Maozhi Xu

dblp:12/6706 · DBLP profile ↗
← Back
39ranked-venue papers
0as first author
11since 2021 · last 2026
0009-0004-1786-5227ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 4 since 2021Computer networks · 7 · 5 since 2021Theory of computation · 7Applied, interdisciplinary, general and emerging computing · 5 · 1 since 2021Databases, data management, data science and information retrieval · 4 · 1 since 2021Systems, architecture and hardware · 1
YearPublicationVenuePosition
2026 Residual network-based authentication scheme with cooperative weight sharing for the Internet of Vehicles
Xiaoying Qiu, Xujie He, Suwen Zhang, Jinwei Yu, Wenbao Jiang, Zhaozhong Guo, Maozhi Xu
Comput. Networks8
2026 Blockchain-Assisted Meta-Learning for Efficient and Reliable Authentication in IoV
abstract
Considering the rapid variations in frequently changing environment and the broadcast nature of wireless signals, security authentication plays a crucial role in ensuring the security of internet of vehicles (IoV) communications. Existing authentication schemes in IoV suffer from two main limitations: First, protocol-based authentication causes high latency and heavy cryptographic overhead when dealing with numerous concurrent requests. Second, although edge computing-assisted methods reduce cloud communication latency, the ability to support model adaptation across environments remains limited. To address these challenges, a blockchain-assisted meta-learning (BAML) authentication scheme is proposed for providing security authentication protection in IoV. Specifically, a meta-learning algorithm is designed to collaboratively learn the device/location/channel-related feature of vehicles from source environments and then to verify their identities. During the movement of vehicles, a blockchain module is proposed to guide the new environment to inherit the most optimal authentication knowledge from the meta-learning knowledge base and achieve high performance even with limited data. The BAML scheme is designed for reliable collaboration and continuous protections in IoV. Extensive experiments are conducted to validate the effectiveness of BAML. When given 9 samples, the BAML of new environments reaches 99.7%, surpassing other competitive baselines.
Xiaoying Qiu, Guangxu Zhao, Xujie He, Jinwei Yu, Wenbao Jiang, Zhaozhong Guo, Maozhi Xu
IEEE Internet Things J.7
2025 UC Secure Privacy-Preserving and Auditable Transaction System for Permissioned Blockchains*
abstract
The inherent tension between transactional privacy and auditing compliance presents a significant challenge to the widespread adoption of permissioned blockchain systems, particularly in highly regulated sectors such as finance. Existing approaches often suffer from inadequate privacy protection, rigid audit frameworks, or excessive computational and user interaction overhead. This paper introduces a novel permissioned blockchain transaction system specifically designed to address these challenges. Our design guarantees complete anonymity for sender and receiver identities as well as transaction amounts. Additionally, we implement a streamlined, non-interactive audit mechanism that allows authorized entities to inspect transactions without participant involvement. A key innovation is certifier-aided balance reconciliation, which significantly enhances transaction efficiency, usability, and scalability by eliminating the need for direct communication between participants. Through a formal security proof within the universal composable framework, we demonstrate the robust ability of the system to reconcile privacy requirements with compliance obligations.
Su Hang, Zhaozhong Guo, Maozhi Xu
TrustCom3
2025 DSDA-IRNet: Inverted Residual Network-Based IIoT Authentication With Double-Parameter Smoothing Data Augmentation Algorithm
abstract
Given the frequently changing and potentially unreliable environment, the cost-effective authentication is essential to achieve security industrial internet of the things (IIoT) environment with dramatically enhanced communication and transportation safety. Although great success has been achieved for multi-identity authentication schemes, it depends on adequate data collection, which is particularly laborious and time-consuming, being impractical for actual IIoT applications or privacy sensitive environments. Moreover, authentication schemes based on deep learning may suffer from high complexity and excessive latency, leading to potential interruption of critical services in dynamic IIoT environments. To overcome the above challenges, this paper proposes a lightweight and robust authentication scheme, namely DSDA-IRNet, which combines inverted residual network (IRNet) and double smoothing data augmentation (DSDA) algorithm. Specifically, IRNet is proposed to achieve a balance between authentication complexity and accuracy. The DSDA significantly alleviates the overfitting and low authentication accuracy caused by scarce training data. Finally, extensive experimental evaluations based on industrial scenarios datasets are conducted to assess the detection performance and robustness of the DSDA-IRNet. Compared with the existing schemes, our results characterize the outperformance of the DSDA-IRNet in authentication accuracy and computational complexity.
Xiaoying Qiu, Jinwei Yu, Wenbao Jiang, Zhaozhong Guo, Maozhi Xu
IEEE Internet Things J.6
2025 Private-Set-Intersection-Based Medical Data Sharing Scheme With Integrity Auditing for IoMT Cloud Storage Systems
abstract
In recent years, the medical industry is generating a large amount of data. How to securely store and reliably share these medical data has been a hot research topic. Cloud storage technology can be applied to the medical industry to adapt to the rapid growth of medical data. However, cloud-based data storage and sharing systems face a series of security issues: whether the integrity of outsourced medical data can be guaranteed, and malicious access between different medical institutions may leak user's privacy. This article proposes a system that simultaneously solves the integrity auditing of medical data and securely data sharing between different medical institutions under the terminal-edge-cloud framework. Specifically, patients/doctors are treated as terminal users, medical institutions are viewed as edge nodes, and medical clouds form the central storage layer. In the process of data auditing, third-party auditor can achieve integrity auditing of medical cloud storage data. Moreover, different medical institutions use private-set-intersection technology to share the common user's electronic medical data, while for other users not in intersection set, their data does not need to be shared. Finally, security and performance analyses show that our proposed system is provable secure and has high computational and communication efficiency.
Zekun Li 0013, Jinyong Chang, Bei Liang, Kaijing Ling, Yanyan Ji, Maozhi Xu
IEEE Trans. Knowl. Data Eng.7
2024 Adaptive Attacks Against FESTA Without Input Validation or Constant-Time Implementation
Tomoki Moriya, Hiroshi Onuki, Maozhi Xu
PQCrypto (2)3
2023 A Polynomial-Time Attack on G2SIDH
Maozhi Xu
ICICS2
2022 Secure medical data management with privacy-preservation and authentication properties in smart healthcare system
Jinyong Chang, Qiaochuan Ren, Yanyan Ji, Maozhi Xu, Rui Xue 0001
Comput. Networks4
2022 Public auditing protocol with dynamic update and privacy-preserving properties in fog-to-cloud-based IoT applications
Jinyong Chang, Maozhi Xu, Rui Xue 0001
Peer-to-Peer Netw. Appl.2
2021 On the Linear Complexity of Feedforward Clock-Controlled Sequence
Yangpan Zhang, Maozhi Xu
Inscrypt2
2021 Secure network coding from secure proof of retrievability
Jinyong Chang, Bilin Shao, Yanyan Ji, Maozhi Xu, Rui Xue 0001
Sci. China Inf. Sci.4
2020 Analysis of the Randomness Generation for PoS-Based Blockchains with Verifiable Delay Functions
Maozhi Xu
BlockSys2
2020 Certificateless Homomorphic Signature Scheme for Network Coding
abstract
Homomorphic signature is an extremely important public key authentication technique for network coding to defend against pollution attacks. As a public key cryptographic primitive, it also encounters the same problem of how to confirm the relationship between some public key pk and the identity ID of its owner. In the setting of distributed network coding, the intermediate and destination nodes need to use the public key of source node S to check the validity of vector-signature pairs. Therefore, the binding of S and its corresponding public key becomes crucial. The popular and traditional solution is based on certificates which are issued by a trusted certification authority (CA) center. However, the generation and management of certificates is extremely cumbersome. Hence, in recent work, Lin et al. proposed a new notion of identity-based homomorphic signature, which intends to avoid using certificates. But the key escrow problem is inevitable for identity-based primitives. In this article, we propose another new notion (for network coding): certificateless homomorphic signature (CLHS), which is a compromise for the above two techniques. In particular, we first describe the definition and security model of certificateless homomorphic signature. Then based on bilinear map and the computational Diffie-Hellman (CDH) assumption, give a concrete implementation and detailedly analyze its security. Finally, performance analysis illustrates that our construction is practical.
Jinyong Chang, Yanyan Ji, Bilin Shao, Maozhi Xu, Rui Xue 0001
IEEE/ACM Trans. Netw.4
2019 On Constructing Prime Order Elliptic Curves Suitable for Pairing-Based Cryptography
Xuehong Chen, Maozhi Xu, Jie Wang 0039
BlockSys3
2019 On the KDM-CCA Security from Partial Trapdoor One-Way Family in the Random Oracle Model
abstract
Abstract In PKC 2000, Pointcheval presented a generic technique to make a highly secure cryptosystem from any partially trapdoor one-way function in the random oracle model. More precisely, any suitable problem providing a one-way cryptosystem can be efficiently derived into a chosen-ciphertext attack (CCA) secure public key encryption (PKE) scheme. In fact, the overhead only consists of two hashing and a XOR. In this paper, we consider the key-dependent message (KDM) security of the Pointcheval’s transformation. Unfortunately, we do not know how to directly prove its KDM-CCA security because there are some details in the proof that we can not bypass. However, a slight modification of the original transformation (we call twisted Pointcheval’s scheme) makes it possible to obtain the KDM-CCA security. As a result, we prove that the twisted Pointcheval’s scheme achieves the KDM-CCA security without introducing any new assumption. That is, we can construct a KDM-CCA secure PKE scheme from partial trapdoor one-way injective family in the random oracle model.
Jinyong Chang, Genqing Bian, Yanyan Ji, Maozhi Xu
Comput. J.4
2019 General transformations from single-generation to multi-generation for homomorphic message authentication schemes in network coding
Jinyong Chang, Yanyan Ji, Maozhi Xu, Rui Xue 0001
Future Gener. Comput. Syst.3
2018 On the RCCA Security of Hybrid Signcryption for Internet of Things
abstract
With the rapid development of the Internet of Things (IoT), a lot of sensitive information in our daily lives are now digitalized and open to remote access. The provision of security and privacy of such data would incur comprehensive cryptographic services and has raised wide concern. Hybrid signcryption schemes could achieve various kinds of cryptographic services (e.g., confidentiality, authenticity, and integrity) with much lower cost than the combination of separate traditional cryptographic schemes with each providing a single cryptographic service. Thus, hybrid signcryption schemes are very suitable for IoT environments where resources are generally very constrained (e.g., lightweight sensors and mobile phones). To ensure that the overall hybrid signcryption scheme provides adequate cryptographic service (e.g., confidentiality, integrity, and authentication), its parts of KEM (key encryption mechanism) and DEM (data encryption mechanism) must satisfy some security requirements. Chosen‐ciphertext attack (CCA) security has been widely accepted as the golden standard requirement for general encryption schemes. However, CCA security appears too strong in some conditions. Accordingly, Canetti et al. (CRYPTO 2003) proposed the notion of replayable CCA security (RCCA) for encryption schemes, which is a strictly weaker security notion than CCA security and naturally more efficient. This new security notion has proved to be sufficient for most existing applications of CCA security, e.g., encrypted password authentication. This is particularly promising for IoT environments, where security is demanding, yet resources are constrained. In this paper, we examine the RCCA security of the well‐known SKEM+DEM style hybrid signcryption scheme by Dent at ISC 2005. Meanwhile, we also examine the RCCA security of the Tag‐SKEM+DEM style hybrid signcryption scheme by Bjorstad and Dent at PKC 2006. We rigorously prove that a hybrid signcryption scheme can achieve RCCA security if both its SKEM part and its DEM part satisfy some security assumptions.
Honglong Dai, Ding Wang 0002, Jinyong Chang, Maozhi Xu
Wirel. Commun. Mob. Comput.4
2017 Finding vulnerable curves over finite fields of characteristic 2 by pairing reduction
abstract
In this paper, we aim at sustaining the claim that curve-based cryptographic schemes over finite fields of characteristic 2 do not provide enough security. We present algorithms to find all the possible supersingular elliptic curves which can be embedded into a predefined finite field. We also consider the case of hyperelliptic curves with genus 2, including both supersingular and ordinary cases. As computational examples, we show even the DLP on a 3060-bit elliptic curve and the DLP on Jacobians of a 255-bit hyperelliptic curve can be solved by embedding to a 6120-bit extension field.In this paper, we aim at sustaining the claim that curve-based cryptographic schemes over finite fields of characteristic 2 do not provide enough security. We present algorithms to find all the possible supersingular elliptic curves which can be embedded into a predefined finite field. We also consider the case of hyperelliptic curves with genus 2, including both supersingular and ordinary cases. As computational examples, we show even the DLP on a 3060-bit elliptic curve and the DLP on Jacobians of a 255-bit hyperelliptic curve can be solved by embedding to a 6120-bit extension field.
Maozhi Xu
ICIS3
2017 The KDM-CCA Security of REACT
Jinyong Chang, Honglong Dai, Maozhi Xu
ISPEC3
2017 The ECCA Security of Hybrid Encryptions
Honglong Dai, Jinyong Chang, Zhenduo Hou, Maozhi Xu
ISPEC4
2016 On Constructing Parameterized Families of Pairing-Friendly Elliptic Curves with \rho =1
Maozhi Xu
Inscrypt3
2016 Construction of Efficient MDS Matrices Based on Block Circulant Matrices for Lightweight Application
abstract
Maximum distance separable (MDS) codes introduce MDS matrices which not only have applications in coding theory but also are of great importance in the design of block ciphers. It has received a great amount of attention. In this paper, we first introduce a special generalization of circulant matrices called block circulants with circulant blocks, which can be used to construct MDS matrices. Then we investigate some interesting and useful properties of this class of matrices and prove that their inverse matrices can be implemented efficiently. Furthermore, we present some 4 × 4 and 8 × 8 efficient MDS matrices of this class which are suitable for MDS diffusion layer. Compared with previous results, our construction provides better efficiency for the implementation of both the matrix and the its inverse matrix.
Huiting Han, Chunming Tang 0001, Yu Lou 0001, Maozhi Xu
Fundam. Informaticae4
2016 Some techniques for faster scalar multiplication on GLS curves
Maozhi Xu
Inf. Process. Lett.3
2016 Security analysis of a TESLA-based homomorphic MAC scheme for authentication in P2P live streaming system
abstract
In this paper, we present a pollution attack on the homomorphic message authentication code scheme PMAC, which was proposed, by Cheng, Jiang, and Zhang in [IEEE Journal on Selected Areas in Communications/Supplement 2013; 319: 291-298]. In particular, Cheng et al. claimed that their main contribution lies in that, compared with the existing scheme, such as SpaceMac, PMAC can achieve a reliable security 1/qi?ź instead of 1/q for SpaceMac, where q is usually set as a small number in practical applications and i?ź is a flexible parameter chosen by users to improve their security level. However, by presenting a pollution attack, we prove that PMAC can only achieve the security at most 1/q no matter how large i?ź is. Our attack shows that it may be dangerous to directly use PMAC in the peer-to-peer live streaming systems. Moreover, we also point out a basic but fatal error in their proof of theorem 1 and hope that by identifying the design flaw, similar mistakes can be avoided in future design of homomorphic message authentication code. Copyright © 2016 John Wiley & Sons, Ltd.
Jinyong Chang, Honglong Dai, Maozhi Xu, Rui Xue 0001
Secur. Commun. Networks3
2016 Separations in circular security for arbitrary length key cycles, revisited
abstract
Abstract The circular security of public key encryptions has been drawn great attentions in recent years. The relationship of notions between circular securities and standard ones such as chosen plaintext security (CPA‐security) and chosen ciphertext security (CCA‐security) deserve to be clarified. For any integer n > 0 and n ≠ 2, whether the notions of n‐circular securities can be implied by that of their standard correspondences, such as CPA or CCA security in public key setting, has largely remained open. Koppula, Ramchen, and Waters in TCC'15 recently made a separation in CPA case by proposing a CPA secure scheme that is not n‐circular secure based on the recent candidate constructions of indistinguishable obfuscation. In this work, we consider the CCA case. In particular, inspired by the indistinguishable‐obfuscation‐based construction of Koppula et al., we obtain the following results: We make a separation between the n‐circular CCA security and CCA security for anyn>0. Specifically, we propose a hybrid encryption scheme that achieves the CCA security but fails even in the n‐circular CPA security. Hence, that makes a separation between the CCA security and the n‐circular CCA security (and even the n‐circular CPA security). By revising the previous construction, we also present a CCA secure (hybrid encryption) scheme, which allows an adversary to recover all secret keys when obtaining an encrypted key cycle. Hence, that implies that: if a key cycle arises in a system, then a passive adversary might be able to recover all secret keys even if CCA‐secure encryptions are used. The results in this work, together with that of Koppula et al., confirm that notions of circular securities are stronger than their standard correspondences. Copyright © 2016 John Wiley & Sons, Ltd.
Jinyong Chang, Honglong Dai, Maozhi Xu, Rui Xue 0001
Secur. Commun. Networks3
2016 A semantically secure public key cryptoscheme using bit-pair shadows
Shenghui Su, Shuwang Lü, Maozhi Xu
Theor. Comput. Sci.3
2015 A Public Key Cryptoscheme Using Bit-Pairs with Provable Semantical Security
Shenghui Su, Shuwang Lü, Maozhi Xu
COCOON3
2015 Cryptography on twisted Edwards curves over local fields
Chunming Tang 0001, Maozhi Xu, Yanfeng Qi
Sci. China Inf. Sci.2
2014 Implementing optimized pairings with elliptic nets
Chunming Tang 0001, Dongmei Ni, Maozhi Xu, Baoan Guo, Yanfeng Qi
Sci. China Inf. Sci.3
2013 The Gallant-Lambert-Vanstone Decomposition Revisited
Maozhi Xu
Inscrypt2
2013 A Note on Semi-bent and Hyper-bent Boolean Functions
Chunming Tang 0001, Yu Lou 0001, Yanfeng Qi, Maozhi Xu, Baoan Guo
Inscrypt4
2013 Generation and Tate Pairing Computation of Ordinary Elliptic Curves with Embedding Degree One
Lin Wang 0024, Maozhi Xu
ICICS3
2012 Implementing the 4-dimensional GLV method on GLS elliptic curves with j-invariant 0
Patrick Longa, Maozhi Xu
Des. Codes Cryptogr.3
2012 The Weight Distributions of Cyclic Codes and Elliptic Curves
abstract
Cyclic codes with two zeros and their dual codes as a practically and theoretically interesting class of linear codes have been studied for many years and find many applications. The determination of the weight distributions of such codes is an open problem. Generally, the weight distributions of cyclic codes are difficult to determine. Utilizing a class of elliptic curves, this paper determines the weight distributions of dual codes ofq-ary cyclic codes with two zeros for a few more cases, whereqis an odd prime power.
Baocheng Wang, Chunming Tang 0001, Yanfeng Qi, Yixian Yang, Maozhi Xu
IEEE Trans. Inf. Theory5
2011 Pseudorandom Generators Based on Subcovers for Finite Groups
Chenggen Song, Maozhi Xu, Chunming Tang 0001
Inscrypt2
2011 Faster pairing computation on genus 2 hyperelliptic curves
Chunming Tang 0001, Maozhi Xu, Yanfeng Qi
Inf. Process. Lett.2
2010 A Generalization of Verheul's Theorem for Some Ordinary Curves
Maozhi Xu, Zhenghua Zhou
Inscrypt2
2010 Efficient 3-dimensional GLV method for faster point multiplication on some GLS elliptic curves
Zhenghua Zhou, Maozhi Xu, Wangan Song
Inf. Process. Lett.3
2004 Weaknesses of a Password-Authenticated Key Exchange Protocol between Clients with Different Passwords
Shuhong Wang 0001, Jie Wang 0038, Maozhi Xu
ACNS3