Yi-Fan Tseng

dblp:143/1242 · DBLP profile ↗
← Back
23ranked-venue papers
8as first author
21since 2021 · last 2026
0000-0001-6948-2405ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 6 first-author · 14 since 2021Computer networks · 4 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 since 2021Theory of computation · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Efficient level-3 secure certificateless signature against malicious KGC attacks for IoT
Yi-Fan Tseng, Chieh-Han Wu
Comput. Networks1
2026 Hierarchical identity-based encryption with receiver selective opening security in the multi-challenge setting
abstract
Receiver selective opening (RSO) security considers the security of encryption schemes under the scenario of a single sender and multiple receivers, where an adversary is allowed to adaptively corrupt some receivers’ secret keys. RSO security has been proven to be more secure than indistinguishability-based security notions. A lot of research has focused on RSO security in terms of public-key encryption and identity-based encryption (IBE); however, hierarchical IBE (HIBE), which is a generalization of IBE, is still lacking in the study, and how to obtain such a construction remains an open problem. To address this gap, we initiate a study of RSO security on HIBE in this work. Precisely, we first formalize the definition of simulation-based RSO against identity-chosen-plaintext/ciphertext attacks in the k-challenge setting (SIM-ID-RSO $$_k$$ -CPA/CCA) for HIBE. We then present generic SIM-ID-RSO $$_k$$ -CCA secure HIBE constructions by introducing the double secret key paradigm. Specifically, we show that a SIM-ID-RSO $$_k$$ -CCA secure HIBE scheme can be obtained from an IND-ID-CPA secure HIBE scheme as well as a one-time signature scheme that satisfies strong unforgeability. Through our general construction, we can derive various concrete schemes based on different hard assumptions (e.g., lattice-based and pairing-based SIM-ID-RSO $$_k$$ -CCA secure HIBE schemes) according to usage requirements.
Zi-Yuan Liu, Masahiro Mambo, Raylin Tso, Yi-Fan Tseng
Des. Codes Cryptogr.4
2026 Public-key encryption with filtered equality test against adaptive chosen-ciphertext attacks
Zi-Yuan Liu, Masahiro Mambo, Raylin Tso, Yi-Fan Tseng
Theor. Comput. Sci.4
2025 Poster: Public Key Encryption with Exclusionary Subset Keyword Search from Lattices
abstract
This paper introduces a novel public-key searchable encryption (PKSE) scheme that supports a new search pattern: exclusionary subset search, which cannot be trivially realized from the current PKSE schemes. This pattern enables users to retrieve ciphertexts that do not contain a specific subset of keywords, offering a more intuitive and efficient approach in scenarios where excluding a limited set of keywords is crucial. Besides, our scheme is built over lattices, and support constant-size trapdoors, which take advantages against the existing lattice-based constructions.
Yi-Fan Tseng, Jheng-Jia Huang, Ting-Hsiang Su
CCS1
2025 Blacklisting access control via negated subset predicate encryption: Constant-size ciphertexts/keys constructions with adaptive security or attribute hiding
Yi-Fan Tseng
J. Inf. Secur. Appl.1
2025 Attribute-Based Encryption Supporting Multi-Keyword Search With Effective User Revocation in Public Cloud Storage
abstract
Cloud computing has become a prevalent service for data proprietors to outsource their data to public cloud servers while allowing data consumers to retrieve cloud-stored data. While encrypting cloud data helps individuals ensure the security and privacy of cloud data, all-or-nothing encryption hinders effective access control and data search. To address this issue, this paper proposes fine-grained attribute-based encryption supporting multi-keyword-based data search to circumvent critical issues, including the assumption of online third-party authority, expensive user revocation, and a lack of expressiveness on keyword search problems. The proposed protocol empowers users to authorize cloud servers to perform keyword searches on encrypted data without forfeiting data privacy. Besides, the length of the ciphertext and the user key is short and fixed, having no noteworthy impact on the user growth in the system. The proposed protocol is formally secure against the indistinguishability under chosen-plaintext (IND-CPA) attack under the standard model with the generalized decisional Diffie-Hellman assumption. The comprehensive performance analysis of the proposed scheme demonstrates that it outperforms state-of-the-art solutions. Thus, our system is suitable for real-world applications due to its enhanced security characteristics, adaptability, and efficacy.
Chun-I Fan, Si-Jing Wu, Yi-Fan Tseng, Arijit Karati
IEEE Trans. Dependable Secur. Comput.3
2024 Predicate encryption with selective-opening security for receivers: formal definition, generic construction, and concrete instantiations for several primitives
Yi-Fan Tseng, Zi-Yuan Liu, Raylin Tso
Des. Codes Cryptogr.1
2023 Cryptanalysis of a round optimal lattice-based multisignature scheme
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso
Inf. Process. Lett.2
2023 An Efficient Data Protection Scheme Based on Hierarchical ID-Based Encryption for MQTT
abstract
As Internet of Things (IoT) thrives over the whole world, more and more IoT devices and IoT-based protocols have been designed and proposed in order to meet people’s needs. Among those protocols, message queueing telemetry transport (MQTT) is one of the most emerging and promising protocols, which provides many-to-many message transmissions based on the “publish/subscribe” mechanism. It has been widely used in industries such as the energy industry, chemical engineering, self-driving, and so on. While transporting important messages, MQTT specification recommends the use of TLS protocol. However, the computation cost of TLS is too heavy. Since topics in a broker are stored with a hierarchical structure, in this manuscript, we propose a novel data protection protocol for MQTT from hierarchical ID-based encryption. Our protocol adopts the intrinsic hierarchical structures of MQTT, and achieves constant-size keys, i.e., independent of the depth in hierarchical structures. Besides, the formal security model for the proposed protocol have been defined in the manuscript. The proposed protocol have been formally proven chosen-plaintext secure under the ℓ-wBDHI assumption.
Chun-I Fan, Cheng-Han Shie, Yi-Fan Tseng, Hui-Chun Huang
ACM Trans. Sens. Networks3
2022 Public-key Authenticated Encryption with Keyword Search: Cryptanalysis, Enhanced Security, and Quantum-resistant Instantiation
abstract
With the rapid development of cloud computing, an increasing number of companies are adopting cloud storage technology to reduce overhead. However, to ensure the privacy of sensitive data, the uploaded data need to be encrypted before being outsourced to the cloud. The concept of public-key encryption with keyword search (PEKS) was introduced by Boneh et al. to provide flexible usage of the encrypted data. Unfortunately, most of the PEKS schemes are not secure against inside keyword guessing attacks (IKGA), so the keyword information of the trapdoor may be leaked to the adversary. To solve this issue, Huang and Li presented public key authenticated encryption with keyword search (PAEKS) in which the trapdoor generated by the receiver is only valid for authenticated ciphertexts. With their seminal work, many PAEKS schemes have been introduced for the enhanced security of PAEKS. Some of them further consider the upcoming quantum attacks. However, our cryptanalysis indicated that in fact, these schemes could not withstand IKGA. To fight against the attacks from quantum adversaries and support the privacy-preserving search functionality, we first introduce a novel generic PAEKS construction in this work. Then, we further present the first quantum-resistant PAEKS instantiation based on lattices. The security proofs show that our instantiation not only satisfies the basic requirements but also achieves enhanced security models, namely the multi-ciphertext indistinguishability and multi-trapdoor privacy. Furthermore, the comparative results indicate that with only some additional expenditure, the proposed instantiation provides more secure properties, making it suitable for more diverse application environments.
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo, Yu-Chi Chen 0001
AsiaCCS2
2022 Blockchain-Based Self-Sovereign Identity System with Attribute-Based Issuance
Yi-Hsiu Lee, Zi-Yuan Liu, Raylin Tso, Yi-Fan Tseng
ISPEC4
2022 Blockchain-Based Confidential Payment System with Controllable Regulation
Yu-Chen Liao, Raylin Tso, Zi-Yuan Liu, Yi-Fan Tseng
ISPEC4
2022 Public-Key Authenticated Encryption with Keyword Search: A Generic Construction and Its Quantum-Resistant Instantiation
abstract
Abstract The industrial Internet of Things (IIoT) integrates sensors, instruments, equipment and industrial applications, enabling traditional industries to automate and intelligently process data. To reduce the cost and demand of required service equipment, IIoT relies on cloud computing to further process and store data. Public-key encryption with keyword search (PEKS) plays an important role, due to its search functionality, to ensure the privacy and confidentiality of the outsourced data and the maintenance of flexibility in the use of the data. Recently, Huang and Li proposed the ‘public-key authenticated encryption with keyword search’ (PAEKS) to avoid the insider keyword guessing attacks (IKGAs) in the previous PEKS schemes. However, all current PAEKS schemes are based on the discrete logarithm assumption and are therefore vulnerable to quantum attacks. In this study, we first introduce a generic PAEKS construction, with the assistance of a trusted authority, that enjoys the security against IKGA in the standard model, if all building blocks are secure under standard model. Based on the framework, we further propose a novel instantiation of quantum-resistant PAEKS that is based on NTRU assumption under random oracle. Compared with its state-of-the-art counterparts, the experiment result indicates that our instantiation is more efficient and secure.
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo, Yu-Chi Chen 0001
Comput. J.2
2022 Quantum-resistant anonymous identity-based encryption with trable identities
abstract
Abstract Identity‐based encryption (IBE), introduced by Shamir, eliminates the need for public‐key infrastructure. The sender can simply encrypt a message by using the recipient's identity (such as email or IP address) without needing to look up the public key. In particular, when ciphertexts of an IBE do not reveal recipient's identity, this scheme is known as an anonymous IBE scheme. Recently, Blazy et al. (ARES '19) analysed the trade‐off between public safety and unconditional privacy in anonymous IBE and introduced a new notion that incorporates traceability into anonymous IBE, called anonymous IBE with traceable identities (AIBET). However, their construction is based on the discrete logarithm assumption, which is insecure in the quantum era. In this paper, we first formalize the consistency of tracing key of the AIBET scheme to ensure that a ciphertext cannot be traced with the use of wrong tracing keys. Subsequently, we present a generic formulation concept that can be used to transform structure‐specific lattice‐based anonymous IBE schemes into an AIBET. Finally, we apply this concept to Katsumata and Yamada's compact anonymous IBE scheme (Asiacrypt '16) to obtain the first quantum‐resistant AIBET scheme that is adaptively secure under the ring learning with errors assumption without random oracle.
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo, Yu-Chi Chen 0001
IET Inf. Secur.2
2022 Extension of elliptic curve Qu-Vanstone certificates and their applications
abstract
In public key infrastructure, a certificate, issued by a certificate authority (CA), is used to guarantee the connection between a user and her/his public key. In order to improve the efficiency, the concept of implicit certificate protocol is introduced by Girault and Gönther. In the existing implicit certificate protocol, a user must issue a certificate request to the CA for each key pair. However, in certain applications (e.g., IoT, sensor networks, and cryptocurrency), a user (or a device) will have multiple public/private key pairs that are related to the same identity. Therefore, the communication cost will be linearly related to the number of key pairs the user has. Furthermore, the storage cost of a large number of certificates is not an ideal property in practice. In this paper, to address the above issues, we proposed two schemes from the most widely used elliptic curve Qu–Vanstone implicit certificate scheme (ECQV). In our first scheme, called M-ECQV I, an ECQV certificate holder, who obtains an ECQV certificate issued by the certificate authority, can further issue multiple credentials with the same identity as ECQV certificate holder and the corresponding key pairs from the ECQV certificate. In our second scheme, called M-ECQV II, it not only supports the comparable functionality of M-ECQV I, but the verifier can ensure that the credentials are only used by the ECQV certificate holder (i.e., these credential are “self-use”) to be suitable to different scenarios. In addition, the security models are well-defined and the rigorous security proofs are also given. Experimental results show that our schemes not only greatly improve the performance, but also reduce the storage cost.
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Peter Shaojui Wang, Qin-Wen Su
J. Inf. Secur. Appl.2
2022 Fast keyword search over encrypted data with short ciphertext in clouds
Yi-Fan Tseng, Chun-I Fan, Zi-Cheng Liu 0001
J. Inf. Secur. Appl.1
2022 Privacy-preserving bidirectional keyword search over encrypted data for cloud-assisted IIoT
Cheng-Yi Lee 0001, Zi-Yuan Liu, Raylin Tso, Yi-Fan Tseng
J. Syst. Archit.4
2022 ID-Based Multireceiver Homomorphic Proxy Re-Encryption in Federated Learning
abstract
Data privacy has become a growing concern with advances in machine learning. Federated learning (FL) is a type of machine learning invented by Google in 2016. In FL, the main aim is to train a high-accuracy global model by aggregating the local models uploaded by participants, and all data in the process are kept locally. However, compromises to security in the cloud server or among participants render this process insufficiently secure. To solve the problem, this article presents an identity-based multireceiver homomorphic proxy re-encryption (IMHPRE) scheme that utilizes homomorphism operations and re-encryption to provide improved encrypted-data processing and access control. When this scheme is employed, participants can directly use public identities for encryption. The IMHPRE scheme is also secure against the chosen-plaintext attacks. Comparison results indicated that the IMHPRE outperforms its counterparts because it allows a cloud server to perform model aggregation on re-encrypted models for multiple receivers.
Chun-I Fan, Ya-Wen Hsu, Cheng-Han Shie, Yi-Fan Tseng
ACM Trans. Sens. Networks4
2021 Designated-ciphertext searchable encryption
Zi-Yuan Liu, Yi-Fan Tseng, Raylin Tso, Masahiro Mambo
J. Inf. Secur. Appl.2
2021 Anonymous Multireceiver Identity-Based Encryption against Chosen-Ciphertext Attacks with Tight Reduction in the Standard Model
abstract
Multireceiver identity-based encryption is a cryptographic primitive, which allows a sender to encrypt a message for multiple receivers efficiently and securely. In some applications, the receivers may not want their identities to be revealed. Motivated by this issue, in 2010, Fan et al. first proposed the concept of anonymous multireceiver identity-based encryption (AMRIBE). Since then, lots of literature studies in this field have been proposed. After surveying the existing works, however, we found that most of them fail to achieve provable anonymity with tight reduction. A security proof with tight reduction means better quality of security and better efficiency of implementation. In this paper, we focus on solving the open problem in this field that is to achieve the ANON-IND-CCA security with tight reduction by giving an AMRIBE scheme. The proposed scheme is proven to be IND-MID-CCA and ANON-MID-CCA secure with tight reduction under a variant of the DBDH assumption. To the best of our knowledge, this is the first scheme proven with tight reducible full CCA security in the standard model.
Yi-Fan Tseng, Chun-I Fan
Secur. Commun. Networks1
2021 Private Predicate Encryption for Inner Product from Key-Homomorphic Pseudorandom Function
abstract
Predicate encryption (PE), formalized by Katz et al., is a new paradigm of public-key encryption that conceptually captures the public-key encryption that supports fine-grained access control policy. Because of the nature of PE, it is used for cloud storage so that users can retrieve encrypted data without revealing any information about the data to cloud servers and other users. Although lots of PE schemes have been studied, the predicate-hiding security is seldom considered; that is, the user’s secret key may leak sensitive information of the predicate. Additionally, the security of the current predicate-hiding PE schemes relies on the discrete logarithm assumption which cannot resist the quantum attacks in the future. In this paper, we propose a generic PE for inner product under symmetric-key setting, called private IPE, from specific key-homomorphic pseudorandom function (PRF). The rigorous proofs are provided to show that the construction is payload-hiding, attribute-hiding, and predicate-hiding secure. With the advantage of the generic construction, if the underlying PRF can resist quantum attacks, then, through our proposed generic construction, a quantum-resistant private IPE can be obtained.
Yi-Fan Tseng, Zi-Yuan Liu, Jen-Chieh Hsu, Raylin Tso
Secur. Commun. Networks1
2019 FGAC-NDN: Fine-Grained Access Control for Named Data Networks
abstract
Named data network (NDN) is one of the most promising information-centric networking architectures, where the core concept is to focus on the named data (or contents) themselves. Users in NDN can easily send a request packet to get the desired content regardless of its address. The routers in NDN have cache functionality to make the users instantly retrieve the desired file. Thus, the user can immediately get the desired file from the nearby nodes instead of the remote host. Nevertheless, NDN is a novel proposal and there are still some open issues to be resolved. In view of previous research, it is a challenge to achieve access control on a specific user and support potential receivers simultaneously. In order to solve it, we present a fine-grained access control mechanism tailored for NDN, supporting data confidentiality, potential receivers, and mobility. Compared to previous works, this is the first to support fine-grained access control and potential receivers. Furthermore, the proposed scheme achieves provable security under the DBDH assumption.
Yi-Fan Tseng, Chun-I Fan, Chin-Yu Wu
IEEE Trans. Netw. Serv. Manag.1
2016 Enabled/disabled predicate encryption in clouds
Shi-Yuan Huang, Chun-I Fan, Yi-Fan Tseng
Future Gener. Comput. Syst.3