Xuexian Hu

dblp:09/4551 · DBLP profile ↗
← Back
31ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0001-9778-9463ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 21 · 2 first-author · 7 since 2021Artificial intelligence and machine learning · 3Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorSystems, architecture and hardware · 2 · 1 since 2021Computer networks · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Forward-Secure Tag-Inverse Puncturable Identity-Based Encryption
Yang Ba, Xuexian Hu, Jianghong Wei
ACISP (2)3
2025 An Enhanced Efficient Password-Authenticated Key Exchange Protocol for the Internet of Things
abstract
The symmetric Password-Authenticated Key Exchange (PAKE) protocol enables two parties sharing a low-entropy password to establish a high-entropy session key, offering advantages in simplicity and efficiency. This makes it particularly suitable for Internet of Things (IoT) devices with limited computational resources, positioning it as one of the most effective security methods for authentication and key exchange in IoT environments. In this paper, we analyze a recently proposed efficient symmetric PAKE protocol for IoT, identifying its vulnerability to offline dictionary attacks and its failure to meet the claimed security goals. Building upon the analysis of these design flaws, we present an enhanced protocol, demonstrating its security within the random oracle model. The enhanced protocol retains the protocol flow and computational operations of the original protocol to the greatest extent possible, maintains nearly the same computational efficiency, and simultaneously addresses the vulnerabilities that made the original protocol susceptible to offline dictionary attacks.
Shouxin Shang, Xuexian Hu, Qihui Zhang, Jianghong Wei, Qinlong Fan
IEEE Internet Things J.2
2025 SECP-AKE: Secure and efficient certificateless-password-based authenticated key exchange protocol for smart healthcare systems
Xuexian Hu, Jianghong Wei, Yuanjun Xia, Yangfan Liang
J. Syst. Archit.2
2024 SDIM: A Subtly Designed Invertible Matrix for Enhanced Privacy-Preserving Outsourcing Matrix Multiplication and Related Tasks
abstract
Matrix multiplication computation (MMC) is one of the most important basic operations with a variety of applications in the scientific and engineering community, including linear regression, k-nearest neighbor classification and biometric identification. However, performing these tasks with large-scale datasets can result in significant computation beyond the capabilities of resource-constrained clients. As outsourcing intensive tasks to cloud server has become a promising method, many matrix-transformation-based privacy-protected schemes have been presented for certain outsourcing tasks, such as Lei et al's scheme for the outsourcing MMC task and Zhao et al's scheme for matrix determinant computation. Nevertheless, Lei et al's scheme suffers from inherent security flaws that reveal the statistical information of zero elements in the original data. Additionally, Zhao et al's scheme can only be applied to specific outsourced tasks and is not suitable for more universal situations, such as MMC, where the client needs to compute the inverse matrix of the secret key. Therefore, designing an invertible matrix is a difficult task that affects privacy security, efficiency, and universality of the matrix-transformation-based privacy-protected outsourcing computing scheme. To address this challenge, we propose a subtly designed invertible matrix (SDIM) and a privacy-protected outsourcing MMC scheme based on the SDIM to remedy the inherent security flaws of Lei et al's scheme. We also propose an optimized matrix-chain multiplication method to maintain high efficiency of the SDIM-based privacy-protected scheme. This optimization also allows the SDIM to be universally applied not only to MMC tasks but also to other related outsourced tasks such as linear regression. Theoretical analyses and experiments show that our methods are more secure in terms of data privacy, with comparable efficiency to the state-of-the-art scheme based on matrix transformation. This SDIM-based scheme has achieved a well-balanced trade-off between security, efficiency and universality.
Xuexian Hu, Xiaofeng Chen 0001, Jianghong Wei, Wenfen Liu
IEEE Trans. Dependable Secur. Comput.2
2023 System-widely and fine-grained forward secure identity-based signature scheme
Jianghong Wei, Xuexian Hu, Kuiwu Yang
J. Inf. Secur. Appl.3
2022 VAEPass: A lightweight passwords guessing model based on variational auto-encoder
Kunyu Yang, Xuexian Hu, Qihui Zhang, Jianghong Wei, Wenfen Liu
Comput. Secur.2
2022 Enabling (End-to-End) Encrypted Cloud Emails With Practical Forward Secrecy
abstract
With the widespread use of cloud emails and frequent reports on large-scale email leakage events, a security property so-called forward secrecy becomes desirable and indispensable for both individuals and cloud email service providers to strengthen the security of cloud email systems. Specifically, forward secrecy can guarantee the confidentiality of those previously encrypted emails even if the user’s secret key gets exposed. However, due to the failure to meet the security and practicality requirements of email systems simultaneously, typical methods of achieving forward secrecy, such as Diffie-Hellman key exchange and forward-secure public-key encryption, have not been widely approved and adopted. In this article, to capture forward secrecy of encrypted cloud email systems without sacrificing the practicability, we introduce a new cryptographic primitive named forward-secure puncturable identity-based encryption (fs-PIBE), which enables an email user to perform fine-grained revocation of decryption capacity. In more detail, the user is allowed to preserve the decryption capacity of unreceived encrypted emails, while abolishing that of those received ones. Thus, it provides more practical forward secrecy than typical manners, in which the decryption capacity of received and unreceived encrypted emails is revoked simultaneously. Based on such a primitive, we build a framework of encrypted cloud email systems, and instantiate it with a concrete fs-PIBE construction that has constant size of ciphertext and provable security in the standard model. Furthermore, to improve the security and efficiency of the presented framework, we extend the proposed fs-PIBE scheme to support end-to-end encryption and outsourced decryption, respectively. In addition, as a proof-of-concept of the proposed fs-PIBE scheme, we implement it and produce various experiments to demonstrate its practicability and correctness.
Jianghong Wei, Xiaofeng Chen 0001, Jianfeng Wang 0001, Xuexian Hu, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.4
2021 Studies of Keyboard Patterns in Passwords: Recognition, Characteristics and Strength Evolution
Kunyu Yang, Xuexian Hu, Qihui Zhang, Jianghong Wei, Wenfen Liu
ICICS (1)2
2021 RS-HABE: Revocable-Storage and Hierarchical Attribute-Based Access Scheme for Secure Sharing of e-Health Records in Public Cloud
abstract
Personal e-health records (EHR) enable medical workers (e.g., doctors and nurses) to conveniently and quickly access each patient's medical history through the public cloud, which greatly facilitates patients' visits and makes telemedicine possible. Additionally, since EHR involve patients' personal privacy information, EHR holders would hesitate to directly outsource their data to cloud servers. A natural and favorite manner of conquering this issue is to encrypt these outsourced EHR such that only authorized medical workers can access them. Specifically, the ciphertext-policy attribute-based encryption (CP-ABE) supports fine-grained access over encrypted data and is considered to be a perfect solution of securely sharing EHR in the public cloud. In this paper, to strengthen the system security and meet the requirement of specific applications, we add functionalities of user revocation, secret key delegation and ciphertext update to the original ABE, and propose a revocable-storage hierarchical attribute-based encryption (RS-HABE) scheme, as the core building of establishing a framework for secure sharing of EHR in public cloud. The proposed RS-HABE scheme features of forward security (a revoked user can no longer access previously encrypted data) and backward security (a revoked user also cannot access subsequently encrypted data) simultaneously, and is proved to be selectively secure under a complexity assumption in bilinear groups, without random oracles. The theoretical analysis indicates that the proposed scheme surpasses existing similar works in terms of functionality and security, at the acceptable cost of computation overhead. Moreover, we implement the proposed scheme and present experiments to demonstrate its practicability.
Jianghong Wei, Xiaofeng Chen 0001, Xinyi Huang 0001, Xuexian Hu, Willy Susilo
IEEE Trans. Dependable Secur. Comput.4
2021 Communication-Efficient and Fine-Grained Forward-Secure Asynchronous Messaging
abstract
In recent years, motivated by the revelation of long-term and widespread surveillance of personal communications, extensive efforts have been putting intostore-and-forwardasynchronous messaging systems (e.g., email and SMS) for providing critical security guarantees. Of particular interest among them is forward security, which makes past messages remain secure in the event that the secret key gets exposed. Traditional forward-secure public key encryption can provide forward security for asynchronous scenarios, but it is not flexible enough for instant messaging systems. This is mainly because that, after updating his/her secret key, the user totally loses the decryption capacity of ciphertexts that have not been received. In this paper, to achieve practical forward-security of asynchronous messaging systems, we investigate the construction of a new primitive named forward-secure puncturable encryption (FSPE) that captures fine-grained forward security. Namely, the user can maintain the decryption capacity of those encrypted messages that have not been received yet. Meanwhile, even if the secret key is disclosed, those received messages can still remain secure. Specifically, we propose a communication-efficient FSPE scheme for achieving fine-grained forward-secure asynchronous messaging. Moreover, to improve the efficiency of asynchronous messaging built upon FSPE, we extend it to support outsourced decryption. We also implement the proposed scheme and evaluate a proof-of-concept of main algorithms, so as to increase confidence on its correctness and practicability.
Jianghong Wei, Xiaofeng Chen 0001, Jianfeng Ma 0001, Xuexian Hu, Kui Ren 0001
IEEE/ACM Trans. Netw.4
2020 Privacy-preserving constrained spectral clustering algorithm for large-scale data sets
abstract
With the increasing concern on the preservation of personal privacy, privacy‐preserving data mining has become a hot topic in recent years. Spectral clustering is one of the most widely used clustering algorithm for exploratory data analysis and usually has to deal with sensitive data sets. How to conduct privacy‐preserving spectral clustering is an urgent problem to be solved. In this study, the authors focus on introducing the notion of differential privacy, which is considered as the de facto standard of privacy‐preserving data analysis, into spectral clustering. Specifically, by combining the well‐studied constrained spectral clustering with the Wishart mechanism in a novel way, the authors propose a differentially private constrained spectral clustering (DP‐CSC) algorithm. The DP‐CSC algorithm is proved to capture asymptotic property and achieves ‐differential privacy. To illustrate the effectiveness and efficiency of DP‐CSC, the authors conduct experiments on five real‐word data sets. The results indicate that the DP‐CSC algorithm can provide acceptable clustering accuracy with short running time while preserving individual privacy.
Ji Li 0004, Jianghong Wei, Mao Ye 0004, Wenfen Liu, Xuexian Hu
IET Inf. Secur.5
2019 Round-Efficient Anonymous Password-Authenticated Key Exchange Protocol in the Standard Model
Qihui Zhang, Wenfen Liu, Kang Yang 0002, Xuexian Hu
Inscrypt4
2019 Forward-Secure Puncturable Identity-Based Encryption for Securing Cloud Emails
Jianghong Wei, Xiaofeng Chen 0001, Jianfeng Wang 0001, Xuexian Hu, Jianfeng Ma 0001
ESORICS (2)4
2019 Forward and backward secure fuzzy encryption for data sharing in cloud computing
Jianghong Wei, Xuexian Hu, Wenfen Liu, Qihui Zhang
Soft Comput.2
2018 Secure Data Sharing in Cloud Computing Using Revocable-Storage Identity-Based Encryption
abstract
Cloud computing provides a flexible and convenient way for data sharing, which brings various benefits for both the society and individuals. But there exists a natural resistance for users to directly outsource the shared data to the cloud server since the data often contain valuable information. Thus, it is necessary to place cryptographically enhanced access control on the shared data. Identity-based encryption is a promising cryptographical primitive to build a practical data sharing system. However, access control is not static. That is, when some user's authorization is expired, there should be a mechanism that can remove him/her from the system. Consequently, the revoked user cannot access both the previously and subsequently shared data. To this end, we propose a notion called revocable-storage identity-based encryption (RS-IBE), which can provide the forward/backward security of ciphertext by introducing the functionalities of user revocation and ciphertext update simultaneously. Furthermore, we present a concrete construction of RS-IBE, and prove its security in the defined security model. The performance comparisons indicate that the proposed RS-IBE scheme has advantages in terms of functionality and efficiency, and thus is feasible for a practical and cost-effective datasharing system. Finally, we provide implementation results of the proposed scheme to demonstrate its practicability.
Jianghong Wei, Wenfen Liu, Xuexian Hu
IEEE Trans. Cloud Comput.3
2017 An Effective Approach for Chinese News Headline Classification Based on Multi-representation Mixed Model with Attention and Ensemble Learning
Zhonglei Lu, Wenfen Liu, Yanfang Zhou, Xuexian Hu, Binyu Wang
NLPCC4
2017 Universally composable anonymous password authenticated key exchange
Xuexian Hu, Jiang Zhang 0001, Zhenfeng Zhang, Jing Xu 0002
Sci. China Inf. Sci.1
2017 Compressed constrained spectral clustering framework for large-scale data sets
Wenfen Liu, Mao Ye 0004, Jianghong Wei, Xuexian Hu
Knowl. Based Syst.4
2017 PMDP: A Framework for Preserving Multiparty Data Privacy in Cloud Computing
abstract
The amount of Internet data is significantly increasing due to the development of network technology, inducing the appearance of big data. Experiments have shown that deep mining and analysis on large datasets would introduce great benefits. Although cloud computing supports data analysis in an outsourced and cost-effective way, it brings serious privacy issues when sending the original data to cloud servers. Meanwhile, the returned analysis result suffers from malicious inference attacks and also discloses user privacy. In this paper, to conquer the above privacy issues, we propose a general framework for Preserving Multiparty Data Privacy (PMDP for short) in cloud computing. The PMDP framework can protect numeric data computing and publishing with the assistance of untrusted cloud servers and achieve delegation of storage simultaneously. Our framework is built upon several cryptography primitives (e.g., secure multiparty computation) and differential privacy mechanism, which guarantees its security against semihonest participants without collusion. We further instantiate PMDP with specific algorithms and demonstrate its security, efficiency, and advantages by presenting security analysis and performance discussion. Moreover, we propose a security enhanced framework sPMDP to resist malicious inside participants and outside adversaries. We illustrate that both PMDP and sPMDP are reliable and scale well and thus are desirable for practical applications.
Ji Li 0004, Jianghong Wei, Wenfen Liu, Xuexian Hu
Secur. Commun. Networks4
2016 Practical Anonymous Password Authentication and TLS with Anonymous Client Authentication
abstract
Anonymous authentication allows one to authenticate herself without revealing her identity, and becomes an important technique for constructing privacy-preserving Internet connections. Anonymous password authentication is highly desirable as it enables a client to authenticate herself by a human-memorable password while preserving her privacy. In this paper, we introduce a novel approach for designing anonymous password-authenticated key exchange (APAKE) protocols using algebraic message authentication codes (MACs), where an algebraic MAC wrapped by a password is used by a client for anonymous authentication, and a server issues algebraic MACs to clients and acts as the verifier of login protocols. Our APAKE construction is secure provided that the algebraic MAC is strongly existentially unforgeable under random message and chosen verification queries attack (suf-rmva), weak pseudorandom and tag-randomization simulatable, and has simulation-sound extractable non-interactive zero-knowledge proofs (SE-NIZKs). To design practical APAKE protocols, we instantiate an algebraic MAC based on the q-SDH assumption which satisfies all the required properties, and construct credential presentation algorithms for the MAC which have optimal efficiency for a randomize-then-prove paradigm. Based on the algebraic MAC, we instantiate a highly practical APAKE protocol and denote it by APAKE, which is much more efficient than the mechanisms specified by ISO/IEC 20009-4. An efficient revocation mechanism for APAKE is also proposed.
Zhenfeng Zhang, Kang Yang 0002, Xuexian Hu
CCS3
2016 UC-secure Two-Server Password-Based Authentication Protocol and Its Applications
abstract
A two-server password-based authentication (2PA) protocol is a special kind of authentication primitive that provides additional protection for the user's password. Through a 2PA protocol, a user can distribute his low-entropy password between two authentication servers in the initialization phase and authenticate himself merely via a matching password in the login phase. No single server can learn any information about the user's password, nor impersonate the legitimate user to authenticate to the honest server. In this paper, we first formulate and realize the security definition of two-server password-based authentication in the well-known universal composability (UC) framework, which thus provides desirable properties such as composable security. We show that our construction is suitable for the asymmetric communication model in which one server acts as the front-end server interacting directly with the user and the other stays backstage.
Lin Zhang 0019, Zhenfeng Zhang, Xuexian Hu
AsiaCCS3
2016 Practical Attribute-based Signature: Traceability and Revocability
abstract
As a new variant of digital signature, attribute-based signature (ABS) is appealing for many scenarios, where both authentication and anonymity are desired. However, in such a paradigm, a user's secret key is not linkable to an authenticated identity, and the same set of attributes might be shared among multiple users. Consequently, a malicious user would leak his secret key for some purposes without the risk of being identified among these equal users. On the other hand, for a cryptosystem with a large number of users, there should be an efficient revocation mechanism to further inform that a user's credential is abolished. We note that none of the existing ABS schemes simultaneously supports traceability and revocability, which are crucial towards the practicability of ABS. In this work, we first give a formal security model for traceable and revocable ABS. Next, we provide a concrete construction that admits flexible threshold signing predicates. Finally, we prove the anonymity and traceability of the proposed scheme in the standard model. To the best of our knowledge, our construction is the first ABS scheme that enjoys the functionalities of traceability and revocability simultaneously, and thus is more feasible for practical applications.
Jianghong Wei, Xinyi Huang 0001, Wenfen Liu, Xuexian Hu
Comput. J.4
2016 Security pitfalls of "ePASS: An expressive attribute-based signature scheme"
Jianghong Wei, Wenfen Liu, Xuexian Hu
J. Inf. Secur. Appl.3
2015 Round-Optimal Password-Based Group Key Exchange Protocols in the Standard Model
Jing Xu 0002, Xuexian Hu, Zhenfeng Zhang
ACNS2
2015 Revocable Threshold Attribute-Based Signature against Signing Key Exposure
Jianghong Wei, Xinyi Huang 0001, Xuexian Hu, Wenfen Liu
ISPEC3
2015 Forward-Secure Threshold Attribute-Based Signature Scheme
abstract
In an attribute-based signature (ABS) scheme, each signer is issued a private key according to his/her attributes, and can sign a message with respect to some signing predicate satisfied by his/her attributes. A recipient of the signature can verify that the signature is indeed endorsed by someone that possesses some attributes satisfying the signing predicate, without learning any information about the attributes that are utilized to produce the signature. Since the introduction of ABS, it has been well investigated in recent years. However, there are few works proposed to solve the problem of key exposure in the setting of ABS. In fact, this problem becomes more acute with the increasing tendency that unprotected and mobile devices are more and more popular. To solve the above problem, this work proposes a forward-secure ABS scheme supporting threshold predicates. The proposed scheme is proved secure under the η-Diffie–Hellman Exponent assumption without random oracles, and is also efficient in terms of communication and computation. Furthermore, it is implemented to show its practical applicability.
Jianghong Wei, Wenfen Liu, Xuexian Hu
Comput. J.3
2014 Security Analysis of EMV Channel Establishment Protocol in An Enhanced Security Model
Yanfei Guo, Zhenfeng Zhang, Jiang Zhang 0001, Xuexian Hu
ICICS4
2014 Traceable attribute-based signcryption
abstract
ABSTRACT Signcryption can provide confidentiality and authenticity for many cryptographic applications. In this study, we propose a new efficient attribute‐based signcryption scheme. This scheme achieves confidentiality against chosen ciphertext attacks and unforgeability against chosen messages attacks in the selective attribute model. In addition, our scheme enjoys traceability by use of non‐interactive witness indistinguishable proofs; that is, the authority can break the anonymity of users when necessary. Compared with previous works, our scheme has advantages in terms of functionality and efficiency simultaneously. Copyright © 2013 John Wiley & Sons, Ltd.
Jianghong Wei, Xuexian Hu, Wenfen Liu
Secur. Commun. Networks2
2013 Fast Estimation of Optimal Marked-Signal Distribution for Reversible Data Hiding
abstract
Recently, code construction approaching the rate-distortion bound of reversible data hiding has been proposed by Lin , in which the coding/decoding process needs the optimal probability distribution of marked-signals as parameters. Therefore, the efficiency and accuracy of estimating the optimal marked-signal distribution will greatly influence the speeds of encoding and decoding. In this paper, we propose a fast algorithm to solve the optimal marked-signal distribution. Furthermore, we modify the method to achieve the optimal distribution directly according to a given distortion constraint or an expected embedding rate, which makes it more practical for applications.
Xiaocheng Hu, Weiming Zhang 0001, Xuexian Hu, Nenghai Yu, Xianfeng Zhao, Fenghua Li 0001
IEEE Trans. Inf. Forensics Secur.3
2009 Efficient Password-Based Authenticated Key Exchange Protocol in the UC Framework
Xuexian Hu, Wenfen Liu
Inscrypt1
2006 On the Rate of Coincidence of Two Clock-Controlled Combiners
Xuexian Hu, Yongtao Ming, Wenfen Liu, Shiqu Li
Inscrypt1