EDBT 2026 Demo / reviewers in the wild / expert
Min Luo 0002
dblp:10/3621-2
· DBLP profile ↗
65ranked-venue papers
1as first author
60since 2021 · last 2026
0000-0002-1819-9332ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 25 since 2021Computer networks · 18 · 16 since 2021Systems, architecture and hardware · 12 · 1 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On the Preimage Leakage of Property-Preserving Hash
Yangzhou Cao, Min Luo 0002, Cong Peng 0005, Yi Wang 0055, Rongmao Chen, Debiao He |
PKC (4) | 2 |
| 2026 | Federated learning of diffusion networks
Kudereti Kuerban, Min Luo 0002, Hao Huang 0001, Zongpeng Li |
Expert Syst. Appl. | 2 |
| 2026 | A survey on threshold digital signature schemesabstractAbstract Threshold signature, as a privacy-preserving distributed signature, has become the underlying technology in various fields over the last decade. It is useful to protect against a single point of failure and can effectively ensure key security. In recent years, many different digital signatures have been thresholded and many new techniques, algorithms, and protocols have been proposed. This paper introduces the mainstream threshold signature schemes based on the signatures by several standards. We comprehensively investigate various aspects of these threshold signature schemes for comparison and evaluation, and provide the relevant applications and more potential directions for threshold signature. Debiao He, Min Luo 0002 |
Frontiers Comput. Sci. | 4 |
| 2026 | Towards privacy preservation in smart grids via controlled redactable signatures
Xiaoying Jia 0002, Min Luo 0002, Zhiyan Xu |
J. Syst. Archit. | 3 |
| 2026 | Threshold Issuance Selective Disclosure Credentials With Equivalence Class SignatureabstractAnonymous credentials offer privacy-preserving authentication and authorization by making assertions about identity in the digital realm. To overcome the reliance on a single trusted issuer, decentralized variants have emerged. A classic approach is to split the responsibility of issuing credentials among multiple issuers in a threshold manner (e.g.,t-out-of-n). Unfortunately, among existing threshold protocols, non-interactive practical constructions can only guarantee security in honest majority settings, while interactive constructions face two primary efficiency bottlenecks: either they require an excessive number of interaction rounds, or they fail to support constant-size credential showings for selective disclosure. In this work, we address these challenges by presenting a threshold issuance anonymous credential (TIAC) protocol, built upon the recent advanced signatures, i.e., Equivalence Class Signatures (EQS). Our proposed solution involves a three-round protocol that realizes a standard threshold issuing functionality, providing composable security against a malicious adversary corrupting the majority of issuers. We thereafter introduce a provably secure construction of the TIAC protocol with constant-size showings by combining the proposed threshold issuing protocol and set commitments. We rigorously prove our protocol in the universal composability (UC) framework. The practicality of our protocol is demonstrated through benchmark comparisons with the state-of-the-art EQS-based solution (ASIACRYPT ’24). The benchmarking results show that, with 64 participating issuers, our improvements go up to 6.72× for the threshold issuance phase when observed over WAN. Debiao He, Cong Peng 0005, Min Luo 0002 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | Secure and Dropout-Resilient Three-Party Clustering Based on Cloud-Edge-Client CollaborationabstractClustering algorithms, as the core technology in data analysis, can extract potential patterns and regularities from complex data. However, deploying k -means clustering on resource-limited devices remains a challenge. Despite the promise of cloud computing, outsourcing data to a remote cloud leads to high latency and privacy risks. Moreover, the stability and speed of cloud can be affected by the state of network and configuration, which leads to computation error. Therefore, we design a secure and dropout-resilient k -means clustering scheme based on cloud-edge-client collaboration architecture. In our scheme, cloud server simply generates multiplication triples in pre-processing phase and can be offline. In online phase, IoT devices secretly share the raw sensing data with three edge servers. Then edge servers accomplish the clustering task interactively. We propose four basic protocols based on vector space secret sharing, including Euclidean distance, comparison, minimum and division protocols. By applying these protocols, we construct a clustering scheme that can tolerate the exit of one edge server and corruption of two edge servers. Since edge servers are generally located in trusted environment, we allow them to reconstruct clustering result and provide low-latency and high-reliability service. We prove that the basic protocols and clustering scheme are secure against semi-honest adversary. We conduct the experiments on two realistic datasets, showing that our scheme has good efficiency and is suitable for practical application. Hong Qin 0009, Debiao He, Min Luo 0002 |
ACM Trans. Internet Techn. | 4 |
| 2025 | A Framework for Efficient Enhanced Privacy ID from Group Actions
Ying Chen 0030, Debiao He, Zijian Bao, Cong Peng 0005, Min Luo 0002 |
Inscrypt (3) | 5 |
| 2025 | Vertical Federated Convolutional Framework Based on Function Secret Sharing
Min Luo 0002, Debiao He |
Inscrypt (3) | 3 |
| 2025 | MDKG: Module-Lattice-Based Distributed Key Generation
Debiao He, Zhichao Yang 0002, Min Luo 0002, Cong Peng 0005 |
ICICS (1) | 4 |
| 2025 | KSFed: A Defense against Poisoning Attacks in Federated Learning using Statistical AnalysisabstractFederated Learning (FL) has been widely applied across various domains for collaborative training while preserving data privacy, but it remains highly vulnerable to poisoning attacks that compromise the global model’s integrity and performance. Existing clustering-based defense methods, such as FLAME, filter out malicious models by calculating vector similarities between local models but rely heavily on the assumption of independent and identically distributed client data. In this paper, we propose KSFed, a novel defense framework that detects poisoning attacks through the analysis of probability distributions of model parameters. KSFed treats model parameters as samples from a distribution, where benign models exhibit similar patterns while malicious models show significant deviations, allowing it to identify and filter out malicious models without relying on assumptions about attack types, adversarial strategies, or client data distributions. Experimental results show that KSFed surpasses FLAME and other clustering-based defenses, reducing backdoor accuracy (BA) by 8.33% to 99.74% under sophisticated attack strategies and highly non-IID client data distributions, while maintaining the global model’s main task accuracy (MA). Jiaxuan Zhao, Qin Liu 0003, Min Luo 0002, Wei Zhao 0054, Debiao He |
TrustCom | 4 |
| 2025 | Efficient Module-Lattice-Based Certificateless Online/Offline Signcryption Scheme for Internet of Medical ThingsabstractThe Internet of Medical Things (IoMT) has achieved remote diagnosis and real-time health monitoring through intelligent sensor devices and Internet of Things (IoT) technology, providing great convenience for analyzing medical conditions between doctors and patients. However, sensitive information such as patient medical data may face security challenges such as data leakage and abuse during transmission in the IoMT. To ensure the confidentiality and unforgeability of medical data transmission, scholars have proposed many cryptographic schemes. With the development of quantum computers, schemes based on traditional cryptographic primitives have become insecure. Existing cryptographic schemes for IoMT cannot simultaneously meet the security requirements of high communication performance, low computational overhead, and resistance to quantum attacks. Therefore, we propose an efficient module-lattice-based certificateless online/offline signcryption (MLCLOOSC) scheme resistant to quantum attacks while meeting the confidentiality and unforgeability requirements under Type I and Type II attacks. Compared with five recent CLOOSC schemes, theoretical analysis, and experimental test results show that the proposed scheme outperforms the other five schemes regarding computational and communication costs and security. Therefore, our scheme is more suitable for application in IoMT scenarios. Debiao He, Zhichao Yang 0002, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 4 |
| 2025 | Verifiable and Forward-Secure Multikeyword Query in Internet of Medical ThingsabstractThe Internet of Medical Things (IoMT) plays a pivotal role in modern healthcare systems, enhancing patients’ medical experiences and improving the efficiency of public medical services. However, concerns regarding security and privacy may hinder the widespread implementation and development of IoMT in practical applications. Dynamic Searchable Symmetric Encryption (DSSE) can maintain search capabilities on encrypted data, even when files are dynamically added or deleted. Earlier DSSE schemes typically support only single keyword query and provide forward security under the assumption of semi-honest servers, which significantly limits their applicability in real-world scenarios. To resolve these limitations, we propose a forward-secure and verifiable DSSE scheme that supports multikeyword conjunctive query. Our scheme ensures forward security by utilizing a chain structure and guarantees correctness and completeness through RSA accumulator and Homomorphic Message Authentication Code (HMAC). Furthermore, we integrate the forward index and inverted index to enable efficient retrieval. Through comprehensive security and performance analysis, we demonstrate that our scheme effectively protects users’ privacy while maintaining low computation and communication overheads. Finally, some experimental evaluations are conducted to verify both the correctness and efficiency of the proposed scheme. Debiao He, Min Luo 0002 |
IEEE Internet Things J. | 4 |
| 2025 | EAPDS: Efficient Auditable and Privacy-Preservation Data-Sharing Scheme Based on Attribute-Based Encryption for IoMTabstractData sharing schemes based on the Internet of Medical Things (IoMT) have emerged as a more convenient way to monitor and manage individuals’ health. However, this scenario faces challenges such as privacy preservation, effectiveness, and practicality, which hinder its further development. To the best of our knowledge, there is no agreed-upon data-sharing method that addresses all of these problems. In this paper, we make a step ahead by designing an Efficient and Auditable Privacy-preservation Data Sharing scheme (EAPDS) based on multi-authority attribute-based encryption. EAPDS designs an auditable anonymous authentication mechanism to realize identity privacy protection, as well as an efficient multi-authority attribute-based encryption mechanism to achieve the efficiency and practicability of data-sharing. Formal security analysis demonstrates EAPDS can resist replayable chosen-ciphertext attack. Many performance evaluation experiments and functional analyses show that EAPDS not only performs better than existing medical data-sharing schemes in terms of efficiency, but also in terms of privacy protection and feasibility. Consequently, our EAPDS scheme holds promising application prospects. Hui Wang 0124, Yong Xie 0003, Min Luo 0002, Yi-Ning Liu 0002, Syed Hamad Shirazi |
IEEE Internet Things J. | 3 |
| 2025 | A quantum-resistant oracle-based conditional payment scheme from lattice
Wenye Liu, Debiao He, Zhichao Yang 0002, Xiaoying Jia 0002, Min Luo 0002 |
J. Inf. Secur. Appl. | 5 |
| 2025 | An Efficient Delegatable Order-Revealing Encryption Scheme for Multi-User Range QueriesabstractTo balance data confidentiality and availability, order-revealing encryption (ORE) has emerged as a pivotal primitive facilitating range queries on encrypted data. However, challenges arise in diverse user domains where data is encrypted with different keys, giving rise to the development of delegatable order-revealing encryption (DORE) schemes. Regrettably, existing DORE schemes are susceptible to authorization token forgery attacks and rely on computationally intensive bilinear pairings. This work proposes a novel solution to address these challenges. We first introduce a delegatable equality-revealing encryption scheme, enabling the comparison of ciphertexts encrypted by distinct secret keys through authorization tokens. Building upon this, we present a delegatable order-revealing encryption that leverages bitwise encryption. DORE supports efficient multi-user ciphertext comparison while robustly resisting authorization token forgery attacks. Significantly, our approach distinguishes itself by minimizing bilinear pairings. Experimental results highlight the efficacy of DORE, showcasing a notable speedup of$2.8\times$in encryption performance and$1.33\times$in comparison performance compared to previous DORE schemes, respectively. Jingru Xu, Cong Peng 0005, Jintao Fu, Min Luo 0002 |
IEEE Trans. Cloud Comput. | 5 |
| 2025 | MISP: An Efficient Quantum-Resistant Misbehavior Preventing Scheme With Self-Enforcement for Vehicle-to-EverythingabstractIn the Vehicle-to-Everything (V2X) communication system, the presence of ambiguous warnings significantly increases the risk of severe accidents, posing a substantial threat to the safety of autonomous driving. It is crucial to detect such confusing warnings to avoid danger. Existing solutions to address this issue heavily rely on trust entities or are constructed based on number theory assumptions, leading to low efficiency and vulnerability to quantum attacks. In this paper, we leverage the double authentication-preventing signature scheme (DAPS) to present a revocable identity-based double-authentication preventing signature scheme (RIDAPS) and provides an instantiation from lattice. Furthermore, we propose a post-quantum secure misbehavior preventing scheme (Misp) based on our RIDAPS scheme. We give a detailed proof in the random oracle model (ROM) to demonstrate that our contribution achieves security requirements. Additionally, the efficiency evaluation results demonstrate that our scheme is suitable to be applied in V2X. Ying Chen 0030, Debiao He, Zijian Bao, Huaqun Wang, Min Luo 0002 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | QuickNLP: Faster Protocol of Secure Natural Language Processing for Edge ComputingabstractArtificial intelligence (AI) on edge refers to combining edge computing and AI, and enjoys the benefit of distributed structure, intelligence, and timeliness. Specifically, natural language processing model, which allows to processing language data right close to the device location within milliseconds and providing intelligent controller, have revolutionized researches. Recently, privacy concerns spiked when it is applied in healthcare, autonomous vehicles, manufacturing, etc. Secure multi-party computation has the advantage of strong security guarantee and computability over multi-sourced data. However, it is challenging to translate the timeliness benefit of Edge AI to secure deployment, as only constrained computation and storage resources are available for the edge nodes. We focus on the natural language processing (NLP), and design an efficient secure three-party computation protocol (called QuickNLP) in the semi-honest setting tolerating one corruption. Specifically, for the non-linear operations, we adopt the constant-round distributed comparison function (${\sf DCF}$) to evaluate the piecewise function efficiently with high accuracy. The proposed framework has been experimented with Python and the results show that QuickNLP could be a valuable solution for data privacy in edge computing. Specifically, compared to the existing protocol, we improve the computation costs by a factor of roughly$7\times$. Lingyan Han, Min Luo 0002, Wei Zhao 0054, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | $k$k-TEVS: A $ k$k-Times E-Voting Scheme on Blockchain With SupervisionabstractThe e-vote is regarded as a way to express the opinion that the voters ask for. Actually, the e-vote could be applied wildly like questionnaire, survey and feedback. Moreover, the coexistences of efficiency and security as well as transparency and privacy could be considered as building blocks in the e-vote system. The blockchain could provide a public access board to reduce the storage costs for the field consisted of the vote group manager (GM) with its vote assistants (VA). Particularly the$k$-times anonymous authentication ($k$-TAA) could also be a practical approach to preserve voters’ privacy and reduce the computation costs during the vote process. However, the e-vote scheme with pure$k$-TAA strategy could damage either the supervision of voting or the efficiency and consistency of authentication process. What’s more, the impacts of dishonest voters couldn’t be stopped until the vote end. To tackle these problems, we apply the accumulator technology to add or revoke the voters at any time and extend the framework of$k$-TAA with the update process for the e-vote on blockchain for supervision ($ k$-TEVS). In our scheme, the voter updates his membership witness and proves the fact that he is still a valid member with respective VA under the latest accumulator value. What’s more, this witness update operation is not contained in the authentication process, which means that the authentication process is still constant and efficient. Moreover, our add or delete update process with signature of knowledge needs only one pairing operation. For the security, we prove that the relaxed anonymity still holds in the$ k$-TEVS framework. Finally, We implement$ k$-TEVS scheme, the Emura’s work [1] and the Huang’s work [2] for comparison. Then we make time cost and communication cost experiments, which present the feasibility and practicality of this scheme. Yang Liu 0368, Debiao He, Min Luo 0002, Lianhai Wang, Cong Peng 0005 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Efficient Three-Party ECDSA Signature Based on Replicated Secret Sharing With Identifiable Abort
Wenjing Cheng, Chenkai Zeng, Min Luo 0002, Qingcai Luo |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | How to Construct Public Timeline for RSA-Formed Time-Lock Cryptography
Huixuan Jin, Cong Peng 0005, Jintao Fu, Min Luo 0002 |
Inscrypt (2) | 4 |
| 2024 | CMAE-MTC: A Contextual Masked AutoEncoder Based Multi-Level Traffic ClassifierabstractTraffic classification is vital for network management, ensuring efficient resource allocation, network security, and quality of service. Due to the increasing complexity and anonymity of network traffic, traditional deep learning methods of traffic classification have exposed the following limitations on this critical task. First, traditional methods tend to consider the whole raw packet data as input of the model, ignoring the importance of a well-formed presentation. Second, direct application of the simple models without targeted improvement cannot deeply capture the feature of the traffic flow, especially those encrypted. Last but not least, supervised learning of traditional methods requires a much higher cost to learn for specific scenarios, resulting from the heavy dependence on labels. To break above limitations, we propose a classifier called CMAE-MTC, which involves a well-designed multi-level presentation matrix of traffic flows, reflecting the association between traffic flows and packets, headers and payloads. Meanwhile, our method introduces an improved masked autoencoder paradigm with a latent contextual regressor for self-supervised learning instead of supervised learning. At last, we replace the naive Vision Transformer in the fine-tuning stage with a multi-level attention module, forcing the model to capture the features from not only the small patches of headers and payloads but also the overall packets and flows. We validate the performance of our model on four real-world available encrypted traffic datasets, ISCXVPN, ISCXTor, USTC-TFC, and CICIoT. Our experimental results demonstrate that our proposed method outperforms state-of-the-art methods for traffic classification tasks. Zecheng Yuan, Min Luo 0002, Cong Peng 0005, Qin Liu 0003 |
ISPA | 2 |
| 2024 | Isogeny-Based Password-Authenticated Key Exchange Based on Shuffle Algorithm
Congrong Peng, Cong Peng 0005, Qingcai Luo, Min Luo 0002 |
ISPEC | 5 |
| 2024 | Secure Federated Distillation Framework for Encrypted Traffic Classification
Wei Zhao 0054, Min Luo 0002, Debiao He |
ISPEC | 4 |
| 2024 | Efficient FSS-based Private Statistics for Traffic MonitoringabstractThe emergence of traffic monitoring systems aims to improve living standards, reduce environmental pollution and minimize the economic impact of traffic accidents. These systems mainly function by collecting user data for analysis and formulating corresponding countermeasures. However, the widespread collection of data inevitably raises concerns about the leakage of personal privacy, which is a key safety issue in traffic monitoring. Many researchers are now focusing on traffic flow data statistics, and researchers such as Mohammadali have used homomorphic encryption to design models that enable statistics while protecting user privacy. However, the associated encryption, decryption, and communication overheads are substantial. Therefore, we have moved away from traditional models and encryption/decryption algorithms, proposing a new, efficient, and lightweight system that leverages Distributed Point Functions (DPF) and Distributed Comparison Functions (DCF). This approach not only preserves user privacy but also significantly reduces overhead. Our system is built on a client dual-server framework, designed to withstand attacks from partially sincere adversaries, enabling third-party access to aggregated data or data exceeding a threshold of t, without compromising individual user privacy. Compared to existing related work, our method offers a substantial improvement in operational efficiency while maintaining the same level of communication overhead. Our research provides an advanced solution for aggregation scenarios in traffic monitoring systems, offering lower costs while ensuring robust user privacy. This work lays a strong foundation for the future development of comprehensive traffic monitoring systems. Min Luo 0002, Zizhong Wei |
TrustCom | 3 |
| 2024 | Multi-party privacy-preserving decision tree training with a privileged party
Yiwen Tong, Min Luo 0002, Debiao He |
Sci. China Inf. Sci. | 3 |
| 2024 | The governance technology for blockchain systems: a surveyabstractAbstract After the Ethereum DAO attack in 2016, which resulted in significant economic losses, blockchain governance has become a prominent research area. However, there is a lack of comprehensive and systematic literature review on blockchain governance. To deeply understand the process of blockchain governance and provide guidance for the future design of the blockchain governance model, we provide an in-depth review of blockchain governance. In this paper, first we introduce the consensus algorithms currently used in blockchain and relate them to governance theory. Second, we present the main content of off-chain governance and investigate two well-known off-chain governance projects. Third, we investigate four common on-chain governance voting techniques, then summarize the seven attributes that the on-chain governance voting process should meet, and finally analyze four well-known on-chain governance blockchain projects based on the previous research. We hope this survey will provide an in-depth insight into the potential development direction of blockchain governance and device future research agenda. Guocheng Zhu, Debiao He, Haoyang An, Min Luo 0002, Cong Peng 0005 |
Frontiers Comput. Sci. | 4 |
| 2024 | PEACS: A Privacy-Enhancing and Accountable Car Sharing SystemabstractCar sharing is gaining increased popularity in urban transportation which allows individuals to conveniently rent vehicles for short periods. Such systems, however, present considerable challenges to security such as unauthorized access and privacy data breaches, as service providers are able to track the precise mobility patterns of all customers. Nevertheless, efforts in solving the security and privacy concerns associated with car-sharing services are relatively few, in particular for a trade-off between privacy preservation and accountability of misbehaviors. In this work, we propose an efficient Privacy-Enhancing and Accountable Car Sharing System (PEACS), introduced to mitigate the aforementioned threats. PEACS primarily employs several key ingredients, including structure-preserving signatures on equivalence classes (J CRYPTOL’s 19), as well as two primitives designed in this paper, namely: signatures of knowledge and identity-based structure-preserving signatures with a tag on equivalence classes. Furthermore, we employ a bivariate polynomial function to establish a revocation mechanism that ensures accountability. We provide thorough security proof to demonstrate the security and privacy of PEACS. Comprehensive performance evaluation and comparison results point out that our proposed scheme is feasible in practical settings. Debiao He, Zijian Bao, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 4 |
| 2024 | A Privacy-Aware K-Nearest Neighbor Query Scheme for Location-Based ServicesabstractThe advancement of spatial positioning technology and mobile Internet makes it possible for location-based services (LBSs), which provide users with personalized services by collecting and analyzing their location information. The$k$-nearest neighbor (kNN) query algorithm can be used in LBS by returning$k$locations closest to the target location. Due to the fact that LBS involves large amounts of private information and is usually outsourced to cloud servers, privacy issues have become increasingly prominent. In order to provide LBS services in outsourced cloud environments while protecting user location privacy, a privacy-aware kNN protocol under the dual cloud server model is presented. In the proposed scheme, location-related information is encrypted using a double-trapdoor public-key encryption algorithm and stored in a$k$-dimension (KD)-tree before being outsourced to cloud servers. A Euclidean distance protocol and a comparison protocol are provided as basic components to realize secure search, insertion, and deletion of the encrypted KD-tree by the cooperation of two cloud servers. Security analysis indicates that the proposed scheme ensures location and query privacy. Performance evaluation results demonstrate that the scheme is practical in terms of time and communication consumption. Jiaqi Qi, Xiaoying Jia 0002, Min Luo 0002 |
IEEE Internet Things J. | 3 |
| 2024 | Ciphertext Range Query Scheme Against Agent Transfer and Permission Extension Attacks for Cloud ComputingabstractRange query is commonly used to support ciphertext retrieval on encrypted databases in a cloud-based environment, and order-revealing encryption (ORE) plays an increasingly important role in range query for ciphertext field processing. Specifically, one can utilize ORE to facilitate comparators to determine whether the order of ciphertext(s) corresponds to the associated plaintext(s). Newer ORE designs include those that are resistant to common attacks (e.g., spectral attacks) and those that are capable of supporting both multi-client and single-client settings. However, in the scenario of cross-database range queries, existing multi-client ORE approaches generally pass the data owner’s query key to the searcher during the authorization process. Consequently, this results in agent transfer and permission extension, which can be exploited to facilitate unauthorized access to the database data. To solve these limitations, we propose om-ORE. The latter uses the oblivious pseudorandom function (OPRF) protocol to further enhance the security of token generation mechanism in ORE, and is designed to ensure that neither the data owner nor the authorized client reveals any secret key or expected query range to each other. Using the proposed om-ORE scheme as a building block, we design a secure multi-client ciphertext range query scheme that is resilient to both agent transfer and permission extension attacks. The performance evaluation shows that om-ORE inherits the advantages of state-of-the-art multi-client ORE approaches, in terms of ciphertext size and comparison efficiency, as well as having comparable performance in the token generation process. Hongyi Qiao, Cong Peng 0005, Min Luo 0002, Debiao He |
IEEE Internet Things J. | 4 |
| 2024 | High-speed batch verification for discrete-logarithm-based signatures via Multi-Scalar Multiplication Algorithm
Cong Peng 0005, Lingyan Han, Min Luo 0002 |
J. Inf. Secur. Appl. | 5 |
| 2024 | The implementation of polynomial multiplication for lattice-based cryptography: A survey
Chenkai Zeng, Debiao He, Cong Peng 0005, Min Luo 0002 |
J. Inf. Secur. Appl. | 5 |
| 2024 | Optimizing Dilithium Implementation with AVX2/-512abstractDilithium is a signature scheme that is currently being standardized to the Module-Lattice-Based Digital Signature Standard by NIST. It is believed to be secure even against attacks from large-scale quantum computers based on lattice problems. The implementation efficiency is important for promoting the migration of current cryptography algorithms to post-quantum cryptography algorithms. In this article, we optimize the implementation of Dilithium with several new approaches proposed. Firstly, we improve the efficiency of parallel NTT implementations. The overhead of shuffling operations is reduced in our implementations, and fewer loading instructions are invoked for the precomputations. Then, we optimize the sampling and bit-packing of polynomial coefficients in Dilithium. We can handle double the number of coefficients within one register using a new approach for the sampling of secret key polynomials. The approaches proposed in this article are applicable to implementations under AVX2 and AVX-512 instruction sets. Take Dilithium2 as an illustration, our AVX2 implementation demonstrates improvements of 22.7%, 16.9%, and 13.5% for KeyGen, Sign, and Verify compared with the previous implementation. Runqing Xu, Debiao He, Min Luo 0002, Cong Peng 0005, Xiangyong Zeng |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2024 | Cryptographic Primitives in Privacy-Preserving Machine Learning: A SurveyabstractAdvances in machine learning have enabled a broad range of complex applications, such as image recognition, recommendation system and machine translation. Data plays an important role in our increasingly complex and diverse environments, and this also reinforces the importance of data privacy in machine learning-enabled applications. Although there are a number of literature survey articles on machine learning, only a few studies have investigated the cryptographic primitives used in privacy-preserving machine learning (PPML). In other words, there is no, or limited, systematization of knowledge (SoK) that provides a comprehensive introduction to cryptography that have been deployed in PPML. In this paper, we firstly introduce some basic concepts such as machine learning tasks and processes. Then, we review and systematize the cryptographic primitives used in PPML. We analyze these existing privacy-preserving schemes in their learning process, especially training and inference. Finally, we conclude our survey and provide an outlook on future trends and research directions in the field. Hong Qin 0009, Debiao He, Muhammad Khurram Khan, Min Luo 0002, Kim-Kwang Raymond Choo |
IEEE Trans. Knowl. Data Eng. | 5 |
| 2024 | Constant-Size Verifiable Timed Signatures from RSA Group for Bitcoin-Based Voting ProtocolsabstractA verifiable timed signature (VTS) scheme allows a signature to be time-locked to a known message for a predetermined duration denoted as$\mathsf {T}$. Verifiability ensures that anyone can verify that the time-lock contains a valid signature without completing the computation. In this paper, we introduce a novel VTS construction method based on the RSA group, designed to maintain a constant level of size. This approach serves as an improvement over the previous linear level size construction method (CCS 2020). First, we construct it by using a commitment to a valid RSA signature. This commitment can only be opened to a regular RSA signature after a sequential computation period. Our scheme utilizes a trapdoor verifiable delay function, RSA signatures, and a specialized zero-knowledge proof to instantiate the proposed scheme. We also conduct proofs in three aspects: correctness, soundness, and security. Furthermore, we identify potential applications for VTS and present a simple Bitcoin voting protocol based on an open vote protocol by utilizing VTS. Experimental results show that our scheme is more efficient compared to the construction of VTS (CCS 2020), reducing the signature size by at least 90.5% and lowering computational costs by at least 77%. Zijian Bao, Debiao He, Min Luo 0002, Xiangyong Zeng |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | Block Ciphers Classification Based on Randomness Test Statistic Value via LightGBM
Min Luo 0002, Cong Peng 0005, Debiao He |
ICICS | 2 |
| 2023 | Secure CNN Training and Inference based on Multi-key Fully Homomorphic EncryptionabstractConvolutional neural network (CNN) has attracted increasing attention and been widely used in imaging processing, bioinformatics and so on. As the cloud computing and multiparty computing are booming, the training and inference data of convolutional neural network often comes from diverse users. These users tend to jointly perform the computation but reluctantly share original data with others. Multi-key fully homomorphic encryption (MKFHE) supports homomorphic computation on ciphertexts encrypted with different keys, which is especially suitable for this scenario. In this paper, we firstly propose secure convolution, matrix multiplication, comparison and maximum protocols based on MKFHE. Then we design the secure CNN training and inference framework, outsourcing almost all computations to cloud server. To improve the efficiency, we use key switching technique for ciphertext transformation. We prove that the proposed frameworks are secure and feasible. The theoretical and experimental analysis show that our framework achieves the trade-off between security, efficiency and scalability. Hong Qin 0009, Debiao He, Min Luo 0002 |
ICPADS | 4 |
| 2023 | FleS: A Compact and Parameter-Flexible Supersingular Isogeny Based Public Key Encryption Scheme
Weihan Huang, Min Luo 0002, Cong Peng 0005, Debiao He |
ProvSec | 2 |
| 2023 | Traceable Ring Signatures from Group Actions: Logarithmic, Flexible, and Quantum Resistant
Min Luo 0002, Zijian Bao, Cong Peng 0005, Debiao He |
SAC | 2 |
| 2023 | CUFT: Cuflow-Based Approach with Multi-headed Attention Mechanism for Encrypted Traffic Classification
Xin Zong, Min Luo 0002, Cong Peng 0005, Debiao He |
SecureComm (1) | 2 |
| 2023 | A Group Signature Scheme With Selective Linkability and Traceability for Blockchain-Based Data Sharing Systems in E-Health ServicesabstractRecently, with the rapid improvement of e-health technology, a large amount of precious medical data has been accumulated in different entities, such as hospitals, clinics, and medical institutions, promoting the development of data sharing in e-health services. However, most of them lacks fine-grained functionalities: selective linkability and traceability, which are critical in an e-health environment. Furthermore, we observe that existing schemes mostly rely on centralized storage centers, which will lead to a single point of failure and privacy disclosure. In this article, we first construct a group signature schemeSLTGSsuitable for a data sharing environment. It supports selectively linking two different message-signature pairs to the same signer. Further, it provides an algorithm to trace the signer. Then, based on theSLTGSscheme, we leverage distributed technology (i.e., interplanetary file system (IPFS) and blockchain) and attribute-based encryption to propose a distributed data sharing scheme. We claim that our scheme meets anonymity, accountability, linkability, traceability, fine-grained and efficient access control, and distributed storage. Moreover, the proposed data sharing scheme yields a practical performance making it suitable for e-health applications. Zijian Bao, Debiao He, Huaqun Wang, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 4 |
| 2023 | A Secure Certificateless Signcryption Scheme Without Pairing for Internet of Medical ThingsabstractThe Internet of Medical Things (IoMT), which integrates medical sensors with the Internet of Things, is helpful for providing remote diagnosis and real-time decision making. Massive data collected by medical and healthcare monitoring sensors in the IoMT involves sensitive patient information. It brings some security challenges to validate the legitimacy of participating entities and protect patient data privacy. A certificateless signcryption (CLSC) scheme combines encryption and signature that can offer authenticity, confidentiality, and unforgeability, providing a viable solution to the data privacy issue of the IoMT. However, existing CLSC schemes fail to meet confidentiality or unforgeability, or require expensive computation overhead to perform pairing operations. This article first presents a new CLSC scheme for secure data transmission and better smart services in IoMT, which replaces the signature part with the Schnorr signature. We then give a thorough security proof under the random oracle model. Besides, we elaborately evaluate the performance and security of some existing solutions with our solution. Finally, the experiment results indicate that our solution can achieve a better balance between security and performance than some existing schemes. Therefore, in terms of feasibility, our scheme is more suitable for the IoMT scenario. Xin Chen 0051, Debiao He, Muhammad Khurram Khan, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 4 |
| 2023 | SAPFS: An Efficient Symmetric-Key Authentication Key Agreement Scheme With Perfect Forward Secrecy for Industrial Internet of ThingsabstractAn edge-cloud Industrial Internet of Things (IIoT) can help meet the computing requirements of industrial applications, particularly in time and latency-sensitive services. Ensuring the security and privacy of (sensitive) information collected by IIoT end devices is crucial, and has an important impact on the decision making as well as operational safety. However, these devices are energy constrained and vulnerable to corruption. The authentication schemes suitable for this environment need to be lightweight, efficient, and concise. In this article, we propose a symmetric-key authentication scheme with a perfect forward secrecy (SAPFS), which relies on both authentication and derivation master keys. The SAPFS scheme uses only XOR operation and hash function to achieve mutual authentication, key exchange, and message integrity. On the condition of the irreversible hash function and indistinguishable master keys, we demonstrate that SAPFS is provably secure under the random oracle model. Finally, a comparative summary with three other competing schemes (in terms of communication cost, storage requirement, and computation complexity) demonstrates its utility. Yunru Zhang, Debiao He, Pandi Vijayakumar, Min Luo 0002, Xinyi Huang 0001 |
IEEE Internet Things J. | 4 |
| 2023 | EPRICE: An Efficient and Privacy-Preserving Real-Time Incentive System for Crowdsensing in Industrial Internet of ThingsabstractIn crowdsensing, we can leverage intelligent devices and real-time incentive mechanisms to facilitate the collection of reliable and timely data in Industrial Internet of Things (IIoT) settings. In such a setting, one can use cryptographic primitives to support data privacy preservation and quality-aware reward distribution simultaneously. However, existing approaches might incur expensive computation costs, suffer from overflow problems, or rely on implicit security conditions. In this paper, we propose anEfficient andPrivacy-preservingReal-timeIncentive system forCrowdsEnsing (EPRICE), designed to estimate the reliability of sensing data in a privacy-preserving setting. The theoretical analysis demonstrates that our proposed system achieves a high level of privacy-preserving for real-time reward distribution and supports practical privacy-preserving properties. The experimental findings show that our proposed EPRICE system significantly decreases the computation costs bythree orders of magnitudecompared with other competing schemes. Debiao He, Min Luo 0002, Xinyi Huang 0001, Kim-Kwang Raymond Choo |
IEEE Trans. Computers | 3 |
| 2023 | High-Performance Implementation of the Identity-Based Signature Scheme in IEEE P1363 on GPUabstractIdentity-based cryptography is proposed to solve the complicated certificate management of traditional public-key cryptography. The pairing computation and high-level tower extension field arithmetic turn out to be the performance bottleneck of pairing-based signature schemes. Graphics processing units have been increasingly popular for general-purpose computing in recent years. They have shown a lot of promise in speeding up cryptographic schemes such as AES, RSA, and ECDSA. However, to our knowledge, the research on parallel implementation of pairings and identity-based cryptographic schemes on graphics processing units is somewhat outdated. Therefore, in this article, we implement the identity-based signature scheme in the IEEE P1363 Standard on a modern NVIDIA RTX 3060 card. We convert the pairing computation in signature verification into a product of pairings with fixed arguments and therefore avoid the scalar multiplication in 𝔾 2 . Then we employ the precomputation technique to improve the elliptic curve scalar multiplication, exponentiation in \(\mathbb {F}_{p^{12}}\) and the pairing computation. We also apply PTX ISA to multiple-precision arithmetic. Experiments demonstrate that our implementation can perform 43,856/46,753/39,798 pairings/sec for the Optimal Ate pairing, the pairing with a fixed argument, and two pairings with fixed arguments, respectively. Peak throughputs of signature generation and verification can achieve 322.6 and 40.6 kops/sec over the BN254 curve. Debiao He, Min Luo 0002, Cong Peng 0005, Xinyi Huang 0001 |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2023 | Faster Implementation of Ideal Lattice-Based Cryptography Using AVX512abstractWith the development of quantum computing, the existing cryptography schemes based on classical cryptographic primitives will no longer be secure. Hence, cryptographers are designing post-quantum cryptographic (PQC) schemes, and ideal lattice-based cryptography has emerged as a prime candidate. Today, as ideal lattice-based cryptography becomes more mature, its performance becomes an important optimization goal. In ideal lattice-based cryptography, polynomial arithmetic and polynomial sampling are the most time-consuming operations and therefore need to be accelerated. In this article, taking advantage of the parallelism of new 512-bit advanced vector instructions (AVX512), we present parallel implementations of polynomial arithmetic and polynomial sampling, thus comprehensively improving their performance. We conduct experiments with the Dilithium scheme(one scheme of NIST PQC Standardization Process Round-4). Our implementation gets a nice performance boost compared to its pure C language and 256-bit advanced vector instructions (AVX2) implementation. Douwei Lei, Debiao He, Cong Peng 0005, Min Luo 0002, Zhe Liu 0001, Xinyi Huang 0001 |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2023 | PERCE: A Permissioned Redactable Credentials Scheme for a Period of MembershipabstractThe anonymous credential has broad-ranging applications, for example for the pay-as-you-go strategy in the electronic subscription. However, the ‘plain vanilla’ pay-as-you-go strategy may not be suitable for non-regular users since the latter group is likely to require a tighter identity supervision mechanism. We also note that a key building block in the construction of an anonymous credential system is identity supervision. Since identity supervision is more than revocation, the approach to regulating user behavior needs to be both reasonable and practical. In a situation where the user is allowed to control their own identities, the latter approach could be more flexible compared to the revocation. There are existing works about the limitation on the k-times or epochs. However, due to the weaknesses of these single limitations, the combination of the customized k-times and epochs is necessary and remains to be done. In this paper, we present a permissioned redactable credentials scheme, which allows fine-grained supervision, user control, and user redaction. In our approach, we choose times and epochs as the regulation dimensions, which limits users invoke the credential show method for customized times in each epoch determined by the certificate authority. The users could also redact their credentials to realize selective disclosure. We then evaluate the proposed scheme’s performance and present a comparative summary to demonstrate potential utility. Yang Liu 0368, Debiao He, Min Luo 0002, Kim-Kwang Raymond Choo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | AADEC: Anonymous and Auditable Distributed Access Control for Edge Computing ServicesabstractEdge computing is an emerging distributed computing concept that allows edge servers to provide authorized consumers with various on-demand services. Due to highly dynamic and untrustworthy network environments, various potential security concerns (e.g., unauthorized access, data manipulation, and privacy leakage) have been the critical factors restricting the development of edge computing. A recent heterogeneous framework proposed by Dougherty et al. (CCS’21), named APECS, deploys token-based authorization and multiple attribute-based encryption (MABE) to guarantee access control and data confidentiality. While APECS achieves a secure asynchronous access control without the “always-on” cloud, it suffers from privacy leakage (caused by the public identity information) and fake data spreading issues (due to the data confidentiality). In this paper, we propose an Anonymous and Auditable Distributed Access Control Framework for Edge Computing (AADEC) to relieve these issues. AADEC is based on two building blocks that we designed, namely a conditional anonymous authentication and an auditable MABE with optimized performance. We also define the formal security models and present security proofs for our proposal. The final qualitative comparison and performance benchmark demonstrate that AADEC can achieve a trade-off among anonymity, confidentiality, auditability and efficiency. Xiaotong Zhou, Debiao He, Jianting Ning, Min Luo 0002, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Efficient Construction of Verifiable Timed Signatures and Its Application in Scalable PaymentsabstractDespite the myriad benefits offered by blockchain technology, most of them still face several interrelated issues, such as limited transaction throughput, exorbitant transaction fees, and protracted confirmation times. Payment channel networks have emerged as a promising scalability solution, allowing two mutually distrustful users to engage in multiple off-chain transactions. However, existing schemes based on Hash Time Lock Contract or Anonymous Multi-hop Lock generally cannot ensure strong unlinkability of payments, due to the fact that the time-lock information still remains on the blockchain. To enhance on-chain privacy, a versatile tool was recently proposed by Thyagarajan et al. (CCS’20), namedVerifiable Timed Signatures, but it suffers from the dual insufficiencies of linear-increasing performance and time unverifiability (i.e., performance is linear to the number of signature shares, and signatures cannot be ensured recoverable after the specified time). In this paper, we first propose an approach to reduce computational overhead of VTS, which can be applied to enhance other established schemes, such as VTD (S&P’22) and VTLRS (ESORICS’22). To further reduce the computational complexity fromO(n)toO(1), we introduce a new cryptographic primitive calledVerifiable Timed Adaptor Signatures. Moreover, we extend the VTAS to VTAS+which provides the security property of verifiable recovery. We demonstrate the practicality of our proposal via presenting a concrete instantiation and constructing a privacy-enhanced payment channel network. Finally, the comprehensive evaluation reveals that our solutions exhibit superior performance than the state-of-the-art schemes. Xiaotong Zhou, Debiao He, Jianting Ning, Min Luo 0002, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | PBidm: Privacy-Preserving Blockchain-Based Identity Management System for Industrial Internet of ThingsabstractIndustrial Internet of Things (IIoT) is revolutionizing plenty of industrial applications by utilizing large-scale smart devices in manufacturing and industrial processes. However, IIoT is facing the disclosure of identity privacy. The identity information is precious and critical, thereby inspiring a line of follow-up privacy-preserving studies, i.e., anonymous credential protocols, or privacy-preserving identity management schemes. However, they are either too anonymous to be used in the IIoT environment, or the system is highly centralized, which implies the risk of a single point of failure. In this article, we proposePBidm, a privacy-preserving blockchain-based identity management scheme for IIoT. Specifically, by leveraging blockchain and diversified cryptographic tools,PBidmcan fully support the desirable properties, i.e., unforgeability, blindness, unlikability, traceability, revocability, and public verifiability. Then, we provide security analysis to ensure reasonable security assurance. Finally, we present a performance evaluation of the proposed scheme to demonstrate the practicability in IIoT applications. Zijian Bao, Debiao He, Muhammad Khurram Khan, Min Luo 0002, Qi Xie 0001 |
IEEE Trans. Ind. Informatics | 4 |
| 2022 | A biometrics-based anonymous authentication and key agreement scheme for wireless sensor networksabstractSummary Wireless sensor networks (WSNs) are widespreadly applicable for information acquisition and processing in various fields such as military, healthcare, envrionment monitoring, and so on. WSNs have three main components: sensors, gateways, and users. The sensing information from sensors is transmitted to users through gateways. However, the public wireless networks are vulnerable to malicious active and passive attacks, which could bring security and privacy issues. Numerous two‐factor based authentication and key agreement (AKA) protocols have been proposed to solve these issues, whereas these schemes still have some deficiencies. Three‐factor based authentication method can make up for the drawbacks of two‐factor based schemes. Kumari and Renuka put forward a biometrics‐based AKA for WSNs with elliptic curve cryptography (ECC). But their scheme cannot maintain anonymity and resist to impersonality attack, replay attack, and DoS attack. In this article, we propose a biometrics‐based anonymous AKA scheme, which is equipped with the covered security requirements of WSNs. Meanwhile, the proposed scheme are provably secure in the three‐party AKA security model. Performance analysis demonstrates that our scheme has better security properties, communication cost, and computational cost compared with five recent and related schemes. Jianhua Chen 0002, Li Li 0073, Min Luo 0002 |
Concurr. Comput. Pract. Exp. | 5 |
| 2022 | A Redesigned Identity-Based Anonymous Authentication Scheme for Mobile-Edge ComputingabstractEnsuring the security and privacy of users and data in a mobile-edge computing (MEC) deployment, without affecting performance, latency and user quality of experience remain challenging. For example, in this article, we revisit an identity-based anonymous authentication scheme designed for MEC deployment. Then, we reveal that the scheme is vulnerable to impersonation, replay, and Denial-of-Service (DoS) attacks, contrary to their claims. It also does not achieve user untraceability, and the registration center must be online during authentication. We also observe that it is unclear from their scheme description, what encryption algorithm should be used in the authentication process. Therefore, we redesign the scheme in order to mitigate the weaknesses pointed out. Our redesigned protocol uses password and biometrics for authentication, which broadens the scope for real-world implementation. We also provide both formal security proof and heuristic security analysis to demonstrate that the proposed scheme achieves the desired security goals. A performance comparison shows that our scheme outperforms four other competing schemes in terms of computation and communication costs. Xiaoying Jia 0002, Min Luo 0002, Kim-Kwang Raymond Choo, Li Li 0073, Debiao He |
IEEE Internet Things J. | 2 |
| 2022 | A Blockchain-Assisted Privacy-Aware Authentication Scheme for Internet of Medical ThingsabstractBenefiting from the progress of Internet of Things (IoT) technology, medical devices, wearables, sensors, and users can be connected with each other to form an Internet of Medical Things (IoMT) ecosystem. IoMT improves efficiency, increases accuracy, and reduces the costs of the traditional healthcare system. However, since IoMT involves different entities and heterogeneous networks and carries a large amount of private information, it is a challenging task to ensure data security and protect privacy in the IoMT ecosystem. In this article, we focus on the issue of privacy-aware authentication between entities. We first propose a blockchain-assisted authentication framework for IoMT applications in the fog computing paradigm. Furthermore, we present two privacy-preserving authentication protocols based on elliptic curve cryptography (ECC) and physically unclonable functions (PUFs), respectively, in terms of the capacity of involved entities. Security analysis and performance evaluation demonstrate that compared with several previous protocols, the proposed protocols have competitive computation and communication costs while achieving expected security requirements. Xiaoying Jia 0002, Min Luo 0002, Huaqun Wang, Jian Shen 0001, Debiao He |
IEEE Internet Things J. | 2 |
| 2022 | Multifunctional and Multidimensional Secure Data Aggregation Scheme in WSNsabstractIn wireless sensor networks (WSNs), data aggregation (DA) has become one of the most practical techniques to reduce processing delay and improve energy efficiency. To support intelligent applications, sensor nodes need to report heterogeneous and diverse data, which induce the demand for multidimensional DA and multifunctional data analysis. To solve the current security problems and functional requirements, we propose a multifunctional and multidimensional secure DA scheme to strike the balance between data availability and privacy. First, we design a Chinese remainder theorem conversion method with the counter to encode multidimensional data into large integers, which can be operated by linear homomorphic encryption schemes. Then, we introduce a multifunctional data analysis method supporting diversified aggregation functions, including linear, polynomial, and continuous functions. Moreover, we demonstrate that the proposed scheme can achieve confidentiality, integrity, authentication, and resistance against false data injection attacks. The experimental results show that the supported max dimension of one ciphertext in our scheme is at least twice that of existing schemes. Thus, in scenarios with high dimensions, our scheme is superior to the existing schemes in terms of computation and communication costs. Cong Peng 0005, Min Luo 0002, Pandi Vijayakumar, Debiao He, Omar Said, Amr Tolba |
IEEE Internet Things J. | 2 |
| 2022 | An Efficient Privacy-Preserving Aggregation Scheme for Multidimensional Data in IoTabstractInternet of Things (IoT) enables terminal devices connecting with the Internet and provides various intelligent applications by analyzing devices data. As a typical IoT technique, edge computing provides a three-tier architecture to reduce communications and improve efficiency. Specifically, edge nodes are responsible for collecting and aggregating device data, and then send processed results to the cloud for subsequent analysis. However, the data aggregation function will compromise the privacy of device data. In this article, we proposed an efficient privacy-preserving multidimensional data aggregation scheme for IoT, called PMDA. The scheme uses the Chinese remainder theorem to design a homomorphic encryption method that encryptes a multiple-dimensional small integer vector into one ciphertext and keeps linear homomorphic properties per dimension. Combining with the signature mechanism and the batch verification method, the scheme guarantees nonrepudiation of device data and enhance verification efficiency at edge nodes. Through theoretical analysis, we demonstrate that the proposed scheme can achieve correctness, privacy, authentication, and integrity. After performance evaluation, we demonstrate that our scheme is superior to other schemes in terms of computation and communication costs. In particular, as the message dimension increases, our scheme computation costs almost a tenth of others at the 80-bits security level. Cong Peng 0005, Min Luo 0002, Huaqun Wang, Muhammad Khurram Khan, Debiao He |
IEEE Internet Things J. | 2 |
| 2021 | An efficient attribute-based encryption scheme based on SM9 encryption algorithm for dispatching and control cloudabstractDispatching and Control Cloud (DCC) is a cloud platform constructed by State Grid Corporation with the technology of cloud computing. DCC has improved the overall operation and monitoring capabilities, the smart level and many other advantages of power grid. However, the development of DCC has been hampered by security and privacy issues. Secure unified identity authentication, access control and authorisation management are significant topics in DCC. To find out a solution for the topics above, we have employed some encryption schemes using the attribute-based encryption(ABE), as ABE can preserve users' privacy and achieve access control with fine grain over the encrypted information. SM9 is a kind of Chinese official standard in the field of cryptography, which contains the SM9 encryption algorithm (SM9-IBE). In this paper, an ABE scheme based on SM9-IBE is proposed, making SM9 support fine-grained access control which would be better applied in DCC. Our proposed scheme (SM9-ABE) has been proven to be of great security in the selective CPA model under DBDH assumption. Furthermore, we implement SM9-ABE and evaluate its practical performance. The implementation indicates our scheme performs well in the matter of security and functionality, at an additional time cost which is acceptable. Honghan Ji, Hongjie Zhang 0006, Lisong Shao, Debiao He, Min Luo 0002 |
Connect. Sci. | 5 |
| 2021 | Efficient Certificateless Online/Offline Signature Scheme for Wireless Body Area NetworksabstractWireless body area networks (WBANs) have become more commonplace, including in healthcare settings. For example, in a healthcare WBAN deployment, body sensor units (BSUs) are used to sense and collect health-related and medical-related information prior to sending relevant information to the server for analysis that can subsequently inform treatment plan. Given the sensitivity of both data-at-rest and data-in-transit, data authentication is fundamental to the success of such systems. However, BSUs are generally resource constrained and, hence, conventional cryptographic algorithms are not practical. Therefore, in this article, we propose an efficient certificateless online/offline signature scheme and design a lightweight data authentication protocol for WBANs. We then evaluate the security and performance of our proposed scheme, where the security analysis demonstrates that the proposed scheme satisfies existential unforgeability under the random oracle model. Findings from the performance evaluation also demonstrate that our scheme incurs very low computational cost during the signing operations. In comparison to several other competing approaches, our proposed scheme achieves a significant reduction in computational cost (up to 89%) for the offline signer and supports batch verification to reduce the verifier's execution time. In addition, we also show that the signature size of our proposed scheme is similar to those of the conventional signature schemes. Cong Peng 0005, Min Luo 0002, Li Li 0073, Kim-Kwang Raymond Choo, Debiao He |
IEEE Internet Things J. | 2 |
| 2021 | A secure and efficient authentication and data sharing scheme for Internet of Things based on blockchain
Jianhua Chen 0002, L. Jegatha Deborah, Min Luo 0002 |
J. Syst. Archit. | 4 |
| 2021 | The Applications of Blockchain in Artificial IntelligenceabstractThere has been increased interest in applying artificial intelligence (AI) in various settings to inform decision-making and facilitate predictive analytics. In recent times, there have also been attempts to utilize blockchain (a peer-to-peer distributed system) to facilitate AI applications, for example, in secure data sharing (for model training), preserving data privacy, and supporting trusted AI decision and decentralized AI. Hence, in this paper, we perform a comprehensive review of how blockchain can benefit AI from these four aspects. Our analysis of 27 English-language articles published between 2018 and 2021 identifies a number of research challenges and opportunities. Min Luo 0002, Yihong Wen, Lianhai Wang, Kim-Kwang Raymond Choo, Debiao He |
Secur. Commun. Networks | 2 |
| 2021 | A Software/Hardware Co-Design of Crystals-Dilithium Signature SchemeabstractAs quantum computers become more affordable and commonplace, existing security systems that are based on classical cryptographic primitives, such as RSA and Elliptic Curve Cryptography ( ECC ), will no longer be secure. Hence, there has been interest in designing post-quantum cryptographic ( PQC ) schemes, such as those based on lattice-based cryptography ( LBC ). The potential of LBC schemes is evidenced by the number of such schemes passing the selection of NIST PQC Standardization Process Round-3. One such scheme is the Crystals-Dilithium signature scheme, which is based on the hard module-lattice problem. However, there is no efficient implementation of the Crystals-Dilithium signature scheme. Hence, in this article, we present a compact hardware architecture containing elaborate modular multiplication units using the Karatsuba algorithm along with smart generators of address sequence and twiddle factors for NTT, which can complete polynomial addition/multiplication with the parameter setting of Dilithium in a short clock period. Also, we propose a fast software/hardware co-design implementation on Field Programmable Gate Array ( FPGA ) for the Dilithium scheme with a tradeoff between speed and resource utilization. Our co-design implementation outperforms a pure C implementation on a Nios-II processor of the platform Altera DE2-115, in the sense that our implementation is 11.2 and 7.4 times faster for signature and verification, respectively. In addition, we also achieve approximately 51% and 31% speed improvement for signature and verification, in comparison to the pure C implementation on processor ARM Cortex-A9 of ZYNQ-7020 platform. Debiao He, Zhe Liu 0001, Min Luo 0002, Kim-Kwang Raymond Choo |
ACM Trans. Reconfigurable Technol. Syst. | 4 |
| 2021 | A Blind Signature-Aided Privacy-Preserving Power Request Scheme for Smart GridabstractSmart grid is an emerging power system capable of providing appropriate electricity generation and distribution adjustments in the two‐way communication mode. However, privacy preservation is a critical issue in the power request system since malicious adversaries could obtain users’ daily schedule through power transmission channel. Blind signature is an effective method of hiding users’ private information. In this paper, we propose an untraceable blind signature scheme under the reputable modification digital signature algorithm (MDSA). Moreover, we put forward an improved credential‐based power request system architecture integrated with the proposed blind signature. In addition, we prove our blind signature’s blindness and unforgeability under the assumption of Elliptic Curve Discrete Logarithm Problem (ECDLP). Meanwhile, we analyze privacy preservation, unforgeability, untraceability, and verifiability of the proposed scheme. Computational cost analysis demonstrates that our scheme has better efficiency compared with other two blind signatures. Zhimin Guo, Nuannuan Li, Min Luo 0002 |
Wirel. Commun. Mob. Comput. | 6 |
| 2020 | Practical Secure Two-Party EdDSA Signature Generation with Key Protection and Applications in CryptocurrencyabstractIn cryptocurrency and blockchain-based distributed ledgers, transfer of money (digital coins) can be presented as a transaction. Due to the irreversibility nature of blockchain transactions, a single fraudulent use of private key (used to sign transactions) could have significant consequences (e.g. financial loss). Key protection alone is not adequate in protecting cryptocurrencies, and threshold signature is a viable method to avoid fraudulent key usage or key theft. In this paper, we focus on the Edwards-curve digital security algorithm (EdDSA), which has been applied in several cryptocurrencies (e.g. Cardano, Zcash, and Decred) and design the first efficient two-party EdDSA signing protocol. Unlike standard secret sharing, a valid signature is generated using an interactive protocol without the original key ever being exposed. We mathematically prove the security of our proposed protocol. Findings from the performance evalation of the protocol show that it achieves good performance for curve Ed25519, with a single signing operation in the malicious setting taking approximately 3.32 ms between two devices. Debiao He, Min Luo 0002, Zengxiang Li, Kim-Kwang Raymond Choo |
TrustCom | 3 |
| 2020 | An Efficient Pairing-Free Certificateless Searchable Public Key Encryption for Cloud-Based IIoTabstractThe Industrial Internet of Things (IIoT), as a special form of Internet of Things (IoT), has great potential in realizing intelligent transformation and industrial resource utilization. However, there are security and privacy concerns about industrial data, which is shared on an open channel via sensor devices. To address these issues, many searchable encryption schemes have been presented to provide both data privacy-protection and data searchability. However, due to the use of expensive pairing operations, most previous schemes were inefficient. Recently, a certificateless searchable public-key encryption (CLSPE) scheme was designed by Lu et al. to remove the pairing operation. Unfortunately, we find that Lu et al.’s scheme is vulnerable to user impersonation attacks. To enhance the security, a new pairing-free dual-server CLSPE (DS-CLSPE) scheme for cloud-based IIoT deployment is designed in this paper. In addition, we provide security and efficiency analysis for DS-CLSPE. The analysis results show that DS-CLSPE can resist chosen keyword attacks (CKA) and has better efficiency than other related schemes. Mimi Ma, Min Luo 0002, Shuqin Fan, Dengguo Feng |
Wirel. Commun. Mob. Comput. | 2 |
| 2020 | Privacy-Protection Scheme Based on Sanitizable Signature for Smart Mobile Medical ScenariosabstractWith the popularization of wireless communication and smart devices in the medical field, mobile medicine has attracted more and more attention because it can break through the limitations of time, space, and objects and provide more efficient and quality medical services. However, the characteristics of a mobile smart medical network make it more susceptible to security threats such as data integrity damage and privacy leakage than those of traditional wired networks. In recent years, many digital signature schemes have been proposed to alleviate some of these challenges. Unfortunately, traditional digital signatures cannot meet the diversity and privacy requirements of medical data applications. In response to this problem, this paper uses the unique security attributes of sanitizable signatures to carry out research on the security and privacy protection of medical data and proposes a data security and privacy protection scheme suitable for smart mobile medical scenarios. Security analysis and performance evaluation show that our new scheme effectively guarantees data security and user privacy while greatly reducing computation and communication costs, making it especially suitable for mobile smart medical application scenarios. Zhiyan Xu, Min Luo 0002, Neeraj Kumar 0001, Pandi Vijayakumar, Li Li 0073 |
Wirel. Commun. Mob. Comput. | 2 |
| 2018 | A General Architecture for Multiserver Authentication Key Agreement with Provable SecurityabstractIn a typical single-server architecture, when a user wishes to access multiple servers to obtain different services, the user needs to register with every single server. This results in multiple identities and password pairs. To eliminate the limitation of the user having to possess and remember multiple identities and password pairs, a number of multiserver authentication protocols have been proposed where a user only needs to register once. However, most existing protocols are subsequently found to be insecure and this topic remains one of the ongoing research interests. Thus, in this paper, we present a multiserver authentication key agreement protocol. We then demonstrate the security of the protocol under the random oracle model, as well as the practicality of the protocol in terms of low computation and communication costs, minimal storage requirements, and operation costs. Yunru Zhang, Min Luo 0002, Kim-Kwang Raymond Choo, Debiao He |
Secur. Commun. Networks | 2 |
| 2016 | Security analysis of a user registration approach
Min Luo 0002, Jingyin Zhang, Debiao He, Jian Shen 0001 |
J. Supercomput. | 1 |