EDBT 2026 Demo / reviewers in the wild / expert
Jinyong Chang
dblp:151/7156
· DBLP profile ↗
35ranked-venue papers
14as first author
18since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 15 · 4 first-author · 13 since 2021Security and privacy · 12 · 5 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 1 since 2021Systems, architecture and hardware · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Blockchain-based proof of retrievability scheme with data deduplication function for cloud storage
Peiru Yang, Jinyong Chang, Youtong Wang, Yanyan Ji |
Comput. Networks | 2 |
| 2026 | Fog-assisted data integrity auditing scheme with deduplication function for cloud storage
Jinyong Chang, Yanyan Ji |
Comput. Secur. | 2 |
| 2026 | Assistant-Based Integrity Auditing Scheme With Privacy Protection Function for Cloud StorageabstractCloud audit scheme is a mechanism for verifying the integrity of user data stored on cloud servers. Existing audit schemes often require data owner (DO) to generate tags, which will be used in the later audit phase, on the data files to be stored itself. However, this mode still has the following issues: (1) The calculation and generation process of tags imposes a significant computational burden on DO; (2) Frequent use of private key for tag generation exposes it to increased security risks. To address these issues, this paper proposes an assistant-based tag collaborative generation process. Specifically, we introduce an assistant that holds a key derived from the DO’s private key and performs the bulk of the tag computation. In this way, the DO only needs to carry out a few lightweight operations to complete the final authentication tag. Moreover, the DO can revoke or update the assistant at any time without changing the original public/secret key pair. In addition, in order to achieve privacy protection against auditor during the audit process, this paper also proposes a transparent audit based on Blockchain. Finally, the security analysis indicates that our scheme achieves the required security in terms of cloud audit reliability, tag collaborative computing security, and privacy protection. The performance analysis also shows that it has certain advantages compared to similar schemes, especially in saving DO’s computation costs. Kaijing Ling, Jinyong Chang, Ru Meng |
IEEE Internet Things J. | 3 |
| 2026 | Blockchain-Assisted Integrity Auditing Scheme With Key-Exposure Resistance in Cloud Storage SettingabstractA cloud audit scheme is a security mechanism that helps cloud users detect whether their data stored on cloud servers is integral. The issue of key exposure is a serious security threat to cloud audit scheme. The reason lies in that once the user’s authentication key is exposed, most existing audit schemes will become insecure. Meanwhile, existing implementation schemes often introduce third-party auditor (TPA) to assist users in performing audit tasks, and even to update user’s key against key-exposure attacks. However, it is well-known that TPA’s core function is to perform audit tasks and it is not entirely trustworthy. The key update operation based on TPA is not realistic in practical applications. In this article, we propose an identity-based cloud auditing scheme, which resists key-exposure attack by regularly issuing new secret keys to users by the key generation center. The identity-based property guarantees that user’s public identity is unchanged. Moreover, in order to prevent TPA from obtaining users’ stored data content through the audit process, an audit mechanism based on the smart contracts of Blockchain will also be given. In addition, introducing a “two-dimensional” partitioning mechanism on data file can greatly reduce the burden of tag generation. Finally, security and performance analyses will be conducted on the proposed scheme. The results show that our scheme has good properties in terms of key-exposure resilience and privacy-protection on stored data, and also has good performance advantages in the implementation process. Jinyong Chang, Kaijing Ling |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | Certificate-based remote auditing protocol with privacy protection and deduplication functions for cloud-assisted applications
Jinyong Chang, Yangxi Chen |
Comput. Networks | 2 |
| 2025 | Identity-Based Integrity Auditing Scheme With Sensitive Information Hiding for Proxy-Server-Assisted Cloud Storage ApplicationsabstractIn recent years, the model of storing personal local data on cloud servers to save local space has become popular. However, this model also has certain security risk: the data stored in the cloud may be accidentally damaged or lost. How to perform remote integrity audit of these data is a meaningful research problem. Many current auditing schemes rely on the encryption of the entire data file to ensure data’s privacy, and the tag-generation of data owner (DO) itself, which bring a significant computational burden to the DO. In this article, we propose a technique of only blinding sensitive locations of user data without encrypting the entire file to improve the computational efficiency of current cloud auditing schemes. At the same time, it is also proposed to delegate the generation process of authentication tags to a proxy server (PS) to save DO’s computing resource. Then the integrity audit process is based on stored data file as well as PS’s authentication tags. In addition, the access control strategy of data user (DU)-request-then-DO-authorization has been implemented to facilitate the sharing of stored data, where DU means data user. Finally, security and performance analyses were conducted on the proposed system. The results indicate that our system is provably secure under classical cryptographic assumption and has certain performance advantages compared with related works. Xinran Hu, Jinyong Chang, Funing Zhang |
IEEE Internet Things J. | 2 |
| 2025 | Private-Set-Intersection-Based Medical Data Sharing Scheme With Integrity Auditing for IoMT Cloud Storage SystemsabstractIn recent years, the medical industry is generating a large amount of data. How to securely store and reliably share these medical data has been a hot research topic. Cloud storage technology can be applied to the medical industry to adapt to the rapid growth of medical data. However, cloud-based data storage and sharing systems face a series of security issues: whether the integrity of outsourced medical data can be guaranteed, and malicious access between different medical institutions may leak user's privacy. This article proposes a system that simultaneously solves the integrity auditing of medical data and securely data sharing between different medical institutions under the terminal-edge-cloud framework. Specifically, patients/doctors are treated as terminal users, medical institutions are viewed as edge nodes, and medical clouds form the central storage layer. In the process of data auditing, third-party auditor can achieve integrity auditing of medical cloud storage data. Moreover, different medical institutions use private-set-intersection technology to share the common user's electronic medical data, while for other users not in intersection set, their data does not need to be shared. Finally, security and performance analyses show that our proposed system is provable secure and has high computational and communication efficiency. Zekun Li 0013, Jinyong Chang, Bei Liang, Kaijing Ling, Yanyan Ji, Maozhi Xu |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2024 | Secure data sharing scheme with privacy-preserving and certificateless integrity auditing in cloud storage
Xuening Guan, Jinyong Chang |
Comput. Commun. | 2 |
| 2024 | LFTDA: A lightweight and fault-tolerant data aggregation scheme with privacy-enhanced property in fog-assisted smart grid
Funing Zhang, Anling Zhang, Jinyong Chang |
Comput. Commun. | 4 |
| 2024 | Certificateless Dynamic Data Sharing Scheme With File Recommendation and Integrity Auditing Functions in Cloud-Fog EnvironmentabstractIn the fog assisted cloud storage environment, data owners can share data efficiently and conveniently. It solves the network congestion problem in the traditional cloud centric sharing mode. In recent research work, Tian et al. proposed an identity-based cloud–fog data sharing scheme [Computers & Security, 105(2021), ID: 102245]. This scheme proposes the concept of “valid auditing” for the storage of cloud–fog data for the first time, and improves the efficiency of auditing in the data sharing process based on user behavior prediction. However, carefully study their scheme, it was found that the data sharing scheme has an audit vulnerability: the cloud server does not need to store the original data after observing system parameters, but can still return a proof that can pass the verification of the auditor. Therefore, in this article, the security analysis of Tian et al.’s work is first presented. Meanwhile, to avoid key escrow attack in identity-based data sharing mechanisms, this article proposes a certificateless scheme. In addition, our proposed scheme also supports efficient dynamic updates and privacy protection against the third-party auditor. More importantly, this article adopts a data file recommendation algorithm that is more suitable for cloud–fog environments and has higher accuracy than the scheme of Tian et al. Finally, behavior analysis and security analysis indicate that the proposed scheme has high efficiency and good security and is suitable for convenient data sharing in cloud–fog environment. Jinyong Chang |
IEEE Internet Things J. | 1 |
| 2024 | Efficient Key-Escrow-Free and Vehicle-Revocable Data Sharing Protocol for Vehicular Ad Hoc NetworkabstractVehicular ad hoc network (VANET), as an important part of intelligent transportation system, attracts more and more attention since it can provide communication about traffic and vehicle conditions, and optimize the transportation. It is noted that it also faces a series of security challenges. One of core issues is how to achieve secure data sharing and access control. Ciphertext-policy attribute-based encryption (CP-ABE) technique is often used to achieve these goals simultaneously. However, in the execution process of applying CP-ABE to VANET, there are two crucial issues that need to be resolved. One is key-escrow issue, which means that all vehicles’ secret keys will be leaked once if the central attribute authority (CAA) is compromised, and another is the revocation issue of departing vehicles from current region. In order to resolve these two issues simultaneously, in this paper, we propose an efficient data sharing protocol for VANET with the key-escrow-free and vehicle-revocable properties. More specifically, we design a sub-protocol between CAA and vehicles, which interactively issues secret keys for these vehicles. But CAA does not know any user’s true secret key, which guarantees that it is still secure even if CAA is compromised. In addition, we additionally introduce an entity named group manager, which manages and updates the unrevoked users in the current group. In order to improve the efficiency of the whole system, we adopt the online/offline encryption method for data owner and outsourced decryption technique for the resource-constraint data users. Finally, the performance analysis show that our proposed protocol is competitive in the phases of online encryption, key generation and CAA-setup, and thus is useful in the practical applications of VANET. Tongda Liu, Zekun Li 0013, Yanyan Ji, Jinyong Chang |
IEEE Internet Things J. | 4 |
| 2024 | Efficient Data Sharing Scheme With Fine-Grained Access Control and Integrity Auditing in Terminal-Edge-Cloud NetworkabstractIn recent years, terminal-edge-cloud frame-work is very popular since it combines the storage ability of cloud servers with the advantages of timely response of edge nodes. How to realize the secure and fast data transmission from the terminal device to the edge node under the premise of weak computational ability and limited storage space for terminal devices, how to ensure that the original data can be securely obtained by authorized users, and how to efficiently audit the integrity of data in the cloud storage are still challenging issues. Although Zhang et al. designed a data sharing scheme, which is based on blockchain and hybrid encryption model, and simultaneously considers these issues, the security and performance of this scheme can be greatly improved. The reason lies in that the storage of symmetric key on blockchain will result in its potential leakage once one entity among the Chain becomes dishonest. Therefore, this article proposes a new data sharing protocol. In our protocol, lightweight symmetric encryption is first used to securely transmit data between terminal devices and edge nodes. Secondly, the edge node uses CPABE technology to encrypt the original data collected by the terminal device. Only authorized users who meet the access policy can correctly recover the data, thus ensuring the fine-grained access control. In addition, in the integrity audit process of stored data, authentication based on homomorphic signatures is adopted to achieve efficient auditing based on third-party auditors. Finally, simulation of the entire data sharing system reveals that our proposed protocol is relatively efficient and competitive in future IoT applications. Jinyong Chang, Anling Zhang |
IEEE Internet Things J. | 2 |
| 2022 | Secure medical data management with privacy-preservation and authentication properties in smart healthcare system
Jinyong Chang, Qiaochuan Ren, Yanyan Ji, Maozhi Xu, Rui Xue 0001 |
Comput. Networks | 1 |
| 2022 | Certificateless public auditing scheme with designated verifier and privacy-preserving property in cloud storage
Jinyong Chang |
Comput. Networks | 2 |
| 2022 | The differential fault analysis on block cipher FeWabstractAbstract Feather weight (FeW) cipher is a lightweight block cipher proposed by Kumar et al. in 2019, which takes 64 bits plaintext as input and produces 64 bits ciphertext. As Kumar et al. said, FeW is a software oriented design with the aim of achieving high efficiency in software based environments. It seems that FeW is immune to many cryptographic attacks, like linear, impossible differential, differential and zero correlation attacks. However, in recent work, Xie et al. reassessed the security of FeW. More precisely, they proved that under the differential fault analysis (DFA) on the encryption states, an attacker can completely recover the master secret key. In this paper, we revisit the block cipher FeW and consider the DFA on its key schedule algorithm, which is rather popular cryptanalysis for kinds of block ciphers. In particular, by respectively injected faults into the 30th and 29th round subkeys, one can recover about 55/80 ≈ 69% bits of master key. Then the brute force searching remaining bits, one can obtain the full master secret key. The simulations and experiment results show that our analysis is practical. Haiyan Xiao, Jinyong Chang |
Cybersecur. | 3 |
| 2022 | Public auditing protocol with dynamic update and privacy-preserving properties in fog-to-cloud-based IoT applications
Jinyong Chang, Maozhi Xu, Rui Xue 0001 |
Peer-to-Peer Netw. Appl. | 1 |
| 2022 | Comment on "A Lightweight Auditing Service for Shared Data With Secure User Revocation in Cloud Storage"abstractRecently, Rabaninejadet al.(2019) proposed an excellent auditing protocol for shared data (CoRPA, for short) [IEEE Trans. Ser. Comp., DOI 10.1109/TSC.2019.2919627], which has many better properties, like the identity-privacy, collusion resistant, efficient user revocation and supporting dynamic update etc. In addition, they also presented the detailed security analysis for CoRPA and described the reduction from the soundness of CoRPA to discrete logarithm assumption. However, in this article, we analyze their original security reduction (to discrete logarithm) and find out that it is incorrect and misleading. That is, the soundness of CoRPA cannot be obtained from the discrete logarithm assumption. Now, we give a new proof for their CoRPA based on the square-CDH assumption, which is also used by them to prove the security of homomorphic proxy re-signature scheme. We also hope the new security proof will provide theoretical guarantee when using CoRPA in practical scenes. Jinyong Chang, Bilin Shao, Yanyan Ji, Genqing Bian |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | Secure network coding from secure proof of retrievability
Jinyong Chang, Bilin Shao, Yanyan Ji, Maozhi Xu, Rui Xue 0001 |
Sci. China Inf. Sci. | 1 |
| 2020 | Certificateless Homomorphic Signature Scheme for Network CodingabstractHomomorphic signature is an extremely important public key authentication technique for network coding to defend against pollution attacks. As a public key cryptographic primitive, it also encounters the same problem of how to confirm the relationship between some public key pk and the identity ID of its owner. In the setting of distributed network coding, the intermediate and destination nodes need to use the public key of source node S to check the validity of vector-signature pairs. Therefore, the binding of S and its corresponding public key becomes crucial. The popular and traditional solution is based on certificates which are issued by a trusted certification authority (CA) center. However, the generation and management of certificates is extremely cumbersome. Hence, in recent work, Lin et al. proposed a new notion of identity-based homomorphic signature, which intends to avoid using certificates. But the key escrow problem is inevitable for identity-based primitives. In this article, we propose another new notion (for network coding): certificateless homomorphic signature (CLHS), which is a compromise for the above two techniques. In particular, we first describe the definition and security model of certificateless homomorphic signature. Then based on bilinear map and the computational Diffie-Hellman (CDH) assumption, give a concrete implementation and detailedly analyze its security. Finally, performance analysis illustrates that our construction is practical. Jinyong Chang, Yanyan Ji, Bilin Shao, Maozhi Xu, Rui Xue 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2020 | Comment on "A Tag Encoding Scheme Against Pollution Attack to Linear Network Coding"abstractIn 2014, Wu et al. proposed a tag encoding scheme, named KEPTE, to protect network coding against pollution attack. They also carefully analyzed the security of KEPTE based on the transmission of a data file through their key-pre-distributed network. In this article, we point out that their security analysis only holds for single data file transmitted in this network. If multiple files are multicasted though it, then any adversary may completely recover source node's signing key. A concrete example says that, after pre-distributing 90 keys to all the nodes in the network, it only allows to securely transmit (at most) 3 data files. More importantly, this scheme is completely insecure in standard security model for network model since the adversary is allowed to make polynomial times queries on any data files of its choice before outputting its final forgery. Finally, we also propose a twisted KEPTE scheme that is secure against any eavesdropping adversary no matter how many data files it has queried. Jinyong Chang, Bilin Shao, Yanyan Ji, Genqing Bian |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2019 | On the KDM-CCA Security from Partial Trapdoor One-Way Family in the Random Oracle ModelabstractAbstract In PKC 2000, Pointcheval presented a generic technique to make a highly secure cryptosystem from any partially trapdoor one-way function in the random oracle model. More precisely, any suitable problem providing a one-way cryptosystem can be efficiently derived into a chosen-ciphertext attack (CCA) secure public key encryption (PKE) scheme. In fact, the overhead only consists of two hashing and a XOR. In this paper, we consider the key-dependent message (KDM) security of the Pointcheval’s transformation. Unfortunately, we do not know how to directly prove its KDM-CCA security because there are some details in the proof that we can not bypass. However, a slight modification of the original transformation (we call twisted Pointcheval’s scheme) makes it possible to obtain the KDM-CCA security. As a result, we prove that the twisted Pointcheval’s scheme achieves the KDM-CCA security without introducing any new assumption. That is, we can construct a KDM-CCA secure PKE scheme from partial trapdoor one-way injective family in the random oracle model. Jinyong Chang, Genqing Bian, Yanyan Ji, Maozhi Xu |
Comput. J. | 1 |
| 2019 | General transformations from single-generation to multi-generation for homomorphic message authentication schemes in network coding
Jinyong Chang, Yanyan Ji, Maozhi Xu, Rui Xue 0001 |
Future Gener. Comput. Syst. | 1 |
| 2019 | KDM security for identity-based encryption: Constructions and separations
Yu Chen 0003, Jiang Zhang 0001, Yi Deng 0002, Jinyong Chang |
Inf. Sci. | 4 |
| 2018 | On the RCCA Security of Hybrid Signcryption for Internet of ThingsabstractWith the rapid development of the Internet of Things (IoT), a lot of sensitive information in our daily lives are now digitalized and open to remote access. The provision of security and privacy of such data would incur comprehensive cryptographic services and has raised wide concern. Hybrid signcryption schemes could achieve various kinds of cryptographic services (e.g., confidentiality, authenticity, and integrity) with much lower cost than the combination of separate traditional cryptographic schemes with each providing a single cryptographic service. Thus, hybrid signcryption schemes are very suitable for IoT environments where resources are generally very constrained (e.g., lightweight sensors and mobile phones). To ensure that the overall hybrid signcryption scheme provides adequate cryptographic service (e.g., confidentiality, integrity, and authentication), its parts of KEM (key encryption mechanism) and DEM (data encryption mechanism) must satisfy some security requirements. Chosen‐ciphertext attack (CCA) security has been widely accepted as the golden standard requirement for general encryption schemes. However, CCA security appears too strong in some conditions. Accordingly, Canetti et al. (CRYPTO 2003) proposed the notion of replayable CCA security (RCCA) for encryption schemes, which is a strictly weaker security notion than CCA security and naturally more efficient. This new security notion has proved to be sufficient for most existing applications of CCA security, e.g., encrypted password authentication. This is particularly promising for IoT environments, where security is demanding, yet resources are constrained. In this paper, we examine the RCCA security of the well‐known SKEM+DEM style hybrid signcryption scheme by Dent at ISC 2005. Meanwhile, we also examine the RCCA security of the Tag‐SKEM+DEM style hybrid signcryption scheme by Bjorstad and Dent at PKC 2006. We rigorously prove that a hybrid signcryption scheme can achieve RCCA security if both its SKEM part and its DEM part satisfy some security assumptions. Honglong Dai, Ding Wang 0002, Jinyong Chang, Maozhi Xu |
Wirel. Commun. Mob. Comput. | 3 |
| 2017 | The KDM-CCA Security of REACT
Jinyong Chang, Honglong Dai, Maozhi Xu |
ISPEC | 1 |
| 2017 | The ECCA Security of Hybrid Encryptions
Honglong Dai, Jinyong Chang, Zhenduo Hou, Maozhi Xu |
ISPEC | 2 |
| 2017 | Homomorphic MAC from Algebraic One-Way Functions for Network Coding with Small Key SizeabstractNetwork coding is a routing technique that differs from traditional ‘store-and-forward’ mechanisms. It allows intermediate nodes to modify packets in transit. It is well known that network coding can increase throughput and improve robustness in network. However, it is the messages mixing feature that makes network coding susceptive to pollution attacks. To address this problem, homomorphic message authentication codes (MACs) have been proposed. The existing homomorphic MAC schemes adopt inner product to authenticate a message with a tag over a field Fq. In practical instantiations, the size of the field Fq is normally chosen (or desired) to be small (typically set as 28) to limit computational and communication overheads. In these settings, an adversary will break the schemes with probability at least 1/q (typically 1/28). The security is not guaranteed in this case. To waver the limitations and enhance the security, multiple tags are adopted for each message, that certainly incurs large key size overhead and is not preferred in applications. A scheme of homomorphic MAC with preferring security and shorter keys is much expected, and till now, to our knowledge, is not successfully constructed. This work solves this problem by presenting a new homomorphic MAC scheme for authentication in network coding. The proposed scheme allows us to authenticate a message in a linear space over a field of moderate size and at the same time, achieves a reliable security with a short key. The construction is based on a recently invented somewhat public-key notion: algebraic one-way function, by Catalano et al. (TCC 2013). Compared to the existing schemes, our scheme possesses the advantages that it achieves stronger security with much shorter keys, and is practical in applications. Hence resolve the longstanding problem. Ying Wu 0008, Jinyong Chang, Rui Xue 0001, Rui Zhang 0016 |
Comput. J. | 2 |
| 2016 | Security analysis of a TESLA-based homomorphic MAC scheme for authentication in P2P live streaming systemabstractIn this paper, we present a pollution attack on the homomorphic message authentication code scheme PMAC, which was proposed, by Cheng, Jiang, and Zhang in [IEEE Journal on Selected Areas in Communications/Supplement 2013; 319: 291-298]. In particular, Cheng et al. claimed that their main contribution lies in that, compared with the existing scheme, such as SpaceMac, PMAC can achieve a reliable security 1/qi?ź instead of 1/q for SpaceMac, where q is usually set as a small number in practical applications and i?ź is a flexible parameter chosen by users to improve their security level. However, by presenting a pollution attack, we prove that PMAC can only achieve the security at most 1/q no matter how large i?ź is. Our attack shows that it may be dangerous to directly use PMAC in the peer-to-peer live streaming systems. Moreover, we also point out a basic but fatal error in their proof of theorem 1 and hope that by identifying the design flaw, similar mistakes can be avoided in future design of homomorphic message authentication code. Copyright © 2016 John Wiley & Sons, Ltd. Jinyong Chang, Honglong Dai, Maozhi Xu, Rui Xue 0001 |
Secur. Commun. Networks | 1 |
| 2016 | Separations in circular security for arbitrary length key cycles, revisitedabstractAbstract The circular security of public key encryptions has been drawn great attentions in recent years. The relationship of notions between circular securities and standard ones such as chosen plaintext security (CPA‐security) and chosen ciphertext security (CCA‐security) deserve to be clarified. For any integer n > 0 and n ≠ 2, whether the notions of n‐circular securities can be implied by that of their standard correspondences, such as CPA or CCA security in public key setting, has largely remained open. Koppula, Ramchen, and Waters in TCC'15 recently made a separation in CPA case by proposing a CPA secure scheme that is not n‐circular secure based on the recent candidate constructions of indistinguishable obfuscation. In this work, we consider the CCA case. In particular, inspired by the indistinguishable‐obfuscation‐based construction of Koppula et al., we obtain the following results: We make a separation between the n‐circular CCA security and CCA security for anyn>0. Specifically, we propose a hybrid encryption scheme that achieves the CCA security but fails even in the n‐circular CPA security. Hence, that makes a separation between the CCA security and the n‐circular CCA security (and even the n‐circular CPA security). By revising the previous construction, we also present a CCA secure (hybrid encryption) scheme, which allows an adversary to recover all secret keys when obtaining an encrypted key cycle. Hence, that implies that: if a key cycle arises in a system, then a passive adversary might be able to recover all secret keys even if CCA‐secure encryptions are used. The results in this work, together with that of Koppula et al., confirm that notions of circular securities are stronger than their standard correspondences. Copyright © 2016 John Wiley & Sons, Ltd. Jinyong Chang, Honglong Dai, Maozhi Xu, Rui Xue 0001 |
Secur. Commun. Networks | 1 |
| 2015 | Verifiable Random Functions from (Leveled) Multilinear Maps
Bei Liang, Hongda Li 0001, Jinyong Chang |
CANS | 3 |
| 2015 | Verifiable Proxy Re-encryption from Indistinguishability Obfuscation
Muhua Liu, Ying Wu 0008, Jinyong Chang, Rui Xue 0001 |
ICICS | 3 |
| 2015 | The Generic Transformation from Standard Signatures to Identity-Based Aggregate Signatures
Bei Liang, Hongda Li 0001, Jinyong Chang |
ISC | 3 |
| 2015 | Constrained Verifiable Random Functions from Indistinguishability Obfuscation
Bei Liang, Hongda Li 0001, Jinyong Chang |
ProvSec | 3 |
| 2015 | Practical key-dependent message chosen-ciphertext security based on decisional composite residuosity and quadratic residuosity assumptionsabstractAbstract An encryption scheme is key‐dependent message chosen plaintext attack (KDM‐CPA) secure if it is secure even against an attacker who has access to encryptions of messages that depend on the secret key. Such situations naturally occur in some scenarios such as formal calculus, hard‐disk encryption, or multi‐party protocols. However, up to now, there are not many schemes that achieve KDM‐CPA security, let alone KDM chosen ciphertext attack (KDM‐CCA) security. The constructions proposed by Camenisch, Chandran, and Shoup (Eurocrypt 2009), and Hofheinz (Eurocrypt 2013) are the only two general constructions that can be proved to be KDM‐CCA secure in the standard model. Besides, Qin, Liu, and Huang (ACISP 2013) also presented another concrete implementation. In particular, they showed how to obtain KDM‐CCA security from the classic Cramer–Shoup cryptosystem (based on the decisional Diffie–Hellman assumption) w.r.t. a new ensemble of functions (we call QLH ensemble). Since the Cramer–Shoup scheme has short ciphertext size and higher computational efficiency, they obtain practical KDM‐CCA security w.r.t. a reasonably large ensemble. In this paper, we study the KDM‐CCA security of other cryptosystems proposed by Cramer and Shoup (Eurocrypt 2002). In particular, we prove that the schemes, based on decisional composite residuosity (DCR) and quadratic residuosity (QR) assumptions, respectively, also achieve KDM‐CCA security w.r.t. the QLH ensemble. On the one hand, because the DCR‐based and QR‐based schemes of Cramer et al. are fairly practical, we also obtain practical KDM‐CCA security based on DCR and QR assumptions, respectively. On the other hand, compared with the result of Qin et al., we need not tailor the original schemes of Cramer et al. because themselves have natural “compatibility” for the message space and the secret key space. Copyright © 2014 John Wiley & Sons, Ltd. Jinyong Chang, Rui Xue 0001 |
Secur. Commun. Networks | 1 |
| 2014 | KDM-CCA Security of the Cramer-Shoup Cryptosystem, RevisitedabstractAn encryption scheme is key-dependent message chosen plaintext attack (KDM-CPA) secure means that it is secure even if an adversary obtains encryptions of messages that depend on the secret key. However, there are not many schemes that are KDM-CPA secure, let alone key-dependent message chosen ciphertext attack (KDM-CCA) secure. So far, only two general constructions, due to Camenisch, Chandran, and Shoup (Eurocrypt 2009), and Hofheinz (Eurocrypt 2013), are known to be KDM-CCA secure in the standard model. Another scheme, a concrete implementation, was recently proposed by Qin, Liu and Huang (ACISP 2013), where a KDM-CCA secure scheme was obtained from the classic Cramer-Shoup (CS) cryptosystem w.r.t. a new family of functions. In this paper, we revisit the KDM-CCA security of the CS-scheme and prove that, in two-user case, the CS-scheme achieves KDM-CCA security w.r.t. richer ensembles, which covers the result of Qin et al. In addition, we present another proof about the result in (QLH13) by extending our approach used in two-user case to n-user case, which achieves a tighter reduction to the decisional Diffie-Hellman (DDH) assumption. Jinyong Chang, Rui Xue 0001 |
SECRYPT | 1 |