Geong Sen Poh

dblp:05/1698 · DBLP profile ↗
← Back
24ranked-venue papers
9as first author
6since 2021 · last 2022
0000-0002-2905-688XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 8 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2022 PSI-Stats: Private Set Intersection Protocols Supporting Secure Statistical Functions
Jason H. M. Ying, Shuwei Cao 0002, Geong Sen Poh, Jia Xu 0006, Hoon Wei Lim
ACNS3
2022 Attribute Based Encryption with Privacy Protection and Accountability for CloudIoT
abstract
The pervasive, ubiquitous, and heterogeneous properties of IoT make securing IoT systems a very challenging task. More so when access and storage are performed through a cloud-based IoT system. IoT data stored on cloud should be encrypted to ensure data privacy. It is also crucial to allow only authorized entities to access and decrypt the encrypted data. In this article, we propose a ciphertext-policy attribute-based encryption (CP-ABE) scheme that enables fine-grained access control of encrypted IoT data on cloud. CP-ABE is regarded as a highly promising approach to provide flexible and fine-grained access control, which is quite suited to secure cloud based IoT systems. We first present an access control system model of CloudIoT platform based on ABE. Based on the presented system model, we construct a ciphertext-policy hiding CP-ABE scheme, which guarantees the privacy of the users. We further construct a white-box traceable CP-ABE scheme with accountability in order to address the user key abuse and authorization center key abuse. Experiment illustrates the proposed systems are efficient.
Jiguo Li 0001, Yichen Zhang 0003, Jianting Ning, Xinyi Huang 0001, Geong Sen Poh, Debang Wang
IEEE Trans. Cloud Comput.5
2022 Update Recovery Attacks on Encrypted Database Within Two Updates Using Range Queries Leakage
abstract
Recently, reconstruction attacks on static encrypted database supporting range queries have been proposed. However, attacks on encrypted database within two updates in the similar setting have not been studied extensively. As far as we know, the only work is theupdate recovery attackpresented by Grubbset al.(CCS 2018). Following their seminal work, we present new update recovery attacks fordensedataset (i.e., at least one record corresponding to each value in the range), which enable a deeper understanding of the impact caused by leakages due to updates on dynamic encrypted database. Our first attack aims at recovering the value of a newly added record in the case of one database update. We further demonstrate that the attack can fully reconstruct thedatabase countsif the updated value is either the minimum or maximum in the range. We then consider a setting where two distinct records are added separately, which leads to our second attack. We next extend our attacks to the setting where the update operation is deletion. To the best of our knowledge, update recovery attack on database supporting deletion has not been considered before. We demonstrate practicality of our attack via extensive simulations using real dataset.
Jianting Ning, Geong Sen Poh, Xinyi Huang 0001, Robert H. Deng, Shuwei Cao 0002, Ee-Chien Chang
IEEE Trans. Dependable Secur. Comput.2
2021 LEAP: Leakage-Abuse Attack on Efficiently Deployable, Efficiently Searchable Encryption with Partially Known Dataset
abstract
Searchable Encryption (SE) enables private queries on encrypted documents. Most existing SE schemes focus on constructing industrial-ready, practical solutions at the expense of information leakages that are considered acceptable. In particular, ShadowCrypt utilizes a cryptographic approach named ''efficiently deployable, efficiently searchable encryption'' (EDESE) that reveals the encrypted dataset and the query tokens among other information. However, recent attacks showed that such leakages can be exploited to (partially) recover the underlying keywords of query tokens under certain assumptions on the attacker's background knowledge.
Jianting Ning, Xinyi Huang 0001, Geong Sen Poh, Jiaming Yuan, Yingjiu Li, Jian Weng 0001, Robert H. Deng
CCS3
2021 PrivHome: Privacy-Preserving Authenticated Communication in Smart Home Environment
abstract
A smart home enables users to access devices such as lighting, HVAC, temperature sensors, and surveillance camera. It provides a more convenient and safe living environment for users. Security and privacy, however, is a key concern since information collected from these devices are normally communicated to the user through an open network (i.e. Internet) or system provided by the service provider. The service provider may store and have access to these information. Emerging smart home hubs such as Samsung SmartThings and Google Home are also capable of collecting and storing these information. Leakage and unauthorized access to the information can have serious consequences. For example, the mere timing of switching on/off of an HVAC unit may reveal the presence or absence of the home owner. Similarly, leakage or tampering of critical medical information collected from wearable body sensors can have serious consequences. Encrypting these information will address the issues, but it also reduces utility since queries is no longer straightforward. Therefore, we propose a privacy-preserving scheme, \sf PrivHomePrivHome. It supports authentication, secure data storage and query for smart home systems. PrivHome provides data confidentiality as well as entity and data authentication to prevent an outsider from learning or modifying the data communicated between the devices, service provider, gateway, and the user. It further provides privacy-preserving queries in such a way that the service provider, and the gateway does not learn content of the data. To the best of our knowledge, privacy-preserving queries for smart home systems has not been considered before. Under our scheme is a new, lightweight entity and key-exchange protocol, and an efficient searchable encryption protocol. Our scheme is practical as both protocols are based solely on symmetric cryptographic techniques. We demonstrate efficiency and effectiveness of our scheme based on experimental and simulation results, as well as comparisons to existing smart home security protocols.
Geong Sen Poh, Prosanta Gope, Jianting Ning
IEEE Trans. Dependable Secur. Comput.1
2021 Secure Fine-Grained Encrypted Keyword Search for E-Healthcare Cloud
abstract
E-Healthcare systems are increasingly popular due to the introduction of wearable healthcare devices and sensors. Personal health records (PHRs) are collected by these devices and stored in a remote cloud. Due to privacy concern, these records should not be accessible by any unauthorized party, and the cloud providers should not be able to learn any information from the stored records. To address the above issues, one promising solution is to employ attribute based encryption (ABE) for fine-grained access control and searchable encryption for keyword search on encrypted data. However, most of existing ABE schemes leak the privacy of access policy which may also contain sensitive information. On the other hand, for users' devices with limited computing power and bandwidth, the mechanism should enable them to be able to search the PHRs efficiently. Unfortunately, most existing works on ABE do not support efficient keyword search on encrypted data. In this work, we propose an efficient hidden policy ABE scheme with keyword search. Our scheme enables efficient keyword search with constant computational overhead and constant storage overhead. Moreover, we enhance the recipient's privacy which hides the access policy. As of independent interest, we present a trapdoor malleability attack and demonstrate that some of previous schemes may suffer from such attack.
Haijiang Wang 0003, Jianting Ning, Xinyi Huang 0001, Guiyi Wei, Geong Sen Poh, Ximeng Liu
IEEE Trans. Dependable Secur. Comput.5
2020 Pine: Enabling Privacy-Preserving Deep Packet Inspection on TLS with Rule-Hiding and Fast Connection Establishment
Jianting Ning, Xinyi Huang 0001, Geong Sen Poh, Shengmin Xu, Jia-Ch'ng Loh, Jian Weng 0001, Robert H. Deng
ESORICS (1)3
2020 PrivateLink: Privacy-Preserving Integration and Sharing of Datasets
abstract
In privacy-enhancing technology, it has been inevitably challenging to strike a reasonable balance between privacy, efficiency, and usability (utility). To this, we propose a highly practical solution for the privacy-preserving integration and sharing of datasets among a group of participants. At the heart of our solution is a new interactive protocol, PrivateLink. Through PrivateLink, each participant is able to randomize his/her dataset via an independent and untrusted third party, such that the resulting dataset can be merged with other randomized datasets contributed by other participants in a privacy-preserving manner. Our approach does not require key sharing among participants in order to integrate different datasets. This, in turn, leads to a user-friendly and scalable solution. Moreover, the correctness of a randomized dataset returned by the third party can be securely verified by the participant. We further demonstrate PrivateLink's general utilities: using it to construct a structure-preserving data integration protocol. This is particularly useful for private, fine-grained integration of network traffic data. We state the security of our protocols under the well-established real-ideal simulation paradigm and demonstrate practicality by a prototype implementation on: 1) healthcare datasets and 2) DNS and NetFlow datasets.
Hoon Wei Lim, Geong Sen Poh, Jia Xu 0006, Varsha Chittawar
IEEE Trans. Inf. Forensics Secur.2
2019 PrivDPI: Privacy-Preserving Encrypted Traffic Inspection with Reusable Obfuscated Rules
abstract
Network middleboxes perform deep packet inspection (DPI) to detect anomalies and suspicious activities in network traffic. However, increasingly these traffic are encrypted and middleboxes can no longer make sense of them. A recent proposal by Sherry et al. (SIGCOMM 2015), named BlindBox, enables the middlebox to perform inspection in a privacy-preserving manner. BlindBox deploys garbled circuit to generate encrypted rules for the purpose of inspecting the encrypted traffic directly. However, the setup latency (which could be 97s on a ruleset of 3,000 as reported) and overhead size incurred by garbled circuit are high. Since communication can only be commenced after the encrypted rules being generated, such delay is intolerable in many real-time applications. In this work, we present PrivDPI, which reduces the setup delay while retaining similar privacy guarantee. Compared to BlindBox, for a ruleset of 3,000, our encrypted rule generation is 288x faster and requires 290,227x smaller overhead for the first session, and is even 1,036x faster and requires 3424,505x smaller overhead over 20 consecutive sessions. The performance gain is based on a new technique for generating encrypted rules as well as the idea of reusing intermediate results generated in previous sessions across subsequent sessions. This is in contrast to Blindbox which performs encrypted rule generation from scratch for every session. Nevertheless, PrivDPI is 6x slower in generating the encrypted traffic tokens, yet in our implementation, the token encryption rate of PrivDPI is more than 17,271 per second which is sufficient for many real-time applications. Moreover, the intermediate values generated in each session can be reused across subsequent sessions for repeated tokens, which could further speedup token encryption. Overall, our experiment shows that PrivDPI is practical and especially suitable for connections with short flows.
Jianting Ning, Geong Sen Poh, Jia-Ch'ng Loh, Jason Chia, Ee-Chien Chang
CCS2
2018 Attribute-Based Encryption with Efficient Keyword Search and User Revocation
Jingwei Wang 0004, Xinchun Yin, Jianting Ning, Geong Sen Poh
Inscrypt4
2016 Preserving Privacy of Agents in Reinforcement Learning for Distributed Cognitive Radio Networks
Geong Sen Poh, Kok-Lim Alvin Yau
ICONIP (1)1
2016 Remote website authentication using dynamic multi-scale code visualization
abstract
Static images selected by a user have been suggested as security indicators for allowing a human user to visually verify a website's authenticity. While being widely adopted, most of the relevant implementations are found to be susceptible to man-in-the-middle (MITM) and replay attacks. In this paper, we propose a reciprocal authentication protocol to minimize these attacks by requiring remote websites to prove their identities based on a session-based ephemeral key that is also visually verified by a user. The key is cryptographically derived from a pre-shared secret between the user and the web server. It is manually verified as a sequence of colours derived using a dynamic multi-scale code visualization scheme. A prototype system was developed to demonstrate the viability and usability of our proposal.
Alwyn Goh, Hoon Sin Cheong, Geong Sen Poh, Seyedvahid Dianat
PST3
2016 On the security advantages of block-based multiserver searchable symmetric encryption
abstract
One of the considerations for the security of searchable symmetric encryption is leakage, defined as the amount of information regarding stored data known to the adversary. Recently, some papers showed that information extracted from leakages, combined with some prior knowledge, enables practical attacks. In this work, we argue in favour on the security of multiserver block-based SSE to resist such attacks, where multiple storage servers are used and the documents are stored in the form of sets of encrypted document blocks. We show that the distribution of documents over keyword subsets in such designs can be used to reduce adversary information gain when conducting such practical attacks on multiserver block-based SSE, therefore offering more resistance to these attacks and achieving higher security guarantees.
Moesfa Soeheila Mohamad, Ji-Jian Chin, Geong Sen Poh
PST3
2014 Human Visualisation of Cryptographic Code Using Progressive Multi-Scale Resolution
abstract
High-entropy codewords frequently occur in the context of cryptographic protocols, and typically range in length from 128 to 1024 bits. Human vision is not well equipped to compare or recognise such codewords, due to the high information (length) and entropy content. In this paper, we propose a human visualisation mechanism to enable representation of long high-entropy codewords via perceptually significant visual images. The main contribution is a mechanism capable of representation at more detailed scales of resolution in progressive steps, so as to allow human visual inspection which is both secure and ergonomic. The generation of these visual representations is either dependent on key-specific or context-sensitive system inputs. The featured representation allows for machine-to-human authentication and authorization.
Alwyn Goh, Geong Sen Poh, Voon-Yee Vee, Kok Boon Chong, Xin Zhe Khooi, Chanan Zhuo Ern Loh, Zhi Yuan Eng
SIN2
2014 Trust and reputation management in cognitive radio networks: a survey
abstract
ABSTRACT Cognitive radio (CR), which is the next generation wireless communication system, enables unlicensed users or secondary users (SUs) to exploit underutilized spectrum (called white spaces) owned by the licensed users or primary users (PUs) so that bandwidth availability improves at the SUs, which helps to improve overall spectrum utilization. Collaboration is an intrinsic characteristic of CR to improve network performance. For instance, in collaborative spectrum sensing, SU hosts generate sensing outcomes, and collaborate amongst themselves through making final decisions at a decision fusion center in order to improve the accuracy of spectrum sensing. The requirement to collaborate has inevitably opened doors to various forms of attacks by malicious SUs, and this critical issue can be addressed using trust and reputation management (TRM), and so this is the focus of this article. Generally speaking, TRM detects malicious SUs, including honest SUs that turn malicious. Hence, TRM is of paramount importance in most kinds of schemes that require collaboration in CR networks. Our contribution in this article is as follows. This article provides an extensive survey on the application of TRM in various schemes in CR networks in order to ameliorate the effects of malicious SUs in collaboration. The discussion is presented with respect to a TRM taxonomy, various approaches to achieve TRM, various attack models, as well as the challenges and characteristics associated with TRM. Because of the significance of TRM in collaboration, this article presents a wide range of open issues to warrant further research in this area. Copyright © 2013 John Wiley & Sons, Ltd.
Mee Hong Ling, Kok-Lim Alvin Yau, Geong Sen Poh
Secur. Commun. Networks3
2013 An authentication framework for peer-to-peer cloud
abstract
Cloud computing provides on demand computation and storage services delivered via applications, system software and hardware rendered as services. Due to its on demand nature, it has high variable workloads and requires real-time efficiency and availability. Most cloud computing systems use a centralised model to provision services, but reliance on a central entity to control scheduling decision and maintain all cloud hosts may constitute a computing bottleneck. A system failure will cause service outage, sometimes for a few hours as had happened before. In addition, the central entity needs to support heavy workloads in terms of service provisioning to all resource hosts. These issues can be addressed by distributing cloud resources using structured peer-to-peer (P2P) overlay networks as was recently proposed. However these proposals do not examine potential security issues of a P2P-based cloud, one of them being how peers verify the identities of one another over a decentralised setting. Therefore we propose an authentication framework for P2P cloud consisting of various approaches for authenticating entities and messages. The framework combines cryptographic primitives and security mechanisms proposed for existing structured P2P network.
Geong Sen Poh, Mohd Amril Nurman Mohd Nazir, Bok-Min Goi, Syh-Yuan Tan, Raphael C.-W. Phan, Maryam Safiyah Shamsudin
SIN1
2012 Verifiable Structured Encryption
Moesfa Soeheila Mohamad, Geong Sen Poh
Inscrypt2
2012 Analysis of a secure cooperative channel sensing protocol for cognitive radio networks
abstract
Cognitive radio (CR) has been introduced to allow unlicensed users, or better known as secondary users (SUs), to exploit underutilised licensed spectrum owned by the primary users (PUs). The SUs perform channel sensing to check the state of the PUs in order to use the channel without interfering with the PUs' activities. It is possible for malicious users or attackers to exploit channel sensing resulting in biased sensing decisions benefiting selfish SUs or attackers. In SIN 2011, a secure cooperative sensing protocol was proposed by Rifà-Paus and Gamgues to address this issue. In this paper, we study their protocol and discuss possible issues in the protocol, including the possibility of creating a rogue fusion centre and replaying session authentication. We also briefly examine the practical threats from more powerful adversanes capable of jamming the channels. We suggest several potential mitigations including use of well-established authenticated key exchange and standard entity authentication mechanisms.
Geong Sen Poh, Kok-Lim Alvin Yau, Mee Hong Ling
SIN1
2011 On the security and practicality of a buyer seller watermarking protocol for DRM
abstract
A buyer seller watermarking (BSW) protocol allows a seller of digital content to prove to a third party that a buyer illegally distributed copies of content when these copies are found. It also protects an honest buyer from being falsely accused of such an act by the seller. We examine the security and practicality of a recent BSW protocol for Digital Rights Management (BSW-DRM) proposed in SIN 2009. We show that the protocol contains weaknesses, which may result in successful replay, modification and content piracy. Furthermore, the heavy reliance on the fully trusted Certificate Authority has its security concern and it is also less practical to be applied in current digital content distribution systems. We further suggest possible improvements based on the many protocols proposed prior to this protocol.
Geong Sen Poh, Muhammad Reza Z'aba
SIN1
2009 Classification Framework for Fair Content Tracing Protocols
Geong Sen Poh, Keith M. Martin
IWDW1
2008 An Efficient Buyer-Seller Watermarking Protocol Based on Chameleon Encryption
Geong Sen Poh, Keith M. Martin
IWDW1
2008 On the (In)Security of Two Buyer-Seller Watermarking Protocols
Geong Sen Poh, Keith M. Martin
SECRYPT1
2007 A Framework for Design and Analysis of Asymmetric Fingerprinting Protocols
abstract
We propose a framework for the design and analysis of asymmetric fingerprinting protocols. By fitting existing approaches within this framework, we are able to highlight strategic differences in design techniques. We then illustrate how the framework can be used to derive new models, which in turn lead to asymmetric fingerprinting schemes with new properties.
Geong Sen Poh, Keith M. Martin
IAS1
2007 An Anonymous waterMarking Scheme for Content Distribution Protection using Trusted Computing
Adrian Leung, Geong Sen Poh
SECRYPT2