EDBT 2026 Demo / reviewers in the wild / expert
Jianbing Ni
dblp:121/2421
· DBLP profile ↗
94ranked-venue papers
15as first author
49since 2021 · last 2026
0000-0002-5639-0883ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 43 · 10 first-author · 20 since 2021Security and privacy · 26 · 3 first-author · 17 since 2021Systems, architecture and hardware · 11 · 1 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 4 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MelShield: Robust Mel-Domain Audio Watermarking for Provenance Attribution of AI Generated Synthesized Speech
Yutong Jin, Qi Li 0033, Lingshuang Liu, Jianbing Ni |
ACISP (3) | 4 |
| 2026 | Bridging Black-Box and No-Box: Embedding Reconstruction Attacks on Deep Recognition SystemsabstractDeep Neural Network (DNN)-based recognition systems are widely deployed for face and speaker authentication, yet remain vulnerable to Embedding Reconstruction Attacks (ERAs), in which adversaries recover biometric data from embeddings. Prior work assumes white-box or black-box access, requiring stronger adversarial knowledge than many real-world deployments provide. We introduce the first ERA framework that systematically characterizes settings withlessknowledge than black-box access. Our four-tier taxonomy progressively reduces adversarial capabilities, ranging from score-only and decision-only interfaces to no-query/no-feedback scenarios, mirroring the spectrum of commercial recognition APIs. To conduct ERAs under these constraints, we design high-fidelity reconstructors using Stable Diffusion for faces and flow-matching transformers for voices, trained via adaptive knowledge distillation. We formalize per-tier feasibility, proving Tiers 1–3 are practically exploitable and Tier 4 is infeasible under our formal threat model. Experiments on face and voice benchmarks show that our methods outperform existing black-box attacks under identical query budgets, achieving 93.27%, 82.60%, and 62.29% success rates for Tiers 1–3, respectively. We further evaluate compressed DNNs (pruned, quantized, and distilled models), providing the first systematic evidence that restricted-access recognition models remain at high risk in production. Qi Li 0033, Jianbing Ni, Mohammad Zulkernine, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | ARC-CBDC: Enhancing Anonymity and Regulatory Compliance in Central Bank Digital CurrencyabstractIn this paper, we propose a novel Central Bank Digital Currency (CBDC) system based on a two-tier architecture, named ARC-CBDC, where the central bank issues digital currency to commercial banks, which in turn manage transactions among anonymous users throughout the currency's lifecycle. Unlike existing systems that offer only conditional anonymity, ARC-CBDC extends traditional electronic cash to provide full user anonymity, even against commercial banks, despite their ability to observe coin accumulation during withdrawals and reductions during deposits. By utilizing BBS+ signatures, users can open bank accounts, withdraw coins, and deposit received coins without revealing their real identities. A distinctive feature of ARC-CBDC is that commercial banks are allowed to modify a recorded transaction only once within a permissioned blockchain shared between the central bank and participating commercial banks. As the trusted authority, the central bank handles coin issuance and enforces financial regulations. To prevent double spending, the central bank performs batch verification of transactions, enabling efficient detection and tracing of double-spent coins. ARC-CBDC is specifically designed with CBDC architectural requirements in mind, introducing novel mechanisms to support strong anonymity and full traceability. Through formal security proofs and performance analysis, we demonstrate that the security of ARC-CBDC relies on standard cryptographic assumptions and that it is both efficient and practical, suitable for implementation on a range of devices, including laptops and mobile phones. Yunke Liu, Jianbing Ni, Mohammad Zulkernine |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | SecureT2I: No More Unauthorized Manipulation on AI Generated Images from Prompts
Xiangman Li, Qi Li 0033, Jianbing Ni, Rongxing Lu |
ESORICS (1) | 4 |
| 2025 | HyFIDS: Hybrid Frequency-Aware Lightweight Intrusion Detection for Internet of VehiclesabstractIntrusion Detection Systems (IDSs) play a crucial role in the Internet of Vehicles (IoV) by safeguarding against reliability and security threats arising from the growing complexity and interconnectivity. However, existing deep learning (DL)-based IDSs, particularly those relying on resource-intensive architectures, often fail to meet the limited computational resource constraints of IoV gateways and tend to overlook real-world deployment considerations. To address these challenges, we propose HyFIDS, a hybrid frequency-aware lightweight intrusion detection system, for IoV ecosystems. HyFIDS integrates raw packet representations with frequency-domain representations through a novel frequency-aware module. This design enables HyFIDS to extract temporal and spectral features of both CAN frames and IP packets, thereby enhancing representational efficiency while maintaining computational lightweightness. To validate its performance, we implement HyFIDS on four benchmark datasets encompassing both inter-vehicle and intra-vehicle scenarios. Extensive experiments demonstrate that HyFIDS achieves a high detection accuracy of 99.98%, maintains a lightweight model with only 20K MACs, and obtains the highest throughput of 8.9 Mbps. Zeling Zhang, Jianbing Ni, Mohammad Zulkernine |
GLOBECOM | 3 |
| 2025 | SRED: Secure and Robust Emotion Detection for Advanced Driver Assistance Systems
Nadia Rubaiyat, Jianbing Ni, Mohammad Zulkernine |
GLOBECOM | 2 |
| 2025 | When There Is No Decoder: Removing Watermarks from Stable Diffusion Models in a No-Box Setting
Xiangman Li, Jianbing Ni, Yong Yu 0002 |
ICICS (3) | 4 |
| 2025 | LAID: Lightweight AI-Generated Image Detection in Spatial and Spectral DomainsabstractThe recent proliferation of photorealistic AIgenerated images (AIGI) has raised urgent concerns about their potential misuse, particularly on social media platforms. Current state-of-the-art AIGI detection methods typically rely on large, deep neural architectures, creating significant computational barriers to real-time, large-scale deployment on platforms like social media. To challenge this reliance on computationally intensive models, we introduce LAID, the first framework-to our knowledge-that benchmarks and evaluates the detection performance and efficiency of off-the-shelf lightweight neural networks. In this framework, we comprehensively train and evaluate selected models on a representative subset of the GenImage dataset across spatial, spectral, and fusion image domains. Our results demonstrate that lightweight models can achieve competitive accuracy, even under adversarial conditions, while incurring substantially lower memory and computation costs compared to current state-of-the-art methods. This study offers valuable insight into the trade-off between efficiency and performance in AIGI detection and lays a foundation for the development of practical, scalable, and trustworthy detection systems. The source code of LAID can be found at: https://github.com/nchivar/LAID. Nicholas Chivaran, Jianbing Ni |
PST | 2 |
| 2025 | Robustness Assessment and Enhancement of Text Watermarking for Google's SynthIDabstractRecent advances in LLM watermarking methods such as SynthID-Text by Google DeepMind offer promising solutions for tracing the provenance of AI-generated text. However, our robustness assessment reveals that SynthID-Text is vulnerable to meaning-preserving attacks, such as paraphrasing, copy-paste modifications, and back-translation, which can significantly degrade watermark detectability. To address these limitations, we propose SynGuard, a hybrid framework that combines the semantic alignment strength of Semantic Invariant Robust (SIR) with the probabilistic watermarking mechanism of SynthID-Text. Our approach jointly embeds watermarks at both lexical and semantic levels, enabling robust provenance tracking while preserving the original meaning. Experimental results across multiple attack scenarios show that SynGuard improves watermark recovery by an average of 11.1% in F1 score compared to SynthID-Text. These findings demonstrate the effectiveness of semantic-aware watermarking in resisting real-world tampering. All code, datasets, and evaluation scripts are publicly available at: https://github.com/githshine/SynGuard. Xia Han, Qi Li 0033, Jianbing Ni, Mohammad Zulkernine |
TrustCom | 3 |
| 2025 | Analysis of 24/7 Remote Arctic Monitoring by Low Earth Orbit SatellitesabstractThis paper investigates the feasibility and optimization of 24/7 remote monitoring in the Arctic using Low Earth Orbit (LEO) satellite constellations, specifically Starlink. Through rigorous link analysis incorporating Equivalent Isotropic Radiated Power (EIRP), Gain-to-Noise Temperature ratio (G/T), free space path loss, and rain attenuation, we assess the Carrier-to-Noise Ratio (CNR) for a specified Arctic location. To enhance system reliability, Particle Swarm Optimization (PSO) is applied to optimize satellite constellation parameters, substantially improving visibility from an initial 92.2% to 96.67%. Further optimization via the Walker-Star constellation achieves an unprecedented 100% visibility for a three-month duration. Results highlight the critical impact of atmospheric conditions, satellite configuration, and elevation angles on the overall communication performance, demonstrating a robust methodology for ensuring continuous, reliable Arctic communication. MATLAB (R2024a), MATLAB Satellite Communications Toolbox ver. 24.1, and Aerospace Toolbox ver. 24.1 were used for the analysis in this paper. Some analysis in this paper was done using the computing resources provided by BC DRI Group and Digital Research Alliance of Canada. The satellite data was retrieved from space-track.org. Kiarash Yousefi Damavandi, Scott S.-H. Yam, François Chan, Ning Lu 0001, Jianbing Ni |
VTC2025-Fall | 5 |
| 2025 | Securing Smart Grid Federated Learning Against Advanced Evasion Attacks Using Ensemble-Based Adversarial Training
Atef H. Bondok, Mahmoud M. Badr, Mohamed Mahmoud 0001, Tariq Alshawi, Jianbing Ni, Maazen Alsabaan |
IEEE Internet Things J. | 5 |
| 2025 | Investigation of the Robustness of XAI-Based Federated Learning Against Adversarial Attacks for Smart Grid False Data DetectionabstractFederated Learning (FL) enables decentralized training of machine learning (ML) models, making it a valuable approach for detecting false data in smart power grids (SGs) to enhance grid stability while protecting consumers privacy. However, FL-based ML models remain vulnerable to adversarial attacks during both training and inference phases, which can compromise data security. To address these vulnerabilities, we first investigate the robustness of a novel FL-based false data detection approach using Explainable Artificial Intelligence (XAI), referred to as XAI-based FL detection. This approach utilizes explanations of consumers power consumption data, rather than raw data, during the training process. We assess the robustness of the XAI-based FL detection compared to traditional data-driven FL detection against two types of adversarial attacks: Gradient Inversion attacks in the training phase, where adversaries reconstruct private data from shared gradients, and Evasion attacks in the inference phase, where adversaries subtly modify input data to deceive the detection model. Then, we propose a secure XAI-based FL detector with adversarial training to defend against both attack types. The key idea is that XAI helps mask model gradients during training because XAI-generated explanations remain nearly identical across different samples. Therefore, attackers struggle to accurately reconstruct the original training data, even if they obtain precise explanations using gradient inversion attacks. Additionally, XAI effectively distinguishes between benign and malicious samples. When combined with adversarial training, XAI strengthens model robustness against evasion attacks without compromising accuracy, effectively resolving the trade-off between security and performance. Our proposed detector reduced the success rate of evasion attacks from 94.99% to 29.11 explanations, and further to 0% with adding adversarial training. It also increased the mean square error for gradient inversion attacks from 0.01 to 2.60 in the most severe attack scenarios, making such attacks ineffective. Islam Elgarhy, Mahmoud M. Badr, Mohamed Mahmoud 0001, Jianbing Ni, Maazen Alsabaan, Tariq Alshawi |
IEEE Internet Things J. | 4 |
| 2025 | Evaluating Security and Robustness for Split Federated Learning Against Poisoning AttacksabstractSplit federated learning (SFL) is a recently proposed distributed collaborative learning architecture that integrates federated learning (FL) with split learning (SL), offering an ingenious solution for safeguarding privacy in resource-limited environments. Despite the compelling potential of SFL and its appealing attributes, its robustness remains uncharted territory. In this paper, we investigate the security and robustness of SFL, with a specific focus on its susceptibility to malicious client-driven poisoning attacks. Specifically, we study the weaknesses of SFL against the well-known poisoning attacks designed for FL, like dataset poisoning, weight poisoning, and label poisoning. We also introduce a novel type of poisoning attacks tailored for SFL, named smash poisoning, and evaluate the robustness against smash poisoning attacks and advanced hybrid attacks (DatasetSmash, LabelSmash, and WeightSmash) that amalgamate smash poisoning with the other three methods for FL. By simulating these attacks across diverse domains over four datasets, we find that most of these attacks (including weight, WeightSmash, and LabelSmash poisoning) can disrupt the converged models with straightforward poisoning actions or have persistent negative influence on the model accuracy even after the termination of the attacks. Furthermore, our findings reveal that the robustness of SFL can be augmented by strategically adjusting the system parameters, such as client quantity, bottleneck size or split type. Finally, we verify the effectiveness of the typical defense mechanisms of poisoning attacks intended for FL and design a new defense strategy that filters out malicious smashed data to improve the robustness of SFL. We observe that the adoption of properly chosen defense mechanisms is beneficial in decreasing the security risks of SFL, but entirely eliminating the impacts of poisoning attacks in SFL is still challenging. Henry Yuan, Xiangman Li, Jianbing Ni, Rongxing Lu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Protecting Your Attention During Distributed Graph Learning: Efficient Privacy-Preserving Federated Graph Attention NetworkabstractFederated graph attention networks (FGATs) are gaining prominence for enabling collaborative and privacy-preserving graph model training. The attention mechanisms in FGATs enhance the focus on crucial graph features for improved graph representation learning while maintaining data decentralization. However, these mechanisms inherently process sensitive information, which is vulnerable to privacy threats like graph reconstruction and attribute inference. Additionally, their role in assigning varying and changing importance to nodes challenges traditional privacy methods to balance privacy and utility across varied node sensitivities effectively. Our study fills this gap by proposing an efficient privacy-preserving FGAT (PFGAT). We present an attention-based dynamic differential privacy (DP) approach via an improved multiplication triplet (IMT). Specifically, we first propose an IMT mechanism that leverages a reusable triplet generation method to efficiently and securely compute the attention mechanism. Second, we employ an attention-based privacy budget that dynamically adjusts privacy levels according to node data significance, optimizing the privacy-utility trade-off. Third, the proposed hybrid neighbor aggregation algorithm tailors DP mechanisms according to the unique characteristics of neighbor nodes, thereby mitigating the adverse impact of DP on graph attention network (GAT) utility. Extensive experiments on benchmarking datasets confirm that PFGAT maintains high efficiency and ensures robust privacy protection against potential threats. Jinhao Zhou, Jun Wu 0001, Jianbing Ni, Yuntao Wang 0004, Yanghe Pan, Zhou Su 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Secure and Efficient Federated Learning Against Model Poisoning Attacks in Horizontal and Vertical Data PartitioningabstractIn distributed systems, data may partially overlap in sample and feature spaces, that is, horizontal and vertical data partitioning. By combining horizontal and vertical federated learning (FL), hybrid FL emerges as a promising solution to simultaneously deal with data overlapping in both sample and feature spaces. Due to its decentralized nature, hybrid FL is vulnerable to model poisoning attacks, where malicious devices corrupt the global model by sending crafted model updates to the server. Existing work usually analyzes the statistical characteristics of all updates to resist model poisoning attacks. However, training local models in hybrid FL requires additional communication and computation steps, increasing the detection cost. In addition, due to data diversity in hybrid FL, solutions based on the assumption that malicious models are distinct from honest models may incorrectly classify honest ones as malicious, resulting in low accuracy. To this end, we propose a secure and efficient hybrid FL against model poisoning attacks. Specifically, we first identify two attacks to define how attackers manipulate local models in a harmful yet covert way. Then, we analyze the execution time and energy consumption in hybrid FL. Based on the analysis, we formulate an optimization problem to minimize training costs while guaranteeing accuracy considering the effect of attacks. To solve the formulated problem, we transform it into a Markov decision process and model it as a multiagent reinforcement learning (MARL) problem. Then, we propose a malicious device detection (MDD) method based on MARL to select honest devices to participate in training and improve efficiency. In addition, we propose an alternative poisoned model detection (PMD) method considering model change consistency. This method aims to prevent poisoned models from being used in the model aggregation. Experimental results validate that under the random local model poisoning attack, the proposed MDD method can save over 50% training costs while guaranteeing accuracy. When facing the advanced adaptive local model poisoning (ALMP) attack, utilizing both the proposed MDD and PMD methods achieves the desired accuracy while reducing execution time and energy consumption. Chong Yu 0002, Zhenyu Meng, Wenmiao Zhang, Lei Lei 0004, Jianbing Ni, Kuan Zhang 0001, Hai Zhao 0002 |
IEEE Trans. Neural Networks Learn. Syst. | 5 |
| 2024 | Accelerating Secure and Verifiable Data Deletion in Cloud Storage via SGX and BlockchainabstractSecure data deletion enables data owners to have full control over the erasure of their data stored on local or cloud data centers, and it is essential for preventing data leakage, especially in cloud storage. However, traditional data deletion methods based on unlinking, overwriting, and cryptographic key management are either ineffective in cloud storage or rely on impractical assumptions. In this paper, we introduce SevDel, a secure and verifiable data deletion scheme that utilizes zero-knowledge proofs to achieve verification of the encryption of outsourced data without retrieving the ciphertexts. Meanwhile, the deletion of encryption keys is guaranteed based on Intel SGX. SevDel implements secure interfaces for performing data encryption and decryption in secure cloud storage. It also utilizes smart contracts to enforce the operations of the cloud service provider, ensuring compliance with service level agreements with data owners and imposing penalties on the service provider for disclosing cloud data on its servers. Evaluation using real-world workloads demonstrates that SevDel efficiently achieves data deletion verification and maintains high bandwidth savings. Xiangman Li, Jianbing Ni |
GLOBECOM | 3 |
| 2024 | Leveraging Group Secret Sharing Technology for FD-RAN: A Lightweight AKA MechanismabstractWith rapid advances in communication technology, a new access architecture of fully decoupled radio access network (FD-RAN) has been proposed. FD-RAN completely decouples the base station (BS) into uplink data base station (UBS), downlink data base station (DBS), and control base station (CBS). Different BSs handle the uplink and downlink data of the user plane, as well as control signaling, and facilitate communication needs through multi-BS cooperation. To ensure the security of multi-BS cooperation and user access, it becomes imperative to conduct key negotiations among multiple parties. However, as the number of simultaneously accessed BSs increases, the existing access security mechanism imposes excessive overhead in FD-RAN, compromising both access security and efficiency. Additionally, it becomes susceptible to distributed denial of service (DDoS) attacks launched by potential attackers. This paper introduces a lightweight authentication and key agreement (AKA) protocol based on secret value ($m_{i},\ n_{i}$) sharing technology to negotiate multi-BS group communication keys, which ensures access security in FD-RAN. By leveraging interpolation polynomial and multi-party key negotiation, the proposed protocol achieves efficient and cost-effective key negotiation on both the user and BS sides, which mitigates the risk of man-in-the-middle (MitM) and DDoS attacks. Security analysis and further evaluation show that the proposed scheme can resist various known attacks, and guarantee the computational and communication efficiency of key negotiation within the FD-RAN context. Ning Wang 0053, Jianbing Ni, Liquan Chen |
VTC Spring | 3 |
| 2024 | Privacy-Preserving Identity-Based Data Rights Governance for Blockchain-Empowered Human-Centric Metaverse CommunicationsabstractMetaverse provides human-centric immersive communication experiences where humans can teleport across different virtual landscapes and build real-time communications via digital identities with others in the same landscape. Despite great benefits, a natural question in human-centric metaverse communications is how to secure digital content among humans. In this regard, blockchain has been widely applied due to its distinct features (e.g., decentralization, transparency, and immutability). Unfortunately, the inherent properties of the blockchain also hinder humans from further deploying preferences to flexibly govern the digital content (i.e., who can read and who can edit), limiting human-centric communication abilities. Some redactable blockchain-based solutions have been proposed, but most of them suffer from the issues of data and preference leakage. To address the issues, we propose a privacy-preserving identity-based data governance (IDRG) scheme for blockchain-empowered human-centric metaverse communications. Combining digital identities, IDRG cryptographically allows humans to govern readability and editability with the right downward compatibility (i.e., humans with editability are endowed with readability) while protecting policy privacy. Specifically, IDRG leverages the polynomial function technique to break through the bottleneck of the traditional identity-based encryption technique (i.e., a policy only contains a user) to achieve a policy for multiple users. Subsequently, the optimized policies are utilized to enrich chameleon hash-based redactable blockchains for comprehensive rights governance. Further, IDRG supports user accountability and revocation by combining the proxy re-encryption technique. Security analysis proves the security of IDRG under the chosen-ciphertext attack. Experiments on the FISCO blockchain platform demonstrate that IDRG requires approximately 0.1 s to process an encryption request, 0.01 s for a reading request, and 1 s for an editing request. Overall, IDRG achieves a$3\times $reduction in computational costs compared with state-of-the-art solutions. Chuan Zhang 0003, Mingyang Zhao 0002, Weiting Zhang, Jianbing Ni, Liehuang Zhu |
IEEE J. Sel. Areas Commun. | 5 |
| 2024 | Revocable and Privacy-Preserving Bilateral Access Control for Cloud Data SharingabstractIn this paper, we propose a revocable and privacy-preserving bilateral access control scheme (named PriBAC) for general cloud data sharing (i.e., end-cloud-based data sharing). PriBAC ensures that preference matching is successful only when both parties’ preferences are satisfied simultaneously. Otherwise, nothing is leaked beyond whether the preference matching occurs. There are three challenges in designing PriBAC. The first challenge is protecting matching information, i.e., concealing two preference matching processes, in a single cloud server. The second challenge is protecting preference content while preventing receivers from receiving much useless information. The third challenge is how to integrate efficient user revocation mechanisms into bilateral access control to handle frequent user revocation cases in practical cloud data sharing applications. To address the above challenges, the punchline in PriBAC is to leverage Newton’s interpolation formula-based secret sharing to enrich the matchmaking encryption technique for constructing a privacy-preserving preference matching mechanism. To achieve efficient user revocation, we integrate a unique symbol into each user’s keys and efficiently revoke users by invaliding the corresponding keys. Security analysis proves that PriBAC can resist the chosen-ciphertext attack and preserves preference privacy and matching privacy. Experiments show that PriBAC achieves approximately$3\times $user performance improvement compared with current state-of-the-art related schemes. Mingyang Zhao 0002, Chuan Zhang 0003, Tong Wu 0011, Jianbing Ni, Ximeng Liu, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Enabling Efficient and Distributed Access Control for Pervasive Edge Computing ServicesabstractIn this paper, we propose an efficient and distributed service access control framework (E-DAC) in the pervasive edge computing (PEC) environment, where the resources of peer devices at the network edge are integrated to provide latencysensitive computing services to the nearby devices on behalf of edge servers. E-DAC addresses the challenge of efficient and distributed service access control, comprising edge service authorization, service access authorization, and mutual authentication between edge servers and edge devices. In dong so, E-DAC first extends a key-aggregate cryptosystem to enable batch service authorization, in which a service provider can aggregate the authorization keys of different services to produce a constant-size aggregate key for an edge server. Second, E-DAC enables users to acquire authorization from the service provider for service access on edge servers by using efficient secret sharing. Third, edge servers and users can authenticate with each other without interacting with a centralized server, while enabling secure zero-round trip communication, so that the service data is protected and the communication bandwidth cost is low. In addition, the service provider is capable of efficiently revoking the authorization of the dropout or compromised edge servers or users in response to the dynamics of the PEC environment. Finally, we prove the security of service access control in E-DAC, including unforgeability of service authorization and confidentiality of service data, and conduct extensive analysis and experiments to demonstrate that E-DAC is highly computational and communication-efficient on service authorization, authentication, and revocation. Lingshuang Liu, Cheng Huang 0001, Dan Zhu 0001, Jianbing Ni, Xuemin Shen |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | Enabling Low Sidelobe Secret Multicast Transmission for mmWave Communication: An Integrated Oblique Projection ApproachabstractThe protection of multicast transmission with optimized secrecy in millimeter-wave (mmWave) communication is still an open problem. In this paper, we propose a low sidelobe secret multicast transmission scheme in mmWave communication based on physical layer security techniques. By utilizing oblique projection, we jointly adopt the directional modulation (DM) and the artificial noise (AN) to achieve secret multicast transmission at low computational costs, without jeopardizing the low sidelobe transmitting pattern. Specifically, considering the constraint of multibeam with the channel knowledge of all target users, a primary transmitting weight vector of the base station (BS) is designed to achieve a low sidelobe transmitting pattern. Then, in each symbol period, the transmitting weight vector of the BS is updated by performing a linear transformation on the primary weight vector with a transformation matrix, which is obtained from the oblique projection matrices of all the target users’ channel vectors. In this way, without deteriorating the primary weight vector’s low sidelobe transmitting pattern, the obtained transmitting weight vector synthesizes the expected symbols at the target users and adds randomness to the eavesdroppers at undesired directions. Finally, the simulations demonstrate that our proposed scheme achieves outstanding communication performance for the target users at low computational costs, while keeping the high symbol error rates at the undesired directions. Jianbing Ni, Meng Li 0006, Alessandro Brighente, Mauro Conti |
IEEE Trans. Wirel. Commun. | 2 |
| 2023 | PAEEA: Privacy-Preserving Online Ad Exchange with Efficient Auction for Smart AdvertisingabstractThe concern of privacy leakage in online smart advertising is continuously serious for Internet users, and the advertising models are increasingly complex to improve the accuracy of ad impression, which make current privacy-preserving adverting protocols that are based on either profile matching or auction impractical. In this paper, we propose a new privacy-preserving ad exchange protocol (PAEEA) by integrating private set interaction and efficient auction. The distinguished feature of PAEEA is that it enables privacy-preserving matching between the profiles of users and the keywords of ads and private auction based on the bids of advertisers in an efficient way. The bid prices are embedded into ad keywords to produce a private vector, which is matched with the vector of user profiles for ad selection. User profiles, ad keywords, and bid prices are protected to preserve the privacy of both internet users and advertisers. Moreover, the system model of PAEEA follows the model of modern smart advertising, so that PAEEA is applicable to current advertising systems, such as Google Ads. Finally, the performance of PAEEA is demonstrated through extensive experiments that it is computationally efficient and practical to be implemented on smart advertising systems.11A part of the study has been published in Brennan Mosher's Master thesis. The authors own the copyright to the thesis as a whole and it is allowed to republish according to Intellectual Property Guidelines at Queen's University. Brennan Mosher, Jianbing Ni |
ICC | 2 |
| 2023 | Verifiable and Privacy-Preserving Ad Exchange for Smart Targeted AdvertisingabstractIn this paper, we propose a novel verifiable and privacy-preserving ad exchange scheme (VPAE) for smart targeted advertising that enables an ad exchange to deliver promotional advertisements to Internet users according to their specific interests, traits, and preferences. VPAE achieves the distinguished feature to preserve private information of both user profiles and advertisers, while allowing users to verify why they receive specific advertisements for adverting transparency. By utilizing homomorphic proxy re-encryption, VPAE addresses the challenge that the ad exchange has the ability to select advertisements for users, but they cannot know more than what they should. Meanwhile, VPAE integrates polynomial evaluations to achieve that the user is capable of verifying why she receives the advertisement, without learning any information of other advertisements that she does not receive. The privacy of both user profiles and advertisers are protected without sacrificing the efficiency of profile matching. We show the computational and communication overhead of VPAE through extensive analysis to demonstrate practicality and resource needs in implementation.1 Brennan Mosher, Xiangman Li, Yuanyuan He 0002, Jianbing Ni |
PST | 4 |
| 2023 | Blockchain-Based Fair and Fine-Grained Data Trading With Privacy PreservationabstractIn this article, we propose a blockchain-based fair and privacy-preserving data trading scheme that supports fine-grained data selling. First, to achieve fairness for trading participants, by incorporating attribute-based credentials, encryption, and zero-knowledge proof, we design a data trading scheme where a buyer first publishes the required data attributes on the blockchain, and a data seller can demonstrate data availability in ciphertext by only disclosing the required attributes to a data buyer and proving the authenticity of data. A data buyer transfers funds only if the correct key material is uploaded to the blockchain. Second, to guarantee fine-grained data trading and preserve identity privacy, we build a Merkle hash tree on the ciphertexts of data with a signature on its root node, which allows a data seller to split data into blocks and remove the sensitive information from the data without affecting data availability verification. The public key of the data seller is not leaked to the data buyer during the trading. Moreover, different trading transactions from the same data seller cannot be linked. We formally prove that our scheme achieves the desired security properties: fairness and privacy preservation. Simulation results demonstrate the feasibility and efficiency of the proposed scheme. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Computers | 2 |
| 2023 | Astraea: Anonymous and Secure Auditing Based on Private Smart Contracts for Donation SystemsabstractMany regions are in urgent need of facial masks for slowing down the spread of COVID-19. To fight the pandemic, people are contributing masks through donation systems. Most existing systems are built on a centralized architecture which is prone to the single point of failure and lack of transparency. Blockchain-based solutions neglect fundamental privacy concerns (donation privacy) and security attacks (collusion attack, stealing attack). Moreover, current auditing solutions are not designed to achieve donation privacy, thus not appropriate in our context. In this work, we design a decentralized, anonymous, and secure auditing frameworkAstraeabased on private smart contracts for donation systems. Specifically, we integrate a Distribute Smart Contract (DiSC) with an SGX Enclave to distribute donations, prove the integrity of donation number (intention) and donation sum while preserving donation privacy. With DiSC, we design a Donation Smart Contract to refund deposits and defend against the stealing attack the collusion attack from malicious collector and transponder. We formally define and prove the privacy and security of Astraea by using security reduction. We build a prototype of Astraea to conduct extensive performance analysis. Experimental results demonstrate that Astraea is practically efficient in terms of both computation and communication. Meng Li 0006, Yifei Chen 0005, Liehuang Zhu, Zijian Zhang 0001, Jianbing Ni, Chhagan Lal, Mauro Conti |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Enabling Regulatory Compliance and Enforcement in Decentralized Anonymous PaymentabstractDecentralized anonymous payment (DAP) enables users to directly transfer cryptocurrencies privately without passing through a central authority. Anonymous cryptocurrencies have been proposed to improve the privacy degree of DAP systems, such as Zerocash and Monero. However, the strong degree of privacy may cause new regulatory concerns, i.e., the anonymity of transactions can be used for illegal activities, such as money laundering. In this paper, we propose a novel DAP scheme that supports regulatory compliance and enforcement. We first introduce regulators into the system, who define regulatory policies for anonymous payment, and the policies are enforced through commitments and non-interactive zero-knowledge proofs for compostable statements. By doing so, users can prove that transactions are valid and comply with regulations. A tracing mechanism is embedded in the scheme to allow regulators to recover the real identities of users when suspicious transactions are detected. The formal security model and proof are provided to demonstrate that the proposed scheme can achieve desired security properties, and the performance evaluation shows its high efficiency. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Incentivizing Secure Edge Caching for Scalable Coded Videos in Heterogeneous NetworksabstractEdge caching has been envisioned as a promising technology in heterogeneous networks (HetNets) to proximally cache (video) contents. Nevertheless, as massive resources (e.g., energy, storage, computing, and bandwidth) are consumed to cache contents, edge caching devices (ECDs) are unwilling to provide caching services. In addition, as the ECDs are usually deployed by untrusted third parties, the cached contents may be illegally accessed, which results in the mobile users’ privacy leakage. To efficiently address these problems, in this paper, we propose a novel secure edge caching scheme for video contents in HetNets. Specifically, to motivate the participation of ECDs, the Nash bargaining game is exploited to model the negotiations between the content provider and ECDs, where the optimal requested caching space of the content provider and the optimal caching price of each ECD are jointly analyzed. Apart from this, to protect the content secrecy, scalable video coding is employed to facilitate secure edge caching, where the ECDs are only utilized to cache the enhancement layers that cannot be independently decoded to reconstruct the original contents. Then, we formulate a non-convex 0–1 integer programming problem to optimize the enhancement layer caching on ECDs, and the modified alternating direction method of multipliers (ADMM) is used to solve the problem optimally. Finally, simulation results show that the proposed scheme provides secure and efficient content caching for mobile users. Qichao Xu, Zhou Su 0001, Jianbing Ni |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Dual-Anonymous Off-Line Electronic Cash for Mobile PaymentabstractMobile devices have become near-ubiquitous tools in our daily lives. Following this trend, mobile commence is developed rapidly which in turns stimulates interests in mobile payment. Some prominent examples include Google’s Wallet, WeChat Pay, and Apple Pay. Most of these technologies, however, are designed for users to be able to pay conveniently to the business. In other words, they are designed with the business to user model in mind. Besides, an active network connection with an external payment server is required either from payer or payee during transaction. Our work intends to supplement existing solutions, which allows payment to be made in an off-line and dual-anonymous manner. In doing so, a dual-anonymous off-line electronic cash scheme is proposed by utilizing BBS+ signature. The feature of our scheme is dual-anonymous payment, which means that both the payer and the payee in any transaction cannot be identified even all other users and the payment server collude. Through security proof and performance analysis, we also demonstrate that the security of the proposed scheme can be reduced to standard assumptions and it is suitable for applications in mobile commerce. Jianbing Ni, Man Ho Au, Wei Wu 0001, Xiapu Luo, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Mob. Comput. | 1 |
| 2022 | Secure and Distributed Access Control for Dynamic Pervasive Edge Computing ServicesabstractPervasive edge computing (PEC) integrates the re-sources of peer devices at the network edge to serve users' latency-sensitive computation needs. Due to the high dynamics of the PEC environment, it is very challenging to achieve efficient service access control of edge servers and users without an “always-online” centralized server. In this paper, we propose a secure, efficient, and distributed service access control frame-work (SE-DAC) in the PEC environment. Specifically, SE-DAC extends the key-aggregate cryptosystem to achieve batch service authorization, where the service provider aggregates the access keys of different services to produce a constant-size aggregate key for the edge servers. Meanwhile, user authentication tasks are delegated to the edge servers by integrating secret sharing. The mutual authentication between the edge servers and the users is based on zero-round trip communication, such that the communication bandwidth cost is low. In addition, the service provider can efficiently revoke the authorization of the dropout or compromised edge servers in response to the dynamics of the PEC environment. Finally, we conduct numerical analysis and experiments to demonstrate that SE-DAC is highly computational efficient on service authorization, authentication, and revocation. Lingshuang Liu, Cheng Huang 0001, Dan Zhu 0001, Jianbing Ni, Xuemin Shen |
GLOBECOM | 5 |
| 2022 | Personalized Privacy-Preserving Federated Learning: Optimized Trade-off Between Utility and PrivacyabstractThe emerging federated learning (FL) offers a feasible solution for the privacy preservation of users' sensitive data in training artificial intelligence (AI) models. Meanwhile, differential privacy (DP) is widely used in FL to ensure that data privacy is not disclosed during model training. However, in the practical deployment of DP in FL, a prominent challenge is that most existing FL solutions set the same privacy level for different users, resulting in over-protection for some users while insufficient protection for others. In this paper, we propose a novel federated learning framework with user-level personalized privacy protection (named FLUP) to meet the personalized privacy requirements of different users while maintaining high data utility. In this framework, we propose a user-level personalized DP mechanism that combines a personalized sampling algorithm and Gaussian perturbation to meet each user's personalized differential privacy corresponding to their privacy parameters. Then, we qualitatively analyze the impact of the sampling threshold on model performance. Furthermore, to balance user privacy requirements and AI model performance, we design a utility-aware game model to distributively determine the optimized sampling threshold and the users' differential privacy parameters. Finally, by conducting validation experiments, we demonstrate the feasibility and effectiveness of our proposed framework in terms of model performance as well as user privacy preservation. Jinhao Zhou, Zhou Su 0001, Jianbing Ni, Yuntao Wang 0004, Yanghe Pan, Rui Xing 0001 |
GLOBECOM | 3 |
| 2022 | Securing E-Petition: A Privacy-Preserving Fine-Grained Electronic Petition System for Health and Political PetitionsabstractE-petition has played an important role in health and politics that collects public opinions and requests a superior or an authority to take actions towards a health or political problem. However, this activity exposes the privacy of the signers who participate to express opinions. In this paper, we propose a privacy-preserving fine-grained e-petition system that supports attribute-based identity verification for signers, while protecting their privacy. By considering the target groups of signers in a specific health or political petition, an attribute policy is defined to ensure that only the signers with the attributes that satisfy the attribute policy can sign the petition. The fine-grained petition is better than the traditional e-petitions because it can improve the trustworthiness of the petition results via proactive signer selection. Moreover, the new petition system protects the identities of the signers by using the non-interactive zero-knowledge proof system, such that the signers are anonymous in signing petitions. In addition, the proposed petition system supports the tracing of double-signing, a cheating behavior that an anonymous signer can submit more than one signature in a petition without being detected. Finally, we prove that the proposed petition system achieves the desirable security properties, including anonymity, unforgeability, and traceability, and demonstrate that the system is efficient to be implemented on the mobile devices. Xiangman Li, Yunke Liu, Jianbing Ni, Yuanyuan He 0002 |
ICC | 3 |
| 2022 | AT-CBDC: Achieving Anonymity and Traceability in Central Bank Digital CurrencyabstractIn this paper, we propose a new central bank digital currency (CBDC) system based on the two-tier architecture. The proposed system enhances the traditional bank-user framework of electronic cash and employs the commercial banks for account and coin management. The coin splitting is supported during coin withdrawal of users and the coin combination is achieved for coin deposit at the commercial banks, such that the efficiency of coin management is improved. The other distinguished feature is that the proposed system achieves the anonymity against the commercial banks, while enabling the central bank to support user tracing and double-spending prevention. Specifically, by utilizing the BBS+ signatures, the users can create bank accounts, withdraw coins, and deposit the received coins at the commercial banks without exposing their real identities. As a trusted party, the central bank is responsible for money issuing and financial regulation. In addition, to ensure the system inclusive, users can receive payments from others even they do not have bank accounts at commercial banks. Finally, we demonstrate that the proposed system achieves the desirable properties of balance, anonymity, and traceability and show the efficiency and practicality for the implementation on mobile devices. Yunke Liu, Jianbing Ni, Mohammad Zulkernine |
ICC | 2 |
| 2022 | Crafting Text Adversarial Examples to Attack the Deep-Learning-based Malicious URL DetectionabstractDetecting malicious URLs is of great significance to reduce cyber crimes and maintain Internet security. Currently, Deep Learning (DL) techniques have been widely used to improve the classical malicious URL detection models, as DL-based detection models can perform an in-depth analysis of the text information of the URL, and detect the fishing URLs of unknown cyber attack types with high accuracy. Any missed blocking of malicious URLs can potentially result in a huge loss of information and property. In this paper, we focus on the vulnerability of the existing DL-based malicious URL detection models and show that they are sensitive to adversarial samples. First, we construct URL adversarial samples based on the component-level and character-level perturbations and use them to attack mainstream DL-based detection models, resulting in obvious decreases in the detection accuracies. Meanwhile, the perturbations are under the constraints that each adversarial sample URL is hardly distinguished from the original URL with naked eyes. Furthermore, under most circumstances, the adversarial samples constructed by replacing 14 types of characters and perturbing other all components except the scheme component lead to the largest increased number of missed blocking of malicious URLs, i.e., a bigger drop in the accuracy than other constructed methods. Finally, extensive experiments demonstrate the effectiveness of our adversarial examples. Even if the adversarial training is used against our adversarial samples, the adversarial samples still work and bring oblivious decreases in their accuracy. Zuquan Peng, Yuanyuan He 0002, Zhe Sun 0005, Jianbing Ni, Ben Niu 0001, Xianjun Deng |
ICC | 4 |
| 2022 | Blockchain-Based Credential Management for Anonymous Authentication in SAGVNabstractIn this paper, we propose a blockchain-based collaborative credential management scheme for anonymous authentication in space-air-ground integrated vehicular networks (SAGVN), namedSAG-BC. First, we build a consortium blockchain among service providers and design a distributed system setup (DSS) scheme to securely generate public parameters for issuing credentials. Second, we design a collaborative credential issuance (CCI) scheme to generate a succinct and easy-to-manage subscription credential. The credential can be used by users to access different access points in SAGVN efficiently without revealing true identities from the authentication messages. With co-designs of zero-knowledge proofs and succinct on-chain commitments,SAG-BCprovides efficient verifiability and incentives for credential management operations in SAGVN. By doing so, expensive on-chain storage and computational overheads are reduced in the DSS and CCI. Finally, we conduct a thorough security analysis to demonstrate thatSAG-BCachieves security and verifiability for credential management in SAGVN. We set up a real-world blockchain network and conduct extensive experiments to show the feasibility and efficiency ofSAG-BC. Huaqing Wu, Cheng Huang 0001, Jianbing Ni, Xuemin Shen |
IEEE J. Sel. Areas Commun. | 4 |
| 2022 | FRUIT: A Blockchain-Based Efficient and Privacy-Preserving Quality-Aware Incentive SchemeabstractIncentive plays an important role in knowledge discovery, as it impels users to provide high-quality knowledge. To promise incentive schemes with transparency, blockchain technology has been widely used in incentive schemes. Currently, privacy, reliability, streamlined processing, and quality awareness are major challenges in designing blockchain-based incentive schemes. In this paper, we design a blockchain-based eFficient and pRivacy-preserving qUality-aware IncenTive scheme called FRUIT. With well-designed smart contracts, FRUIT achieves privacy, reliability, streamlined processing, and quality awareness during the whole procedure. Specifically, we design a novel lightweight encryption method by combining matrix decomposition with proxy re-encryption and a privacy-preserving task allocation based on the polynomial fitting function and hash function. Then, we leverage our proposed lightweight encryption and task allocation to build an efficient and privacy-preserving knowledge discovery protocol in order to securely calculate the data quality and truthful knowledge. To promise user reliability in the incentive scheme, we utilize the Dirichlet distribution to realize the automatic reputation prediction based on the data quality by deploying the reputation management on the blockchain. Moreover, we also deploy the payment management on the blockchain, endowing the incentive scheme to reward participants based on the data quality automatically. Through a detailed security analysis, we demonstrate that data privacy and task privacy are well preserved during the whole process. Theoretical analysis and extensive experiments on real-world datasets demonstrate that FRUIT has acceptable efficiency and affordable performance in terms of computation cost, communication overhead, and gas consumption. Chuan Zhang 0003, Mingyang Zhao 0002, Liehuang Zhu, Weiting Zhang, Tong Wu 0011, Jianbing Ni |
IEEE J. Sel. Areas Commun. | 6 |
| 2022 | Blockchain-Cloud Transparent Data Marketing: Consortium Management and FairnessabstractData are generated by Internet of Things (IoT) devices and centralized at a cloud server, that can later be traded with third parties, i.e., data marketing, to enable various data-intensive applications. However, the centralized approach is recently under debate due to the lack of (1) transparent and distributed marketplace management, and (2) marketing fairness for both IoT users (data sellers) and third parties (data buyers). In this paper, we propose a Blockchain-Cloud Transparent Data Marketing (Block-DM) with consortium management and executable fairness. First, we introduce a hybrid data-marketing architecture, where the cloud acts as an efficient data management unit and a consortium blockchain serves as a transparent marketing controller. Under the architecture, consent-based secure data trading and identity privacy for data owners are achieved with the distributed credential issuance and threshold credential openings. Second, with a consortium committee, we design a fair on/off-chain data marketing protocol. By financial incentives and succinct ‘commitments’ of marketing operations, the protocol can achieve the marketing fairness and effective detection of unfair marketing operations. We demonstrate the security of Block-DM with thorough analysis. We conduct extensive experiments with a consortium blockchain network on Hyperledger Fabric to show the feasibility and practicality of Block-DM. Cheng Huang 0001, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Computers | 3 |
| 2022 | Fine-Grained Query Authorization With Integrity Verification Over Encrypted Spatial Data in Cloud StorageabstractIn this article, a fine-grained query authorization scheme with integrity verification is proposed over encrypted spatial data for location-based services (LBS). The fine-grained query authorization is enabled based on a distribution of the spatial data by employing a non-uniform partition in the spatial domain to generate a density-based space filling curve (DSC), which can be used to generate index values for querying and transformation keys. The transformation keys can be used to generate query tokens for a secure spatial query as well as construct a transformation key tree whose subtree can be distributed by the LBS provider to an authorized user as transformation key for query tokens generation. Furthermore, the proposed scheme constructs a Merkle quad tree (MQ-tree) to support integrity verification by aggregating a digest of the spatial data based on the DSC and employing the MQ-tree as a verification structure. The LBS provider can share a subtree of the MQ-tree to authorized user as his verification structure, which corresponds to the transformation key of the authorized user. In this way, the authorized user can only generate the valid query tokens and verify the query results in his authorized region. The security properties of the proposed scheme is discussed, and extensive experimental results demonstrate the high efficiency of verification structure generation and verification operations. Feng Tian 0004, Zhenqiang Wu, Xiaolin Gui, Jianbing Ni, Xuemin Shen |
IEEE Trans. Cloud Comput. | 4 |
| 2022 | Identity-Based Provable Data Possession From RSA Assumption for Secure Cloud StorageabstractAs cloud storage services have become popular nowadays, the integrity of outsourced data stored at untrusted servers received increased attention. Provable data possession (PDP) provides an effective and efficient solution for cloud data integrity by asking the cloud server to prove that the stored data are not tampered with or maliciously discarded without returning the actual data to users. In this article, we propose an efficient identity-based privacy-preserving provable data possession scheme (ID-P$^3$DP) based on the RSA assumption for secure cloud storage. In ID-P$^3$DP, a cloud user takes the outsourcing file and a global parameter in a time period as inputs to generate identity-based homomorphic authenticators, and any third-party auditor (TPA) can check the integrity of the outsourced file by verifying the validity of homomorphic authenticators. The distinguished feature of ID-P$^3$DP is to support the aggregation of identity-based homomorphic authenticators generated by different users under the RSA assumption, which is an open problem in provable data possession. Specifically, we transfer the identity-based homomorphic authenticators generated in distinct time periods into those with the same period parameter, and the cloud can compress the homomorphic authenticators of different users to generate a data possession proof for integrity verification. Besides, by exploiting zero-knowledge proof, the leakage of outsourced data to TPA can be prevented. The soundness of ID-P$^3$DP is proved based on the RSA assumption, and the privacy against TPA is perfectly preserved. Finally, we demonstrate ID-P$^3$DP is more efficient on integrity verification than the existing BLS-based schemes, and cross-user aggregate verification can significantly reduce computational and communication overhead for TPA. Jianbing Ni, Kuan Zhang 0001, Yong Yu 0002, Tingting Yang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Differentially Private Set Intersection for Asymmetrical ID AlignmentabstractPrivate Set Intersection (PSI) is typically used to achieve ID alignment with protection of IDs in the preparation phase of Vertical Federated Learning (VFL). However, existing PSI approaches are limited to protecting IDs that are outside the intersection of participants, and most ignore the sensitivity of intersection for a weak party in an asymmetrical ID alignment. Since the set size of the strong party is much greater than the weak party’s in an asymmetrical federation, and the intersection usually accounts for a substantial part of the weak party set, the weak party’s sensitive sample IDs would be severely compromised through sharing the intersection. To address this issue, we propose Differentially private PSI Cardinality and PSI (DPSI-CA, DPSI) protocols, which protect the intersection cardinality and sensitive IDs inside the intersect ion for the weak party, respectively. First, DPSI-CA encodes IDs in binary notation, and combines them with the GM encryption, to perform the ID-matchmaking by executing bitwise plaintext XOR. Then, the encrypted matching results are independently perturbed using randomized responses to produce differentially private outputs for PSI-CA, and its unbiased estimate is added to remove the deviation brought by the randomization. Furthermore, DPSI fuses Pseudo-Random Function (PRF)-based zero sharing, garbled Bloom filter, and Oblivious PRF (OPRF)-based shares reconstruction, to successfully reconstruct the shares corresponding to sampled IDs in the intersection. Meanwhile, a randomized response is used to sample the inputs and perturb the outputs of the OPRF-based shares reconstruction, producing a randomly sampled intersection for the weak party and differentially private intersection for the strong party. Finally, the privacy analysis shows that our protocols provide differential privacy for the weak party’s sensitive sample IDs, and extensive experiment results illustrate the feasibility of the asymmetrical ID alignment involving millions of IDs. Yuanyuan He 0002, Jianbing Ni, Laurence T. Yang, Xianjun Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Differentially Private Tripartite Intelligent Matching Against Inference Attacks in Ride-Sharing ServicesabstractIn intelligent transportation systems, the key issue of the Ride-Sharing Service (RSS) is to find proper drivers for the passengers by Intelligent Matching (IM) of two or three objects, including the positions of drivers, the travel information of passengers, and the spots where passengers and drivers meet and separate. Unfortunately, the exposure of travel plans of passengers in the IM process due to inference attacks has raised concerns about the privacy violation. To resist the inference attacks, we propose a Differentially Private Tripartite IM (DPTIM) protocol for RSS. DPTIM is based on the tripartite IM process, which intelligently finds the suitable threshold to filter out the matched objects with satisfaction scores below the threshold, so as to provide the high average satisfaction score of matched passengers. Compared to existing relevant mechanisms, DPTIM is distinguished by the feature that it leverages the inference error and differential privacy techniques to prevent the prior-information-based inference attacks and constrain the posterior information leakage, while providing satisfactory matching results. Furthermore, DPTIM meets the personalized demand of location privacy by using the passenger-specific tolerance estimation on inference errors and the personalized privacy budget. Finally, we implement DPTIM on real-world datasets, and demonstrate the satisfactory performance of DPTIM in terms of the average satisfaction score of passengers, the anti-inference-attack capability, and the passenger-specific privacy requirement. Yuanyuan He 0002, Jianbing Ni, Laurence T. Yang, Wei Wei 0006, Xianjun Deng, Deqing Zou, Syed Hassan Ahmed |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | Efficient and Anonymous Authentication With Succinct Multi-Subscription Credential in SAGVNabstractIn this paper, we propose an efficient and anonymous authentication protocol with a succinct multi-subscription credential (AnMsc) in Space-air-ground integrated vehicular networks (SAGVN). First, we adopt a subscription-based service model in SAGVN. Specifically, vehicular users (VEs) can subscribe to network services and conduct direct mutual authentication with subscribed access points (APs) to avoid message exchanges with VEs’ home network. Early application data can also be transmitted with authentication messages to improve communication efficiency. Second, we carefully tailor the design of the redactable signature and propose an efficient credential management mechanism in SAGVN. Multiple service subscriptions can be embedded into a succinct (constant-size) credential. With the credential, VEs can anonymously access any subscribed AP without revealing other subscription information. Thorough security analysis and comprehensive performance evaluation demonstrate that AnMsc can guarantee key-exchange security, VE anonymity, and service fairness while ensuring credential management and authentication efficiency. Huaqing Wu, Jianbing Ni, Xuemin Shen |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2022 | Digital Twin-Driven Vehicular Task Offloading and IRS Configuration in the Internet of VehiclesabstractDigital mymargin Twin (DT) and Intelligent Reflective Surface (IRS), the most two promising technologies of 6G make the Internet of Vehicles (IoV) more adaptive. However, future autonomous driving needs powerful networking resources and high-quality wireless communications to guarantee the Quality of Service (QoS). Especially considering the time-varying physical operating environments of IoV, it is extremely urgent to improve resource utilization and wireless channel quality. In this work, we propose a Digital Twin-Driven Vehicular Task Offloading and IRS Configuration Framework (DTVIF) to efficiently monitor, learn, and manage the IoV. Specifically, we adopt Mobile Edge Computing (MEC) and IRS to provide augmented computing capacities for vehicles and improve transmission performance when vehicles communicate to MEC servers. DT is employed to achieve real-time data collection and digital representation of physical operating environments of IoV to better support decisions making. In order to reduce the overall delay and energy consumption of DTVIF, we propose a Two-Stage Optimization for Jointly Optimizing Task Offloading and IRS Configuration (TSJTI) algorithm based on Deep Reinforcement Learning (DRL) and Transfer Learning (TFL). In the first stage, we introduce Double Deep$Q$-learning Networks (DDQN) to find the optimal offloading decision. In the second stage, based on the parameters learned from the first stage, we migrate the parameters from the first stage to find the optimal IRS configuration based on the Deep Deterministic Policy Gradient (DDPG) method. The simulations demonstrate that the proposed algorithm can effectively reduce the processing latency of task offloading and reduce the average energy consumption in DTVIF. Xiaoming Yuan 0002, Ning Zhang 0007, Jianbing Ni, F. Richard Yu, Victor C. M. Leung |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | Location Privacy-Preserving Task Recommendation With Geometric Range Query in Mobile CrowdsensingabstractIn mobile crowdsensing, location-based task recommendation requires each data requester to submit a task-related geometric range to crowdsensing service providers such that they can match suitable workers within this range. Generally, a trusted server (i.e., database owner) should be deployed to protect location privacy during the process, which is not desirable in practice. In this paper, we propose the location privacy-preserving task recommendation (PPTR) schemes with geometric range query in mobile crowdsensing without the trusted database owner. Specifically, we first propose a PPTR scheme with linear search complexity, named PPTR-L, based on a two-server model. By leveraging techniques of polynomial fitting and randomizable matrix multiplication, PPTR-L enables the service provider to find the workers located in the data requester’s arbitrary geometric query range without disclosing the sensitive location privacy. To further improve query efficiency, we design a novel data structure for task recommendation and propose PPTR-F to achieve faster-than-linear search complexity. Through security analysis, it is shown that our schemes can protect the confidentiality of workers’ locations and data requesters’ queries. Extensive experiments are performed to demonstrate that our schemes can achieve high computational efficiency in terms of geometric range query. Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Jianbing Ni, Cheng Huang 0001, Xuemin Shen |
IEEE Trans. Mob. Comput. | 4 |
| 2021 | FL-PATE: Differentially Private Federated Learning with Knowledge TransferabstractFederated learning provides a solution for data privacy protection, while enabling training over the local data samples, without exchanging them. However, it is far from practical and secure because data privacy is still vulnerable due to the well-studied attacks, e.g., membership inference attacks and model inversion attacks. In this paper, to further prevent data leakage against these attacks, we propose FL-PATE, a differentially private federated learning framework with knowledge transfer. Specifically, participants with sensitive data are grouped to train teacher models under federated learning settings, and the knowledge of teacher models is transferred to a publicly accessible student model for prediction via aggregating teacher models' outputs of public datasets. A modified client-level differential privacy mechanism is used to guarantee each participant's data privacy during the corresponding teacher model's training process. The proposed framework preserves participant's privacy against membership inference attacks and the differential privacy cost is fixed. The privacy analysis and experiments demonstrate that trained teacher and student models have an excellent performance in accuracy and robustness theoretically and empirically. Yanghe Pan, Jianbing Ni, Zhou Su 0001 |
GLOBECOM | 2 |
| 2021 | Balancing Efficiency and Security for Network Access Control in Space-Air-Ground Integrated NetworksabstractIn this paper, we investigate the efficiency of network access control with the co-existence of multiple network operators and propose an efficient and secure network access control architecture (ESNAC) that offers fast identity authentication and access authorization in space-air-ground integrated networks. The major challenge lies in enabling multiple independent network operators to authorize and authenticate mobile users for network access in a secure and efficient way, even they are not mutually trusted. To address this challenge, we introduce an aggregate anonymous credential mechanism to enable a mobile user to present network access authorization of a group of network operators based on the consolidated anonymous credential that is aggregated from the partial anonymous credentials of the network operators. In addition, the efficient authentication of packet delivery is provided based on a sequential aggregate signature that allows each network operator to sign network packets for authentication and sequentially aggregate signatures for communication efficiency. Finally, we discuss the desired security properties of ESNAC and demonstrate its computational and communication efficiency by comparing with the conventional scheme without aggregation. Xiangman Li, Jianbing Ni, Haomiao Yang |
PST | 3 |
| 2021 | Guest Editorial Special Issue on Cybertwin-Driven 6G: Architectures, Methods, and ApplicationsabstractInternet of Everything (IoE) brings unprecedented challenges regarding scability, mobility, availability, and security to wireless communications. Cybertwin emerges as a promising paradigm for the next-generation mobile network, i.e., 6G. Basically, it serves as the communication anchor of a user at the edge and performs fundamental authentication and network resources control functionalities. Cybertwin is also an indispensable enabler of the cloud native network paradigm and can efficiently support the digital twin and metaverse. With cybertwin, heterogeneous access networks can be easily exploited in a synergic manner, such that advanced applications, such as multiscreen multistream rich media delivery, can be realized with guaranteed QoS. Furthermore, a user’s activities in cyberspace can be recorded naturally which becomes his/her/its digital asset. In the future, cybertwin may become the personal assistant and even an immortal second life of the user. Quan Yuan 0004, Miao Wang 0003, Jianbing Ni, Sandra Céspedes Umaña |
IEEE Internet Things J. | 4 |
| 2021 | Practical and Secure SVM Classification for Cloud-Based Remote Clinical Decision ServicesabstractSupport vector machine (SVM) classification techniques have been widely adopted for building clinical decision models. In cloud-based remote clinical decision services, a healthcare center outsources the clinical decision model to a cloud server, which then provides remote clinical decision services to end users. In this article, we propose a practical and secure SVM classification scheme (${\sf SSVMC}$) for cloud-based remote clinical decision services. Specifically, we first extract SVM decision rules from an SVM classifier. Then, we leverage symmetric key encryption to protect the confidentiality of medical data and prevent the cloud service provider from misusing intellectual property of the outsourced clinical model. Finally, we build encrypted indexes to achieve efficient SVM classification. We define a leakage function, formulate a security definition, and provide a simulation-based security proof for${\sf SSVMC}$. The performance analysis demonstrates that${\sf SSVMC}$achieves linear computational complexity when an SVM classifier (a.k.a., the clinical decision model) is pre-trained. The simulations evaluate the impact of several parameters on time costs. The experimental evaluations show the performance differences between${\sf SSVMC}$and several existing schemes in terms of time costs, storage costs, communication costs, and precisions in a real-world clinical dataset, which demonstrate that${\sf SSVMC}$is computationally efficient with high decision accuracy. Jinwen Liang, Zheng Qin 0001, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Computers | 3 |
| 2021 | Blockchain-Assisted Public-Key Encryption with Keyword Search Against Keyword Guessing Attacks for Cloud StorageabstractCloud storage enables users to outsource data to storage servers and retrieve target data efficiently. Some of the outsourced data are very sensitive and should be prevented for any leakage. Generally, if users conventionally encrypt the data, searching is impeded. Public-key encryption with keyword search (PEKS) resolves this tension. Whereas, it is vulnerable to keyword guessing attacks (KGA), since keywords are low-entropy. In this paper, we present a secure PEKS scheme called SEPSE against KGA, where users encrypt keywords with the aid of dedicated key servers via a threshold and oblivious way. SEPSE supports key renewal to periodically replace an existing key with a new one on each key server to thwart the key compromise. Furthermore, SEPSE can efficiently resist online KGA, where each keyword request made by a user is integrated into a transaction on a public blockchain (e.g., Ethereum), which allows key servers to learn the number of keyword requests made by the user without requiring a synchronization between them for per-user rate limiting. Security analysis and performance evaluation demonstrate that SEPSE provides a stronger security guarantee compared with existing schemes, at the expense of acceptable computational costs. Yuan Zhang 0006, Chunxiang Xu, Jianbing Ni, Hongwei Li 0001, Xuemin Shen |
IEEE Trans. Cloud Comput. | 3 |
| 2021 | Achieving Accountable and Efficient Data Sharing in Industrial Internet of ThingsabstractIn this article, we propose an accountable and efficient data sharing scheme for industrial IoT (IIoT), named an accountable and data sharing scheme (ADS), in which a data owner can pursue the responsibility of a data receiver if the latter leaks some sensitive shared data to the public for profits while without permission (i.e., accountability). Specifically, ADS is built upon an adaptive decentralized oblivious transfer protocol together with a zero-knowledge proof technique, which enables the data receiver's private key to be hidden from the data owner and yet correctly embedded into the shared data during the process of data sharing. Once data breaches occur, the private key can be automatically revealed to the data owner so as to achieve the accountability. In addition, with ADS, a group of sharing providers can also assist IIoT devices in handling heavy computational tasks via the secret sharing technique without sacrificing the security. Extensive performance evaluations are conducted, and the simulation results demonstrate that ADS has high computational efficiency, making it well fit for IIoT. Cheng Huang 0001, Jianbing Ni, Rongxing Lu, Xuemin Shen |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | Efficient and Privacy-Preserving Non-Interactive Truth Discovery for Mobile CrowdsensingabstractTruth discovery is one of the key technologies to extract truthful information from unreliable sensory data collected by different mobile devices in mobile crowdsensing, but the sensory data and the outputs of truth discovery (i.e., truths and mobile devices' weights) may contain sensitive information and cause serious privacy concerns. In this paper, we propose an efficient and privacy-preServing non-interActive Truth discovEry scheme (SATE) in mobile crowdsensing. Specifically, SATE is designed based on a two-cloud model. First, the sensory data is encoded into two parts (i.e., perturbed data and noises) at the mobile device, which are maintained by two clouds separately. Second, by utilizing an adapted distributed public key homomorphic cryptosystem, two clouds can co-operatively exchange the intermediate weights and truths in a privacy preserving manner and thus achieve privacy-preserving truth discovery without the participation of the mobile devices. Security analysis demonstrates that SATE can provide full privacy protection for sensory data, weights, and truths. Performance evaluation also shows that SATE can achieve high computational efficiency and low communication overhead on the mobile devices, since there is no time-consuming cryptographic operation involved. Chuan Zhang 0003, Liehuang Zhu, Chang Xu 0004, Jianbing Ni, Cheng Huang 0001, Xuemin Shen |
GLOBECOM | 4 |
| 2020 | Consent-based Privacy-preserving Decision Tree EvaluationabstractDecision trees are prevalent machine learning models used for data classification. Cloud servers can build their decision tree models and provide users with many classification services, such as remote medical diagnosis. Moreover, users would also like to share the classification results with third-party applications for customized services. For example, the medical diagnosis results can be further utilized by a nutrition application to provide users with dietary recommendations. However, as stringent privacy regulations of personal data, such as GDPR, takes effect, the decision tree evaluation must comply with the following requirements. First, the model parameters and user data (input and output) should be protected from public disclosure. Second, different applications should obtain the classification results with users' consent in the context of user-customised services. In this paper, we propose a consent-based privacy-preserving decision tree evaluation scheme, named CPDE. Specifically, to achieve model parameter privacy and user data privacy, the original decision tree evaluation is conducted in a private manner in CPDE. As a result, all operations can be performed in the encrypted domain using an additively homomorphic encryption primitive and a secure comparison protocol. In addition, by integrating a proxy re-encryption technique, CDPE enables user-authorized applications to obtain the user's classification results even if the user is offline. The security analysis shows that CPDE achieves the desirable security properties and performance evaluation demonstrates CPDE is efficient and is suitable for real-world implementations. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
ICC | 3 |
| 2020 | Secure and Lightweight Authentication With Key Agreement for Smart Wearable SystemsabstractNowadays, an increasing number of wearable devices (WDs) have been widely deployed in smart wearable systems to collect health status measures and body information of users. Due to the openness of wireless transmission and the low capabilities of WDs in terms of energy and computation, it is of a great challenge to ensure the security of the users' physiological information. In this article, we propose a secure and lightweight authentication and key agreement scheme (SLAKA) by using the fuzzy extractor, the cryptographic hash function, and the bitwise exclusive-or operation. In SLAKA, mutual authentication between a WD and the mobile terminal (MT) can be achieved, after that, a session key can be negotiated at both ends for future secure communications. Detailed security analysis shows that SLAKA has the resilience against various well-known attacks, such as replay attacks, stolen/lost MT/WD attacks, man-in-the-middle attacks, MT/WD impersonation attacks, password change attacks, anonymity and untraceability attacks, and privileged-insider attacks. Through performance comparison and extensive simulation, SLAKA is demonstrated to be more efficient than the existing schemes, while providing more extractive features and security guarantees. Jiping Li, Ning Zhang 0007, Jianbing Ni, Jing Chen 0003, Ruiying Du |
IEEE Internet Things J. | 3 |
| 2020 | Secure and Efficient Distributed Network Provenance for IoT: A Blockchain-Based ApproachabstractNetwork provenance is essential for Internet-of-Things (IoT) network administrators to conduct the network diagnostics and identify root causes of network errors. However, the distributed nature of the IoT network results in the management of the provenance data at different trust domains, which poses concerns on the security and trustworthiness of the cross-domain network diagnostics. In this article, we propose a blockchain-based architecture for secure and efficient distributed network provenance (SEDNP) in the IoT. Instead of directly storing and querying the whole provenance data on the blockchain with prohibitive implementation cost, we introduce a unified provenance query model and develop a provenance digest strategy that: 1) enables compact (constant size) on-blockchain digests of provenance data and a multilevel index regardless of provenance data volume and 2) ensures the correctness and integrity of provenance query results through the verification of the on-blockchain digests. We formally define the security requirements as Archiving Security along with thorough security analysis. Moreover, we conduct extensive experiments with the integration of a verifiable computation (VC) framework and a blockchain testing network. The experimental results are provided as performance benchmarks to demonstrate the application feasibility of SEDNP. Jianbing Ni, Cheng Huang 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Internet Things J. | 2 |
| 2020 | Secure and Efficient k NN Classification for Industrial Internet of ThingsabstractThe k-nearest neighbors (kNN) classification has been widely used for defective product identification and anomaly detection in the Industrial Internet of Things (IIoT). In this article, we propose a secure and efficient distributed kNN classification algorithm (SEED-kNN) to prevent information and control flow exposure while supporting large-scale data classification on distributed servers. Specifically, we first design a secure and efficient vector homomorphic encryption (VHE) scheme by constructing a key-switching matrix and a noise matrix for data encryption. Based on the designed VHE, SEEDkNN is proposed to efficiently achieve the confidentiality of data flow, kNN query, and class label, while enabling homomorphic operations on the encrypted data. Moreover, by leveraging the Map/Reduce architecture, SEED-kNN enables the kNN classification over the large-scale encrypted data on distributed servers for industrial control systems. Finally, we demonstrate that SEEDkNN achieves semantic security and high classification accuracy, and is applicable in IIoT due to its high efficiency. Haomiao Yang, Shaopeng Liang, Jianbing Ni, Hongwei Li 0001, Xuemin Shen |
IEEE Internet Things J. | 3 |
| 2020 | Privbus: A privacy-enhanced crowdsourced bus service via fog computing
Yuanyuan He 0002, Jianbing Ni, Ben Niu 0001, Fenghua Li 0001, Xuemin Shen |
J. Parallel Distributed Comput. | 2 |
| 2020 | 5G Vehicle-to-Everything Services: Gearing Up for Security and Privacyabstract5G is emerging to serve as a platform to support networking connections for sensors and vehicles on roads and provide vehicle-to-everything (V2X) services to drivers and pedestrians. 5G V2X communication brings tremendous benefits to us, including improved safety, high reliability, large communication coverage, and low service latency. On the other hand, due to ubiquitous network connectivity, it also presents serious trust, security, and privacy issues toward vehicles, which may impede the success of 5G V2X. In this article, we present a comprehensive survey on the security of 5G V2X services. Specifically, we first review the architecture and the use cases of 5G V2X. We also study a series of trust, security, and privacy issues in 5G V2X services and discuss the potential attacks on trust, security, and privacy in 5G V2X. Then, we offer an in-depth analysis of the state-of-the-art strategies for securing 5G V2X services and elaborate on how to achieve the trust, security, or privacy protection in each strategy. Finally, by pointing out several future research directions, it is expected to draw more attention and efforts into the emerging 5G V2X services. Rongxing Lu, Lan Zhang 0005, Jianbing Ni, Yuguang Fang |
Proc. IEEE | 3 |
| 2020 | Providing Task Allocation and Secure Deduplication for Mobile Crowdsensing via Fog ComputingabstractMobile crowdsensing enables a crowd of individuals to cooperatively collect data for special interest customers using their mobile devices. The success of mobile crowdsensing largely depends on the participating mobile users. The broader participation, the more sensing data are collected; nevertheless, the more replicate data may be generated, thereby bringing unnecessary heavy communication overhead. Hence it is critical to eliminate duplicate data to improve communication efficiency, a.k.a., data deduplication. Unfortunately, sensing data is usually protected, making its deduplication challenging. In this paper, we propose a fog-assisted mobile crowdsensing framework, enabling fog nodes to allocate tasks based on user mobility for improving the accuracy of task assignment. Further, a fog-assisted secure data deduplication scheme (Fo-SDD) is introduced to improve communication efficiency while guaranteeing data confidentiality. Specifically, a BLS-oblivious pseudo-random function is designed to enable fog nodes to detect and remove replicate data in sensing reports without exposing the content of reports. To protect the privacy of mobile users, we further extend the Fo-SDD to hide users' identities during data collection. In doing so, Chameleon hash function is leveraged to achieve contribution claim and reward retrieval for anonymous mobile users. Finally, we demonstrate that both schemes achieve secure, efficient data deduplication. Jianbing Ni, Kuan Zhang 0001, Yong Yu 0002, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Balancing Privacy and Accountability for Industrial Mortgage ManagementabstractIndustrial mortgage enables companies to acquire loan for business venture or investment purposes by pledging their industrial assets to financial institutions. To prevent double-mortgage fraud of borrowers, information exchange among different financial institutions is necessary. On the other hand, it results in the privacy leakage of borrowers. In this article, we construct a blockchain-based accountable and privacy-preserving industrial mortgage scheme (BAPIM). BAPIM enables financial institutions to share the mortgage data of borrowers in an efficient and secure manner, that achieves the borrower identity privacy and accountability at the same time. Specifically, borrower identity is concealed on the blockchain by anonymous identity credential, while financial institutions can still uncover the identity of a misbehaving borrower if he pledges the same asset for multiple mortgages. We demonstrate that BAPIM achieves the desirable security properties and has high computational efficiency, so as to be suitable for the industrial mortgage management. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | Enabling Strong Privacy Preservation and Accurate Task Allocation for Mobile CrowdsensingabstractMobile crowdsensing engages a crowd of individuals to use their mobile devices to cooperatively collect data about social events and phenomena for customers with common interest. It can reduce the cost on sensor deployment and improve data quality with human intelligence. To enhance data trustworthiness, it is critical for the service provider to recruit mobile users based on their personal features, e.g., mobility pattern and reputation, but it leads to the privacy leakage of mobile users. Therefore, how to resolve the contradiction between user privacy and task allocation is challenging in mobile crowdsensing. In this paper, we propose SPOON, a strong privacy-preserving mobile crowdsensing scheme supporting accurate task allocation based on geographic information and credit points of mobile users. In SPOON, the service provider enables to recruit mobile users based on their locations, and select proper sensing reports according to their trust levels without invading user privacy. By utilizing proxy re-encryption and BBS+ signature, sensing tasks are protected and reports are anonymized to prevent privacy leakage. In addition, a privacy-preserving credit management mechanism is introduced to achieve decentralized trust management and secure credit proof for mobile users. Finally, we show the security properties of SPOON and demonstrate its efficiency in terms of computation and communication. Jianbing Ni, Kuan Zhang 0001, Qi Xia 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Mob. Comput. | 1 |
| 2019 | Exploring Anonymous User Reviews: Linkability Analysis Based on Machine LearningabstractIdentity anonymization is believed to be a common mechanism to protect users' privacy in a public review platform, as each user's unique identifier is removed to ensure pseudonymity and unlinkability. However, the usefulness of the mechanism is not explicit, i.e., whether it is possible for an adversary to link anonymous reviews from the same user has not been well studied. In this paper, we attempt to explore this issue by means of machine learning techniques. Specifically, we first extract major features from anonymous reviews and propose some adaptive metrics to measure their effectiveness. Then, we exploit these features and several machine learning methods to link the anonymous reviews created by the same user in a real- world dataset. Considering that different adversaries has different background knowledge, both supervised and unsupervised methods, such as random forest and hierarchical agglomerative clustering, are designed and utilized to perform linkability attacks. The simulation results demonstrate that the supervised methods have a good performance, i.e., almost 40% anonymous reviews can be accurately linked to users if an adversary has the background knowledge. The unsupervised methods, compared with supervised methods, has a bad performance, i.e., it is difficult for an adversary without the background knowledge to link anonymous reviews with a high probability. Cheng Huang 0001, Jianbing Ni, Rongxing Lu, Xuemin Shen |
GLOBECOM | 2 |
| 2019 | Online Advertising with Verifiable FairnessabstractOnline advertising is a popular business model where advertisers can deliver promotional marketing messages to their potential consumers via Ad brokers. However, as the proxy between advertisers and customers, a malicious Ad broker could arbitrarily fabricate the advertising rates to overcharge advertisers, which causes unnecessary financial loss. To deal with this issue, we propose a publicly verifiable and fair online advertising scheme. Specifically, a proof-of-downloading (PoD) protocol is first designed based on the zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK), to help the customer generate a unique acknowledgment for downloading the Ad; the acknowledgment will then be published to both the advertiser and the Ad broker such that anyone can verify the acknowledgment to guarantee the fairness and transparency of online advertising. Moreover, as long as the customer's private key is not leaked, our scheme can resist the collusion attack, i.e., the Ad broker and the customer collude with each other to deceive the advertiser, which has not been addressed in previous works. Finally, we evaluate the performance of the proposed scheme to demonstrate its computational efficiency. Cheng Huang 0001, Jianbing Ni, Rongxing Lu, Xuemin Shen |
ICC | 2 |
| 2019 | Efficient and Privacy-Preserving Outsourced SVM Classification in Public CloudabstractData classification has become an important and prevailing technique for big data analytics. Typically, a data classifier is designed and outsourced to a public cloud. A service provider then can easily provide various services and handle frequent and massive classification requests from users. With privacy concerns as well as Intellectual Property(IP) protection issues, the valuable classifier and the sensitive user data cannot be directly exposed to the public cloud. In this paper, we focus on the Support Vector Machine (SVM), one of the most popular classifiers, and propose an efficient and privacy-preserving outsourcing scheme for SVM classification in public clouds. Specifically, the service provider is allowed to transform the traditional SVM classifier to fixed hyper-rectangles and the order-preserving encryption is utilized to encrypt these hyper-rectangles as the encrypted classifier. Afterwards, the encrypted classifier is outsourced to the public cloud, and a user can submit an encrypted range query to the cloud and obtain the classification results back. Security analysis and extensive experimental evaluation demonstrate that our scheme can protect the confidentiality of classifier and users' data and achieves efficient SVM classification in terms of computational cost. Jinwen Liang, Zheng Qin 0001, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
ICC | 3 |
| 2019 | Towards Private and Efficient Ad Impression Aggregation in Mobile AdvertisingabstractIn the secure mobile advertising, mobile users privately select advertisements of interest for displaying without exposing their preferences to the ad network. However, the strong privacy guarantee has uncovered limitations on gathering aggregated ad impression statistics for the ad network to enforce correct billing on the merchants who run their ad campaigns. Early efforts integrated cryptographic voting mechanism to address this challenge, which introduces additional bandwidth overhead on mobile devices due to the construction of the ballot proof. In this paper, we propose a private and efficient ad impression aggregation scheme in mobile advertising to protect the individual ad impression statistics while preventing the ad-fraud attack. The main idea of the proposed scheme is the design of an efficient cryptographic voting mechanism based on the compact hamming weight proof technique and additive homomorphic encryption. The proposed scheme has better bandwidth efficiency by reducing the ballot proof size from O(logN) to O(1), where N denotes the dimension of the ballot. Security analysis demonstrates the confidentiality of the individual impression statistics and the verifiability of the ballot proof under standard cryptographic assumptions. Experimental results consolidate that the proposed scheme is feasible for real-world implementations on mobile devices. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
ICC | 2 |
| 2019 | Against Pilot Spoofing Attack with Double Channel Training in Massive MIMO NOMA SystemsabstractTo combat the pilot spoofing attack in non-orthogonal multiple access (NOMA) systems, we propose a double channel training scheme in this paper. Specifically, we consider two users in each cluster and both users send the training sequence in the first uplink training phase, while one of them keeps silent in the second phase. By exploiting channel estimation results in the two phases, more accurate legitimate channel estimation can be obtained by removing the contamination from the eavesdropping channel. Thus, the pilot spoofing attack can be mitigated effectively. We then analyze the achievable downlink secrecy rate with matched filter precoding scheme. Simulation results demonstrate that the achievable secrecy rate can be improved dramatically with the proposed scheme even under very strong pilot attack power. Wei Wang 0100, Zhisheng Yin, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
ICC | 3 |
| 2019 | Forward Secure and Fine-grained Data Sharing for Mobile CrowdsensingabstractSecure task-driven data sharing can improve the sensing data usage and protect data confidentiality in mobile crowdsensing (MCS). However, the existing data sharing schemes lack efficient support of forward secrecy, i.e., if the secret key of a data requester is compromised, all the historically shared data will be leaked. In this paper, we propose a forward secure and fine-grained data sharing scheme in mobile crowdsensing to provide a strong security guarantee and flexible access control over the sensing data. Specifically, by incorporating puncturable encryption and attribute based encryption, a shared symmetric key for data sharing can be encrypted by an access structure over the attributes of data requesters and the introduced Bloom filter attributes. Moreover, the shared key establishment between the MCS server and data requesters can be done jointly with the both sides authentication. By utilizing the structure of the Bloom filter, the update of a private key which is used to achieve forward secrecy only needs several deletion operations and no communication with the key distributor is involved. The security proof shows our scheme is provably secure under the security model. Experiment results demonstrate the practicability of the scheme. Jianbing Ni, Cheng Huang 0001, Xiaodong Lin 0001, Xuemin Shen |
PST | 2 |
| 2019 | Fine-grained data access control with attribute-hiding policy for cloud-based IoT
Jialu Hao, Cheng Huang 0001, Jianbing Ni, Hong Rong, Ming Xian, Xuemin Shen |
Comput. Networks | 3 |
| 2019 | Fuzzy Identity-Based Data Integrity Auditing for Reliable Cloud Storage SystemsabstractData integrity, a core security issue in reliable cloud storage, has received much attention. Data auditing protocols enable a verifier to efficiently check the integrity of the outsourced data without downloading the data. A key research challenge associated with existing designs of data auditing protocols is the complexity in key management. In this paper, we seek to address the complex key management challenge in cloud data integrity checking by introducing fuzzy identity-based auditing, the first in such an approach, to the best of our knowledge. More specifically, we present the primitive of fuzzy identity-based data auditing, where a user's identity can be viewed as a set of descriptive attributes. We formalize the system model and the security model for this new primitive. We then present a concrete construction of fuzzy identity-based auditing protocol by utilizing biometrics as the fuzzy identity. The new protocol offers the property of error-tolerance, namely, it binds with private key to one identity which can be used to verify the correctness of a response generated with another identity, if and only if both identities are sufficiently close. We prove the security of our protocol based on the computational Diffie-Hellman assumption and the discrete logarithm assumption in the selective-ID security model. Finally, we develop a prototype implementation of the protocol which demonstrates the practicality of the proposal. Yannan Li 0001, Yong Yu 0002, Geyong Min, Willy Susilo, Jianbing Ni, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2019 | Anonymous Reputation System for IIoT-Enabled Retail Marketing Atop PoS BlockchainabstractIndustrial Internet of Things (IIoT) is revolutionizing the retail industry for manufacturers, suppliers, and retailers to improve operational efficiency and consumer experience. In IIoT-enabled retail marketing, reputation systems play a critical role to boost mutual trust among industrial entities and build consumer confidence. In this paper, we focus on reputation management in the consumer–retailer channel, where retailers can accumulate reputations from consumer feedbacks. To encourage consumers to post feedbacks without worrying about being tracked or retaliated, we propose an anonymous reputation system that preserves consumer identities and individual review confidentialities. To increase system transparency and reliability, we further exploit the tamper-proof nature and the distributed consensus mechanism of the blockchain technology. With system designs based on various cryptographic primitives and a Proof-of-Stake consensus protocol, our blockchain-based reputation system is more efficient to offer high levels of privacy guarantees compared with existing ones. Finally, we explore the implementation challenges of the blockchain-based architecture and present a proof-of-concept prototype system by Parity Ethereum. We measure the on/off -chain performance with the scalability discussion to demonstrate the feasibility of the proposed system. Amal Alahmadi, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Ind. Informatics | 3 |
| 2018 | Achieving Adaptive Linkability for Cellular V2X Group Communications in 5GabstractCellular vehicle-to-everything (C-V2X) in 5G enables device-to-device (D2D) group communications to support a variety of proximity-based services. While D2D group communication can improve mobile network spectrum efficiency and user experience by offloading local traffic and extending the coverage of cellular base stations, it has also raised new privacy challenges on balancing UE anonymity and message linkability. In this paper, we first identify the limitations of current standardization and literature on addressing this issue. Then, we design a Service-oriented Authentication Framework (SAF) that supports secure service delegation and anonymous message authentication. Specifically, a UE-controlled linking method is introduced to support adaptive linkability for different V2X use cases. Security analysis demonstrates the SAF is secure under cryptographic assumptions. Moreover, we conduct extensive simulations based on Vissim and NS3 to show that the SAF is more efficient compared with the state-or-art literature and is feasible for 3GPP standardized V2X group communications. Jianbing Ni, Hongwei Li 0001, Xuemin Shen |
GLOBECOM | 2 |
| 2018 | Reliable and Privacy-Preserving Selective Data Aggregation for Fog-Based IoTabstractInternet of Things (IoT) is reshaping our daily lives by bridging the gaps between physical and digital world. To enable ubiquitous sensing, seamless connection and real-time processing for IoT applications, fog computing is considered as a key component in a heterogeneous IoT architecture, which deploys storage and computing resources to network edges. However, the fog-based IoT architecture can lead to various security and privacy risks, such as compromised fog nodes that may impede developments of IoT by attacking the data collection and gathering period. In this paper, we propose a novel privacy-preserving and reliable scheme for the fog-based IoT to address the data privacy and reliability challenges of the selective data aggregation service. Specifically, homomorphic proxy re-encryption and proxy re-authenticator techniques are respectively utilized to deal with the data privacy and reliability issues of the service, which supports data aggregation over selective data types for any type-driven applications. We define a new threat model to formalize the non-collusive and collusive attacks of compromised fog nodes, and it is demonstrated that the proposed scheme can prevent both non-collusive and collusive attacks in our model. In addition, performance evaluations show the efficiency of the scheme in terms of computational costs and communication overheads. Cheng Huang 0001, Jianbing Ni, Rongxing Lu, Xuemin Shen |
ICC | 3 |
| 2018 | Efficient and Privacy-Preserving Ad Conversion for V2X-Assisted Proximity MarketingabstractVehicle-to-Everything (V2X) assisted proximity marketing is one of the most promising V2X services due to its huge potential, and has attracted a lot of research efforts recently. In proximity marketing, roadside merchants rely on third-party ad networks to target their advertisements to nearby vehicles or pedestrians with related interests, and pay ad networks according to some pricing mechanisms, such as cost per-view. It is therefore important for merchants to learn ad conversion rate (how much of their revenue can be attributed to proximity marketing) such that merchants can adjust their advertising strategy. For ad conversion, two-party private set intersection (PSI) technique has been widely adopted, where ad networks and merchants can jointly compute ad conversion rate without leaking sensitive customer information. However, state-of-art literature on PSI either assumes the involved two parties honestly follow the protocol or only tolerates limited adversarial behaviors. In this paper, we first design a novel and efficient PSI scheme that is secure in the presence of malicious adversaries, where two parties can arbitrarily deviate from the scheme. By integrating an efficient input certification mechanism into the designed PSI scheme, we propose a privacy-preserving ad conversion protocol for V2X-assisted proximity marketing, that can achieve input privacy, unlinkability, unforgeability, and output verifiability. Security analysis demonstrates that the proposed ad conversion protocol is secure under cryptographic assumptions. Finally, we show that the proposed ad conversion protocol outperforms the state-of-art approaches when considering both security strength and computation complexity. Jianbing Ni, Hongwei Li 0001, Xiaodong Lin 0001, Xuemin Shen |
MASS | 2 |
| 2018 | Privacy-preserving ride clustering for customized-bus sharing: A fog-assisted approachabstractCustomized-bus Sharing Service (CSS) enables a centralized server to schedule comfortable bus trips for users by ride clustering based on the individual requirements. It has been increasingly popular in crowded metropolises, bringing a lot of convenience and reducing trip costs to users. Ride clustering is essential for the server to determine the stops of a customized bus, but it also leads to the exposure of users' current locations and spatio-temporal patterns. Although privacy-preserving ride clustering can generate optimal bus routes, it depends on frequent interactions between users and the server, so all the users should be always online. In this paper, we propose a privacy-preserving ride clustering scheme for CSS to support off-line users, in which fog computing is introduced to assist the server in generating bus route without the exposure of users' travel plans. Fog servers are able to perform ride clustering interacting with the server, after receiving the preferred pick-up and drop-off positions from users. Thus, the users are unnecessary to be always online. In addition, the Paillier cryptosystem and randomization technique are leveraged to protect the user's privacy without sacrificing the clustering quality. Finally, the proposed privacy-preserving ride clustering scheme is demonstrated to have the advantage of low computational and communication overhead with high security guarantees. Yuanyuan He 0002, Jianbing Ni, Ben Niu 0001, Fenghua Li 0001, Xuemin Shen |
WiOpt | 2 |
| 2018 | Efficient and Secure Service-Oriented Authentication Supporting Network Slicing for 5G-Enabled IoTabstract5G network is considered as a key enabler in meeting continuously increasing demands for the future Internet of Things (IoT) services, including high data rate, numerous devices connection, and low service latency. To satisfy these demands, network slicing and fog computing have been envisioned as the promising solutions in service-oriented 5G architecture. However, security paradigms enabling authentication and confidentiality of 5G communications for IoT services remain elusive, but indispensable. In this paper, we propose an efficient and secure service-oriented authentication framework supporting network slicing and fog computing for 5G-enabled IoT services. Specifically, users can efficiently establish connections with 5G core network and anonymously access IoT services under their delegation through proper network slices of 5G infrastructure selected by fog nodes based on the slice/service types of accessing services. The privacy-preserving slice selection mechanism is introduced to preserve both configured slice types and accessing service types of users. In addition, session keys are negotiated among users, local fogs and IoT servers to guarantee secure access of service data in fog cache and remote servers with low latency. We evaluate the performance of the proposed framework through simulations to demonstrate its efficiency and feasibility under 5G infrastructure. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE J. Sel. Areas Commun. | 1 |
| 2018 | Exploiting Social Network to Enhance Human-to-Human Infection Analysis without Privacy LeakageabstractHuman-to-human infection, as a type of fatal public health threats, can rapidly spread, resulting in a large amount of labor and health cost for treatment, control and prevention. To slow down the spread of infection, social network is envisioned to provide detailed contact statistics to isolate susceptive people who has frequent contacts with infected patients. In this paper, we propose a novel human-to-human infection analysis approach by exploiting social network data and health data that are collected by social network and e-healthcare technologies. We enable the social cloud server and health cloud server to exchange social contact information of infected patients and user's health condition in a privacy-preserving way. Specifically, we propose a privacy-preserving data query method based on conditional oblivious transfer to guarantee that only the authorized entities can query users’ social data and the social cloud server cannot infer anything during the query. In addition, we propose a privacy-preserving classification-based infection analysis method that can be performed by untrusted cloud servers without accessing the users’ health data. The performance evaluation shows that the proposed approach achieves higher infection analysis accuracy with the acceptable computational overhead. Kuan Zhang 0001, Xiaohui Liang 0002, Jianbing Ni, Kan Yang 0001, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | Privacy-Preserving Data Forwarding in VANETs: A Personal-Social Behavior Based ApproachabstractVehicular communications enable a variety of applications to improve road safety, driving experience, and traffic management. Many of these applications require data to be routed through multiple hops until they reach to the destination. Unfortunately, due to highly dynamic driving patterns of vehicles, it is challenging to achieve effective and time-sensitive data forwarding in vehicular ad hoc networks (VANETs). Both social- based and trajectory-assisted data forwarding strategies have been proposed to improve packet delivery performance in VANETs. The former reaches limited data delivery ratio and the latter leaks location privacy of drivers. In this paper, we propose a privacy-preserving data forwarding protocol based on personal-social behaviors of drivers to achieve highly reliable transmissions and privacy preservation for drivers in VANETs. Specifically, by observing the phenomenon that vehicles regularly visit some social spots, such as shopping malls, museums and busy intersections, we can obtain the personal-social behaviors of drivers. Based on these behaviors, the messages can be delivered to roadside units (RSUs) at the social spots frequently visited by vehicles. Later, once a vehicle visits the social spots, it can successfully retrieve the messages destined for it from the RSUs anonymously. In addition, the identities of senders are conditionally preserved and the personal-social behaviors of drivers are protected against a global adversary. Performance evaluation demonstrates its efficiency in terms of high delivery ratio and low average delay. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
GLOBECOM | 1 |
| 2017 | Dual-anonymous reward distribution for mobile crowdsensingabstractMobile crowdsensing enables individuals to collect data from social events and phenomena for performing tasks released by customers using their mobile devices. It removes the necessity of sensors deployment and hence supports large-scale sensing applications efficiently. Nevertheless, incentive and privacy remain as the major obstacles that need additional attention. If privacy is not presered or no benefit obtains, no mobile user prefers to participate in crowdsensing activities. In this paper, we propose DARD, a dual-anonymous reward distribution scheme to achieve the incentive for mobile users and privacy protection for both customers and mobile users in mobile crowdsensing. Specifically, we design a reward sharing incentive mechanism to encourage mobile users to participate in tasks and employ randomizable techniques to protect the identities of customers and mobile users during reward claim, distribution and deposit. Our analysis further shows that DARD achieves reward balance and cheater detection with low computational and communication overhead. Jianbing Ni, Xiaodong Lin 0001, Qi Xia 0001, Xuemin Shen |
ICC | 1 |
| 2017 | Privacy-preserving mobile crowdsensing for located-based applicationsabstractMobile crowdsensing is a new paradigm which explores the mobility and intelligence of mobile users to collect high-quality data from social events and phenomena for conducting complex sensing tasks. Nevertheless, privacy preservation and task allocation become main obstacles that need additional attention. To achieve accurate task allocation, it is inevitable to share some sensitive information of mobile users and customers, such as identities, location and points of interest. In this paper, we propose a privacy-preserving mobile crowdsensing framework (PPMC) for location-based applications to balance the tradeoff between privacy preservation and task allocation. In PPMC, we develop a matrix-based location matching mechanism for the service provider to achieve location-based task allocation without disclosing the location of mobile users and the sensing area of tasks. We also extend BBS+ signature and proxy reencryption to preserve identity privacy and data privacy for both customers and mobile users under the condition that they are honest to release and perform tasks, respectively. Finally, we discuss security properties and demonstrate the efficiency of PPMC in terms of computational and communication overhead. Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Qi Xia 0001, Xuemin Shen |
ICC | 1 |
| 2016 | Secure and Deduplicated Spatial Crowdsourcing: A Fog-Based ApproachabstractWith the proliferation of mobile devices, spatial crowdsourcing is rising as a new paradigm that enables individuals to participate in tasks related to some locations in the physical world. Nevertheless, how to allocate these tasks to proper mobile users and improve communication efficiency are critical in spatial crowdsourcing. In this paper, we propose Fo-DSC, a fog-based deduplicated spatial crowdsourcing framework to achieve precise task allocation and secure data deduplication. Specifically, by integrating fog computing, we design a two-step task allocation mechanism to improve the accuracy of tasks allocation in spatial crowdsourcing. The fog nodes can detect and erase the repeated data in crowdsensing reports without learning any information about the reports. Furthermore, Fo-DSC efficiently records the contributions of mobile users whose data are reduplicated and deleted. As a result, these users do not become discouraged. Finally, we demonstrate that Fo-DSC satisfies the properties of fog-based task allocation and secure data deduplication with low computational and communication overheads. Jianbing Ni, Xiaodong Lin 0001, Kuan Zhang 0001, Yong Yu 0002 |
GLOBECOM | 1 |
| 2016 | EDAT: Efficient data aggregation without TTP for privacy-assured smart meteringabstractSmart meters are integral to power dispatch in the emerging smart grid, by periodically collecting and reporting the electricity consumption of users to the control center to satisfy practical requirements. However, the real-time electricity measurements of individual households may contain plenty of users' privacy, e.g., activities and habits. To resist the privacy exposure from the individual measurements, we propose an Efficient Data AggregaTion (EDAT) scheme, in which every smart meter in the residential area uses a random noise to protect the concrete reading from being exposed to the attackers and the local gateway aggregates the individual measurements into a compact report before forwarding to the control center. In EDAT scheme, we remove the trusted third party and allow the smart meters to negotiate and generate the sum of the noise using polynomials, by which the control center can recover the power consumption of a residential area, other than a specific household. The security of the EDAT scheme can be reduced to the Decisional Diffie-Hellman assumption, and both the computational and communication overhead of each smart meter are small. Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Xuemin Shen |
ICC | 1 |
| 2016 | AMA: Anonymous mutual authentication with traceability in carpooling systemsabstractCarpooling, as an effective and eco-friendly travel mode, becomes a kind of public spontaneous behavior with multiple travellers sharing a vehicle to reduce individuals' travel cost, carbon emissions and traffic congestion. Although ubiquitous network access offers great convenience for travellers to find carpools, the safety becomes a big obstacle for them to accept this emerging travel mode. To address the safety concern, it seems inevitable to sacrifice the identity privacy for both drivers and passengers. In this paper, we propose an Anonymous Mutual Authentication (AMA) protocol to solve the contradiction between safety and privacy preservation by utilizing the BBS+ signature. In AMA, the passenger and the driver can mutually authenticate the identities without exposing their actual identities, but showing their membership of a trustable group. The AMA also allows to trace the identity of the driver (the passenger) on behalf of a judger if the passenger (the driver) complains the misbehavior of the driver (the passenger). The AMA is secure and efficient for real applications. Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Haomiao Yang, Xuemin Shen |
ICC | 1 |
| 2016 | Cloud-Based Privacy-Preserving Parking Navigation Through Vehicular Communications
Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Yong Yu 0002, Xuemin Shen |
SecureComm | 1 |
| 2016 | Privacy-Preserving Real-Time Navigation System Using Vehicular CrowdsourcingabstractTraffic congestions cause not only the time- consuming and frustrating experiences to drivers, but also other critical problems, such as fuel waste, air pollution and accidents. Real-time traffic information exchange can avoid vehicles being congested on roads. However, when the drivers are acquiring the traffic information, their privacy is inevitable to be disclosed. To preserve the driver's privacy, in this paper, we propose a privacy-preserving real-time navigation system (PRIN) using vehicular crowdsourcing. In PRIN, the RSUs cooperatively find an optimal path for the querying vehicle to the destination according to the real-time traffic information crowdsourced by the vehicles in their coverage areas. The querying vehicle retrieves the navigation result from each RSU successively when entering its coverage area, and follows the proper driving route to the next RSU, until reaching its destination. During these querying, crowdsourcing and retrieving processes, the driver's personal information, such as location, identity, is protected from being disclosed to attackers. In addition, a trusted authority can trace the drivers' identities if they upload false traffic information. Finally, we discuss the properties of conditional privacy preservation and demonstrate the efficiency of PRIN. Jianbing Ni, Xiaodong Lin 0001, Kuan Zhang 0001, Xuemin Shen |
VTC Fall | 1 |
| 2016 | SDIVIP2: shared data integrity verification with identity privacy preserving in mobile cloudsabstractSummary Mobile networks integrate cloud computing to impair the weaknesses of the mobile terminals. With mobile cloud storage, mobile users can fully enjoy the advantages from both mobile networks and cloud storage. However, a major concern of mobile users is how to guarantee the integrity of their outsourced data. Taking into account the mobility of mobile devices, in this paper, we propose a shared data integrity verification protocol with identity privacy preserving, named SDIVIP2, for mobile cloud storage. In the construction of SDIVIP2, the dynamic group key agreement technique is employed for key sharing among a group of mobile users and the proxy re‐signature mechanism is utilized to update tags efficiently when users in the group change. In this new protocol, a third party auditor is able to verify the correctness of cloud data without the knowledge of mobile users' identities during the data integrity checking process. Performance analysis demonstrates that SDIVIP2outperforms the existing schemes in the sense that it can significantly enhance the efficiency of mobile users' joining and leaving a group. Copyright © 2015 John Wiley & Sons, Ltd. Yong Yu 0002, Jianbing Ni, Qi Xia 0001, Haomiao Yang, Xiaosong Zhang 0001 |
Concurr. Comput. Pract. Exp. | 2 |
| 2016 | Provable multiple replication data possession with full dynamics for secure cloud storageabstractSummary Cloud storage has been gaining tremendous popularity among individuals and corporations because of its low maintenance cost and on‐demand services for the clients. To improve the availability and the reliability of critical data, storing multiple replicas on multiple servers is a commonly used strategy. Currently, several provable data possession (PDP) protocols for multiple replicas of dynamic data have been proposed to ensure the integrity of outsourced multi‐copy data, but the efficiency of these protocols on verifying multiple replicas one by one is not satisfactory. In this paper, we propose a provable multiple replication data possession protocol with full dynamics, named MR‐DPDP. In MR‐DPDP, we utilize a novel authenticated data structure called Merkle hash tree with rank to support both full dynamic data updates and efficient integrity verification. In addition, our construction with RSA signature can support both variable‐sized file blocks and public verification. Through security proof and performance evaluation, we demonstrate that MR‐DPDP not only is sound but also incurs less communication overhead when updating data blocks as well as verifying a proof of the integrity of multiple replicas. Copyright © 2015 John Wiley & Sons, Ltd. Yafang Zhang, Jianbing Ni, Xiaoling Tao, Yong Wang 0031, Yong Yu 0002 |
Concurr. Comput. Pract. Exp. | 2 |
| 2016 | Cloud data integrity checking with an identity-based auditing mechanism from RSA
Yong Yu 0002, Man Ho Au, Willy Susilo, Jianbing Ni, Yafang Zhang, Athanasios V. Vasilakos, Jian Shen 0001 |
Future Gener. Comput. Syst. | 5 |
| 2016 | Comments on "Public Integrity Auditing for Dynamic Data Sharing With Multiuser Modification"abstractRecently, a practical public integrity auditing scheme supporting multiuser data modification (IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, DOI 10.1109/TIFS.2015.2423264) was proposed. Although the protocol was claimed secure, in this paper, we show that the proposal fails to achievesoundness, the most essential property that an auditing scheme should provide. Specifically, we show that a cloud server can collude with a revoked user to deceive a third-party auditor (TPA) that a stored file keeps virgin even when the entire file has been deleted. Yong Yu 0002, Yannan Li 0001, Jianbing Ni, Guomin Yang, Yi Mu 0001, Willy Susilo |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2015 | Security-Enhanced Data Aggregation against Malicious Gateways in Smart GridabstractIn smart grid, to monitor, predict and control the power consumption in real time, energy usage data have to be periodically collected through publicly accessible communication channels, and are stored in a centralized operation center. However, electricity consumption data may disclose the privacy information of users. Therefore, protecting privacy of users and validity of power usage reports becomes a crucial security issue. In this paper, we propose a security-enhanced data aggregation scheme for smart grid communications based on homomorphic cryptosystem, trapdoor hash functions and homomorphic authenticators. Our scheme can achieve data confidentiality and integrity against the malicious aggregator (e.g. gateway), meaning that the aggregator is not able to access users' private information or corrupt the power consumption reports during the aggregation process. Through extensive analysis, we demonstrate that our scheme can resist potential threats and be proved secure under cryptographic hard assumptions. It has less computational and communication overheads than existing approaches. Jianbing Ni, Khalid Nawaf Alharbi, Xiaodong Lin 0001, Xuemin Shen |
GLOBECOM | 1 |
| 2015 | Remote data possession checking with enhanced security for cloud storage
Yong Yu 0002, Yafang Zhang, Jianbing Ni, Man Ho Au, Lanxiang Chen |
Future Gener. Comput. Syst. | 3 |
| 2015 | Comments on a Public Auditing Mechanism for Shared Cloud Data ServiceabstractRecently, a public auditing protocol for shared data called Panda (IEEE Transactions on Services Computing, doi: 10.1109/TSC.2013.2295611) was proposed to ensure the correctness of the outsourced data. A distinctive feature of Panda is the support of data sharing and user revocation. Unfortunately, in this letter, we show that Panda is insecure in the sense that a cloud server can hide data loss without being detected. Specifically, we show that even some stored file blocks have been lost, the server is able to generate a valid proof by replacing a pair of lost data block and its signature with another block and signature pair. We also provide a solution to the problem while preserving all the desirable features of the original protocol. Yong Yu 0002, Jianbing Ni, Man Ho Au, Yi Mu 0001, Boyang Wang 0001, Hui Li 0006 |
IEEE Trans. Serv. Comput. | 2 |
| 2014 | Improvement of a Remote Data Possession Checking Protocol from Algebraic Signatures
Yong Yu 0002, Jianbing Ni, Jian Ren 0001, Wei Wu 0001, Lanxiang Chen, Qi Xia 0001 |
ISPEC | 2 |
| 2014 | Identity Privacy-Preserving Public Auditing with Dynamic Group for Secure Mobile Cloud Storage
Yong Yu 0002, Yi Mu 0001, Jianbing Ni, Jiang Deng, Ke Huang 0002 |
NSS | 3 |
| 2014 | Improved security of a dynamic remote data possession checking protocol for cloud storage
Yong Yu 0002, Jianbing Ni, Man Ho Au, Chunxiang Xu |
Expert Syst. Appl. | 2 |
| 2014 | Efficient public key encryption with revocable keyword searchabstractABSTRACT Public key encryption with keyword search is a novel cryptographic primitive enabling one to search on the encrypted data directly. In the known schemes, once getting a trapdoor, the server can search associated data without any restrictions. However, in reality, it is sometimes essential to prevent the server from searching the data all the time because the server is not fully trusted. In this paper, we propose the notion of public key encryption with revocable keyword search to address the issue. We also develop a concrete construction by dividing the whole life of the system into distinct times to achieve our goals. The proposed scheme achieves the properties of the indistinguishability of ciphertexts against an adaptive chosen keywords attack security under the co‐decisional bilinear Diffie–Hellman assumption in our security model. Compared with two somewhat schemes, ours offers much better performance in terms of computational cost. Copyright © 2013 John Wiley & Sons, Ltd. Yong Yu 0002, Jianbing Ni, Haomiao Yang, Yi Mu 0001, Willy Susilo |
Secur. Commun. Networks | 2 |
| 2014 | On the Security of an Efficient Dynamic Auditing Protocol in Cloud StorageabstractUsing cloud storage, data owners can remotely store their data and enjoy the on-demand high quality cloud services without the burden of local data storage and maintenance. However, this new paradigm does trigger many security concerns. A major concern is how to ensure the integrity of the outsourced data. To address this issue, recently, a highly efficient dynamic auditing protocol (IEEE Transactions on Parallel and Distributed Systems, doi:10.1109/TPDS.2013.199) for cloud storage was proposed which enjoys many desirable features. Unfortunately, in this letter, we demonstrate that the protocol is insecure when an active adversary is involved in the cloud environment. We show that the adversary is able to arbitrarily modify the cloud data without being detected by the auditor in the auditing process. We also suggest a solution to fix the problem while preserving all the properties of the original protocol. Jianbing Ni, Yong Yu 0002, Yi Mu 0001, Qi Xia 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |