Yannan Li 0001

dblp:136/0901 · DBLP profile ↗
← Back
32ranked-venue papers
7as first author
15since 2021 · last 2026
0000-0002-4407-9027ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 5 first-author · 13 since 2021Computer networks · 5 · 1 first-authorSystems, architecture and hardware · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Adaptor Multi-Signatures: Definition, Applications and Construction from Cryptographic Group Actions
Thanh Xuan Khuc, Willy Susilo, Dung Hoang Duong, Yannan Li 0001, Partha Sarathi Roy 0001, Kazuhide Fukushima, Shinsaku Kiyomoto
EuroS&P4
2026 Realizing Quantum-Secure Proof-of-Stake Blockchain With Lattice-Based Weighted Threshold Signature
abstract
Proof-of-Stake (PoS) blockchain protocols have gained increasing prominence in recent years due to their energy efficiency. In PoS systems, users stake tokens to become validators. Those who stake more tokens are elected to propose new blocks with higher probabilities and possess greater voting power in consensus decisions. At first glance, threshold signatures appear to be a promising mechanism for aggregating multiple block attestations in PoS blockchain protocols. However, traditional threshold signatures treat each participant equally in signature generation, disregarding the differing weights of participants. This lack of weight consideration poses a challenge in PoS blockchains, where validators inherently have varying levels of influence. To address this issue, a weighted threshold signature scheme is necessary—one that accounts for the distinct weights of signers, reflecting their respective voting power in PoS blockchains. Despite this need, no existing weighted threshold signature schemes are resistant to attacks by quantum computing. To fill this gap in the literature, we propose the first lattice-based weighted threshold signature scheme, proven secure under the module short integer solution (MSIS) assumption in the random oracle model. Furthermore, we demonstrate the integration of this novel scheme into PoS blockchain protocols for block attestation. Finally, we implement our weighted threshold signature scheme and present its efficiency evaluation.
Mei Jiang, Willy Susilo, Dung Hoang Duong, Yannan Li 0001
IEEE Trans. Dependable Secur. Comput.4
2026 Closing the Proof-of-Stake Security Gap: A Signature-Based Defense Against Malicious Validators in Long-Range Attacks
abstract
Long-range attacks pose a significant threat to the integrity of Proof-of-Stake (PoS) blockchains by enabling adversaries to reconstruct an alternative chain history embedded with fraudulent transactions. These attacks can deceive honest participants into accepting a maliciously crafted branch as the canonical chain. While Key Evolving Signature (KES) schemes are widely adopted to mitigate such threats, they typically rely on the assumption that validators behave honestly. In this work, we challenge this assumption by demonstrating how a malicious validator can exploit inherent limitations in existing KES-based mechanisms to mount a successful long-range attack. To address this critical vulnerability, we introduce a novel cryptographic construction that combines one-time signatures with commitment schemes. Our approach imposes constraints on the signing capabilities of validators, thereby significantly reducing the feasibility of long-range attacks. We provide rigorous formal security proofs to substantiate the robustness of our scheme and conduct a comprehensive performance evaluation. The results show that our solution is both computationally and storage efficient, making it a practical and scalable defense mechanism for real-world PoS blockchain deployments.
Zhanwen Chen, Yannan Li 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.2
2025 Strong Designated Verifier Signatures from Isogeny Assumptions
Thanh Xuan Khuc, Willy Susilo, Dung Hoang Duong, Yannan Li 0001, Partha Sarathi Roy 0001, Kazuhide Fukushima, Shinsaku Kiyomoto
CANS4
2025 Mecon: A GNN-based graph classification framework for MEV activity detection
Zihao Yao, Fanding Huang, Yannan Li 0001, Wei Duan 0003, Willy Susilo
Expert Syst. Appl.3
2025 SVOC: Secure Aggregatable and Extractable System for Outsourced Cloud Computation
abstract
With the rapid advancement of technology, cloud computing has emerged as the most popular and promising service platform. A cloud user can delegate heavy computation tasks to cloud servers. To ensure the correctness of outsourced processing (e.g., machine learning and data mining), the cloud server must prove that the processing has been executed properly. However, even without malicious intent, it is possible for a cloud server to produce incorrect results. Consequently, clients may outsource the same task to multiple cloud servers and receive various results, aiding them in selecting the best outcome. To protect data privacy, the cloud server must encrypt the results before sending them back to the user. Yet, processing and verifying encrypted results remain significant challenges. To avoid the expensive computational overhead of decrypting ciphertexts from cloud servers one by one, clients prefer to use homomorphic encryption (HE) to obtain the combined output from a single server. However, existing schemes fall short of efficiently verifying the correctness of computations over encrypted data processed by multiple cloud servers, especially in extracting the results computed by each server. In this paper, we introduce a new framework for verifiable outsourced computing systems. In this system, each cloud server's computation result is protected by Paillier encryption, and the edge server can verify these results using zero-knowledge proofs and aggregate the verified ciphertexts. The client can extract the combined plaintext through the Base-3 conversion algorithm to identify each cloud server's results and any non-participating servers. We also prove the security of our scheme and analyze its performance from both theoretical and experimental aspects. Performance analysis shows that our system significantly reduces the client's workload and is userfriendly
Willy Susilo, Yumei Li 0003, Fuchun Guo, Zhen Zhao 0005, Yannan Li 0001, Chunpeng Ge 0001
IEEE Trans. Dependable Secur. Comput.5
2025 Accountable Many-to-One Signature With Short Verification Key for Self-Sovereign Identity
abstract
Self-Sovereign Identity (SSI) shifts identity management authority from central institutions to users, enhancing privacy protections. However, malicious identity providers may collude with users to issue credentials that pass verification but contain false information. While multi-signature schemes enable joint credential issuance by multiple identity providers to mitigate this risk, they result in a linear increase in the size of signatures within credentials and verification keys as the number of identity providers grows, leading to substantial storage overhead for both users and verifiers. Furthermore, malicious verifiers may leak users' credentials to third parties or unlawfully duplicate them, causing users to lose control over the distribution of their credentials. To address these challenges, we propose the Accountable Many-to-One Signature Scheme with Short Verification Key (ASVK-MOSS), a multi-signature scheme with designated verifiers and accountability that ensures fixed sizes for both the verification key and the signature. We prove the security of the proposed ASVK-MOSS under the random oracle model. Building on ASVK-MOSS, we design a novel SSI system, namedMO-SSI, in which multiple identity providers jointly sign the user's personal information to generate a credential with fixed sizes. Service providers only need to store a minimal, fixed-size verification key to validate the credentials from any set of identity providers. Additionally, the designated verifier and accountability mitigate risks posed by malicious service providers and identity providers within MO-SSI. The theoretical analysis and experimental results demonstrate its effectiveness and feasibility.
Yong Yu 0002, Haochen Yang 0001, Yannan Li 0001, Xiaojiang Du
IEEE Trans. Dependable Secur. Comput.3
2025 Calling Out Trustless Users: A Trust Propagation Scheme for Decentralized Trust Management
abstract
Trust management has been widely employed to determine a user's trustworthiness based on evaluations from other entities, and trustless users are those with low trustworthiness due to dishonest or malicious behaviors. To overcome the defects of traditional centralized trust management, decentralized trust management has been proposed, leveraging blockchain to store trust data, e.g., user interaction evaluations, securely. However, blockchain-based decentralized trust management usually suffers from throughput limitation, hindering timely record users' trust data, delaying expose trustless users. As a result, trustless users may still interact with others in the system with the outdated trustworthiness, undermining the reliability and fairness of the system. Furthermore, decentralized pseudonymous networks suffer from a trust cold-start problem due to lacking users' prior interaction history or endorsements from trusted third parties, making it hard for newly joined users to assess the trustworthiness. To address these issues, we propose TUES in this paper, an efficient Trustless User Exposure Scheme. TUES stores trust data in a trust blockchain collectively maintained by all users. To efficiently expose trustless users, we design a dynamic consensus mechanism for TUES. This dynamic consensus mechanism integrates three novel consensus algorithms, efficiently utilizing network throughput to record trust data of trustless users and ensure the consistency of the blockchain. Additionally, TUES includes a multi-signature-based scheme to allocate initial trust values to users, thus resolving the trust cold-start problem in decentralized pseudonymous networks. Analysis and experiments show that TUES improves the efficiency of exposing trustless users while maintaining the consistency of the trust blockchain. It also increases the cost for adversaries conducting Sybil, whitewashing and Byzantine attacks.
Yong Yu 0002, Haochen Yang 0001, Yannan Li 0001, Robert H. Deng
IEEE Trans. Serv. Comput.3
2024 Quantum-Safe Puncturable Signatures With Their Application in Blockchain
abstract
Energy-efficient proof-of-stake (PoS) consensus protocols in blockchain have gained much attention from academia and industry recently. Despite their potential advantages, PoS protocols have not been extensively deployed in the existing digital currency market due to inherent security concerns, e.g., long-range attacks. Such attacks enable an adversary to rewrite the entire transaction history of a blockchain, severely compromising its immutability. The puncturable signature provides an efficient solution against long-range attacks due to secret key leakage. More specifically, a signer can update the secret key with chosen messages selectively, while the public key is unchanged. Unfortunately, the existing puncturable signature schemes suffer from either updating the public key repeatedly or large key size, which makes them unsuitable for PoS protocols. To resolve these drawbacks, we adopt a different approach to performing key puncture operations and propose a generic puncturable signature construction from delegated (key-policy) constrained signatures. We present a concrete puncturable signature scheme over lattices that is proven secure based on the short integer solution (SIS) assumption in the standard model.
Mei Jiang, Yannan Li 0001, Willy Susilo, Dung Hoang Duong
IEEE Trans. Inf. Forensics Secur.2
2023 Threshold Ring Signature Scheme from Cryptographic Group Action
Minh Thuy Truc Pham, Dung Hoang Duong, Yannan Li 0001, Willy Susilo
ProvSec3
2022 Public Cloud Data Auditing Revisited: Removing the Tradeoff Between Proof Size and Storage Cost
Willy Susilo, Yannan Li 0001, Fuchun Guo, Jianchang Lai, Ge Wu 0001
ESORICS (2)2
2022 A Blockchain-Based Self-Tallying Voting Protocol in Decentralized IoT
abstract
The Internet of Things (IoT) is experiencing explosive growth and has gained extensive attention from academia and industry in recent years. However, most of the existing IoT infrastructures are centralized, which may cause the issues of unscalability and single-point-of-failure. Consequently, decentralized IoT has been proposed by taking advantage of the emerging technology called blockchain. Voting systems are widely adopted in IoT, for example a leader election in wireless sensor networks. Self-tallying voting systems are alternatives to unsuitable, traditional centralized voting systems in decentralized IoT. Unfortunately, self-tallying voting systems inherently suffer from fairness issues, such as adaptive and abortive issues caused by malicious voters. To address these issues, in this article, we introduce a framework of the self-tallying voting system in decentralized IoT based on blockchain. We propose a concrete construction and prove that the proposed system satisfies all the security requirements, including fairness, dispute-freeness, and maximal ballot secrecy. We simulate the algorithms on a laptop, an Android phone, and a Raspberry Pi to test the time consumption and evaluate the gas cost of each algorithm in a private blockchain as well. The implementation results demonstrate the practicability of our system.
Yannan Li 0001, Willy Susilo, Guomin Yang, Yong Yu 0002, Dongxi Liu, Xiaojiang Du, Mohsen Guizani
IEEE Trans. Dependable Secur. Comput.1
2021 Concise Mercurial Subvector Commitments: Definitions and Constructions
Yannan Li 0001, Willy Susilo, Guomin Yang, Tran Viet Xuan Phuong, Yong Yu 0002, Dongxi Liu
ACISP1
2021 Non-Equivocation in Blockchain: Double-Authentication-Preventing Signatures Gone Contractual
abstract
Equivocation is one of the most fundamental problems that need to be solved when designing distributed protocols. Traditional methods to defeat equivocation rely on trusted hardware or particular assumptions, which may hinder their adoption in practice. The advent of blockchain and decentralized cryptocurrencies provides an auspicious breakthrough paradigm to resolve the problem above. In this paper, we propose a blockchain-based solution to address contractual equivocation, which supports user-defined fine-grained policy-based equivocation. Specifically, users will be de-incentive if the statements they made breach the predefined access rules. The core of our solution is a newly introduced primitive named Policy-Authentication-Preventing Signature (PoAPS), which combined with a deposit mechanism allows a signer to make conflict statements corresponding to a policy to be penalized. We present a generic construction of PoAPS based on Policy-Based Verifiable Secret Sharing (PBVSS) and demonstrate its practicality via a concrete implementation in the blockchain. Compared with the existing solutions that only handle specific types of equivocation, our proposed approach is more generic and can be instantiated to deal with various kinds of equivocation.
Yannan Li 0001, Willy Susilo, Guomin Yang, Yong Yu 0002, Tran Viet Xuan Phuong, Dongxi Liu
AsiaCCS1
2021 Traceable Monero: Anonymous Cryptocurrency with Enhanced Accountability
abstract
Monero provides a high level of anonymity for both users and their transactions. However, many criminal activities might be committed with the protection of anonymity in cryptocurrency transactions. Thus, user accountability (or traceability) is also important in Monero transactions, which is unfortunately lacking in the current literature. In this paper, we fill this gap by introducing a new cryptocurrency named Traceable Monero to balance the user anonymity and accountability. Our framework relies on a tracing authority, but is optimistic, in that it is only involved when investigations in certain transactions are required. We formalize the system model and security model of Traceable Monero. We present a detailed construction of Traceable Monero by overlaying Monero with two types of tracing mechanisms, tracing the one-time addresses with money flows and tracing the long-term addresses. We prove the security of Traceable Monero and implement a prototype of the system, which demonstrates that Traceable Monero incurs merely a very small overhead in generating and verifying a transaction compared to Monero transactions.
Yannan Li 0001, Guomin Yang, Willy Susilo, Yong Yu 0002, Man Ho Au, Dongxi Liu
IEEE Trans. Dependable Secur. Comput.1
2020 Blockchain-Based Dynamic Provable Data Possession for Smart Cities
abstract
Smart cities have experienced rapid development with the advances of information and communication technologies such as Internet of Things (IoT). To tackle the data storage issues raised by large-scale data generated by IoT devices, an increasing number of enterprises and individuals prefer to outsource their data to cloud, where data integrity becomes a concern to cloud users. A variety of provable data possession (PDP) protocols have been proposed for centralized cloud storage scenarios so far. However, a centralized cloud relies too much on the trust of the central servers and, thus, is prone to the single point of failure. In this article, we describe a blockchain-based PDP model to realize the decentralized outsourcing storage framework, and then present a concrete construction of decentralized PDP by using multireplica storage tricks. Moreover, our protocol provides dynamic operations for outsourced data and at the same time, guarantees the fairness of all parties involved. We provide a detailed security proof for the proposed protocol and deploy a smart contract for the protocols as well. We finally evaluate the algorithms and the implementation results demonstrate the practicability of the proposed protocol.
Yannan Li 0001, Yong Yu 0002, Xiaofeng Chen 0001, Willy Susilo
IEEE Internet Things J.2
2020 IntegrityChain: Provable Data Possession for Decentralized Storage
abstract
Outsourced storage enables data owners to host their data on remote storage resources without keeping a local copy so as to target their core business. However, a serious problem is data integrity in the sense that data owners lose their physical control over the remote-stored data. Existing provable data possession protocols are overwhelmingly designed for centralized storage such as cloud, in which the server is assumed dishonest but the client is reliable. Moreover, the centralized storage suffers single-point-of-failure threat. In this paper, to deal with these issues, we propose the notion of IntegrityChain, a decentralized storage framework supporting provable data possession (PDP) based on blockchain. We formalize the system model, in which a data owner can store files to the peers in a blockchain network and check the integrity of the outsourced data periodically by paying some cryptocurrencies while the hosts can earn money if honestly provide storage service and will be punished by losing the pre-made deposit if data loss happens. In the security model, we consider the fairness in trading between a host and a data user and the soundness of the underlying decentralized PDP in this system. We come up with a concrete construction by borrowing the idea of multi-replica PDP and proof-of-retrievability and present the security analysis of the proposal. The evaluation for the construction contain two segments: the offchain part, in which we implement the algorithms locally to test the time consumption, and onchain part, in which we program a smart contract and launch it in a test network to test the gas cost for the functions.
Yannan Li 0001, Yong Yu 0002, Xiaojiang Du, Mohsen Guizani
IEEE J. Sel. Areas Commun.1
2020 Key-Policy Attribute-Based Encryption With Keyword Search in Virtualized Environments
abstract
Cloud computing is a model for convenient, on-demand network access to virtualized environments of configurable computing resources. It is challenging to search data encrypted and stored in cloud storage servers. Searchable encryption enables data users to search on ciphertext without leaking any information about keywords and the plaintext of the data. Currently, a number of searchable encryption schemes have been proposed, but most of them provide unlimited search privileges to data users, which is not desirable in certain scenarios. In this paper, we propose a new construction of searchable encryption with fine-grained access control by using key-policy attribute-based cryptography to generate trapdoors to support AND, OR and threshold gates. The main idea is that the data owner encrypts the index keywords according to the specified access policy. The data user can generate a trapdoor to search on data, if and only if the attributes of the data user satisfy the access policy. We provide formal security proofs for the scheme, including the indistinguishability of ciphertexts and the indistinguishability of trapdoors, which are used to resist the chosen keyword attack and the keyword guessing attack of external adversaries. Comprehensive security analysis and implementation results show that the proposed scheme is provably secure and feasible in real-world applications.
Yong Yu 0002, Junbin Shi, Yannan Li 0001, Xiaojiang Du, Mohsen Guizani
IEEE J. Sel. Areas Commun.4
2020 Blockchain-Based Anonymous Authentication With Selective Revocation for Smart Industrial Applications
abstract
Personal privacy disclosure is one of the most serious challenges in smart industrial applications. Anonymous authentication is an effective solution to protect personal privacy. However, the existing anonymous credential protocols are not perfectly suitablefor smart industrial environments such as smart vehicles in the sense that the credential revocation issue is not well-solved. In this article, we propose a Blockchain-based Anonymous authentication with Selective revocation for Smart industrial applications (BASS) for smart industrial applications supporting attribute privacy, selective revocation, credential soundness, and multishowing-unlinkability. Specifically, an efficient selective revocation mechanism is proposed based on dynamic accumulators and the signature algorithm due to Pointcheval and Sanders as the overlay of the BASS. According to the diverse demands of credential authorities, BASS can selectively provide revocation of credentials or revocation of users. We extend BASS from single-attribute privacy to multiattribute privacy as well. Finally, we implement a prototype to evaluate the cryptographic core primitives of BASS by deploying smart contracts in Ethereum to demonstrate the validity of BASS in smart industrial applications.
Yong Yu 0002, Yanqi Zhao, Yannan Li 0001, Xiaojiang Du, Lianhai Wang, Mohsen Guizani
IEEE Trans. Ind. Informatics3
2019 An efficient linkable group signature for payer tracing in anonymous cryptocurrencies
Lingyue Zhang, Yannan Li 0001, Yong Yu 0002, Man Ho Au, Baocang Wang
Future Gener. Comput. Syst.3
2019 LRCoin: Leakage-Resilient Cryptocurrency Based on Bitcoin for Data Trading in IoT
abstract
Currently, the number of Internet of Things (IoT) devices making up the IoT is more than 11 billion and this number has been continuously increasing. The prevalence of these devices leads to an emerging IoT business model called Device-as-a-service, which enables sensor devices to collect data disseminated to all interested devices. The devices sharing data with other devices could receive some financial reward, such as Bitcoin. However, side-channel attacks, which aim to exploit some information leaked from the IoT devices during data trade execution, are possible since most of the IoT devices are vulnerable to be hacked or compromised. Thus, it is challenging to securely realize data trading in IoT environment due to the information leakage, such as leaking the private key for signing a Bitcoin transaction in Bitcoin system. In this paper, we propose LRCoin, a kind of leakage-resilient cryptocurrency based on bitcoin in which the signature algorithm used for authenticating bitcoin transactions is leakage-resilient. LRCoin is suitable for the scenarios where information leakage is inevitable, such as IoT applications. Our core contribution is proposing an efficient bilinear-based continual-leakage-resilient ECDSA signature. We prove the proposed signature algorithm is unforgeable against adaptively chosen messages attack in the generic bilinear group model under the continual leakage setting. Both the theoretical analysis and the implementation demonstrate the practicability of the proposed scheme.
Yong Yu 0002, Yujie Ding, Yanqi Zhao, Yannan Li 0001, Yi Zhao 0011, Xiaojiang Du, Mohsen Guizani
IEEE Internet Things J.4
2019 Efficient attribute-based encryption with attribute revocation for assured data deletion
Yong Yu 0002, Yannan Li 0001, Man Ho Au, Xiaojiang Du, Bo Yang 0003
Inf. Sci.3
2019 Machine learning based privacy-preserving fair data trading in big data market
Yanqi Zhao, Yong Yu 0002, Yannan Li 0001, Xiaojiang Du
Inf. Sci.3
2019 Fuzzy Identity-Based Data Integrity Auditing for Reliable Cloud Storage Systems
abstract
Data integrity, a core security issue in reliable cloud storage, has received much attention. Data auditing protocols enable a verifier to efficiently check the integrity of the outsourced data without downloading the data. A key research challenge associated with existing designs of data auditing protocols is the complexity in key management. In this paper, we seek to address the complex key management challenge in cloud data integrity checking by introducing fuzzy identity-based auditing, the first in such an approach, to the best of our knowledge. More specifically, we present the primitive of fuzzy identity-based data auditing, where a user's identity can be viewed as a set of descriptive attributes. We formalize the system model and the security model for this new primitive. We then present a concrete construction of fuzzy identity-based auditing protocol by utilizing biometrics as the fuzzy identity. The new protocol offers the property of error-tolerance, namely, it binds with private key to one identity which can be used to verify the correctness of a response generated with another identity, if and only if both identities are sufficiently close. We prove the security of our protocol based on the computational Diffie-Hellman assumption and the discrete logarithm assumption in the selective-ID security model. Finally, we develop a prototype implementation of the protocol which demonstrates the practicality of the proposal.
Yannan Li 0001, Yong Yu 0002, Geyong Min, Willy Susilo, Jianbing Ni, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.1
2018 An Efficient Anonymous Authentication Scheme Based on Double Authentication Preventing Signature for Mobile Healthcare Crowd Sensing
Yong Yu 0002, Yannan Li 0001, Yanqi Zhao, Xiaojiang Du
Inscrypt3
2018 CrowdBuy: Privacy-friendly Image Dataset Purchasing via Crowdsourcing
abstract
In recent years, advanced machine learning techniques have demonstrated remarkable achievements in many areas. Despite the great success, one of the bottlenecks in applying machine learning techniques in real world applications lies in the lack of a large amount of high-quality training data from diverse domains. Meanwhile, massive personal data is being generated by mobile devices and is often underutilized. To bridge the gap, we propose a general dataset purchasing framework, named CrowdBuy and CrowdBuy++, based on crowdsourcing, with which a buyer can efficiently buy desired data from available mobile users with quality guarantee in a way respecting users' data ownership and privacy. We present a complete set of tools including privacy-preserving image dataset quality measurements and image selection mechanisms, which are budget feasible, truthful and highly efficient for mobile users. We conducted extensive evaluations of our framework on large-scale images and demonstrate that the system is capable of crowdsourcing high quality datasets while preserving image privacy with little computation and communication overhead.
Lan Zhang 0002, Yannan Li 0001, Xiang-Yang Li 0001, Anxin Zhou, Qiang Li 0054
INFOCOM2
2018 Privacy preserving cloud data auditing with efficient key update
Yannan Li 0001, Yong Yu 0002, Bo Yang 0003, Geyong Min, Huai Wu
Future Gener. Comput. Syst.1
2018 Assured Data Deletion With Fine-Grained Access Control for Fog-Based Industrial Applications
abstract
The advances of cloud computing, fog computing, and Internet of things (IoT) make industries more prosperous than ever. A wide range of industrial systems such as transportation and manufacturing systems have been developed by integrating cloud computing, fog computing, and IoT infrastructure successfully. However, in this sophisticated system, security and privacy issues are major concerns that hinder the widespread adoptions of these novel techniques. In this paper, we focus on assured data deletion, an issue that is important but received less attention in academia and industry. We first propose a framework to integrate the cloud, the fog, and the things together to manage stored data from industries or individuals. We then focus on secure data deletion in this framework by proposing an assured data deletion scheme that fulfills verifiable data deletion as well as flexible access control over sensitive data. Only data owners and fog devices are involved when deleting cloud data and validating the deletion of these data, which makes the protocol practical due to the features of low latency as well as real-time interaction with fog. The proposed protocol takes advantage of the attribute-based encryption, whose security can be proved under the standard model. The theoretical analysis shows good performance and functionality requirements while the implementation results demonstrate the feasibility of our proposal.
Yong Yu 0002, Yannan Li 0001, Xiaojiang Du, Mohsen Guizani, Bo Yang 0003
IEEE Trans. Ind. Informatics3
2017 Improved dynamic remote data auditing protocol for smart city security
Li Zang, Yong Yu 0002, Yannan Li 0001, Yujie Ding, Xiaoling Tao
Pers. Ubiquitous Comput.4
2016 Public Cloud Data Auditing with Practical Key Update and Zero Knowledge Privacy
Yong Yu 0002, Yannan Li 0001, Man Ho Au, Willy Susilo, Kim-Kwang Raymond Choo, Xinpeng Zhang 0001
ACISP (1)2
2016 Delegation of signing rights for emerging 5G networks
abstract
Summary 5G mobile networks are promising to offer mobile users unrivaled experiences with infinite networking capability at any period and from anywhere. However, it appears unnecessary and impractical for the customers and servers to be connected permanently in wireless networks because battery life is a bottleneck in such kind of networks. Therefore, the authorized entity needs to delegate its right to others in order to ensure the services available. This paper aims to address the issue of delegating authentication in 5G networks by proposing a new proxy signature scheme with efficient proxy signing operations. Concretely, we present a new and efficient proxy signature algorithm whose unforgeability can be reduced to the well‐known discrete logarithm assumption. In the proposal, the original signer delegates his signing right by signing an exposure‐free chameleon hash value on the warrant, and the proxy signer can generate a proxy signature on a message only by calculating a chameleon hash collision between the warrant and the message. This approach is computationally cost‐effective for the proxy signer. Further analysis of the new scheme demonstrates that it offers the desirable properties of delegation of signing sights. Copyright © 2015 John Wiley & Sons, Ltd.
Yongyong Ge, Yannan Li 0001, Zhusong Liu
Concurr. Comput. Pract. Exp.2
2016 Comments on "Public Integrity Auditing for Dynamic Data Sharing With Multiuser Modification"
abstract
Recently, a practical public integrity auditing scheme supporting multiuser data modification (IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, DOI 10.1109/TIFS.2015.2423264) was proposed. Although the protocol was claimed secure, in this paper, we show that the proposal fails to achievesoundness, the most essential property that an auditing scheme should provide. Specifically, we show that a cloud server can collude with a revoked user to deceive a third-party auditor (TPA) that a stored file keeps virgin even when the entire file has been deleted.
Yong Yu 0002, Yannan Li 0001, Jianbing Ni, Guomin Yang, Yi Mu 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.2