Xiao Tan 0003

dblp:116/7143-3 · DBLP profile ↗
← Back
17ranked-venue papers
5as first author
4since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 2 since 2021Computer networks · 3 · 2 since 2021Theory of computation · 3 · 2 first-authorArtificial intelligence and machine learning · 2Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 Public auditing with semantic secure data privacy for low-entropy files in cloud storage
Xiao Tan 0003, Qi Xie 0001, Lidong Han, Shengbao Wang
Comput. Secur.1
2024 Blockchain-Based Traffic Accident Handling Protocol Without Third Party for VANETs
abstract
In vehicular ad-hoc networks (VANETs), existing traffic accident handling schemes are adoptable only in the scenario with roadside unit (RSU) deployment, and the generation of accident reports relies on RSUs and witness vehicles. Without the confirmation from involved vehicles in the accident, it will probably cause disputes afterward, and RSU captured attacks may also affect authentication of vehicles and correctness of accident reports. To address the above issues, we propose a vehicle to vehicle (V2V) and vehicle to RSU (V2R) authentication and traffic accident handling protocol, in which accident vehicles are sufficient to generate accident reports, thereby enhancing autonomy of the vehicular communication system and reducing reliance on external infrastructure. Furthermore, for ensuring integrity and traceability of accident reports, we utilize blockchain to keep registration information and jointly signed reports, which realizes efficient and secure mutual authentications in V2V and V2R protocols. Finally, for preserving privacy of vehicles, we integrate elliptic curve cryptosystem (ECC) and symmetric encryption to design a dynamic pseudo-identity strategy, which still allows the registration center to track malicious vehicles. The formal security proof and comparative analysis validate that our protocol preserves higher security and lower overhead by comparison with related schemes.
Qi Xie 0001, Zixuan Ding, Qingyun Xie, Xiao Tan 0003, Debiao He
IEEE Internet Things J.4
2024 Security-Enhanced Lightweight and Anonymity-Preserving User Authentication Scheme for IoT-Based Healthcare
abstract
Ensuring trust within the healthcare system and addressing privacy and security challenges in the Internet of Medical Things (IoMT) is of paramount importance. Based on our preliminary analysis results of Masud et al.’s authentication protocol, we propose an improved solution building upon their protocol. Our improved protocol incorporates various security measures to enhance its security. To validate the effectiveness of our improved protocol, we employ a comprehensive range of heuristic and formal security analysis methods. Comparative evaluations with other relevant protocols reveal that our proposed solution achieves satisfactory operational performance in resource-constrained IoMT scenarios.
Shengbao Wang, Kang Wen, Xiao Tan 0003, Qi Xie 0001
IEEE Internet Things J.5
2023 Proof of retrievability with flexible designated verification for cloud storage
Xiao Tan 0003, Qi Xie 0001, Lidong Han, Shengbao Wang
Comput. Secur.1
2020 Plaintext related image hybrid encryption scheme using algebraic interpolation and generalized chaotic map
Xikun Liang, Xiao Tan 0003, Limin Tao
Multim. Tools Appl.2
2019 Image Hybrid Encryption Based on Matrix Nonlinear Operation and Generalized Arnold Transformation
abstract
In this paper, we propose a scheme to implement hybrid encryption of images using generalized Arnold transformation and matrix nonlinear operations. This scheme consists of two stages. In the first stage, the pixels scrambling encryption is achieved by using generalized Arnold transformation. In the second stage, the pixels sequence encryption is carried out by a nonlinear matrix operation based on the key stream generated by a random matrix. Accordingly, the decryption process is completed by two steps inverse transformations. The hybrid encryption algorithm is one-time pad, and therefore has good anti-attack performance. The algorithm is featured by good confidentiality, low computational complexity, and easy-to-program processing. Moreover, the effectiveness, security and robustness of the algorithm are demonstrated by an image encryption simulation and the encryption performance analysis. Compared with the traditional Arnold scrambling encryption scheme and the chaotic encryption method based on the generalized standard mapping, the superiority of the proposed algorithm is demonstrated.
Xikun Liang, Xiao Tan 0003, Limin Tao
Int. J. Pattern Recognit. Artif. Intell.2
2018 An efficient and secure three-factor based authenticated key exchange scheme using elliptic curve cryptosystems
Lidong Han, Xiao Tan 0003, Shengbao Wang, Xikun Liang
Peer-to-Peer Netw. Appl.2
2017 Provably Secure Dynamic ID-Based Anonymous Two-Factor Authenticated Key Exchange Protocol With Extended Security Model
abstract
Authenticated key exchange (AKE) protocol allows a user and a server to authenticate each other and generate a session key for the subsequent communications. With the rapid development of low-power and highly-efficient networks, such as pervasive and mobile computing network in recent years, many efficient AKE protocols have been proposed to achieve user privacy and authentication in the communications. Besides secure session key establishment, those AKE protocols offer some other useful functionalities, such as two-factor user authentication and mutual authentication. However, most of them have one or more weaknesses, such as vulnerability against lost-smart-card attack, offline dictionary attack, de-synchronization attack, or the lack of forward secrecy, and user anonymity or untraceability. Furthermore, an AKE scheme under the public key infrastructure may not be suitable for light-weight computational devices, and the security model of AKE does not capture user anonymity and resist lost-smart-card attack. In this paper, we propose a novel dynamic ID-based anonymous two-factor AKE protocol, which addresses all the above issues. Our protocol also supports smart card revocation and password update without centralized storage. Further, we extend the security model of AKE to support user anonymity and resist lost-smart-card attack, and the proposed scheme is provably secure in extended security model. The low-computational and bandwidth cost indicates that our protocol can be deployed for pervasive computing applications and mobile communications in practice.
Qi Xie 0001, Duncan S. Wong, Guilin Wang, Xiao Tan 0003, Kefei Chen, Liming Fang 0001
IEEE Trans. Inf. Forensics Secur.4
2017 A New ADS-B Authentication Framework Based on Efficient Hierarchical Identity-Based Signature with Batch Verification
abstract
Automatic dependent surveillance-broadcast (ADS-B) has become a crucial part of next generation air traffic surveillance technology and will be mandatorily deployed for most of the airspaces worldwide by 2020. Each aircraft equipped with an ADS-B device keeps broadcasting plaintext messages to other aircraft and the ground station controllers once or twice per second. The lack of security measures in ADS-B systems makes it susceptible to different attacks. Among the various security issues, we investigate the integrity and authenticity of ADS-B messages. We propose a new framework for providing ADS-B with authentication based on three-level hierarchical identity-based signature (HIBS) with batch verification. Previous signature-based ADS-B authentication protocols focused on how to generate signatures efficiently, while our schemes can also significantly reduce the verification cost, which is critical to ADS-B systems, since at any time an ADS-B receiver may receive lots of signatures. We design two concrete schemes. The basic scheme supports partial batch verification and the extended scheme provides full batch verification. We give a formal security proof for the extended scheme. Experiment results show that our schemes with batch verification are tremendously more efficient in batch verifying n signatures than verifying n signatures independently. For example, the running time of verifying 100 signatures is 502 and 484 ms for the basic scheme and the extended scheme respectively, while the time is 2500 ms if verifying the signatures independently.
Anjia Yang, Xiao Tan 0003, Joonsang Baek, Duncan S. Wong
IEEE Trans. Serv. Comput.2
2015 L-EncDB: A lightweight framework for privacy-preserving data queries in cloud computing
Jin Li 0002, Zheli Liu, Xiaofeng Chen 0001, Fatos Xhafa, Xiao Tan 0003, Duncan S. Wong
Knowl. Based Syst.5
2015 OPoR: Enabling Proof of Retrievability in Cloud Computing with Resource-Constrained Devices
abstract
Cloud computing moves the application software and databases to the centralized large data centers, where the management of the data and services may not be fully trustworthy. In this work, we study the problem of ensuring the integrity of data storage in cloud computing. To reduce the computational cost at user side during the integrity verification of their data, the notion of public verifiability has been proposed. However, the challenge is that the computational burden is too huge for the users with resource-constrained devices to compute the public authentication tags of file blocks. To tackle the challenge, we propose OPoR, a new cloud storage scheme involving a cloud storage server and a cloud audit server, where the latter is assumed to be semi-honest. In particular, we consider the task of allowing the cloud audit server, on behalf of the cloud users, to pre-process the data before uploading to the cloud storage server and later verifying the data integrity. OPoR outsources and offloads the heavy computation of the tag generation to the cloud audit server and eliminates the involvement of user in the auditing and in the pre-processing phases. Furthermore, we strengthen the proof of retrievability (PoR) model to support dynamic data operations, as well as ensure security against reset attacks launched by the cloud storage server in the upload phase.
Jin Li 0002, Xiao Tan 0003, Xiaofeng Chen 0001, Duncan S. Wong, Fatos Xhafa
IEEE Trans. Cloud Comput.2
2015 Concurrent signature without random oracles
Xiao Tan 0003, Qiong Huang 0001, Duncan S. Wong
Theor. Comput. Sci.1
2014 Securely Outsourcing Exponentiations with Single Untrusted Program for Cloud Storage
Qianhong Wu, Duncan S. Wong, Sherman S. M. Chow, Zhen Liu 0008, Xiao Tan 0003
ESORICS (1)7
2014 A practical anonymous authentication protocol for wireless roaming
abstract
ABSTRACT Recently, Chen et al. proposed a practical authentication protocol for supporting anonymous roaming in wireless access networks, then the protocol is further improved by Hsieh and Leu. In this paper, we demonstrate the adversarial model of this type of protocols and show that Hsieh‐Leu scheme is not as secure as they originally claimed to be. In particular, we show that their protocol does not provide user privacy protection, and it is vulnerable to off‐line password guessing attack mounted by a side channel adversary who has compromised all the information stored in the user's smart card. To fix these weaknesses, a new practical authentication protocol with anonymity for wireless roaming is proposed. We use the formal verification tool ProVerif, which is based on applied pi calculus, to prove the security of the proposed scheme. The experimental results confirm that the new scheme not only achieves many desirable properties, such as strong anonymity, perfect forward secrecy and support of session key update, but also provides robustness against all those attacks that Hsieh–Leu protocol does not resist. Copyright © 2013 John Wiley & Sons, Ltd.
Qi Xie 0001, Xiao Tan 0003, Duncan S. Wong, Guilin Wang, Mengjie Bao
Secur. Commun. Networks2
2014 Chosen-ciphertext secure multi-hop identity-based conditional proxy re-encryption with constant-size ciphertexts
Kaitai Liang, Cheng-Kang Chu, Xiao Tan 0003, Duncan S. Wong, Chunming Tang 0003, Jianying Zhou 0001
Theor. Comput. Sci.3
2014 Extending concurrent signature to multiple parties
Xiao Tan 0003, Qiong Huang 0001, Duncan S. Wong
Theor. Comput. Sci.1
2012 Generalized First Pre-image Tractable Random Oracle Model and Signature Schemes
Xiao Tan 0003, Duncan S. Wong
ACISP1