EDBT 2026 Demo / reviewers in the wild / expert
Zhiwei Wang 0003
dblp:10/293-3
· DBLP profile ↗
32ranked-venue papers
24as first author
9since 2021 · last 2025
0000-0003-2932-890XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 8 first-author · 3 since 2021Systems, architecture and hardware · 7 · 5 first-author · 2 since 2021Computer networks · 7 · 5 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Theory of computation · 2 · 2 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Blockchain-Assisted Robust Subgroup ECDSA Multisignature for ConsensusabstractThe robust subgroup multisignature allows any subgroup of signers to generate a multisignature on behalf of the whole group, which can be flexibly applied in many blockchain consensus mechanisms. Unlike the security model of traditional subgroup multisignatures, robustness can prevent dishonest signers from joining a subgroup by checking each individual signature before combining. To enhance the robustness of subgroup multisignatures, we utilize an on-chain smart contract instead of an off-chain combiner to check each individual signature. We propose a blockchain-assisted robust subgroup elliptic curve digital signature (ECDSA) multisignature scheme and prove its robustness and unforgeability. Since the ECDSA signature is the most popular signature used for blockchains and some blockchain platforms, such as Ethereum, already have a precompiled contract for the verification of the ECDSA, the on-chain costs for each single ECDSA signature are very low. Experiments show that our blockchain-assisted subgroup ECDSA multisignature has efficient on-chain costs. On the other hand, multiplicative-to-additive (MtA) protocols are used in the construction of subgroup multisignatures, which results in increased communication and computational costs. We use two popular additive homomorphic encryption scheme (Paillier and Castagnos and Laguillaumie)-based MtA protocols to construct our scheme and test its performance. Finally, we apply our scheme in a consensus mechanism of a distributed blockchain interoperability oracle. Zhiwei Wang 0003 |
IEEE Internet Things J. | 1 |
| 2025 | Multi-Signature and Game Based Blockchain Interoperability OracleabstractTo solve the problem of blockchain interoperability, we propose an efficient decentralization oracle solution. We design a subgroup Schnorr multisignature for the off-chain aggregation mechanism of our system, which is proven to be secure and robust. Compared with threshold signature-based schemes, the subgroup multisignature-based scheme does not require the execution of the distributed key generation protocol, which greatly reduces off-chain costs. The on-chain verification of the Schnorr signature is also more efficient than the pairing-based signatures. Then, we design a fair incentive mechanism to encourage the oracle nodes to work hard to validate the external data, which is based on a repeated dynamic game. Compared with the existing incentive mechanisms, our mechanism considers the real actions of each node to determine whether it should be rewarded or penalized. We implement our system over the Ethereum blockchain, and the experiments show its good performance. Zhiwei Wang 0003, Siu-Ming Yiu, Longwen Lan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | A Privacy-Enhanced Traceable Anonymous Transaction Scheme for BlockchainabstractBlockchain transaction privacy is a highly researched topic across various application scenarios. Current privacy-preserving schemes in blockchain employ advanced cryptographic techniques, such as homomorphic encryption and zero-knowledge proofs, to balance transaction privacy with regulatory requirements. However, these schemes encounter challenges, including computational inefficiency, data expansion, and overlooked metadata privacy, such as timestamp protection. In this paper, we first propose a privacy-enhanced traceable anonymous transaction scheme based on data transaction scenarios. This scheme integrates ring signature and Merkle hash tree techniques, effectively shortening the signature size and optimizing the verification process compared to existing combinations of ring signatures and zero-knowledge proofs. A novel verifiable timestamp privacy protection method is introduced, which obfuscates timestamps to prevent tampering without compromising integrity. To enhance scalability, this method extends to multiple transaction processing scenarios and implements a timestamp-sharing strategy to reduce the computational burden. It also allows tracking authorities to monitor the long-term addresses of both transaction parties if necessary. Rigorous security analysis and extensive experimental evaluations demonstrate that this scheme achieves superior privacy, traceability, and scalability compared to existing approaches. Lingyan Xue, Haiping Huang, Fu Xiao 0001, Qi Li 0011, Zhiwei Wang 0003 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | A Decentralized Oracle Network Constructed From Weighted Schnorr MultisignatureabstractA decentralized oracle network is a good solution for blockchain interoperability, and a multisignature is a proper cryptographic primitive for off-chain aggregation where each participating signer’s public key can be identified during verification. An important requirement for the decentralized oracle network is that some important data requests may require high-reputation nodes to validate the external data, while some common data requests may need only low-cost nodes to execute the validation. Thus, we present a weighted Schnorr multisignature to meet this requirement, which is proven to be unforgeable. However, purely relying on the cryptographic scheme cannot fully identify each participating node’s reputation; thus, we design three on-chain contracts for recording and identifying the oracle nodes’ reputation and realizing the reword mechanism. The on-chain components (e.g., smart contracts) and the off-chain components (e.g., oracle nodes) constitute a whole blockchain interoperability system. We implement our system over the Ethereum platform and analyze its on-chain and off-chain costs. Zhiwei Wang 0003 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | Permissioned Blockchain-Based Secure and Privacy-Preserving Data Sharing ProtocolabstractIn this Internet of Things era, privacy preserving is one of the most vital barriers for personal data sharing. In this article, we present a secure and privacy-preserving data sharing protocol over the permissioned blockchains which require to certificate the users before they submit the transactions. We use the structure-preserving Groth signature to construct the anonymous credentials for satisfying the requirement of permissioned blockchains, and the anonymous credentials does not disclose the real identities of data owners. We prove that the anonymous credential in our protocol achieves the ideal functionality. For the secure access control and privacy protection of the data accessors, we propose an efficiently anonymous authentication scheme which utilizes the ElGamal commitment and the one-out-of-many proof to ensure a data accessor is authorized, but any unauthorized entities cannot learn the real identity of the data accessor, and even the data owner does not know who (although in the access control list) and when downloads his/her data. The blockchain platform is used to record the data storing, access control list, and the storage addresses, which helps to enhance the security level of the protocol. We implement our protocol over the ThinkPad, the RaspBerry Pi, the Huawei cloud, and the Hyperledger Fabric, and the experiments show the good performances. Zhiwei Wang 0003 |
IEEE Internet Things J. | 1 |
| 2023 | Online/Offline and History Indexing Identity-Based Fuzzy Message DetectionabstractFuzzy message detection is a novel cryptographic primitive in which the remote storage cloud can help the client carry out fuzzy detections with some false-positive rate. This primitive protects the privacy of clients and does not reveal exactly the matching messages to the untrusted cloud. However, the existing public-key-based schemes require many public keys to generate a single flag ciphertext. This introduces heavy costs in terms of public-key certificate management. In this paper, we propose an efficient identity-based fuzzy message detection method based on a novel identity-based online/offline encryption scheme. All heavy cost computation operations are carried out in the offline phase without the knowledge of the identities for each message, and the single flag ciphertext can be generated quickly with the message’s identities since only light cost computations are required in the online phase. We apply our scheme to the blockchain-based fuzzy message detection systems. Additionally, we design a new history indexing scheme based on Dodis’ verifiable random function and Schnorr’s signature. The transactions history and order of accessing storage cloud (storing and detecting messages) are indexed, and signed by each client. We provide the analysis of privacy guarantees and differential privacy requirements for our online/offline ID-FMD scheme, and implement our FMD system over the Fibos platform and the Huawei Elastic Cloud. Zhiwei Wang 0003, Feng Liu 0005, Siu-Ming Yiu, Longwen Lan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Chameleon Hash Based Efficiently Updatable Oblivious Key ManagementabstractUpdatable oblivious key management (UOKM) schemes are considered an important backbone of key management for large storage systems, which allows the key management server to periodically update all its clients’ ciphertexts stored in the remote storage cloud without interacting with the clients. All the encrypted data can only be decrypted by the current key (tag), which ensures security against forward and post compromise. In this paper, we propose two UOKM schemes: the first is public key-based, while the second is identity-based. Compared with Jarecki et al.'s UOKM scheme from oblivious pseudorandom functions, the implementations show that our chameleon hash-based schemes have faster updating processes. Moreover, our identity-based UOKM scheme does require ”heavy” public key certificate management and maintains a secure channel from the key management server to the storage cloud, which greatly enhances security and efficiency. Our proofs show that theunconditional obliviousandsecurityof our schemes are based on the security of chameleon hash functions. Zhiwei Wang 0003, Longwen Lan, Siu-Ming Yiu |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Flexible Threshold Ring Signature in Chronological Order for Privacy Protection in Edge ComputingabstractEdge computing can process data at the network edge rather than in the remote cloud. To protect the security of the collected data, blockchain can be used in edge computing. Any request sent from an edge server requesting data storage is a transaction added into the blockchain, which should include the data owners’ signature. For protecting the privacy of data owners, a threshold ring signature can be utilized for the blockchain. In this article, we propose a flexible threshold ring signature scheme in chronological order that has two advantages for solving theupdate problemandchronological problemin practice. Our scheme is a nontrivial extension of Yuenet al.’s signature scheme and has three security properties:unforgeability,anonymity,andchronological sorting. We prove our scheme without random oracles and test our scheme over the Intel Edison development platform simulating practical edge servers. Zhiwei Wang 0003, Jiaxing Fan |
IEEE Trans. Cloud Comput. | 1 |
| 2021 | Identity-Based Verifiable Aggregator Oblivious Encryption and Its Applications in Smart GridsabstractVerifiable aggregator oblivious encryption is a useful notion that not only allows an untrusted aggregator to compute aggregated data without learning any other information but also requires the aggregator to generate a proof of the aggregated data so that anyone can verify the accuracy. Since the aggregator does not learn data that may reveal users' private information and also cannot forge the aggregated data, verifiable aggregator oblivious encryption is suitable for privacy-preserving smart metering. However, NIST has recommended not using public-key-based cryptography in the smart grid because public-key cryptography cannot provide sufficient scalability. Thus, we propose a notion of identity-based verifiable aggregator oblivious encryption and design concrete schemes in this paper. We prove the aggregator oblivious security and aggregator unforgeability of our schemes via the smooth projective hash function and computational Diffie-Hellman assumption. Furthermore, based on our identity-based verifiable aggregator oblivious encryption scheme, we propose an identity-based data aggregation protocol for the smart grid and provide a security analysis in the context of seven typical attacks on smart grids. The implementation of our protocol via the Intel Edison platform shows that it is sufficiently lightweight for resource-constrained smart meters. Zhiwei Wang 0003 |
IEEE Trans. Sustain. Comput. | 1 |
| 2019 | Provably secure key-aggregate cryptosystems with auxiliary inputs for data sharing on the cloud
Zhiwei Wang 0003 |
Future Gener. Comput. Syst. | 1 |
| 2019 | Blind Batch Encryption-Based Protocol for Secure and Privacy-Preserving Medical Services in Smart Connected HealthabstractSmart connected health is a vital Internet of Things (IoT) application proposed to improve the efficiency of healthcare systems and reduce healthcare costs. However, there are many complex security and privacy-preserving concerns in medical services. Blind batch encryption provides a solution for the tradeoff between privacy and security. We propose an efficient blind batch encryption scheme from the CDH assumption, which can be proven to be suitably secure and blind. Based on this scheme, we design a protocol for secure and privacy-preserving medical services in smart connected health. We analyze our protocol in the context of six typical attacks and implement the prototype over the Intel Edison platform. The experiments show that our protocol is efficient for resource-limited devices and “cheap” communication protocols. Zhiwei Wang 0003 |
IEEE Internet Things J. | 1 |
| 2019 | Incentive and Unconditionally Anonymous Identity-Based Public Provable Data PossessionabstractWhen the data is stored in public clouds, provable data possession (for short, PDP) is of crucial importance in cloud storage. PDP can make the users verify whether their outsourced data is kept intact without downloading the whole data. In some application scenarios, anonymity is very important in order to protect the user identity privacy. In order to encourage users to disclose bad event, the government or organization or individual may pay for the user who provides the precious data. Thus, incentive and unconditionally anonymous identity-based public PDP (for short, IAID-PDP) is a very important security concept. From the above requirements, for the first time, we propose the concept of IAID-PDP. We formalize its system model and security model. Based on the bilinear pairings, a concrete IAID-PDP protocol is presented. Based on the standard hard problems, the proposed IAID-PDP protocol is provably secure. IAID-PDP protocol eliminates the complex certificate management since it is designed in the identity-based public key cryptography. Through the performance analysis and security analysis, our IAID-PDP protocol satisfies the following properties: certification elimination, incentive, unconditional anonymity and remote data integrity checking. Huaqun Wang, Debiao He, Jia Yu 0003, Zhiwei Wang 0003 |
IEEE Trans. Serv. Comput. | 4 |
| 2018 | On security challenges and open issues in Internet of Things
Kewei Sha, Wei Wei 0043, T. Andrew Yang, Zhiwei Wang 0003, Weisong Shi |
Future Gener. Comput. Syst. | 4 |
| 2018 | A privacy-preserving and accountable authentication protocol for IoT end-devices with weaker identity
Zhiwei Wang 0003 |
Future Gener. Comput. Syst. | 1 |
| 2018 | Leakage resilient ID-based proxy re-encryption scheme for access control in fog computing
Zhiwei Wang 0003 |
Future Gener. Comput. Syst. | 1 |
| 2018 | Anonymous and secure aggregation scheme in fog-based public cloud computing
Huaqun Wang, Zhiwei Wang 0003, Josep Domingo-Ferrer |
Future Gener. Comput. Syst. | 2 |
| 2017 | EdgeSec: Design of an Edge Layer Security Service to Enhance IoT SecurityabstractWith the widespread availability of connected smart devices, Internet of Things (IoT) is becoming the world's largest computing platform. These large-scale, heterogeneous and resource-constrained devices bring many significant new challenges to the design of efficient and reliable IoT systems. Security is one of the most crucial ones that need to be effectively addressed for the wide adoption of IoT systems. In this paper, we first present an in-depth analysis of security challenges in IoT. Then, we propose EdgeSec, the design of a novel security service which is deployed at the Edge layer to enhance the security of IoT systems. EdgeSec consists of seven major components that work together to systematically handle specific security challenges in IoT systems. Finally, the effectiveness of EdgeSec is demonstrated in the context of a typical IoT application, Smart Home. Kewei Sha, Ranadheer Errabelly, Wei Wei 0043, T. Andrew Yang, Zhiwei Wang 0003 |
ICFEC | 5 |
| 2017 | ABE with improved auxiliary input for big data security
Zhiwei Wang 0003, Nianhua Yang, Victor Chang 0001 |
J. Comput. Syst. Sci. | 1 |
| 2017 | An Identity-Based Data Aggregation Protocol for the Smart GridabstractThe smart grid significantly improves the reliability, efficiency, security, and sustainability of electricity services. It plays an important role in modern energy infrastructure. A drawback of this new technique, however, is that the fine-grained metering data may leak private customer information. Thus, various public-key based data aggregation protocols for privacy protection have been proposed. However, the National Institute of Standards and Technology has recommended not using public-key based cryptography in the smart grid, since maintaining the public-key infrastructure is a heavy cost. In this paper, we propose an identity-based data aggregation protocol for the smart grid, which cannot only prevent unauthorized reading and fine-grained analyzing but can also protect against unintentional errors and maliciously altered messages. The basic building block of our protocol is an identity-based encryption and signature scheme in which an identity-based encryption scheme is combined with an identity-based signature scheme. They share the same private/public parameters, which greatly reduces the complexity of the protocol in the smart grid. Security analysis demonstrates the effectiveness of our protocol in the context of six typical attacks against the smart grid. A prototype implementation based on the Intel Edison platform shows that our protocol is efficient enough for physically constrained smart grid operators, such as smart meters. Zhiwei Wang 0003 |
IEEE Trans. Ind. Informatics | 1 |
| 2017 | Privacy-Preserving Meter Report Protocol of Isolated Smart Grid DevicesabstractSmart grid aims to improve the reliability, efficiency, and security of the traditional grid, which allows two-way transmission and efficiency-driven response. However, a main concern of this new technique is that the fine-grained metering data may leak the personal privacy information of the customers. Thus, the data aggregation mechanism for privacy protection is required for the meter report protocol in smart grid. In this paper, we propose an efficient privacy-preserving meter report protocol for the isolated smart grid devices. Our protocol consists of an encryption scheme with additively homomorphic property and a linearly homomorphic signature scheme, where the linearly homomorphic signature scheme is suitable for privacy-preserving data aggregation. We also provide security analysis of our protocol in the context of some typical attacks in smart grid. The implementation of our protocol on the Intel Edison platform shows that our protocol is efficient enough for the physical constrained devices, like smart meters. Zhiwei Wang 0003 |
Wirel. Commun. Mob. Comput. | 1 |
| 2016 | Improvement on the fault-tolerant group key agreement protocol of Zhao et alabstractAbstract In 2010, Zhaoet al. proposed a fault‐tolerant group key agreement protocol based on RSA cryptosystem. In their protocol, malicious participants can be detected in the fault detection phase. Thus, they do not disrupt the key agreement process. However, there exists a drawback in the protocol of Zhaoet al. After two rounds of trying, an adversary can impersonate any other group member in the third round. We propose an improved protocol to overcome this drawback. The efficiency and security analysis of our improved protocol are also provided in detail. Copyright © 2012 John Wiley & Sons, Ltd. Zhiwei Wang 0003 |
Secur. Commun. Networks | 1 |
| 2016 | CP-ABE with outsourced decryption and directionally hidden policyabstractAbstract Ciphertext‐policy attribute‐based encryption (CP‐ABE) is a novel cryptographic primitive for access controlling. However, the existing CP‐ABE schemes are very inefficient as the decryptions involve many expensive pairing operations. Another drawback is that the access policy itself may disclose some privacies of the users. In certain applications, access structures also should be protected. In this work, we propose a notion of CP‐ABE with outsourced decryption and directionally hidden policy, which allows a semi‐trusted proxy in the cloud to help a user decrypt a ciphertext, but the proxy cannot learn the plaintext and the access policy. We construct a concrete scheme from Waters' CP‐ABE and prove its security, verifiability, and directionally hidden policy. Copyright © 2016 John Wiley & Sons, Ltd. Zhiwei Wang 0003, Wenyang Liu |
Secur. Commun. Networks | 1 |
| 2015 | CCA Secure PKE with Auxiliary Input Security and Leakage Resiliency
Zhiwei Wang 0003, Siu-Ming Yiu |
ISC | 1 |
| 2015 | Attribute-Based Encryption Resilient to Auxiliary Input
Zhiwei Wang 0003, Siu-Ming Yiu |
ProvSec | 1 |
| 2014 | One-time symmetric key based cloud supported secure smart meter readingabstractWith wide deployments of Smart Grid systems, a large amount of energy usage and grid status data have been collected by smart meters. To secure those critical and sensitive data, it is crucial to prevent unauthorized readings to smart meters. Many authentication protocols have been proposed to control the access to the smart meters that are a part of Smart Grid data communication network, but authentication protocols to control readings to the isolated smart meters are mostly ignored. In this paper, we design a one-time symmetric key based cloud supported protocol to enable secure data reading from the isolated smart meters. The protocol mainly consists of two steps. First, an asymmetric key based authentication is designed for the reader-cloud authentication. Then, the cloud assists the meter reader to generate a new one-time symmetric key which is shared with the smart meter. Second, a symmetric key based authentication is designed for the reader-meter authentication. Security analysis shows that our protocol is reliable under most typical attacks. Kewei Sha, Chenguang Xu, Zhiwei Wang 0003 |
ICCCN | 3 |
| 2014 | A privacy protection policy combined with privacy homomorphism in the Internet of ThingsabstractRecently, IOT (Internet of Things) develops very rapidly. However, the personal privacy protection is one of directly important factors that impact the large-scale applications of IOT. To solve this problem, this paper proposes a privacy protection policy based on privacy homomorphism. It can protect the security of personal information well by processing the needs of users without acquiring of plaintext. In another aspect, it also greatly improves the performance of the original multiplication homomorphism algorithm. Guozi Sun, Wan Bao, Zhiwei Wang 0003 |
ICCCN | 5 |
| 2014 | A new definition of homomorphic signature for identity management in mobile cloud computing
Zhiwei Wang 0003, Guozi Sun, Danwei Chen |
J. Comput. Syst. Sci. | 1 |
| 2013 | An ID-based online/offline signature scheme without random oracles for wireless sensor networks
Zhiwei Wang 0003 |
Pers. Ubiquitous Comput. | 1 |
| 2013 | Improved group key transfer protocols from the protocol of Harn et alabstractABSTRACT In 2010, Harn et al. proposed an authenticated group key transfer protocol‐based secret sharing. In their protocol, for distributing a secret group key involving t group members, the key generation center (KGC) needs to broadcast a message containing (t + 1) elements to all group members, whereas each group member needs to compute a tth‐degree interpolating polynomial to recover the secret group key. Thus, the protocol of Harn et al. is only suitable for small‐size groups. We propose an improved protocol from the protocol of Harn et al. In our protocol, the size of a broadcasted message from the KGC is fixed, and each group member only needs to compute a fixed‐degree interpolating polynomial to recover the group key. Thus, our protocol can be suitable for large‐size groups. On the other hand, in the protocol of Harn et al., the KGC should be mutually trusted because it knows all group keys for every communication. If the KGC is untrustworthy, it can bring great threats to the group communications. In this paper, we also propose another improved group key transfer protocol based on untrustworthy KGC. Copyright © 2012 John Wiley & Sons, Ltd. Zhiwei Wang 0003 |
Secur. Commun. Networks | 1 |
| 2012 | Improvement on Ahn et al.'s RSA P-Homomorphic Signature Scheme
Zhiwei Wang 0003 |
SecureComm | 1 |
| 2009 | Remark on Yu et al.'s Online/Offline Signature Scheme in CT-RSA 2008abstractIn CT-RSA 2008, Yu et al. proposed a family of three efficient Online/Offline signature schemes, which are especially suitable for the devices with limited computing capabilities. In this paper, we propose a new security model of Online/Offline signature. We find that Yu et al.' basic scheme is insecure under our model. We repair Yu et al.'s loophole by proposing a modified scheme. Xiao-Long Ma, Zhiwei Wang 0003, Lize Gu, Yixian Yang |
IAS | 2 |
| 2008 | A New Construction of Multivariate Public Key Encryption Scheme through Internally Perturbed Plus
Zhiwei Wang 0003, Xuyun Nie, Shihui Zheng, Yixian Yang |
ICCSA (2) | 1 |