Yafang Yang

dblp:132/7888 · DBLP profile ↗
← Back
14ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0002-1432-3885ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 6 since 2021Computer networks · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 An Insider Attack Resistant Threshold Anonymous Traffic Violation Reporting Scheme for Fog-Assisted VANETs
abstract
Traffic violation reporting schemes for fog-assisted vehicular ad hoc networks are generally designed to support traffic management centers (TMCs) in detecting traffic violations so that appropriate actions can be taken against the involved vehicle owners. However, there are ongoing challenges such as ensuring accuracy or accountability with minimal privacy dis closure (e.g., accurate and reliable detection of traffic violations without disclosing the contents of the incident, achieving identity authentication while protecting the privacy of reporters), and how to guarantee the reports are correctly processed complicate the design of such schemes. To address these challenges, we propose a threshold anonymous traffic violation reporting (TATVR) scheme under the assumptions that the fog nodes (i.e., roadside units) and the TMC are semi-trusted, and the number of colluding vehicles is limited. We then extend the TATVR scheme (i.e., extended TATVR or E-TATVR) that does not rely on these assumptions. We explain how TMC can process the received reports more efficiently using the proposed E-TATVR scheme. We also evaluate the security of both proposed schemes and demonstrate that they simultaneously support (strong) confidentiality, non-frameability, conditional unlinkability, unforgeability, and conditional anonymity. In particular, we show that both schemes guarantee strong confidentiality, and the E-TATVR scheme additionally supports report traceability.
Yafang Yang, Lei Zhang 0009, Yunlei Zhao, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.1
2025 Certificateless Signature Scheme With Batch Verification for Secure and Privacy-Preserving V2V Communications in VANETs
abstract
The importance of designing efficient and secure vehicular ad hoc networks (VANETs), for example to address pressing traffic-related challenges in busy cities, is crucial but challenging. For example, existing approaches may suffer from vehicle-to-vehicle (V2V) communication-related limitations such as certificate management, key escrow, and performance. Seeking to contribute to the knowledge gap, we propose a new secure and privacy-preserving scheme for V2V communications. Our proposal is based on a new provably secure certificateless signature scheme with batch verification, which eliminates the need for certificates while ensuring better efficiency. Our performance and security evaluations demonstrate that the proposed approach overcomes our previously discussed limitations while achieving both message authentication and conditional privacy. In addition, we also shown that it incurs low overhead.
Lei Zhang 0009, Yafang Yang, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.3
2024 Faster Post-quantum TLS 1.3 Based on ML-KEM: Implementation and Assessment
Jieyu Zheng, Haoliang Zhu, Yafang Yang, Yunlei Zhao
ESORICS (2)6
2024 MELPD-Detector: Multi-level ensemble learning method based on adaptive data augmentation for Parkinson disease detection via free-KD
Yafang Yang, Bin Guo 0001, Kaixing Zhao, Yunji Liang, Zhiwen Yu 0001
CCF Trans. Pervasive Comput. Interact.1
2024 Cross-device free-text keystroke dynamics authentication using federated learning
Yafang Yang, Bin Guo 0001, Yunji Liang, Kaixing Zhao, Zhiwen Yu 0001
Pers. Ubiquitous Comput.1
2024 Message Linkable Group Signature With Information Binding and Efficient Revocation for Privacy- Preserving Announcement in VANETs
abstract
In vehicular ad hoc networks (VANETs), the broadcasting of fake announcement messages by malicious vehicles can potentially misguide nearby vehicles. Ensuring the trustworthiness of announcement messages while preserving the privacy of vehicles is a significant challenge in the design of an announcement scheme for VANETs. To address this challenge, we propose a privacy-preserving announcement scheme with strong trustworthiness based on a new security tool called message linkable group signature with information binding and efficient revocation. Compared with the existing privacy-preserving announcement schemes, our proposed scheme not only achieves the traditional trustworthiness requirement of an announcement message but also provides strong trustworthiness, which makes it resistant to sybil and collusive attacks. To the best of our knowledge, our scheme realizes strong trustworthiness for the first time. Simulations were also performed to show the practicability of the scheme.
Lei Zhang 0009, Jiangtao Li 0003, Yafang Yang
IEEE Trans. Dependable Secur. Comput.3
2024 Rebuttal to "On the Unforgeability of 'Privacy-Preserving Aggregation-Authentication Scheme for Safety Warning System in Fog-Cloud Based VANET"'
abstract
Lin recently claimed that the privacy-preserving aggregation authentication scheme (PPAAS) based on a certificateless aggregation signcryption scheme (CASS) proposed in our paper (IEEE Transactions on Information Forensics and Security, vol.17, pp.317-331, Jan.2022) suffers from a forgery attack from type II adversary. In this paper, we show that this attack is not valid since the adversary outputs a trivial forged ciphertext. Specifically, the adversary has the master secret key and randomly selects the secret values of all users.
Yafang Yang, Lei Zhang 0009, Yunlei Zhao, Kim-Kwang Raymond Choo, Yan Zhang 0103
IEEE Trans. Inf. Forensics Secur.1
2023 Efficient and Strong Symmetric Password Authenticated Key Exchange With Identity Privacy for IoT
abstract
Password authenticated key exchange (PAKE) allows two parties with a shared password to establish a session key. In order to provide secure and private communication between devices in an Internet of Things (IoT) environment, the PAKE protocol is considered one of the most common and promising security methods. However, many existing PAKE proposals still face challenges in security and efficiency. First, both the terminals of participants may suffer from the compromise attack and precomputation attack, which will lead to the leakage of password. Second, the majority of the existing schemes cannot guarantee participants’ identity privacy. Third, most PAKE protocols are not suitable for IoT devices with limited computing capability because of a large number of exponential and pairing operations. To address these issues, we propose a strong symmetric PAKE protocol for IoT devices, which only requires 3 exponentiations per party. The proposed scheme can protect both parties from compromise and precomputation attacks, in which the password file relies on the identity and random salt. What’s more, our protocol guarantees the identity privacy, that is, the transmitted record and password file will not reveal the identity information. We further present a new security model for our protocol, and prove that the proposed scheme is secure under this model. Finally, we show the practicality of our PAKE via experiments and efficiency analysis.
Huanhuan Lian, Yafang Yang, Yunlei Zhao
IEEE Internet Things J.2
2022 CRFs for Digital Signature and NIZK Proof System in Web Services
Burong Kang, Lei Zhang 0009, Yafang Yang
ICA3PP3
2022 Privacy-Preserving Aggregation-Authentication Scheme for Safety Warning System in Fog-Cloud Based VANET
abstract
As cities become smarter, the importance of vehicular ad hoc networks (VANETs) will be increasingly pronounced. To support latency- and time-sensitive applications, there have been attempts to utilize fog-cloud computing in VANETs. There are, however, a number of limitations in existing fog-cloud based VANET deployments, ranging from computation and communication bottlenecks to privacy leakage to costly certificate/ pseudonym management to key escrow, and so on. Therefore, in this paper we propose a privacy-preserving aggregation authentication scheme (PPAAS). The scheme is designed for deployment in a safety warning system for fog-cloud based VANETs. Specifically, the PPAAS scheme is realized using a novel efficient anonymous certificateless aggregation signcryption scheme (CASS) proposed in this paper, and allows a fog node to aggregate signcrypted traffic-related messages from surrounding vehicles into an aggregated ciphertext and unsigncrypt them in a batch. We then evaluate the security of PPAAS and demonstrate that it supports confidentiality, authentication, and (efficient) conditional privacy, and key escrow freeness. In particular, our scheme is the first in the literature to achieve efficient conditional privacy, which avoids the need for costly pseudonym management. We also demonstrate that the scheme is practical, based on our simulation results.
Yafang Yang, Lei Zhang 0009, Yunlei Zhao, Kim-Kwang Raymond Choo, Yan Zhang 0103
IEEE Trans. Inf. Forensics Secur.1
2021 Detection of Behavior Aging from Keystroke Dynamics
abstract
Keystroke dynamics-based authentication (KDA) is one of human behavioral-based authentication methods based on the unique typing rhythm of an individual. Nevertheless, the typing characteristics gradually change over time. Various solutions have been suggested to remedy the concept drift problem, including multimodal and unimodal adaptive methods. However, these solutions don't consider that temporal concept drift has a negative impact on performance and update frequency increases computation cost. The paper proposes weighted EDDM to detect concept drift and capture permanent concept drift (behavioral natural aging). Experimental results show that our method can accurately capture behavioral natural aging and filter temporal concept drift. Our proposed method has better performance and less computation.
Yafang Yang, Bin Guo 0001, Yunji Liang, Zhiwen Yu 0001
ICPADS1
2020 Behavior Fingerprints Based Smartphone User Authentication: A Review
Imane Lamiche, Bin Guo 0001, Yafang Yang, Zhiwen Yu 0001
GPC3
2019 BehaveSense: Continuous authentication for security-sensitive mobile apps using behavioral biometrics
Yafang Yang, Bin Guo 0001, Zhu Wang 0001, Mingyang Li 0003, Zhiwen Yu 0001, Xingshe Zhou 0001
Ad Hoc Networks1
2013 An efficient authentication protocol with user anonymity for mobile networks
abstract
Existing mobile authentication protocols are low in efficiency, because asymmetric encryption algorithms with large computational overheads are employed in these protocols to ensure user anonymity. In addition, the existing mobile authentication protocols have a long delay in fast reconnection, because these protocols may suffer from desynchronization attacks. In order to solve these problems, an efficient mutual authentication protocol with user anonymity for mobile networks is proposed. The proposed protocol ensures user anonymity by using one-way hash function. It reduces the delay time in fast reconnection, because once the session key between the mobile user and the foreign agent is found to be desynchronized in reconnection process, mobile users start the process of login and authentication from a new beginning immediately. The security of the proposed protocol is proved by using the provable security model. Compared with several existing authentication protocols for mobile networks, the proposed protocol is more secure and more effective.
Huixian Li, Yafang Yang, Liaojun Pang
WCNC2