared to other related schemes.
Jing Zhang 0024, Hong Zhong 0001, Jie Cui 0004, Yan Xu 0007, Lu Liu 0001
IEEE Trans. Inf. Forensics Secur.4
2021 QoS-Aware Multicast for Scalable Video Streaming in Software-Defined Networks
abstract
Scalable Video Coding (SVC) is a promising coding technique that enables flexible video transmission to support heterogeneous devices. However, the current best-effort delivery model characterized by the Internet cannot fully exploit the scalability feature of SVC because the network nodes are transparent for multimedia streaming applications. Software-defined networking (SDN) has emerged as an innovative network paradigm that decouples the control and forwarding planes while routing. This architecture with the OpenFlow protocol enables network operators to obtain per-flow QoS control in a more scalable, flexible, and finely granular manner compared to the conventional network architecture. Inspired by these facts, this paper designs a comprehensive QoS-aware multicast scheme for scalable video streaming over SDN networks. First, we present the designed multimedia streaming multicast system architecture and formulate the QoS-aware multicast routing problem as a non-linear programming model. We then propose a fundamental tree construction algorithm that decomposes the video streaming requests into subrequests and serves them in a bottom-up manner. Furthermore, we design a layer switching strategy based on the video distortion model to mitigate network-induced video quality distortion. Finally, the experimental results are presented to validate the performance of our methods in terms of scalability, network utility, video playout quality, and playback interruption ratio.
Hong Zhong 0001, Yan Xu 0007, Jie Cui 0004
IEEE Trans. Multim.3
2020 PrivGMM: Probability Density Estimation with Local Differential Privacy
Xinrong Diao, Wei Yang 0011, Shaowei Wang 0003, Liusheng Huang, Yan Xu 0007
DASFAA (1)5
2020 LPE-RCM: Lightweight Privacy-Preserving Edge-Based Road Condition Monitoring for VANETs
Yan Xu 0007, Jie Cui 0004, Jing Zhang 0024, Hong Zhong 0001
WASA (2)1
2020 Two-stage index-based central keyword-ranked searches over encrypted cloud data
Hong Zhong 0001, Zhanfei Li, Yan Xu 0007, Jie Cui 0004
Sci. China Inf. Sci.3
2020 An Extensible and Effective Anonymous Batch Authentication Scheme for Smart Vehicular Networks
abstract
In recent years, research on the security of Industry 4.0 and the Internet of Things (IoT) has attracted a close attention from industry, government, and the scientific community. Smart vehicular networks, as a type of industrial IoT, inevitably exchange large amounts of security and privacy-sensitive data, which make them attractive targets for attackers. For protecting network security and privacy, we have proposed an extensible and effective anonymous batch authentication scheme. In contrast to traditional pseudonym authentication schemes, the same system private key need not to be preloaded in our scheme, effectively avoiding a system failure when destroying a vehicle. Besides, the certificate revocation list (CRL) size is merely related to the number of vehicles that have been revoked, regardless of the number of pseudonym certificates for revoked vehicles. Moreover, this scheme maintains the effectiveness of the traditional scheme, effectively reduces the scale of the CRL, and employs an identity revocation scheme that supports rapid distribution. The scheme supports conditional privacy protection, namely, only the trusted authority (TA) can uniquely trace and revoke vehicles. For illegal vehicles, the TA releases the two hashed seeds to facilitate traceability by all entities in its domain. Furthermore, security analysis indicates that our solution is secure under the random oracle model and fulfills a series of security requirements of vehicular networks. Compared to existing authentication schemes, performance evaluations show that the scheme offers relatively good performance in terms of time consumption.
Jing Zhang 0024, Hong Zhong 0001, Jie Cui 0004, Yan Xu 0007, Lu Liu 0001
IEEE Internet Things J.4
2020 Intrusion-resilient public cloud auditing scheme with authenticator update
Yan Xu 0007, Jie Cui 0004, Hong Zhong 0001
Inf. Sci.1
2020 Edge Computing in VANETs-An Efficient and Privacy-Preserving Cooperative Downloading Scheme
abstract
With the advancements in social media and rising demand for real traffic information, the data shared in vehicular ad hoc networks (VANETs) indicate that the size and amount of requested data will continue increasing. Vehicles in the same area often have similar data downloading requests. If we ignore the common requests, the resource allocation efficiency of the VANET system will be quite low. Motivated by this fact, we propose an efficient and privacy-preserving data downloading scheme for VANETs, based on the edge computing concept. In the proposed scheme, a roadside unit (RSU) can find the popular data by analyzing the encrypted requests sent from nearby vehicles without having to sacrifice the privacy of their download requests. Further, the RSU caches the popular data in nearby qualified vehicles called edge computing vehicles (ECVs). If a vehicle wishes to download the popular data, it can download it directly from the nearby ECVs. This method increases the downloading efficiency of the system. The security analysis results show that the proposed scheme can resist multiple security attacks. The performance analysis results demonstrate that our scheme has reasonable computation and communication overhead. Finally, the OMNeT++ simulation results indicate that our scheme has good network performance.
Jie Cui 0004, Lu Wei 0003, Hong Zhong 0001, Jing Zhang 0024, Yan Xu 0007, Lu Liu 0001
IEEE J. Sel. Areas Commun.5
2019 RTEF-PP: A Robust Trust Evaluation Framework with Privacy Protection for Cloud Services Providers
Hong Zhong 0001, JianZhong Zou, Jie Cui 0004, Yan Xu 0007
ICA3PP (1)4
2019 HS-TCN: A Semi-supervised Hierarchical Stacking Temporal Convolutional Network for Anomaly Detection in IoT
abstract
The rapid development of Internet of Things (IoT) accumulates lots of communication data. Not being processed in time, these massive data increase the difficulty of anomaly detection for smart service. Furthermore, labeling all communication data is unpractical. Therefore, it is necessary to accomplish some feasible ways which can incorporate unlabeled data effectively. In recent years, Temporal Convolutional Network (TCN) has been proposed to solve sequence problems and got better performance compared to Recurrent Neural Network (RNN) in most cases. This paper proposes a semi-supervised hierarchical stacking TCN for the first time, which concentrates on the anomaly detection of the communication in smart home. The ideology of hierarchical model fully considers the features of streaming data in smart home scenario, and the stacking method is used to weed out the outliers. In this way, the detection accuracy can be highly improved. Finally, experimental results demonstrate that the proposed model can promote the security of the communication in smart home with a large extent as well as get much better performance.
Yongliang Cheng, Yan Xu 0007, Hong Zhong 0001
IPCCC2
2019 OOABKS: Online/offline attribute-based encryption for keyword search in mobile cloud
Jie Cui 0004, Yan Xu 0007, Hong Zhong 0001
Inf. Sci.3
2019 Privacy-preserving authentication scheme with full aggregation in VANET
Hong Zhong 0001, Shunshun Han, Jie Cui 0004, Jing Zhang 0024, Yan Xu 0007
Inf. Sci.5
2019 SCPLBS: a smart cooperative platform for load balancing and security on SDN distributed controllers
Hong Zhong 0001, Jianqiao Sheng, Yan Xu 0007, Jie Cui 0004
Peer-to-Peer Netw. Appl.3
2019 An Efficient Message-Authentication Scheme Based on Edge Computing for Vehicular Ad Hoc Networks
abstract
With the progress in wireless communication technology and the increasing number of vehicles, vehicular ad hoc networks (VANETs) have become essential for improving road conditions and enhancing driving experience. The core of the VANETs is the communication between different vehicles, and the security of the communication is based on message authentication. Several schemes have been designed to enhance the efficiency of message authentication. However, these schemes have the disadvantage of redundant authentication, i.e., repeated authentication of the same message, and fail to seek invalid messages from the batch of messages. To solve these problems, this paper introduces a novel edge-computing concept into the message-authentication process of VANETs. In our scheme, the roadside unit can efficiently authenticate messages from nearby vehicles and broadcast the authentication results to the vehicles within its communication range, thereby reducing redundant authentication and enhancing the efficiency of the entire system. The security analysis results show that the proposed scheme satisfies the security requirements of the VANETs. The performance analysis results show that the proposed scheme can not only work well in an ideal environment where the attacker is absent but also capable of quickly identifying valid and invalid messages even if the VANET is attacked.
Jie Cui 0004, Lu Wei 0003, Jing Zhang 0024, Yan Xu 0007, Hong Zhong 0001
IEEE Trans. Intell. Transp. Syst.4
2018 TDDAD: Time-Based Detection and Defense Scheme Against DDoS Attack on SDN Controller
Jie Cui 0004, Jiantao He, Yan Xu 0007, Hong Zhong 0001
ACISP3
2018 Intrusion-Resilient Public Auditing Protocol for Data Storage in Cloud Computing
Yan Xu 0007, Jie Cui 0004, Hong Zhong 0001
ACISP1
2018 Transaction-Based Flow Rule Conflict Detection and Resolution in SDN
abstract
Software-defined Networking (SDN) brings new vitality to traditional network technology as its nice property of network programmability makes our network more open and flexible. By using interfaces of SDN controllers, different applications with diverse network functions can deploy their needed flow rules into SDN switches. However, some of these flow rules would probably produce conflicts that result in invalidation of network functions and cause security issues. To address this issue, we design a novel approach, Transaction-based flow rule Conflict Detection and Resolution (TCDR), which can isolate the flow rules of different network functions to avoid interference between different network functions. Meanwhile, our proposed method introduces a transaction-based authentication to guarantee the legality of flow rules. Finally, we implement a prototype of our solution, and evaluate its effectiveness and efficiency. The performance evaluation shows that TCDR can reject illegal flow rules and avoid many flow rule conflicts with a small overhead.
Jie Cui 0004, Hong Zhong 0001, Yan Xu 0007, Kewei Sha
ICCCN4
2018 An efficient certificateless aggregate signature without pairings for vehicular ad hoc networks
Jie Cui 0004, Jing Zhang 0024, Hong Zhong 0001, Yan Xu 0007
Inf. Sci.5
2018 AKSER: Attribute-based keyword search with efficient revocation in cloud computing
Jie Cui 0004, Hong Zhong 0001, Yan Xu 0007
Inf. Sci.4
2018 An efficient and secure recoverable data aggregation scheme for heterogeneous wireless sensor networks
Hong Zhong 0001, Lili Shao, Jie Cui 0004, Yan Xu 0007
J. Parallel Distributed Comput.4
2018 Data aggregation with end-to-end confidentiality and integrity for large-scale wireless sensor networks
abstract
In wireless sensor networks, data aggregation allows in-network processing, which leads to reduced packet transmissions and reduced redundancy, and thus is helpful to prolong the overall lifetime of wireless sensor networks. In current studies, Elliptic Curve ElGamal homomorphic encryption algorithm has been widely used to protect end-to-end data confidentiality. However, these works suffer from the expensive mapping function during decryption. If the aggregated results are huge, the base station has no way to gain the original data due to the hardness of the elliptic curve discrete logarithm problem. Therefore, these schemes are unsuitable for the large-scale WSNs. In this paper, we propose a secure energy-saving data aggregation scheme designed for the large-scale WSNs. We employ Okamoto-Uchiyama homomorphic encryption algorithm to protect end-to-end data confidentiality, use MAC to achieve in-network false data filtering, and utilize the homomorphic MAC algorithm to achieve end-to-end data integrity. Two popular IEEE 802.15.4-compliant wireless sensor network platforms, Tmote Sky and iMote 2 have been used to evaluate the efficiency and feasibility of our scheme. The results demonstrate that our scheme achieved better performance in reducing energy consumption. Moreover, system delay, especially decryption delay at the base station, has been reduced when compared to other state-of-art methods.
Jie Cui 0004, Lili Shao, Hong Zhong 0001, Yan Xu 0007, Lu Liu 0001
Peer-to-Peer Netw. Appl.4
2018 Multi-authority attribute-based encryption access control scheme with policy hidden for cloud storage
Hong Zhong 0001, Yan Xu 0007, Jie Cui 0004
Soft Comput.3
2017 Secure, efficient and practical double spectrum auction
abstract
Truthful spectrum auction is believed to be an effective method for spectrum redistribution. However, privacy concerns have largely hampered the practical applications of truthful spectrum auctions. In this paper, to make the applications of double spectrum auctions practical, we present a secure, efficient and practical double spectrum auction design, SDSA. Specifically, by combining three security techniques: homomorphic encryption, secret sharing and garbled circuits, we design a secure two-party protocol computing a socially efficient double spectrum auction, TDSA, without leaking any information about sellers' requests or buyers' bids beyond the auction outcome. We give the formal security definition in our context, and theoretically prove the security that our design achieves. Experimental results show that our design is efficient and practical even for large-scale double spectrum auctions.
Xuemei Wei, Hong Zhong 0001, Jie Cui 0004, Yan Xu 0007, Shun Zhang 0002
IWQoS5
2016 Efficient extensible conditional privacy-preserving authentication scheme supporting batch verification for VANETs
abstract
Abstract By using pseudo‐identity‐based signature, a conditional privacy‐preserving authentication scheme was proposed in this paper, called EECB, to solve the anonymous authentication issue in vehicular ad hoc networks. In this scheme, pseudo‐identities and the corresponding private keys are generated by the private key generator alone, which is credible and independent. So only Adding private key generators can satisfy the increasing pseudo‐identities demand. In other words, it has achieved the extensible of the scheme. However, the malicious vehicle can only be traced by trust authority. Furthermore, the protocol supports batch verification and the operation of a signature verification only needs two bilinear pairings and some point multiplication. The security of the signature scheme in EECB can be proved to be equivalent to the standard computational Diffie–Hellman problem in the random oracle. The experiment and the analysis indicated that, compared with the existing well‐known schemes, EECB has higher authentication efficiency and less communication cost. Copyright © 2017 John Wiley & Sons, Ltd.
Yimin Wang 0004, Hong Zhong 0001, Yan Xu 0007, Jie Cui 0004, Fuchun Guo
Secur. Commun. Networks3