EDBT 2026 Demo / reviewers in the wild / expert
Boyang Wang 0001
dblp:05/11538-1
· DBLP profile ↗
36ranked-venue papers
18as first author
8since 2021 · last 2025
0000-0001-8973-2328ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 7 first-author · 4 since 2021Computer networks · 10 · 4 first-author · 3 since 2021Systems, architecture and hardware · 6 · 4 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Mitigating Data Poisoning Attacks to Local Differential PrivacyabstractThe distributed nature of local differential privacy (LDP) invites data poisoning attacks and poses unforeseen threats to the underlying LDP-supported applications. In this paper, we propose a comprehensive mitigation framework for popular frequency estimation, which contains a suite of novel defenses, including malicious user detection, attack pattern recognition, and damaged utility recovery. In addition to existing attacks, we explore new adaptive adversarial activities for our mitigation design. For detection, we present a new method to precisely identify bogus reports, and thus LDP aggregation can be performed over the ''clean'' data. When the attack behavior becomes stealthy and direct filtering out malicious users is difficult, we further propose a detection that can effectively recognize hidden adversarial patterns, thus facilitating the decision-making of service providers. These detection methods require no additional data or attack information and incur minimal computational cost. Our experiment demonstrates their excellent performance and substantial improvement over previous work in various settings. In addition, we conduct an empirical analysis of LDP post-processing for corrupted data recovery and propose a new post-processing method, through which we reveal new insights into protocol recommendations in practice and key design principles for future research. Xiaolin Li 0015, Ninghui Li 0001, Boyang Wang 0001, Wenhai Sun |
CCS | 3 |
| 2024 | A Second Look at the Portability of Deep Learning Side-Channel Attacks over EM TracesabstractDeep learning side-channel attacks can recover encryption keys on a target by analyzing power consumption or electromagnetic (EM) signals. However, they are less portable when there are domain shifts between training and test data. While existing studies have shown that pre-processing and unsupervised domain adaptation can enhance the portability of deep learning side-channel attacks given domain shifts over EM traces, the findings are limited to easy targets (e.g. 8-bit microcontrollers). Mabon Ninan, Evan Nimmo, Shane Reilly, Channing Smith, Wenhai Sun, Boyang Wang 0001, John Marty Emmert |
RAID | 6 |
| 2023 | Portability of Deep-Learning Side-Channel Attacks against Software DiscrepanciesabstractDeep-learning side-channel attacks can reveal encryption keys on a device by analyzing power consumption with neural networks. However, the portability of deep-learning side-channel attacks can be affected when training data (from the training device) and test data (from the test device) are discrepant. Recent studies have examined the portability of deep-learning side-channel attacks against hardware discrepancies between two devices. In this paper, we investigate the portability of deep-learning side-channel attacks against software discrepancies between the training device and test device. Specifically, we examine four factors that can lead to software discrepancies, including random delays, instruction rewriting, optimization levels, and code obfuscation. Our experimental results show that software discrepancies caused by each factor can significantly downgrade the attack performance of deep-learning side-channel attacks, and even prevent an attacker from recovering keys. To mitigate the impacts of software discrepancies, we investigate three mitigation methods, including adjusting Points of Interest, domain adaptation, and multi-domain training, from the perspective of an attacker. Our results indicate that multi-domain training is the most effective approach among the three, but it can be difficult to scale given the diversity of software discrepancies. Mabon Ninan, Shane Reilly, Joel Ward, William Hawkins 0001, Boyang Wang 0001, John Marty Emmert |
WISEC | 6 |
| 2023 | FastReach: A system for privacy-preserving reachability queries over location data
Hanyu Quan, Boyang Wang 0001, Ming Li 0003, Iraklis Leontiadis |
Comput. Secur. | 2 |
| 2022 | AdvTraffic: Obfuscating Encrypted Traffic with Adversarial ExamplesabstractWebsite fingerprinting can reveal which sensitive website a user visits over encrypted network traffic. Obfuscating encrypted traffic, e.g., adding dummy packets, is considered as a primary approach to defend against website fingerprinting. How-ever, existing defenses relying on traffic obfuscation are either ineffective or introduce significant overheads. As recent website fingerprinting attacks heavily rely on deep neural networks to achieve high accuracy, producing adversarial examples could be utilized as a new way to obfuscate encrypted traffic. Unfortunately, existing adversarial example algorithms are designed for images and do not consider unique challenges for network traffic.In this paper, we design a new method, named AdvTraffic, which can customize perturbations produced by any existing adversarial example algorithm on images and derive adversarial examples over encrypted traffic. Our experimental results show that the integration of AdvTraffic, particularly with Generative Adversarial Networks, can effectively mitigate the accuracy of website fingerprinting from 95.0% to 10.2%, even if an attacker retrains a classifier with defended traffic. Compared to other defenses, our method outperforms most of them in mitigating attack accuracy and offers the lowest bandwidth overhead. Jimmy Dani, Hongkai Yu, Wenhai Sun, Boyang Wang 0001 |
IWQoS | 5 |
| 2022 | QuickN: Practical and Secure Nearest Neighbor Search on Encrypted Large-Scale DataabstractIn this article, we propose a scheme, named QuickN, which can efficiently and securely enable nearest neighbor search over encrypted data on untrusted clouds. Specifically, we modify the search algorithm of nearest neighbors in tree structures (e.g., R-trees), such that the modified algorithm adapts to lightweight cryptographic primitives (e.g., Order-Preserving Encryption) without affecting the original faster-than-linear search complexity. Moreover, we propose an optimized algorithm on top of our modified search algorithm, where it can significantly save communication overheads of a client without introducing any additional information leakage. We devise an approximate algorithm to$k$-nearest neighbor search to improve search efficiency by taking a tradeoff in the completeness of search results. In addition, we also demonstrate our design only leaks minimal privacy against advanced inference attacks. Our experimental results on Amazon EC2 show that our algorithms are extremely practical over massive datasets. Boyang Wang 0001, Yantian Hou, Ming Li 0003 |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | Eclipse: Preserving Differential Location Privacy Against Long-Term Observation AttacksabstractMechanisms built upon geo-indistinguishability render location privacy, where a user can submit obfuscated locations to Location-Based Service providers but still be able to correctly utilize services. However, these mechanisms are vulnerable under inference attacks. Particularly, with background knowledge of a user’s obfuscated locations, an attacker can infer actual locations by carrying out long-term observation attacks. Unfortunately, how to defend long-term observation attacks in the field of differential location privacy remains open. In this paper, we first demonstrate the vulnerabilities of existing mechanisms under long-term observation attacks. In light of these vulnerabilities, we devise a novel mechanism, referred to as Eclipse, which bridges the gap between location protection and usability of services. Specifically, we harness geo-indistinguishability and$k$-anonymity to obfuscate locations and hide each location based on an anonymity set. As a result, our mechanism effectively perturbs the distribution of locations and suppresses leakage under long-term observation attacks. Moreover, the set of possible outputs is utilized to minimize the impacts to usability and correctness. We formally define and rigorously prove the security of the proposed mechanism by leveraging differential privacy. Moreover, we implement the proposed mechanism and conduct a series of experiments on real-world datasets to demonstrate its efficacy and efficiency. Ben Niu 0001, Yahong Chen, Zhibo Wang 0001, Fenghua Li 0001, Boyang Wang 0001, Hui Li 0006 |
IEEE Trans. Mob. Comput. | 5 |
| 2021 | AdaPDP: Adaptive Personalized Differential PrivacyabstractUsers usually have different privacy demands when they contribute individual data to a dataset that is maintained and queried by others. To tackle this problem, several personalized differential privacy (PDP) mechanisms have been proposed to render statistical information of the entire dataset without revealing individual privacy. However, existing mechanisms produce query results with low accuracy, which leads to poor data utility. This is primarily because (1) some users are over protected; (2) utility is not explicitly included in the design objective. Poor data utility impedes the adoption of PDP in the real-world applications. In this paper, we present an adaptive personalized differential privacy framework, called AdaPDP. Specifically, to maximize data utility in different cases, AdaPDP adaptively selects underlying noise generation algorithms and calculates the corresponding parameters based on the type of query functions, data distributions and privacy settings. In addition, AdaPDP performs multiple rounds of utility-aware sampling to satisfy different privacy requirements for users. Our privacy analysis shows that the proposed framework renders rigorous privacy guarantee. We conduct extensive experiments on synthetic and real-world datasets to demonstrate the much less utility losses of the proposed framework over various query functions. Ben Niu 0001, Yahong Chen, Boyang Wang 0001, Zhibo Wang 0001, Fenghua Li 0001, Jin Cao 0001 |
INFOCOM | 3 |
| 2020 | Data inference from encrypted databases: a multi-dimensional order-preserving matching approachabstractDue to increasing concerns of data privacy, databases are being encrypted before they are stored on an untrusted server. To enable search operations on the encrypted data, searchable encryption techniques have been proposed. Representative schemes use order-preserving encryption (OPE) for supporting efficient Boolean queries on encrypted databases. Yet, recent works showed the possibility of inferring plaintext data from OPE-encrypted databases, merely using the order-preserving constraints, or combined with an auxiliary plaintext dataset with similar frequency distribution. So far, the effectiveness of such attacks is limited to single-dimensional dense data (most values from the domain are encrypted), but it remains challenging to achieve it on high-dimensional datasets (e.g., spatial data), which are often sparse in nature. In this paper, for the first time, we study data inference attacks on multi-dimensional encrypted databases (with 2-D as a special case). We formulate it as a 2-D order-preserving matching problem and explore both unweighted and weighted cases, where the former maximizes the number of points matched using only order information and the latter further considers points with similar frequencies. We prove that the problem is NP-hard, and then propose a greedy algorithm, along with a polynomial-time algorithm with approximation guarantees. Experimental results on synthetic and real-world datasets show that the data recovery rate is significantly enhanced compared with the previous 1-D matching algorithm. Yanjun Pan 0001, Alon Efrat, Ming Li 0003, Boyang Wang 0001, Hanyu Quan, Joseph S. B. Mitchell, Jie Gao 0001, Esther M. Arkin |
MobiHoc | 4 |
| 2020 | SmartSwitch: Efficient Traffic Obfuscation Against Stream Fingerprinting
Ben Niu 0001, Boyang Wang 0001 |
SecureComm (1) | 3 |
| 2020 | Utility-aware Exponential Mechanism for Personalized Differential PrivacyabstractPersonalized Differential Privacy (PDP) was proposed to satisfy users' different privacy requirements. However, most of the existing PDP mechanisms may significantly destroy the utility of released statistical results. Differentially private statistical results with poor utility may mislead the data analysts, thus it may even decrease the acceptability of the technique used to protect data privacy. Therefore, in this paper, our goal is to pursue higher data utility while satisfying personalized differential privacy. To achieve this goal, we propose the Utility-aware Personalized Exponential Mechanism (UPEM) to effectively achieve PDP while pursuing better utility. UPEM distinguishes the different possible results with the same personalized score, which is used in Personalized Exponential Mechanism (PEM) [1]. PEM considers the personalized privacy budgets of changing elements to achieve PDP. Based on PEM, our UPEM further considers the quantitative changes of these changing tuples to enhance the utility. We confirm the effectiveness and efficiency of UPEM through extensive experiments. Ben Niu 0001, Yahong Chen, Boyang Wang 0001, Jin Cao 0001, Fenghua Li 0001 |
WCNC | 3 |
| 2020 | Fingerprinting encrypted voice traffic on smart speakers with deep learningabstractThis paper investigates the privacy leakage of smart speakers under an encrypted traffic analysis attack, referred to as voice command fingerprinting. In this attack, an adversary can eavesdrop both outgoing and incoming encrypted voice traffic of a smart speaker, and infers which voice command a user says over encrypted traffic. We first built an automatic voice traffic collection tool and collected two large-scale datasets on two smart speakers, Amazon Echo and Google Home. Then, we implemented proof-of-concept attacks by leveraging deep learning. Our experimental results over the two datasets indicate disturbing privacy concerns. Specifically, compared to 1% accuracy with random guess, our attacks can correctly infer voice commands over encrypted traffic with 92.89% accuracy on Amazon Echo. Sean Kennedy, King Hudson, Gowtham Atluri, Xuetao Wei, Wenhai Sun, Boyang Wang 0001 |
WISEC | 8 |
| 2020 | Toward Practical Privacy-Preserving Frequent Itemset Mining on Encrypted Cloud DataabstractFrequent itemset mining, which is the essential operation in association rule mining, is one of the most widely used data mining techniques on massive datasets nowadays. With the dramatic increase on the scale of datasets collected and stored with cloud services in recent years, it is promising to carry this computation-intensive mining process in the cloud. Amount of work also transferred the approximate mining computation into the exact computation, where such methods not only improve the accuracy also aim to enhance the efficiency. However, while mining data stored on public clouds, it inevitably introduces privacy concerns on sensitive datasets. In this paper, we propose a new framework for enforcing privacy in frequent itemset mining, where data are both collected and mined in an encrypted form in a public cloud service. We specifically design three secure frequent itemset mining protocols on top of this framework. Our first protocol achieves more efficient mining performance while our second protocol provides a stronger privacy guarantee. In order to further optimize the performance of the second protocol, we leverage a minor trade-off of privacy to get our third protocol. Finally, we evaluate the performance of our protocols with extensive experiments, and the results demonstrate that our protocols obviously outperform previous solutions in performance with the same security level. Shuo Qiu, Boyang Wang 0001, Ming Li 0003, Jiqiang Liu, Yanfeng Shi |
IEEE Trans. Cloud Comput. | 2 |
| 2019 | A Behavior-Aware Profiling of Smart Contracts
Xuetao Wei, Fatma Rana Ozcan, Boyang Wang 0001, Di Wu 0002, Qiang Tang 0005 |
SecureComm (2) | 5 |
| 2019 | FastGeo: Efficient Geometric Range Queries on Encrypted Spatial DataabstractSpatial data have wide applications, e.g., location-based services, and geometric range queries (i.e., finding points inside geometric areas, e.g., circles or polygons) are one of the fundamental search functions over spatial data. The rising demand of outsourcing data is moving large-scale datasets, including large-scale spatial datasets, to public clouds. Meanwhile, due to the concern of insider attackers and hackers on public clouds, the privacy of spatial datasets should be cautiously preserved while querying them at the server side, especially for location-based and medical usage. In this paper, we formalize the concept of Geometrically Searchable Encryption, and propose an efficient scheme, named FastGeo, to protect the privacy of clients' spatial datasets stored and queried at a public server. With FastGeo, which is a novel two-level search for encrypted spatial data, an honest-but-curious server can efficiently perform geometric range queries, and correctly return data points that are inside a geometric range to a client without learning sensitive data points or this private query. FastGeo supports arbitrary geometric areas, achieves sublinear search time, and enables dynamic updates over encrypted spatial datasets. Our scheme is provably secure, and our experimental results on real-world spatial datasets in cloud platform demonstrate that FastGeo can boost search time over 100 times. Boyang Wang 0001, Ming Li 0003, Li Xiong 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2018 | Are Friends of My Friends Too Social?: Limitations of Location Privacy in a Socially-Connected WorldabstractWith the ubiquitous adoption of smartphones and mobile devices, it is now common practice for one's location to be sensed, collected and likely shared through social platforms. While such data can be helpful for many applications, users start to be aware of the privacy issue in handling location and trajectory data. While some users may voluntarily share their location information (e.g., for receiving location-based services, or for crowdsourcing systems), their location information may lead to information leaks about the whereabouts of other users, through the co-location of events when two users are at the same location at the same time and other side information, such as upper bounds of movement speed. It is therefore crucial to understand how much information one can derive about other's positions through the co-location of events and occasional GPS location leaks of some of the users. In this paper we formulate the problem of inferring locations of mobile agents, present theoretically-proven bounds on the amount of information that could be leaked in this manner, study their geometric nature, and present algorithms matching these bounds. We will show that even if a very weak set of assumptions is made on trajectories' patterns, and users are not obliged to follow any 'reasonable' patterns, one could infer very accurate estimation of users' locations even if they opt not to share them. Furthermore, this information could be obtained using almost linear-time algorithms, suggesting the practicality of the method even for huge volumes of data. Boris Aronov, Alon Efrat, Ming Li 0003, Jie Gao 0001, Joseph S. B. Mitchell, Valentin Polishchuk, Boyang Wang 0001, Hanyu Quan, Jiaxin Ding 0001 |
MobiHoc | 7 |
| 2018 | Search Ranges Efficiently and Compatibly as Keywords over Encrypted DataabstractWith recent studies in Searchable Symmetric Encryption (SSE), a client can efficiently perform keyword queries over its outsourced data on a remote but untrusted server (e.g., a public cloud), and correctly retrieve associated files without revealing the confidentiality of his/her data. Besides keyword search, many recent schemes also studied range queries on encrypted data, where range search is also one of the most extensively used queries in databases and information retrieval. However, most of these previous works supporting range search are neither efficient nor compatible with existing keyword SSE schemes. In this paper, we propose two range SSE schemes to enable range queries on encrypted data. Both of our schemes are not only efficient, but also highly compatible with existing keyword SSE schemes. Specifically, the search time of our first scheme is extremely efficient when the values in a range query are sparsely presenting in a dataset; while our second design can achieve an optimal token size and significantly save token generation costs. Moreover, we rigorously define and analyze the security of our schemes, and also conduct extensive experiments with a real dataset to demonstrate the performance of our schemes. Boyang Wang 0001, Xinxin Fan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | SecReach: Secure Reachability Computation on Encrypted Location Check-in Data
Hanyu Quan, Boyang Wang 0001, Iraklis Leontiadis, Ming Li 0003, Yuqing Zhang 0001 |
CANS | 2 |
| 2016 | Practical and secure nearest neighbor search on encrypted large-scale dataabstractNearest neighbor search (or k-nearest neighbor search in general) is one of the most fundamental queries on massive datasets, and it has extensive applications such as pattern recognition, statistical classification, graph algorithms, Location-Based Services and online recommendations. With the raising trend of outsourcing massive sensitive datasets to public clouds, it is urgent for companies and organizations to demand fast and secure nearest neighbor search solutions over their outsourced data, but without revealing privacy to untrusted clouds. However, existing solutions for secure nearest neighbor search still face significant limitations, which make them far from practice. In this paper, we propose a new searchable encryption scheme, which can efficiently and securely enable nearest neighbor search over encrypted data on untrusted clouds. Specifically, we modify the search algorithm of nearest neighbors with tree structures (e.g., R-trees), where the modified algorithm adapts to lightweight cryptographic primitives (e.g., Order-Preserving Encryption) without affecting the original faster-than-linear search complexity. As a result, we address all the limitations in the previous works while still maintaining correctness and security. Moreover, our design is general, which can be used for secure k-nearest neighbor search, and it is compatible with other similar tree structures. Our experimental results on Amazon EC2 show that our scheme is extremely practical over massive datasets. Boyang Wang 0001, Yantian Hou, Ming Li 0003 |
INFOCOM | 1 |
| 2016 | Geometric Range Search on Encrypted Spatial DataabstractGeometric range search is a fundamental primitive for spatial data analysis in SQL and NoSQL databases. It has extensive applications in location-based services, computer-aided design, and computational geometry. Due to the dramatic increase in data size, it is necessary for companies and organizations to outsource their spatial data sets to third-party cloud services (e.g., Amazon) in order to reduce storage and query processing costs, but, meanwhile, with the promise of no privacy leakage to the third party. Searchable encryption is a technique to perform meaningful queries on encrypted data without revealing privacy. However, geometric range search on spatial data has not been fully investigated nor supported by existing searchable encryption schemes. In this paper, we design a symmetric-key searchable encryption scheme that can support geometric range queries on encrypted spatial data. One of our major contributions is that our design is a general approach, which can support different types of geometric range queries. In other words, our design on encrypted data is independent from the shapes of geometric range queries. Moreover, we further extend our scheme with the additional use of tree structures to achieve search complexity that is faster than linear. We formally define and prove the security of our scheme with indistinguishability under selective chosen-plaintext attacks, and demonstrate the performance of our scheme with experiments in a real cloud platform (Amazon EC2). Boyang Wang 0001, Ming Li 0003, Haitao Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Circular Range Search on Encrypted Spatial DataabstractSearchable encryption is a promising technique enabling meaningful search operations to be performed on encrypted databases while protecting user privacy from untrusted third-party service providers. However, while most of the existing works focus on common SQL queries, geometric queries on encrypted spatial data have not been well studied. Especially, circular range search is an important type of geometric query on spatial data which has wide applications, such as proximity testing in Location-Based Services and Delaunay triangulation in computational geometry. In this poster, we propose two novel symmetric-key searchable encryption schemes supporting circular range search. Informally, both of our schemes can correctly verify whether a point is inside a circle on encrypted spatial data without revealing data privacy or query privacy to a semi-honest cloud server. We formally define the security of our proposed schemes, prove that they are secure under Selective Chosen-Plaintext Attacks, and evaluate their performance through experiments in a real-world cloud platform (Amazon EC2). To the best of our knowledge, this work represents the first study in secure circular range search on encrypted spatial data. Boyang Wang 0001, Ming Li 0003, Haitao Wang 0001, Hui Li 0006 |
ICDCS | 1 |
| 2015 | Panda: Public Auditing for Shared Data with Efficient User Revocation in the CloudabstractWith data storage and sharing services in the cloud, users can easily modify and share data as a group. To ensure shared data integrity can be verified publicly, users in the group need to compute signatures on all the blocks in shared data. Different blocks in shared data are generally signed by different users due to data modifications performed by different users. For security reasons, once a user is revoked from the group, the blocks which were previously signed by this revoked user must be re-signed by an existing user. The straightforward method, which allows an existing user to download the corresponding part of shared data and re-sign it during user revocation, is inefficient due to the large size of shared data in the cloud. In this paper, we propose a novel public auditing mechanism for the integrity of shared data with efficient user revocation in mind. By utilizing the idea of proxy re-signatures, we allow the cloud to re-sign blocks on behalf of existing users during user revocation, so that existing users do not need to download and re-sign blocks by themselves. In addition, a public verifier is always able to audit the integrity of shared data without retrieving the entire data from the cloud, even if some part of shared data has been re-signed by the cloud. Moreover, our mechanism is able to support batch auditing by verifying multiple auditing tasks simultaneously. Experimental results show that our mechanism can significantly improve the efficiency of user revocation. Boyang Wang 0001, Baochun Li, Hui Li 0006 |
IEEE Trans. Serv. Comput. | 1 |
| 2015 | Comments on a Public Auditing Mechanism for Shared Cloud Data ServiceabstractRecently, a public auditing protocol for shared data called Panda (IEEE Transactions on Services Computing, doi: 10.1109/TSC.2013.2295611) was proposed to ensure the correctness of the outsourced data. A distinctive feature of Panda is the support of data sharing and user revocation. Unfortunately, in this letter, we show that Panda is insecure in the sense that a cloud server can hide data loss without being detected. Specifically, we show that even some stored file blocks have been lost, the server is able to generate a valid proof by replacing a pair of lost data block and its signature with another block and signature pair. We also provide a solution to the problem while preserving all the desirable features of the original protocol. Yong Yu 0002, Jianbing Ni, Man Ho Au, Yi Mu 0001, Boyang Wang 0001, Hui Li 0006 |
IEEE Trans. Serv. Comput. | 5 |
| 2014 | Maple: scalable multi-dimensional range search over encrypted cloud data with tree-based indexabstractCloud computing promises users massive scale outsourced data storage services with much lower costs than traditional methods. However, privacy concerns compel sensitive data to be stored on the cloud server in an encrypted form. This posts a great challenge for effectively utilizing cloud data, such as executing common SQL queries. A variety of searchable encryption techniques have been proposed to solve this issue; yet efficiency and scalability are still the two main obstacles for their adoptions in real-world datasets, which are multi-dimensional in general. In this paper, we propose a tree-based public-key Multi-Dimensional Range Searchable Encryption (MDRSE) to overcome the above limitations. Specifically, we first formally define the leakage function and security of a tree-based MDRSE. Then, by leveraging an existing predicate encryption in a novel way, our tree-based MDRSE efficiently indexes and searches over encrypted cloud data with multi-dimensional tree structures (i.e., R-trees). Moreover, our scheme is able to protect single-dimensional privacy while previous efficient solutions fail to achieve. Our scheme is selectively secure, and through extensive experimental evaluation on a large-scale real-world dataset, we show the efficiency and scalability of our scheme. Boyang Wang 0001, Yantian Hou, Ming Li 0003, Haitao Wang 0001, Hui Li 0006 |
AsiaCCS | 1 |
| 2014 | Tree-Based Multi-dimensional Range Search on Encrypted Data with Enhanced Privacy
Boyang Wang 0001, Yantian Hou, Ming Li 0003, Haitao Wang 0001, Hui Li 0006, Fenghua Li 0001 |
SecureComm (1) | 1 |
| 2014 | An anonymous data aggregation scheme for smart grid systemsabstractABSTRACT By integrating the traditional grid with the advanced communication and information technologies, smart grid can provide a reliable and efficient energy service for our modern society. Data aggregation plays an important role in evaluating the current energy usage information of consumer domains, based on which the operation center can accommodate distributed power sources to maximize the utilization efficiency. However, it also incurs a potential risk to the consumer privacy. In this paper, we propose an anonymous multi‐dimensional data aggregation for smart grid systems. With the proposed scheme, the operation center can compute both additive and non‐additive aggregation functions over the collected reports from consumers. The computation cost of each consumer is independent of the number of collected data types. In addition, by using the batch verification technique, the operation center's computation cost can be significantly reduced. The security analysis demonstrates that the proposed scheme can achieve identity privacy preserving, data authentication, and confidentiality. Copyright © 2013 John Wiley & Sons, Ltd. Xuefeng Liu 0002, Yuqing Zhang 0001, Boyang Wang 0001, Huaqun Wang |
Secur. Commun. Networks | 3 |
| 2014 | Preserving identity privacy on multi-owner cloud data during public verificationabstractABSTRACT The low prices on cloud data storage and sharing services incentive users to outsource their data to the cloud. Because data stored in the cloud may be lost or corrupted, users are suggested to verify data integrity before the utilization of cloud data. A series of schemes have been proposed to enable a public verifier to efficiently check the correctness of cloud data without downloading the whole data from the cloud server. Unfortunately, few of them have considered about public verification onmulti‐ownercloud data while still preserving identity privacy of owners from public verifiers, where each block in these cloud data should be signed by multiple owners. In this paper, we design a novel public verification scheme to audit the integrity of multi‐owner data stored in the cloud. With our scheme, a public verifier is able to efficiently check the integrity of multi‐owner data with a very small communication cost compared with the size of the entire data. Meanwhile, the private identities of these owners are protected and not revealed to any public verifier. In addition, our scheme can also efficiently support group dynamics for multiple owners and enable batch verification. Security analyses and experimental results indicate our scheme is correct, secure and efficient. Copyright © 2013 John Wiley & Sons, Ltd. Boyang Wang 0001, Hui Li 0006, Xuefeng Liu 0002, Xiaoqing Li 0001, Fenghua Li 0001 |
Secur. Commun. Networks | 1 |
| 2014 | Oruta: Privacy-Preserving Public Auditingfor Shared Data in the CloudabstractWith cloud data services, it is commonplace for data to be not only stored in the cloud, but also shared across multiple users. Unfortunately, the integrity of cloud data is subject to skepticism due to the existence of hardware/software failures and human errors. Several mechanisms have been designed to allow both data owners and public verifiers to efficiently audit cloud data integrity without retrieving the entire data from the cloud server. However, public auditing on the integrity of shared data with these existing mechanisms will inevitably reveal confidential information—identity privacy—to public verifiers. In this paper, we propose a novel privacy-preserving mechanism that supports public auditing on shared data stored in the cloud. In particular, we exploit ring signatures to compute verification metadata needed to audit the correctness of shared data. With our mechanism, the identity of the signer on each block in shared data is kept private from public verifiers, who are able to efficiently verify shared data integrity without retrieving the entire file. In addition, our mechanism is able to perform multiple auditing tasks simultaneously instead of verifying them one by one. Our experimental results demonstrate the effectiveness and efficiency of our mechanism when auditing shared data integrity. Boyang Wang 0001, Baochun Li, Hui Li 0006 |
IEEE Trans. Cloud Comput. | 1 |
| 2013 | Privacy-preserving public auditing for shared cloud data supporting group dynamicsabstractIn the cloud, data is often shared by a group of users. To ensure the long-term correctness of cloud shared data, a third-party public verifier can be introduced to audit data integrity. During the auditing, protecting the privacy of the contributors of shared data from the public auditor is a fundamental issue. However, this makes it challenging to simultaneously support group membership dynamics efficiently, due to the significant amount of computation needed to update the signatures on shared data. In this paper, we propose a novel privacy-preserving public auditing mechanism for shared cloud data. With our proposed mechanism, a public verifier is able to audit the integrity of shared data without retrieving the entire data from the cloud, and also without learning private identity information of the group members. Group dynamics (user join and user revocation) are efficiently handled by outsourcing signature updating operations to the cloud via a secure proxy re-signature scheme. Experimental results show that our mechanism is highly efficient for dynamic groups. Boyang Wang 0001, Hui Li 0006, Ming Li 0003 |
ICC | 1 |
| 2013 | Storing Shared Data on the Cloud via Security-MediatorabstractNowadays, many organizations outsource data storage to the cloud such that a member (owner) of an organization can easily share data with other members (users). Due to the existence of security concerns in the cloud, both owners and users are suggested to verify the integrity of cloud data with Provable Data Possession (PDP) before further utilization on data. However, previous methods either unnecessarily reveal the identity of a data owner to the untrusted cloud or any public verifiers, or introduce significant overheads on verification metadata to preserve anonymity. In this paper, we propose a simple and efficient publicly verifiable approach to ensure cloud data integrity without sacrificing the anonymity of data owners nor requiring significant verification metadata. Specifically, we introduce a security-mediator (SEM), which is able to generate verification metadata (i.e., signatures) on outsourced data for data owners. Our approach decouples the anonymity protection mechanism from the PDP. Thus, an organization can employ its own anonymous authentication mechanism, and the cloud is oblivious to that since it only deals with typical PDP-metadata, Consequently, there is no extra storage overhead when compared with existing non-anonymous PDP solutions. The distinctive features of our scheme also include data privacy, such that the SEM does not learn anything about the data to be uploaded to the cloud at all, which is able to minimize the requirement of trust on the SEM. In addition, we can also extend our scheme to work with the multi-SEM model, which can avoid the potential single point of failure existing in the single-SEM scenario. Security analyses prove our scheme is secure, and experiment results demonstrate our scheme is efficient. Boyang Wang 0001, Sherman S. M. Chow, Ming Li 0003, Hui Li 0006 |
ICDCS | 1 |
| 2013 | Public auditing for shared data with efficient user revocation in the cloudabstractWith data services in the cloud, users can easily modify and share data as a group. To ensure data integrity can be audited publicly, users need to compute signatures on all the blocks in shared data. Different blocks are signed by different users due to data modifications performed by different users. For security reasons, once a user is revoked from the group, the blocks, which were previously signed by this revoked user must be re-signed by an existing user. The straightforward method, which allows an existing user to download the corresponding part of shared data and re-sign it during user revocation, is inefficient due to the large size of shared data in the cloud. In this paper, we propose a novel public auditing mechanism for the integrity of shared data with efficient user revocation in mind. By utilizing proxy re-signatures, we allow the cloud to re-sign blocks on behalf of existing users during user revocation, so that existing users do not need to download and re-sign blocks by themselves. In addition, a public verifier is always able to audit the integrity of shared data without retrieving the entire data from the cloud, even if some part of shared data has been re-signed by the cloud. Experimental results show that our mechanism can significantly improve the efficiency of user revocation. Boyang Wang 0001, Baochun Li, Hui Li 0006 |
INFOCOM | 1 |
| 2013 | Mona: Secure Multi-Owner Data Sharing for Dynamic Groups in the CloudabstractWith the character of low maintenance, cloud computing provides an economical and efficient solution for sharing group resource among cloud users. Unfortunately, sharing data in a multi-owner manner while preserving data and identity privacy from an untrusted cloud is still a challenging issue, due to the frequent change of the membership. In this paper, we propose a secure multi-owner data sharing scheme, named Mona, for dynamic groups in the cloud. By leveraging group signature and dynamic broadcast encryption techniques, any cloud user can anonymously share data with others. Meanwhile, the storage overhead and encryption computation cost of our scheme are independent with the number of revoked users. In addition, we analyze the security of our scheme with rigorous proofs, and demonstrate the efficiency of our scheme in experiments. Xuefeng Liu 0002, Yuqing Zhang 0001, Boyang Wang 0001, Jingbo Yan |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2012 | Oruta: Privacy-Preserving Public Auditing for Shared Data in the CloudabstractWith cloud storage services, it is commonplace for data to be not only stored in the cloud, but also shared across multiple users. However, public auditing for such shared data - while preserving identity privacy - remains to be an open challenge. In this paper, we propose the first privacy-preserving mechanism that allows public auditing on shared data stored in the cloud. In particular, we exploit ring signatures to compute the verification information needed to audit the integrity of shared data. With our mechanism, the identity of the signer on each block in shared data is kept private from a third party auditor (TPA), who is still able to verify the integrity of shared data without retrieving the entire file. Our experimental results demonstrate the effectiveness and efficiency of our proposed mechanism when auditing shared data. Boyang Wang 0001, Baochun Li, Hui Li 0006 |
IEEE CLOUD | 1 |
| 2012 | Knox: Privacy-Preserving Auditing for Shared Data with Large Groups in the Cloud
Boyang Wang 0001, Baochun Li, Hui Li 0006 |
ACNS | 1 |
| 2012 | Gmatch: Secure and privacy-preserving group matching in social networksabstractGroups are becoming one of the most compelling features in both online social networks and Twitter-like micro-blogging services. A stranger outside of an existing group may have the need to find out more information about attributes of current members in the group, in order to make a decision to join. However, in many cases, attributes of both group members and the stranger need to be kept private and should not be revealed to others, as they may contain sensitive and personal information. How can we find out matching information exists between the stranger and members of the group, based on their attributes that are not to be disclosed? In this paper, we present a new group matching mechanism, by taking advantage private set intersection and ring signatures. With our scheme, a stranger is able to collect correct group matching information while sensitive information of the stranger and group members are not disclosed. Finally, we propose to use batch verification to significantly improve the performance of the matching process. Boyang Wang 0001, Baochun Li, Hui Li 0006 |
GLOBECOM | 1 |
| 2012 | An efficient MAC scheme for secure network coding with probabilistic detection
Boyang Wang 0001, Hui Li 0006, Jin Cao 0001 |
Frontiers Comput. Sci. | 1 |