Tran Viet Xuan Phuong

dblp:148/1452 · DBLP profile ↗
← Back
19ranked-venue papers
15as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 12 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2025 Practical Inner Product Encryption for Privacy-Preserved Internet-of-Things Applications
abstract
In recent years, we have witnessed a remarkable proliferation of Internet of Things (IoT) devices, which are quickly penetrating into almost every industry and making tremendous impacts on the national economy and the entire society. However, security and privacy remain a fundamental hurdle in the collection, transmission, and processing of IoT data. This work focuses on privacy-preserved data access that is critical for implementing and exploiting the full potential of future IoT. This work represents the first endeavor to develop practical Compact Inner Product Encryption (C-IPE) aiming to achieve privacy-preserved data access in IoTs. We propose a practical scheme that provides effective, fine-grained, and privacy-preserved access to IoT data while at the same time, is computationally efficient for practical deployment on resource-constrained IoT devices to preserve the designers of energy-efficient embedded systems and applications a balance between performance, power, security, and cost-effectiveness. We also analyze the efficiency of C-IPE. Compared with the original IPE, the key size is reduced from n + 1 to a small constant; the ciphertext size is reduced by half, i.e., from 2n + 2 to n + 1; and the decryption effectively avoids the high cost of cryptographic pairing. These salient properties result in high efficiency in computation and storage, making C-IPE well-suited for IoT applications. To demonstrate the practicality of our scheme, we implement C-IPE in three representative privacy-preserving applications: privacy-preserved attribute matching, distance matching, and linear regression in IoT settings. We carry out extensive experiments on four platforms, i.e., Dell workstation, Raspberry Pi 3 with an ARM Cortex processor, Samsung Galaxy 7, and ultra-low-power Arduino Nano 33 micro-controller using 32-bit ARM Cortex-M0 CPU with 256KB Flash and 16KB RAM. The experimental results demonstrate significant improvements over existing IPE schemes, supported by detailed numerical evidence and comparative figures across practical application settings.
Tran Viet Xuan Phuong, Dat H. Tran, Hongyi Wu
WISEC1
2024 Secure Lightweight Data Communication Between the IoT Devices and Cloud Service
Tran Viet Xuan Phuong, Tho Thi Ngoc Le, Huy Le Ngoc
AINA (2)1
2024 CFE: Secure Filtered Words in End-to-End Encrypted Messaging System
abstract
We introduce a new lightweight Symmetric Threshold Predicate Encryption (STPE) scheme, which expands the definition of Predicate Encryption. In STPE, the recipient’s private key evaluates only k predicates instead of all predicates on the sender’s encrypted data. The recipient can decrypt the data if at least k predicates are satisfied. As a new building block, we design a Content-Filtered Encryption (CFE) scheme based on STPE, which allows the sender to encrypt the message with the extracted words and the recipient to generate a filter with abusive words. The recipient can decrypt the message if the evaluation of extracted words and abusive words does not intersect more than a threshold k, where k is a flexible limit of sensitive words the recipient can accept. Otherwise, the recipient can refuse to read the message. It is essential for the recipient to generate a filter of abusive words beforehand; the incoming encrypted message will be delivered only if it bypasses this filter. Therefore, our proposed scheme enables secure filtering of words in the end-to-end encryption messaging protocol, which achieves selective security and efficiency for all communication devices. We prove that our STPE and CFE schemes are secure under the selected security assumptions. Furthermore, by utilizing the Pseudo-Random Function and XOR gate, our construction achieves lightweight computation, which benefits from the primitives of symmetric crypto mechanisms. We experimented on multiple devices, such as PCs and mobile devices. Additionally, our work demonstrates the feasibility across heterogeneous devices.
Tran Viet Xuan Phuong, Albert Baker, Philip D. Huff, Jan P. Springer, Tho Thi Ngoc Le
TrustCom1
2024 Anonymous attribute-based broadcast encryption with hidden multiple access structures
abstract
Abstract Due to the high demands of data communication, the broadcasting system streams the data daily. This service not only sends out the message to the correct participant but also respects the security of the identity user. In addition, when delivered, all the information must be protected for the party who employs the broadcasting service. Currently, Attribute-Based Broadcast Encryption (ABBE) is useful to apply for the broadcasting service. (ABBE) is a combination of Attribute-Based Encryption (ABE) and Broadcast Encryption (BE), which allows a broadcaster (or encrypter) to broadcast an encrypted message, including a predefined user set and specified access policy to install the authorization mechanism. It is desirable to hide all the information when producing in the ciphertext, which has not been considered in the previous works of ABBE. Motivated by the above issue, we devise a solution to achieve anonymity for the ABBE scheme, which not only hides the access structures but also anonymizes the user’s identity. In this work, we propose two schemes as Anonymous Key Policy (AKP)-ABBE and Anonymous Ciphertext Policy (ACP)-ABBE with supporting multiple access structures by using $$\textsf {OR}/\textsf {AND}$$ OR / AND gates. Specifically, we present the generic constructions of AKP/ACP-ABBE on the building block of the Inner Product Encryption ( $$\textsf {IPE}$$ IPE ), which enables the hidden user’s identity and complex $$\textsf {OR}/\textsf {AND}$$ OR / AND -Gate access structure. We show that our proposed schemes are secured under the standard models.
Tran Viet Xuan Phuong
Des. Codes Cryptogr.1
2021 Concise Mercurial Subvector Commitments: Definitions and Constructions
Yannan Li 0001, Willy Susilo, Guomin Yang, Tran Viet Xuan Phuong, Yong Yu 0002, Dongxi Liu
ACISP4
2021 Non-Equivocation in Blockchain: Double-Authentication-Preventing Signatures Gone Contractual
abstract
Equivocation is one of the most fundamental problems that need to be solved when designing distributed protocols. Traditional methods to defeat equivocation rely on trusted hardware or particular assumptions, which may hinder their adoption in practice. The advent of blockchain and decentralized cryptocurrencies provides an auspicious breakthrough paradigm to resolve the problem above. In this paper, we propose a blockchain-based solution to address contractual equivocation, which supports user-defined fine-grained policy-based equivocation. Specifically, users will be de-incentive if the statements they made breach the predefined access rules. The core of our solution is a newly introduced primitive named Policy-Authentication-Preventing Signature (PoAPS), which combined with a deposit mechanism allows a signer to make conflict statements corresponding to a policy to be penalized. We present a generic construction of PoAPS based on Policy-Based Verifiable Secret Sharing (PBVSS) and demonstrate its practicality via a concrete implementation in the blockchain. Compared with the existing solutions that only handle specific types of equivocation, our proposed approach is more generic and can be instantiated to deal with various kinds of equivocation.
Yannan Li 0001, Willy Susilo, Guomin Yang, Yong Yu 0002, Tran Viet Xuan Phuong, Dongxi Liu
AsiaCCS5
2021 SyLPEnIoT: Symmetric Lightweight Predicate Encryption for Data Privacy Applications in IoT Environments
Tran Viet Xuan Phuong, Willy Susilo, Guomin Yang, Jongkil Kim, Yang-Wai Chow, Dongxi Liu
ESORICS (2)1
2021 An Efficient Privacy Preserving Message Authentication Scheme for Internet-of-Things
abstract
As an essential element of the next generation Internet, Internet of Things (IoT) has been undergoing an extensive development in recent years. In addition to the enhancement of people's daily lives, IoT devices also generate/gather a massive amount of data that could be utilized by machine learning and big data analytics for different applications. Due to the machine-to-machine communication nature of IoT, data security and privacy are crucial issues that must be addressed to prevent different cyber attacks (e.g., impersonation and data pollution/poisoning attacks). Nevertheless, due to the constrained computation power and the diversity of IoT devices, it is a challenging problem to develop lightweight and versatile IoT security solutions. In this article, we propose an efficient, secure, and privacy-preserving message authentication scheme for IoT. Our scheme supports IoT devices with different cryptographic configurations and allows offline/online computation, making it more versatile and efficient than the previous solutions.
Jiannan Wei, Tran Viet Xuan Phuong, Guomin Yang
IEEE Trans. Ind. Informatics2
2019 Location Based Encryption
Tran Viet Xuan Phuong, Willy Susilo, Guomin Yang, Jun Yan 0005, Dongxi Liu
ACISP1
2019 Puncturable Proxy Re-Encryption Supporting to Group Messaging Service
Tran Viet Xuan Phuong, Willy Susilo, Jongkil Kim, Guomin Yang, Dongxi Liu
ESORICS (1)1
2018 Puncturable Attribute-Based Encryption for Secure Data Delivery in Internet of Things
abstract
While the Internet of Things (IoT) is embraced as important tools for efficiency and productivity, it is becoming an increasingly attractive target for cybercriminals. This work represents the first endeavor to develop practical Puncturable Attribute Based Encryption schemes that are light-weight and applicable in IoTs. In the proposed scheme, the attribute-based encryption is adopted for fine grained access control. The secret keys are puncturable to revoke the decryption capability for selected messages, recipients, or time periods, thus protecting selected important messages even if the current key is compromised. In contrast to conventional forward encryption, a distinguishing merit of the proposed approach is that the recipients can update their keys by themselves without key re-issuing from the key distributor. It does not require frequent communications between IoT devices and the key distribution center, neither does it need deleting components to expunge existing keys to produce a new key. Moreover, we devise a novel approach which efficiently integrates attribute-based key and punctured keys such that the key size is roughly the same as that of the original attribute-based encryption. We prove the correctness of the proposed scheme and its security under the Decisional Bilinear Diffie-Hellman (DBDH) assumption. We also implement the proposed scheme on Raspberry Pi and observe that the computation efficiency of the proposed approach is comparable to the original attribute-based encryption. Both encryption and decryption can be completed within tens of milliseconds.
Tran Viet Xuan Phuong, Rui Ning, Chunsheng Xin, Hongyi Wu
INFOCOM1
2018 Criteria-Based Encryption
abstract
We present a new type of public-key encryption called Criteria-based Encryption (or CE, for short). Different from Attribute-based Encryption, in CE, we consider the access policies as criteria carrying different weights. A user must hold some cases (or answers) satisfying the criteria and have sufficient weights in order to successfully decrypt a message. We then propose two CE Schemes under different settings: the first scheme requires a user to have at least one case for a criterion specified by the encryptor in the access structure, while the second scheme requires a user to have all the cases for each criterion. We prove that both schemes are secure under the Decisional q-Bilinear Diffie Hellman Exponent assumption without random oracles. In addition, we also present two special CE schemes for the above two settings without considering the weight requirement. We show that under this special case CE schemes can be constructed much more efficiently.
Tran Viet Xuan Phuong, Guomin Yang, Willy Susilo
Comput. J.1
2017 Sequence aware functional encryption and its application in searchable encryption
Tran Viet Xuan Phuong, Guomin Yang, Willy Susilo, Fuchun Guo, Qiong Huang 0001
J. Inf. Secur. Appl.1
2016 Edit Distance Based Encryption and Its Application
Tran Viet Xuan Phuong, Guomin Yang, Willy Susilo, Kaitai Liang
ACISP (2)1
2016 Hidden Ciphertext Policy Attribute-Based Encryption Under Standard Assumptions
abstract
We propose two new ciphertext policy attribute-based encryption (CP-ABE) schemes where the access policy is defined by AND-gate with wildcard. In the first scheme, we present a new technique that uses only one group element to represent an attribute, while the existing ABE schemes of the same type need to use three different group elements to represent an attribute for the three possible values (namely, positive, negative, and wildcard). Our new technique leads to a new CP-ABE scheme with constant ciphertext size, which, however, cannot hide the access policy used for encryption. The main contribution of this paper is to propose a new CP-ABE scheme with the property of hidden access policy by extending the technique we used in the construction of our first scheme. In particular, we show a way to bridge ABE based on AND-gate with wildcard with inner product encryption and then use the latter to achieve the goal of hidden access policy. We prove that our second scheme is secure under the standard decisional linear and decisional bilinear Diffie-Hellman assumptions.
Tran Viet Xuan Phuong, Guomin Yang, Willy Susilo
IEEE Trans. Inf. Forensics Secur.1
2015 Attribute Based Broadcast Encryption with Short Ciphertext and Decryption Key
Tran Viet Xuan Phuong, Guomin Yang, Willy Susilo, Xiaofeng Chen 0001
ESORICS (2)1
2014 POSTER: Efficient Ciphertext Policy Attribute Based Encryption Under Decisional Linear Assumption
abstract
We propose a new Ciphertext Policy Attribute Based Encryption(CP-ABE) scheme where access structures are defined by AND-Gates with wildcards. One major difference between our scheme and the existing ones is that we can use a single element to represent one attribute, while the previous schemes require three different elements to represent the three possible values (namely positive, negative, and wildcard) of an attribute. Our proposed scheme also achieves both constant-size ciphertext and constant number of decryption operations, and is proven secure under the standard Decision Linear Assumption.
Tran Viet Xuan Phuong, Guomin Yang, Willy Susilo
CCS1
2014 Efficient Hidden Vector Encryption with Constant-Size Ciphertext
Tran Viet Xuan Phuong, Guomin Yang, Willy Susilo
ESORICS (1)1
2014 A DFA-Based Functional Proxy Re-Encryption Scheme for Secure Public Cloud Data Sharing
abstract
In this paper, for the first time, we define a general notion for proxy re-encryption (PRE), which we call deterministic finite automata-based functional PRE (DFA-based FPRE). Meanwhile, we propose the first and concrete DFA-based FPRE system, which adapts to our new notion. In our scheme, a message is encrypted in a ciphertext associated with an arbitrary length index string, and a decryptor is legitimate if and only if a DFA associated with his/her secret key accepts the string. Furthermore, the above encryption is allowed to be transformed to another ciphertext associated with a new string by a semitrusted proxy to whom a re-encryption key is given. Nevertheless, the proxy cannot gain access to the underlying plaintext. This new primitive can increase the flexibility of users to delegate their decryption rights to others. We also prove it as fully chosen-ciphertext secure in the standard model.
Kaitai Liang, Man Ho Au, Joseph K. Liu, Willy Susilo, Duncan S. Wong, Guomin Yang, Tran Viet Xuan Phuong
IEEE Trans. Inf. Forensics Secur.7