EDBT 2026 Demo / reviewers in the wild / expert
Qingyang Zhang 0001
dblp:157/9827-1
· DBLP profile ↗
50ranked-venue papers
18as first author
44since 2021 · last 2026
0000-0002-2600-6748ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 18 · 6 first-author · 17 since 2021Systems, architecture and hardware · 17 · 5 first-author · 13 since 2021Security and privacy · 12 · 6 first-author · 12 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Blockchain-Assisted Proxy Re-Encryption Scheme With Revocation for Federal DiagnosticsabstractFederated diagnosis, a concept emerging in Internet of Things (IoT)-based e-health systems, addresses the interconnectivity challenges of medical resources across different regions. Furthermore, flexible access control is required, which allows users to modify the access policy for encrypted data in the cloud without revealing sensitive information. Current solutions rely on third parties for policy modification, incur high computational overheads during user revocation, and expose user attributes to plaintext access policies. To address these issues, this study introduces a blockchain-assisted revocable federated diagnostic ciphertext policy attribute-based encryption (RFD-CPABE) scheme that enables policy conversion and revocation, which allows users to convert attribute-based encryption ciphertext to inner product encryption ciphertext swiftly and facilitates fast revocation using binary trees. This scheme enhances privacy protection by separating attribute names from values, thus concealing sensitive information within the access policies. Moreover, to reduce the computational burden on trusted institutions, the workload is decentralized utilizing a blockchain to minimize the pressure on the central servers. The formal security proof demonstrates the resilience of the scheme against selective chosen-plaintext attacks, and the experimental analysis confirms its superior efficiency compared to existing solutions. Qingyang Zhang 0001, Jie Cui 0004, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Internet Things J. | 1 |
| 2026 | Runtime Threshold Signature-Based Unmanned Aerial Vehicle Swarm Authentication With Autonomous Splitting SupportabstractRecently, unmanned aerial vehicles (UAVs) have undergone rapid development, demonstrating significant potential in various fields, including logistics, military operations, and entertainment. By collaborating to form swarms, UAVs can undertake more complex tasks such as mapping and disaster relief. To address the limited flexibility of UAV swarm identity authentication and the requirement for swarm splitting during task execution, we propose a runtime threshold signature (RTS) scheme. Unlike traditional threshold signatures, RTS defers the selection of the threshold from the initialization phase to the signing phase, allowing verifiers to dynamically adjust the threshold as required, thus achieving an effective balance between efficiency and security. Moreover, the RTS has the same signature size as the Schnorr signature, which is a non-interactive threshold signature. Building on the RTS primitive, we designed a novel identity authentication scheme that supports the autonomous splitting of UAV swarms. This scheme enables secure swarm-level identity authentication while adapting naturally to dynamic swarm restructuring. Furthermore, we demonstrate that the proposed scheme satisfies unforgeability under the t-VCDH assumption. To evaluate its performance, we implemented our scheme in C++ on AmovLab Prometheus 600 (P600) UAVs and assessed it under varying network latency and bandwidth conditions. Comparative results with existing schemes demonstrate that our approach achieves lower computational overhead and high practical applicability. Notably, even with the threshold set to 128, the authentication process takes only 2.6 ms per UAV. Mingwei Zeng, Hong Zhong 0001, Qingyang Zhang 0001, Fengqun Wang, Jiaxin Li 0001, Jie Cui 0004 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | MPDA-HPR: Multi-Dimensional Privacy-Preserving Data Aggregation Based on Homomorphic Proxy Re-Encryption for Industrial Internet of ThingsabstractAs modern communication technologies advance, the Industrial Internet of Things (IIoT) is progressively evolving towards greater intelligence. The extensive implementation of smart grids has significantly affected IIoT factories. Data aggregation is commonly used to protect the factory's privacy. However, existing multi-dimensional data aggregation schemes lack flexibility and are vulnerable to internal attacks, where private data from certain smart devices may be decrypted by insiders. Moreover, replacing related devices necessitates updating the keys of the entire system, which incurs heavy overhead. To address these issues, a multi-dimensional privacy-preserving data aggregation scheme based on homomorphic proxy re-encryption (MPDA-HPR) is proposed. Using a modified Paillier encryption algorithm supported by proxy re-encryption and super-increasing sequences, the proposed scheme enhances flexibility and scalability. Security analyses demonstrate that the proposed scheme can withstand various security threats and effectively preserve the privacy of devices. Finally, the prototype is implemented and evaluated, demonstrating that the proposed scheme is robust, efficient, and feature-rich. Qingyang Zhang 0001, Jie Cui 0004, Hulin Jin, Fengqun Wang, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Anonymous Integrity Auditing Scheme Based on Trusted Execution Environment for Distributed Edge ComputingabstractMulti-replica data storage is widely adopted in edge computing to improve both data availability and access efficiency for latency-sensitive applications. Integrity auditing is a critical mechanism for ensuring data reliability in this distributed setting. However, existing schemes face a trade-off between security and efficiency: ensuring replica authenticity typically requires users to generate unique tags for all copies, creating a bottleneck for resource-constrained devices. Delegation schemes reduce this burden but struggle to prevent collusion or on-the-fly generation attacks. Therefore, this study proposes ATRIA to resolve this dilemma. Uniquely, ATRIA leverages the Trusted Execution Environments (TEEs) not only for isolation but to securely offload the intensive replica tag generation from the user, ensuring authentic physical storage with minimal user overhead. By leveraging the hardware isolation of the TEEs, this mechanism ensures authentic physical storage and protects against on-the-fly and collusion attacks. In addition, the scheme incorporates a privacy-preserving identity management solution that balances anonymity and traceability. It employs a traceable anonymous identity mechanism whereby users interact via pseudonyms, hiding their real identities while allowing a trusted Key Generation Center (KGC) to perform identity tracing only when authorized. Our security analysis demonstrates that the proposed scheme achieves its security objectives and resists various attacks. Furthermore, a comprehensive performance evaluation demonstrates that ATRIA outperforms related schemes in terms of computational overhead. Qingyang Zhang 0001, Jie Cui 0004, Fengqun Wang, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Distributed Multi-Attribute Anonymous Certificate Management Scheme With Fine-Grained Revocation for Uncrewed Aerial VehiclesabstractIn unmanned aerial vehicle (UAV) scenarios, the execution of specific flight missions requires anonymous certificates containing multiple attributes as proof of authorization. However, existing certificate- management schemes are ineffective in achieving an optimal trade-off between verification overhead and attribute-level revocation. First, most existing schemes bind multiple attributes to a single certificate but typically lack the capability of fine-grained revocation at the individual attribute level. Second, most existing schemes rely on centralized certificate authorities, necessitating UAVs to apply for certificates from multiple regions separately when performing cross-regional access. This scenario increases the certificate management burden. To address these challenges, this paper proposes a distributed multiattribute anonymous certificate management scheme for UAVs. First, the proposed scheme integrates redactable signatures and dynamic accumulators, enabling the selective disclosure and fine-grained revocation of attributes within a single certificate. Second, the proposed scheme utilizes a distributed key-generation mechanism, enabling decentralized certificate issuance and secure management. Qingyang Zhang 0001, Hong Zhong 0001, Fengqun Wang, Mingwei Zeng, Jie Cui 0004 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Distributed and Autonomous Group Management Supporting Group Fusion for UAVsabstractWith increasingly complex tasks, cooperation among multiple unmanned aerial vehicle (UAV) groups has become more significant. However, in complex operational environments, UAVs may operate outside the communication coverage of the trusted authority (TA), making continuous online TA services unavailable. Under such circumstances, most existing group management methods have difficulty achieving group fusion and cannot flexibly update post-fusion member certificates. Therefore, we propose an autonomous UAV group management scheme based on mobile proactive secret sharing. First, the scheme achieves autonomous group fusion by updating the subsecrets of UAVs. Second, without the participation of a TA, the scheme supports the dynamic self-updating of certificates, ensuring secure communication in the new group and continuous availability of certificates. Security proofs and analyses show that the proposed scheme is secure under the random oracle model and can resist several common attacks. The experimental results demonstrate that the proposed scheme outperforms related schemes in computational performance and is suitable for secure and efficient UAV group management scenarios. Fengqun Wang, Manting Gan, Hong Zhong 0001, Qingyang Zhang 0001, Jie Cui 0004, Debiao He |
IEEE Trans. Mob. Comput. | 4 |
| 2026 | Forward Secure Data Sharing Based on Proxy Re-Encryption in Industrial Internet of ThingsabstractIn the Industrial Internet of Things (IIoT), data is shared among different production segments for collaborative production. However, industrial production processes often involve corpus sensitive information, and during data sharing, every flow of data between different subjects increases its exposure to vulnerabilities. Proxy re-encryption offers a practical approach to enabling secure data exchange, thereby partially mitigating the tension between information sharing and privacy protection. Many scholars have proposed data-sharing schemes utilizing proxy re-encryption technologies. However, existing schemes still face issues, such as excessive communication and computational overhead, and cannot guarantee forward security. Therefore, this study proposes a lightweight and forward-secure data-sharing scheme. First, the proxy generates the re-encryption key, substantially alleviating the overhead on the data owner. Second, whenever the time node changes or a data user is revoked, the data user loses access to historical data, which effectively ensures forward security. The security proof confirms the scheme’s IND-CPA security under the DBDH assumption. Performance analyses reveals that the proposed scheme achieves higher security in data sharing with a lower computational overhead. Qingyang Zhang 0001, Siqi Fu, Jie Cui 0004, Fengqun Wang, Jiaxin Li 0001, Hong Zhong 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2026 | NVLIM: MTJ and CMOS-Based Nonvolatile Latch Design With Protection Against Triple-Node-Upsets for Robust ComputingabstractSoft errors and power dissipation emerge as critical challenges in developing high-reliability and cost-sensitive embedded systems. To address these issues, the magnetic tunnel junction (MTJ) is considered a promising solution due to its nonvolatility and its compatibility with traditional CMOS manufacturing processes. In this work, we propose a novel nonvolatile (NV) latch consisting of inverters and MTJs, namely, NVLIM, which provides nonvolatility and robust partial tolerance against triple-node-upsets (TNUs) at low cost. NVLIM integrates a TNU-tolerant block based on CMOS with a backup-restore block using MTJs. Simulation results incorporating process, voltage, and temperature (PVT) variations, bias temperature instability (BTI) impact, and Monte Carlo simulations demonstrate the balanced performance in terms of nonvolatility, robust partial TNU tolerance, and comprehensive overhead of the proposed latch. Aibin Yan, Litao Wang, Zhengfeng Huang, Qingyang Zhang 0001, Tianming Ni, Patrick Girard 0001, Xiaoqing Wen |
IEEE Trans. Very Large Scale Integr. Syst. | 5 |
| 2025 | Edge Computing-Based Anonymous Cross-Domain Authentication Scheme for VANETsabstractIn the vehicular ad-hoc networks (VANETs), crossdomain communication among vehicles significantly improves traffic efficiency and road safety. However, due to the vulnerabilities of vehicle communication, it faces numerous security challenges when performing cross-domain communication. Existing schemes rely on trusted third parties for cross-domain authentication, resulting in issues such as low computational efficiency and weak privacy protection for vehicles, which cannot meet the demands of large-scale vehicle cross-domain communication. To address these problems, we propose an efficient and anonymous cross-domain authentication scheme based on edge computing. By using edge gateways to manage vehicle groups and handle cross-domain event requests, we solve the performance bottleneck issues caused by centralized authentication. Additionally, the use of a batch authentication mechanism further improves computational efficiency during large-scale authentications and reduces authentication latency. Security and performance analyses show that the proposed scheme can meet the security and performance requirements for cross-domain vehicle communication. Hong Zhong 0001, Chengdong Gu, Jing Zhang 0024, Qingyang Zhang 0001, Jiaxin Li 0001, Jie Cui 0004 |
HPCC | 5 |
| 2025 | A Secure Anonymous Authentication and Key Agreement Scheme for UAV Swarms in Emergency Rescue EnvironmentsabstractTo achieve secure communication in unmanned aerial vehicle (UAV) swarms during emergency rescue operations, A wide range of authentication key agreement (AKA) schemes has emerged in recent research. However, these schemes generally face three critical limitations. First, UAVs may struggle to maintain persistent communication with the trusted authority in complex environments, and efficient authentication cannot be guaranteed when the TA is offline. Second, most existing schemes lack traceability, preventing the TA from revealing the true identity of malicious UAVs. Finally, UAVs are constrained by limited computational and communication resources. So we propose an AKA scheme that enables secure communication between the UAV and BS. Specifically, proposed scheme eliminates reliance on a trusted authority during the AKA phase, while still ensuring the establishment of a secure communication channel. In addition, by combining the Chinese remainder theorem with the chameleon hash function, the scheme not only enables mutual authentication between UAVs and base stations but also enhances overall computational efficiency in complex environments. Formal security analysis and rigorous proof indicate this design upholds various protective attributes and effectively withstands diverse known attacks. Finally, experimental evaluations validate efficiency and practicality about proposed scheme in some environments. Fengqun Wang, Hang Hai, Jie Cui 0004, Wuquan Wen, Qingyang Zhang 0001, Hong Zhong 0001 |
ICPADS | 5 |
| 2025 | FEELPGen: Data-Free Knowledge Distillation for Personalized Federated Learning Across Heterogeneous Edge SilosabstractDeploying machine learning models on large-scale IoT devices in edge networks is challenging. Federated edge learning (FEEL) has emerged as a potential solution based on a hierarchical architecture. However, existing research relies primarily on an idealized cross-device assumption, overlooking more realistic cross-silo scenarios where devices typically belong to different organizational silos. To facilitate multi-group collaboration, we first propose a semi-decentralized FEEL structure called FEELPGen, in which different silos collaborate in training to maximize local model benefits without relying on trusted third-party coordination. Based on that, a two-layer aggregation algorithm is proposed to enhance the generalization ability under highly heterogeneous data distribution. For inner-silo learning, we devise a heterogeneity-aware, synchronous inner-silo aggregation algorithm utilizing data-free knowledge distillation based on generative learning (Gen). Feature vectors are generated to approximate silo knowledge. For inter-silo learning, a personalized (P), asynchronous inter-silo aggregation algorithm is proposed with adaptive selection and dynamic weight queues. To further improve efficiency, we introduce an optional optimized scheme, FEELPGen+, which integrates a privacy-preserving dimension-reduction algorithm. Finally, we provide a detailed analysis for convergence and complexity to verify the feasibility of FEELPGen. Extensive experiments demonstrate that FEELPGen achieves significant improvement in accuracy compared to the state-of-the-art schemes. Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Jie Cui 0004 |
IEEE Internet Things J. | 5 |
| 2025 | Achieving Fair and Efficient Revocable Access Control for IIoT Data Sharing: A Blockchain-Enabled ApproachabstractWith the advancement of computing and communication technologies, Industrial Internet of Things (IIoT) has emerged accordingly. In IIoT environments, efficient data sharing is achieved through collaboration among end devices, edge servers, and cloud servers. However, ensuring the security, efficiency, and fairness of service data access for end devices remains a significant challenge. To address this, we propose a fair and efficient revocable access control scheme based on blockchain. The proposed scheme leverages smart contracts to establish a fair payment mechanism, ensuring fairness for IIoT data sharing. In addition, a proxy-assisted decryption approach is employed to minimize the decryption overhead on end devices. Moreover, the scheme supports efficient user revocation without requiring updates to the private keys of end users. This enhances the overall security and usability of the system. Finally, a thorough security and performance analysis indicate that the proposed scheme fits well within IIoT scenarios. Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Jiaxin Li 0001, Jie Cui 0004 |
IEEE Internet Things J. | 4 |
| 2025 | Conditional Privacy-Preserving Transaction for the Unspent Transaction Output-Based Multi-Chain Blockchain SystemabstractThe anonymity of blockchain may be exploited by criminals for illegal fund transfers, thus a conditional privacy-preserving scheme is important for blockchain regulation. Currently, sharding technology under a multi-chain architecture is used to improve blockchain scalability. However, current conditional privacy-preserving schemes cannot work on this architecture. To protect the privacy of the transaction, we present a conditional privacy-preserving transaction scheme (MC-CPPT) for multi-chain blockchain system. In this system, we proposed a zero-knowledge proof based anonymous transaction, in terms of the identities of transaction participants and amounts, which also enables the unlinkability of transactions and indistinguishability between cross-chain and intra-chain transactions in multi-chain blockchain system. In addition, a multi-node regulatory agency is introduced to control the transaction amount and frequency in the system without a single point of failure. Moreover, an ECC-based encryption scheme is proposed to achieve the traceability of suspicious transactions. A security model is defined and the security of MC-CPPT is demonstrated to meet the expected security goals. Evaluating the prototype revealed acceptable performance and additional security features. Jie Cui 0004, Wenting Zhuang, Hong Zhong 0001, Qingyang Zhang 0001, Fengqun Wang, Debiao He |
IEEE Trans. Computers | 4 |
| 2025 | Blockchain-Based Privacy-Preserving Deduplication and Integrity Auditing in Cloud StorageabstractEnsuring cloud data security and reducing cloud storage costs have become particularly important. Many schemes expose user file ownership privacy when deduplicating authentication tags and during integrity auditing. Moreover, key management becomes more difficult as the number of files increases. Also, many audit schemes rely on third-party auditors (TPAs), but finding a fully trustworthy TPA is challenging. Therefore, we propose a blockchain-based integrity audit scheme supporting data deduplication. It protects file tag privacy during deduplication of ciphertexts and authentication tags, safeguards audit proof privacy, and effectively protects user file ownership privacy. To reduce key management costs, we introduce identity-based broadcast encryption (IBBE) that does not require interaction with key servers, eliminating additional communication costs. Additionally, we use smart contracts for integrity auditing, eliminating the need for a fully trusted TPA. We evaluate the proposed scheme through security and theoretical analyses and a series of experiments, demonstrating its efficiency and practicality. Qingyang Zhang 0001, Shuai Qian, Jie Cui 0004, Hong Zhong 0001, Fengqun Wang, Debiao He |
IEEE Trans. Computers | 1 |
| 2025 | DBCSec: DBC File-Guided Secure Communication Mechanism for CAN-FD BusabstractThe network architecture of modern vehicles is composed of multiple communication protocols and electronic control units (ECU). Compared to the widely used protocol of Controller Area Network (CAN), CAN with Flexible Data-Rate (CAN-FD) protocol is suitable for applications requiring higher data throughput. However, the CAN-FD bus is vulnerable to intrusion by external attackers. Nowadays, several secure mechanisms have been proposed to protect the security of in-vehicle data. However, there are still two issues: 1) Most schemes use a centralized controller for key distribution, which can easily lead to a single point of failure; 2) The existing key management modes are not suitable for real-world CAN-FD networks in vehicle manufacturing. To address these issues, we propose a lightweight semi-decentralized scheme based on Database CAN (DBC) files to secure in-vehicle communication. ECUs are grouped on the send-receive relationships set in the DBC file, considering both the communication mode and sending efficiency. Furthermore, the proposed scheme overcomes reliance on long-term keys. Moreover, the security is analyzed by the random oracle model. The performance analysis is evaluated on microcontroller units (MCU) STM32H743IIT and Raspberry Pi 3B. The proposed scheme optimizes the computational costs of authentication, key agreement, and secure communication stages by up to 97.89%, 99.95%, and 82.35%, and optimizes the communication costs by up to 75.52%, 98.42%, and 29.41% compared to existing methods. Simulation experiments demonstrate that the bus load of the scheme increases by up to 9.84% compared to the baseline network. Jie Cui 0004, Hong Zhong 0001, Jing Zhang 0024, Qingyang Zhang 0001, Lu Wei 0003, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Efficient Revocable Cross-Domain Anonymous Authentication Scheme for IIoTabstractThe rapid evolution of the Industrial Internet of Things (IIoT) has necessitated increased device interactions across various management domains. This entails devices from different domains collaborating on the same production task. This poses significant challenges for the dynamics of cross-domain authentication schemes. Traditional cross-domain authentication schemes struggle to support seamless switching between domains and face difficulties when accommodating devices that join and leave the same domain. Moreover, these schemes suffer from intricate interactions and suboptimal efficiency. To address these issues, we propose a dynamic group signature scheme based on a dynamic accumulator and a non-interactive zero-knowledge proof. We integrated this scheme with blockchain technology to construct an efficient revocation cross-domain authentication scheme. The proposed scheme enables cross-domain anonymous authentication with simple interactions and provides an efficient revocation function for illegal devices. This approach ensures conditional privacy-preserving and enables efficient member joining and exiting through a dynamic accumulator. It effectively addresses the dynamic requirements of devices involved in IIoT production and manufacturing processes. We prove the security of the proposed scheme using a random Oracle model and conduct thorough analyses to verify its resistance against various attacks. Furthermore, the experimental results demonstrate that the proposed scheme achieves better performance in terms of computational and communication costs. Mingwei Zeng, Jie Cui 0004, Qingyang Zhang 0001, Hong Zhong 0001, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Nonvolatile and SEU-Recoverable Latch Based on FeFET and CMOS for Energy-Harvesting DevicesabstractNonvolatile memories are widely used in emerging energy-harvesting Internet-of-Things (IoT) applications, and nonvolatile memories constructed from FeFET devices hold great promise. This paper presents a nonvolatile and single-event-upset (SEU)-recoverable latch based on FeFET and CMOS for energyharvesting devices. The latch uses n-type FeFET devices to provide nonvolatility without any additional control signals. Moreover, since the soft error problem has become increasingly severe, radiation hardening by design gains a great attention as a promising approach to mitigate the reliability issue. The latch uses feedback interlocked loops with n-type FeFETs and C-elements, enabling it to provide nonvolatility and SEU-recovery simultaneously. Simulation results with Candence Virtuoso verifies that the proposed latch design has correct functioning with excellent performance compared to the state-of-the-art designs. Aibin Yan, Zhuoyuan Lin, Guangzhu Liu, Qingyang Zhang 0001, Zhengfeng Huang, Jie Cui 0004, Xiaoqing Wen, Patrick Girard 0001 |
ISCAS | 4 |
| 2024 | CQCTL: A Cost-Optimized and Quadruple-Node-Upset Completely Tolerant Latch Design for Safety-Critical ApplicationsabstractWith the rapid development of semiconductor technologies, latches are becoming increasingly sensitive to multiple node upsets, such as triple node upsets and quadruple node upsets (QNUs). Therefore, they should be considered for safety-critical applications. To effectively tolerate QNUs, this paper proposes a QNU-tolerant latch design with moderate overhead. The latch mainly comprises two parallel storage cells, and three 2-input C-elements. When any four internal nodes are flipped at the same time, the output value of the latch will not be affected. Simulation results not only confirm the QNU tolerance of the proposed latch but also demonstrate that the latch can reduce by 40.93% delay, 40.73% area, 13.11% power, and 71.19% delay-area-power product (DAPP) on average compared to the existing QNU-tolerant latches. Qingyang Zhang 0001, Byeong-Hee Roh, Xiaoqing Wen |
ITC-Asia | 2 |
| 2024 | Verifiable Data Sharing Based on Autonomous Path Proxy Re-Encryption for Industrial Internet of ThingsabstractIn the Industrial Internet of Things (IIoT), massive amounts of data are generated and shared among different industrial entities, and it is crucial to realize the security and flexibility of data sharing. Autonomous path proxy re-encryption technology enables the autonomous creation of an ordered data-sharing path as specified by the data owner, supporting multi-hop re-encryption. However, the security of this technology requires further enhancement. Therefore, we propose a verifiable data-sharing scheme. To prevent data leakage due to collusion between the proxy and users, we introduce blockchain technology to supervise the decryption behavior of users in the autonomous path. Second, we verify the proxy re-encryption computation, ensuring its validity. Finally, a security analysis demonstrates that the proposed scheme meets the security requirements. Furthermore, we evaluated the performance of the proposed scheme, and the results show that our scheme has only increased less overhead, but has enhanced security. Jie Cui 0004, Xiaoxi Sun, Qingyang Zhang 0001, Fengqun Wang, Hong Zhong 0001 |
MSN | 3 |
| 2024 | Efficient Blockchain-Based Mutual Authentication and Session Key Agreement for Cross-Domain IIoTabstractSeveral studies have introduced edge computing and blockchain into the Industrial Internet of Things (IIoT) to satisfy the requirements of delay-sensitive applications and support cross-domain authentication. Although there have been many protocols to ensure the security and privacy of devices in the IIoT, existing protocols still suffer from problems. Updating keys and pseudonyms of devices by a trusted third party (e.g., certificate authority) will cause high communication and computation overhead, especially when the number of devices becomes much larger. Furthermore, an increasing number of transactions also cause high storage overhead on the blockchain. Therefore, we propose a blockchain-based cross-domain authentication protocol. Specifically, we propose a privacy-preserving method based on pseudonyms that offloads the task of generating pseudonyms from a trusted third party to edge servers to ensure the conditional anonymity of the devices. The device is allowed to request pseudonyms in bulk to reduce the number of transactions, thus reducing the storage overhead on the blockchain. Security analysis and experimental results demonstrate that our scheme achieves an efficient tradeoff between security and efficiency. Jie Cui 0004, Yihu Zhu, Hong Zhong 0001, Qingyang Zhang 0001, Chengjie Gu, Debiao He |
IEEE Internet Things J. | 4 |
| 2024 | Lightweight and Secure Data Sharing Based on Proxy Re-Encryption for Blockchain-Enabled Industrial Internet of ThingsabstractIn the Industrial Internet of Things (IIoT), data sharing is crucial for promoting the intelligent development of industrial production. To achieve effective data supervision, introducing blockchain into traditional cloud-based data-sharing frameworks has attracted widespread attention. However, existing blockchain-based data-sharing schemes still have issues with security and efficiency. Therefore, we propose a blockchain-enabled data-sharing scheme based on proxy re-encryption. First, the scheme considers both storage and access authentication, guaranteeing data sources’ trustworthiness and preventing data misuse. Second, the scheme uses an on-chain and off-chain cooperative storage mechanism, saving the storage resources of the blockchain. Third, the scheme supports data packing, which effectively improves data storage efficiency. The security analysis shows that our scheme satisfies the security requirements. Finally, we build a blockchain platform using the hyperledger fabric. The performance evaluation shows that our scheme is more advantageous regarding computational overhead than other related schemes. Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Chengjie Gu, Hong Zhong 0001 |
IEEE Internet Things J. | 3 |
| 2024 | Revocable and Efficient Blockchain-Based Fine-Grained Access Control Against EDoS Attacks in Cloud StorageabstractUsers have become accustomed to storing data on the cloud using ciphertext policy attribute-based encryption (CP-ABE) for fine-grained access control. However, this encryption method does not consider the ability of malicious users to launch thousands of file download requests when launching an economic denial of sustainability attack (EDoS), which may be more expensive for data owners. Existing solutions typically use a cloud server to verify the download permissions of the data users. However, cloud servers are not completely trusted and cloud server providers and colluding data users can still launch an EDoS attack. With our scheme, using CP-ABE, a blockchain is introduced for verifying the download permission of data users. In addition, we propose a new mechanism to solve the problem of malicious user revocations under EDoS attacks by updating the ciphertext and symmetric encryption technology. A formal security proof has demonstrated that the proposed scheme is suitable for plaintext attack security. Theoretical and experimental analyses show that our scheme performs more efficiently than previous methods. Qingyang Zhang 0001, Chang Xu 0015, Hong Zhong 0001, Chengjie Gu, Jie Cui 0004 |
IEEE Trans. Computers | 1 |
| 2024 | DSChain: A Blockchain System for Complete Lifecycle Security of Data in Internet of ThingsabstractThere is a growing concern about the complete lifecycle security of data in Internet of Things (IoT). This may cause privacy and trust problems for users regarding data sources, data storage, and access control for data sharing. Blockchain is a valuable solution to the above problems through distributed ledger technology, and it has been widely applied in various fields such as public services, finance, and IoT. However, the data in IoT are characterized by a large quantity, large capacity, and timely response, and existing blockchain systems only partially resolve them for data security and performance. We propose DSChain for IoT data security to address the challenges mentioned above. Our system uses a certificateless signature to ensure a trusted data source and public auditing to ensure the integrity of stored data while using ciphertext-policy attribute-based encryption to control access to shared data. Moreover, we propose a packaging mechanism based on the Merkle Hash Tree that effectively improves system performance. We implement the DSChain and provide a detailed analysis of performance and security. The experimental results indicate that DSChain can achieve approximately 1,035 transactions per second on a single peer and is scalable. Jie Cui 0004, Yatao Li, Qingyang Zhang 0001, Hong Zhong 0001, Chengjie Gu, Debiao He |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Blockchain-Based Lightweight Message Authentication for Edge-Assisted Cross-Domain Industrial Internet of ThingsabstractIn edge-assisted cross-domain Industrial Internet of Things (IIoT), blockchain-based authentication is an effective way to build cross-domain trust and secure cross-domain data. However, existing authentication schemes still have serious challenges in terms of efficiency and security. In this paper, we propose a blockchain-based lightweight message authentication scheme. First, to address efficiency challenges, we build a blockchain-enabled edge-assisted lightweight authentication framework. This framework uses edge servers to assist smart devices in achieving cross-domain authentication and effectively reduce redundant interactions between entities. Second, to resolve the security challenges, we design a lightweight message authentication algorithm for cross-domain IIoT. The algorithm guarantees message security with low computational overhead and is suitable for multi-receiver cross-domain IIoT. The security proof and analysis demonstrate that the proposed scheme is secure under the random oracle model and can resist various attacks. The performance evaluation shows that our proposed scheme is superior in terms of computation and communication overhead when compared with other related schemes. Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Chengjie Gu, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Efficient Fine-Grained Data Sharing Based on Proxy Re-Encryption in IIoTabstractWith the development of the industrial Internet of Things (IIoT), the amount of data generated by industrial manufacturing equipment will increase. To reduce the cost of data management while achieving secure data sharing, data owners generally upload the resulting ciphertexts to a cloud server after encrypting their data. Attribute-based encryption (ABE) is a valuable technology that implements fine-grained access control over shared information; however, its computational complexity is not suitable for resource-constrained IIoT devices, making it difficult to apply directly to an IIoT environment. To address this problem, we design a fine-grained data sharing scheme based on proxy re-encryption in IIoT. In the proposed scheme, data files are encrypted through an identity-based encryption and a data owner can authorize a semi-trusted proxy server to transform the ciphertext into an ABE ciphertext. This realizes fine-grained access control and decreases a data owner's computational cost in data sharing. In addition, the computational burden is outsourced to a cloud server, and users only need to perform simple computing operations. A formal security proof indicates the proposed scheme's selective chosen-plaintext attack security. Theoretical and experimental analyses illustrate that our construction is more efficient than previous schemes. Qingyang Zhang 0001, Yujie Fu, Jie Cui 0004, Debiao He, Hong Zhong 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Blockchain-Based Secure Cross-Domain Data Sharing for Edge-Assisted Industrial Internet of ThingsabstractIn the Industrial Internet of Things (IIoT), blockchain-based data-sharing frameworks can effectively build cross-domain trust and facilitate data sharing. However, secure data-sharing schemes are lacking for the IIoT scenario, in which smart devices cannot communicate across domains and can only access data through edge servers. In this study, we propose a lightweight and secure data-sharing scheme for the blockchain-enabled cross-domain IIoT, in which authorized smart devices can access cross-domain data anonymously. First, smart devices can dynamically generate pseudonyms by themselves and without the online participation of domain authorization centers, effectively reducing the storage overhead of smart devices and the workload of domain authorization centers. Second, the scheme combines broadcast encryption and proxy re-encryption techniques, which realize flexible data sharing across domains while protecting the privacy of smart devices. Detailed security proofs and analyses demonstrate that the proposed scheme is secure and resistant to various attacks. The performance analysis shows that our proposed scheme is efficient and performs better than related schemes. Fengqun Wang, Jie Cui 0004, Qingyang Zhang 0001, Debiao He, Hong Zhong 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Device-Side Lightweight Mutual Authentication and Key Agreement Scheme Based on Chameleon Hashing for Industrial Internet of ThingsabstractSeveral authentication and key agreement (AKA) schemes have been proposed to ensure secure communication in the Industrial Internet of Things (IIoT). However, most of these schemes face two primary problems. First, they cannot resist various attacks, such as impersonation and device capture attacks. Second, these schemes overlook the resource-constrained IIoT devices, failing to guarantee lightweight overhead for device operations. Therefore, we propose a novel and efficient AKA scheme. Utilizing the chameleon hash function and physical unclonable function, the proposed scheme implements a lightweight overhead for both authentication parties while maintaining the overhead of the gateway within a reasonable range. Furthermore, we implement device anonymity based on lightweight operations such as hash and XOR. In addition, we perform a rigorous security analysis using the widely accepted Real-Or-Random model, BAN logic, and Proverif tool. Finally, through heuristic analysis and experiments, we substantiate that our scheme surpasses the compared schemes in terms of both security attributes and system overhead. Qingyang Zhang 0001, Hong Zhong 0001, Jie Cui 0004, Jiaxin Li 0001, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | An Efficient Authentication and Key Agreement Scheme for CAV Internal Applications
Yang Li 0215, Qingyang Zhang 0001, Wenwen Cao, Jie Cui 0004, Hong Zhong 0001 |
CollaborateCom (2) | 2 |
| 2023 | SLCSA: Scalable Layered Cooperative Service Attestation Scheme in Cloud-Edge-End Cooperation EnvironmentsabstractIn a cloud-edge-end cooperation environment, edge and core cloud services are complementary and synergistic, jointly processing a large amount of private data uploaded by users. To prevent the leakage of private data, users must ensure that services are secure and trusted through remote attestation. Traditional one-to-one remote attestation schemes are typically used to test the cloud services. However, as the cloud platform scales and the number of edge and core cloud services grows rapidly, the traditional attestation method has problems, such as poor scalability and low attestation efficiency. Thus far, there has been a lack of feasible methods for users to verify multiple related services in a cloud-edge-end cooperation environment quickly. This paper presents a scalable layered cooperative service attestation (SLCSA) scheme, the first secure and scalable protocol for the efficient attestation of multiple cooperative services. The SLCSA scheme is based on a Boneh–Lynn–Shacham (BLS) multi-signature to improve the scalability of the scheme while enabling users to conduct the batch verification of services. We also analyze the security of the proposed scheme. To evaluate the proposed scheme, we implement it using Intel SGX, which can provide basic hardware-assisted attestation and a trusted execution environment for services. The experimental results show that the SLCSA scheme is practical and efficient in a cloud-edge-end cooperative environment. Jie Cui 0004, Qipeng Chen, Yang Li 0215, Qingyang Zhang 0001, Lu Liu 0001, Hong Zhong 0001 |
ICPADS | 5 |
| 2023 | Multi-factor based session secret key agreement for the Industrial Internet of Things
Jie Cui 0004, Fangzheng Cheng, Hong Zhong 0001, Qingyang Zhang 0001, Chengjie Gu, Lu Liu 0001 |
Ad Hoc Networks | 4 |
| 2023 | Conditional privacy-preserving message authentication scheme for cross-domain Industrial Internet of Things
Hong Zhong 0001, Chengdong Gu, Qingyang Zhang 0001, Jie Cui 0004, Chengjie Gu, Debiao He |
Ad Hoc Networks | 3 |
| 2023 | Efficient Integrity Auditing Mechanism With Secure Deduplication for Blockchain StorageabstractMassive nodes in a blockchain form an off-chain distributed storage network to provide storage resources for users to meet large data upload requirements. However, this storage approach introduces security and performance issues. Firstly, it is difficult to guarantee the integrity of the data uploaded, and these data may be easily corrupted or lost. Moreover, uploading excessive duplicate data leads to a waste of storage resources. In this study, to address these issues, with a double-copy storage model for blockchain off-chain storage, a novel public auditing scheme with client-side deduplication is proposed to reduce the storage overhead of nodes and check the integrity of the off-chain data. Based on smart contracts, our scheme could realize efficient user ownership and off-chain data integrity verification automatically. In addition, both data encryption and deduplication are achieved based on message-locked encryption and an improved authenticator generation algorithm. Security analysis and experimental comparisons show that the proposed scheme is effective and practical. Qingyang Zhang 0001, Dongfang Sui, Jie Cui 0004, Chengjie Gu, Hong Zhong 0001 |
IEEE Trans. Computers | 1 |
| 2023 | Efficient Anonymous Authentication Based on Physically Unclonable Function in Industrial Internet of ThingsabstractOwing to the open Industrial Internet of Things (IIoT) environment, information interacting between devices and servers is transmitted over the public channel, which may lead to privacy breach of the device identity. Furthermore, communication entities are not fully trusted, and they may maliciously disclose the device identity information. Therefore, the anonymity of devices must be guaranteed. In addition, IIoT is resource-constrained, and complex algorithms are unsuitable for the IIoT system. Several researchers have attempted to design anonymous authentication schemes. The one-authentication-multiple-access approach allows devices to access server resources multiple times after a single authentication, and its authentication overhead is independent of the number of accesses. This can reduce the computational burden for devices that need to access the server frequently. However, existing anonymous authentication schemes do not support multiple accesses after one authentication, and still suffer from privacy issues and low efficiency for devices that need frequent access to the server. To address these issues, we propose a new anonymous authentication scheme that uses group signature technology to ensure device anonymity and uses Merkle hash tree technology to achieve multiple accesses after one authentication, thereby greatly reducing the authentication overhead of IIoT devices. Then, we validate the security of the scheme using the random oracle model and the BAN logic. Finally, compared with other related schemes, the experimental results show that our proposed scheme is more efficient and practical for resource-constrained IIoTs than other schemes. Qingyang Zhang 0001, Hong Zhong 0001, Debiao He, Jie Cui 0004 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Efficient Batch Authentication Scheme Based on Edge Computing in IIoTabstractIn the industrial Internet of Things (IIoT) environment (e.g., a smart factory), smart devices with limited computing power can bring large amounts of privacy-sensitive data into insecure networks when they interact. If a network attacker intercepts and tampers with this data, it may cause chaos in production and even paralyze the entire IIoT system. Therefore, to ensure the regular operation of intelligent production, data receivers must authenticate the data before using them. However, existing message authentication schemes in the IIoT environment authenticate each message individually, which creates many redundant operations. Hence, to ensure data security among smart devices and reduce the computational overhead of data processing, we propose a batch authentication scheme based on edge computing in IIoT. Specifically, we design a lightweight batch authentication algorithm and use edge servers to assist smart devices in authenticating data, thus reducing the computational burden on smart devices and improving the efficiency of message authentication. The security analysis shows that the proposed scheme is secure in the random oracle model and meets the series of security requirements of the IIoT. In addition, we illustrate the efficiency of the scheme through experiments. Jie Cui 0004, Fengqun Wang, Qingyang Zhang 0001, Chengjie Gu, Hong Zhong 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Efficient Blockchain-Based Data Integrity Auditing for Multi-Copy in Decentralized StorageabstractAs the disruptor of cloud storage, decentralized storage could lead to a major shift in how organizations store data in the future. To ensure data availability, users generally encrypt the data and distribute it to multiple storage service providers. It is necessary to study data integrity verification in decentralized storage. Although some recent studies have proposed the using blockchain technology to assist auditing work in decentralized storage networks, the on-chain overhead still increases linearly with an increase in audit requests. Blockchain networks will inevitably be overloaded. In this study, we propose an efficient data integrity auditing scheme for multiple copies in decentralized storage. Particularly, using different polynomial commitment schemes, we first propose a basic scheme for verifying multiple copies of a single file, and then we propose an efficient batch auditing scheme for multiple copies of multiple files. Our scheme can significantly reduce the computation overhead of storage service providers while keeping the on-chain storage overhead constant. Security analysis and performance analysis show that our scheme is efficient and practical. Qingyang Zhang 0001, Jie Cui 0004, Hong Zhong 0001, Yang Li 0215, Chengjie Gu, Debiao He |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2022 | Parallel Key-Insulated Multiuser Searchable Encryption for Industrial Internet of ThingsabstractWith the rapid development of the industrial Internet of Things (IIoT) and cloud computing, an increasing number of companies outsource their data to cloud servers to save costs. To protect data privacy, sensitive industrial data must be encrypted before being outsourced to cloud servers. A multiuser searchable encryption (MUSE) scheme was introduced to ensure high efficiency of encrypted data retrieval. In an IIoT system with numerous users, the existing MUSE schemes suffer from certain key exposure problems owing to the limited key protection of smart devices and frequent queries by users. In this article, we propose a parallel key-insulated MUSE scheme for IIoT. This scheme utilizes broadcast encryption technology to implement MUSE. In addition, our scheme introduces a key-insulated primitive to improve the tolerance to key exposure. The security of our scheme is proved in the random oracle model. The experimental results show that our scheme achieves high computational efficiency. Jie Cui 0004, Hong Zhong 0001, Qingyang Zhang 0001, Chengjie Gu, Lu Liu 0001 |
IEEE Trans. Ind. Informatics | 4 |
| 2022 | Toward Data Transmission Security Based on Proxy Broadcast Re-encryption in Edge CollaborationabstractWith the development of IoT, more and more data is offloaded from the cloud to the edge for computing, eventually forming a collaborative computing model at the edge. However, in this model, the problem of secure data transmission has not been solved. In this model, data is transmitted and forwarded in multiple messaging systems, and existing security schemes cannot achieve end-to-end security in a multi-hop, broadcast transmission model. Therefore, in this paper, we propose a new security scheme based on proxy re-encryption and broadcast encryption techniques. Moreover, the performance and security of the scheme are further enhanced by using online-offline techniques and a trusted execution environment when integrating the scheme with edge collaboration. Finally, this paper proves the security of the scheme in theory, compares the functionality of the scheme, analyzes the theoretical performance of the scheme, and finally measures the actual performance of the scheme in the edge collaboration system. Qingyang Zhang 0001, Jie Cui 0004, Hong Zhong 0001, Lu Liu 0001 |
ACM Trans. Sens. Networks | 1 |
| 2021 | Privacy-Preserving Neural Network Inference Framework via Homomorphic Encryption and SGXabstractEdge computing is a promising paradigm that pushes computing, storage, and energy to the networks' edge. It utilizes the data nearby the users to provide real-time, energy-efficient, and reliable services. Neural network inference in edge computing is a powerful tool for various applications. However, edge server will collect more personal sensitive information of users inevitably. It is the most basic requirement for users to ensure their security and privacy while obtaining accurate inference results. Homomorphic encryption (HE) technology is confidential computing that directly performs mathematical computing on encrypted data. But it only can carry out limited addition and multiplication operation with very low efficiency. Intel software guard extension (SGX) can provide a trusted isolation space in the CPU to ensure the confidentiality and integrity of code and data executed. But several defects are hard to overcome due to hardware design limitations when applying SGX in inference services. This paper proposes a hybrid framework utilizing SGX to accelerate the HE-based convolutional neural network (CNN) inference, eliminating the approximation operations in HE to improve inference accuracy in theory. Besides, SGX is also taken as a built-in trusted third party to distribute keys, thereby improving our framework's scalability and flexibility. We have quantified the various CNN operations in the respective cases of HE and SGX to provide the foresight practice. Taking the connected and autonomous vehicles as a case study in edge computing, we implemented this hybrid framework in CNN to verify its feasibility and advantage. Huizi Xiao, Qingyang Zhang 0001, Qingqi Pei, Weisong Shi |
ICDCS | 2 |
| 2021 | A trusted and collaborative framework for deep learning in IoT
Qingyang Zhang 0001, Hong Zhong 0001, Weisong Shi, Lu Liu 0001 |
Comput. Networks | 1 |
| 2021 | An efficient and outsourcing-supported attribute-based access control scheme for edge-enabled smart healthcare
Hong Zhong 0001, Yiyuan Zhou, Qingyang Zhang 0001, Yan Xu 0007, Jie Cui 0004 |
Future Gener. Comput. Syst. | 3 |
| 2021 | Toward Achieving Fine-Grained Access Control of Data in Connected and Autonomous VehiclesabstractA connected and autonomous vehicle (CAV) is often fitted with a large number of onboard sensors and applications to support autonomous driving functions. Based on the current research, little work on applications' access to in-vehicle data has been done. Furthermore, most existing autonomous driving operating systems lack authentication and encryption units. As such, applications can excessively obtain confidential information, such as vehicle location and owner preferences and even upload it to the cloud, threatening the security of the vehicle and the privacy of the owner. In this study, we propose a fine-grained access control scheme to restrict applications' access to data in CAVs (FGAC-inCAVs). First, we present a system model composed of the following elements: a trusted third party (TTP), which is a fully trusted authority; perception components like sensors, which can capture the road information (pictures, videos, etc.); and multiple applications. Then, a fast attribute-based encryption (ABE) is presented, and security analysis also shows it is secure against selective and chosen-plaintext attacks. Furthermore, we propose a key update scheme based on the Chinese remainder theorem (CRT). Finally, the theoretical analysis and simulation experiments demonstrate its feasibility and efficiency. Jie Cui 0004, Xuelian Chen, Jing Zhang 0024, Qingyang Zhang 0001, Hong Zhong 0001 |
IEEE Internet Things J. | 4 |
| 2021 | Computing Systems for Autonomous Driving: State of the Art and ChallengesabstractThe recent proliferation of computing technologies (e.g., sensors, computer vision, machine learning, and hardware acceleration) and the broad deployment of communication mechanisms (e.g., dedicated short-range communication, cellular vehicle-to-everything, 5G) have pushed the horizon of autonomous driving, which automates the decision and control of vehicles by leveraging the perception results based on multiple sensors. The key to the success of these autonomous systems is making a reliable decision in real-time fashion. However, accidents and fatalities caused by early deployed autonomous vehicles arise from time to time. The real traffic environment is too complicated for current autonomous driving computing systems to understand and handle. In this article, we present state-of-the-art computing systems for autonomous driving, including seven performance metrics and nine key technologies, followed by 12 challenges to realize autonomous driving. We hope this article will gain attention from both the computing and automotive communities and inspire more research in this direction. Liangkai Liu, Sidi Lu, Ren Zhong, Baofu Wu, Yongtao Yao, Qingyang Zhang 0001, Weisong Shi |
IEEE Internet Things J. | 6 |
| 2021 | AC4AV: A Flexible and Dynamic Access Control Framework for Connected and Autonomous VehiclesabstractSensing data plays a pivotal role in connected and autonomous vehicles (CAVs), enabling CAV to perceive surroundings. For example, malicious applications might tamper this life-critical data, resulting in erroneous driving decisions and threatening the safety of passengers. Access control, one of the promising solutions to protect data from unauthorized access, is urgently needed for vehicle sensing data. However, due to the intrinsic complexity of vehicle sensing data, including historical and real time, and access patterns of different data sources, there is currently no suitable access control framework that can systematically solve this problem; current frameworks only focus on one aspect. In this article, we propose a novel and flexible access control framework,AC4AV, which aims to support various access control models, and provide APIs for dynamically adjusting access control models and developing customized access control models, thus supporting access control research on CAV for the community. In addition, we propose a data abstraction method to clearly identify data, applications, and access operations in CAV, and therefore is easily able to configure the permits of each data and application in access control policies. We have implemented a prototype to demonstrate our architecture on NATS for real-time data and NGINX for historical data, and three access control models as built-in models. We measured the performance of ourAC4AVwhile applying these access control models to real-time and historical data. The experimental results show that the framework has little impact on real-time data access within a tolerable range. Qingyang Zhang 0001, Hong Zhong 0001, Jie Cui 0004, Lingmei Ren, Weisong Shi |
IEEE Internet Things J. | 1 |
| 2021 | Toward Trusted and Secure Communication Among Multiple Internal Modules in CAVabstractBy equipping various sensors and analyzing sensed data, vehicles can perform automatic driving; these vehicles are known as connected and autonomous vehicles (CAVs). In CAVs, tampered data will result in incorrect driving decisions. Hence, secure data transmission should be ensured to enable correct life-critical decisions. Untrusted resource-constrained modules allow attackers to obtain private data from CAVs, such as the key. Benefitting from trusted computing, the proposed scheme can verify the trusted status of internal modules and achieve secure data transmission by adopting the remote attestation and hash message authentication code. The scheme is proven to be secure in the random oracle model under the computational Diffie–Hellman problem. Furthermore, we perform experiments and evaluate the performance using Intel Software Guard eXtensions, which provide part of the trusted computing function. The experimental results show that the scheme could be efficient and suitable for CAVs. Hong Zhong 0001, Wenwen Cao, Qingyang Zhang 0001, Jing Zhang 0024, Jie Cui 0004 |
IEEE Internet Things J. | 3 |
| 2019 | MobileEdge: Enhancing On-Board Vehicle Computing Units Using Mobile Edges for CAVsabstractAs the rapid growth of connected and autonomous vehicles (CAVs) and 5G intensifies, more third-party applications are increasingly being deployed on CAVs. They not only improve user experience but also provide more helpful services, for example, enhancing public safety by recognizing criminals in real-time videos. Current CAVs prefer to process collected data on the vehicle to avoid long transmission latency and extra network cost. However, due to the limitations of the on-board vehicle computing unit (VCU) and increasing use of computing-intensive in-vehicle applications, the burden of on-board VCU has sharply increased, which may affect driving safety. In particular, for existing vehicles on the road, adding more computing devices is a challenge if not impossible due to cost concerns. Inspired by edge computing, we propose a novel platform, MobileEdge, to enhance the computing capability of the unchangeable on-board VCU, which leverages mobile devices as edge nodes, e.g., the passengers' smartphones, by offloading computing tasks to them for collaboratively computing. Moreover, MobileEdge provides the dynamic management of mobile devices, monitoring device status and interfaces for customizable task offloading strategies and eventually achieves optimal task scheduling. We build a prototype to demonstrate the designed platform and evaluate three task offloading strategies which were implemented based on the developed interfaces. The results show that MobileEdge significantly reduces the application response latency. Compared with the baseline which does not employ task offloading, the response latency is almost near real-time when more computing resources are available. In addition, the proposed shortest response latency strategy outperforms the best overall task scheduling among the three strategies. Qingyang Zhang 0001, Youhuizi Li, Hong Zhong 0001, Weisong Shi |
ICPADS | 2 |
| 2019 | Edge Video Analytics for Public Safety: A ReviewabstractWith the installation of enormous public safety and transportation infrastructure cameras, video analytics has come to play an essential part in public safety. Typically, video analytics is to collectively leverage the advanced computer vision (CV) and artificial intelligence (AI) to solve the four-W problem. That is to identify Who has done something (What) at a specific place (Where) at some time (When). According to the difference of latency requirements, video analytics can be applied to postevent retrospective analysis, such as archive management, search, forensic investigation and real-time live video stream analysis, such as situation awareness, alerting, and interested object (criminal suspect/missing vehicle) detection. The latter is characterized as having higher requirements on hardware resources as the sophisticated image processing algorithms under the hood. However, analyzing large-scale live video streams on the Cloud is impractical as the edge solution that conducts the video analytics on (or close to) the camera provides a silvering light. Analyzing live video streams on the edge is not trivial due to the constrained hardware resources on edge. The AI-dominated video analytics requires higher bandwidth, consumes considerable CPU/GPU resources for processing, and demands larger memory for caching. In this paper, we review the applications, algorithms, and solutions that have been proposed recently to facilitate edge video analytics for public safety. Qingyang Zhang 0001, Hui Sun 0002, Xiaopei Wu, Hong Zhong 0001 |
Proc. IEEE | 1 |
| 2018 | OpenVDAP: An Open Vehicular Data Analytics Platform for CAVsabstractIn this paper, we envision the future connected and autonomous vehicles (CAVs) as a sophisticated computer on wheels, with substantial on-board sensors as data sources and a variety of services running on top to support autonomous driving or other functions. In general, these services are computationally expensive, especially for the machine learning based applications (e.g., CNN-based object detection). Nevertheless, the on-board computation unit possess limited compute resources, raising a huge challenge to deploy these computation-intensive services on the vehicle. On the contrary, the cloud-based architecture conceptually with unconstrained resources suffers from unexpected extended latency that attributes to the large-scale Internet data transmission; thus, adversely affecting the services' real-time performance, quality of services and user experiences. To address this dilemma, inspired by the promising edge computing paradigm, we propose to build an Open Vehicular Data Analytics Platform (OpenVDAP) for CAVs, which is a full-stack edge based platform including an on-board computing/communication unit, an isolation-supported and security & privacy-preserved vehicle operation system, an edge-aware application library, as well as an optimal workload of?oading and scheduling strategy, allowing CAVs to dynamically detect each service's status, computation overhead and the optimal of?oading destination so that each service could be finished within an acceptable latency and limited bandwidth consumption. Most importantly, contrast to the proprietary platform, OpenVDAP is an open-source platform that offers free APIs and real-?eld vehicle data to the researchers and developers in the community, allowing them to deploy and evaluate applications on the real environment. Qingyang Zhang 0001, Yifan Wang 0005, Xingzhou Zhang, Liangkai Liu, Xiaopei Wu, Weisong Shi, Hong Zhong 0001 |
ICDCS | 1 |
| 2018 | Distributed Collaborative Execution on the Edges and Its Application to AMBER AlertsabstractIn the Internet of Everything era, billions of geographically distributed things will connect to the Internet and generate hundreds of zettabytes of data per year. Pushing that data to the cloud requires tremendous network bandwidth cost and latency. This is too onerous for some latency-sensitive applications, such as vehicle tracking using city-wide cameras. One application currently limited by such obstacles is the America's Missing Broadcast Emergency Response (AMBER) Alert system-but edge computing could transform this system's capabilities. Edge computing is a new computing paradigm that greatly diminishes data transmission and response latency by processing data at the proximity of data sources. However, most vision-based analytics are compute-intensive, and an edge device might be overwhelmed given tens of frames each second for real-time analysis. Also, the system needs a customized and flexible interface to implement efficient tracking strategies. To meet these needs, here we extend a big data processing framework, called Firework, to support collaboration between multiple edge devices and customizable task-scheduling strategies. Based on this extended version of Firework, we implement the AMBER alert assistant (A3), which efficiently tracks and locates a vehicle by analyzing city cameras' data in real time. We also propose two kinds of customized task-scheduling algorithms for vehicle tracking in A3. Comprehensive evaluation results show that A3 achieves real-time video analytics by collaborating among multiple edge devices; and the proposed location-direction-related diffusion strategy effectively controls the searching area for vehicle tracking by smartly selecting candidate cameras. Qingyang Zhang 0001, Quan Zhang 0001, Weisong Shi, Hong Zhong 0001 |
IEEE Internet Things J. | 1 |
| 2018 | Firework: Data Processing and Sharing for Hybrid Cloud-Edge AnalyticsabstractNow we are entering the era of the Internet of Everything (IoE) and billions of sensors and actuators are connected to the network. As one of the most sophisticated IoE applications, real-time video analytics is promising to significantly improve public safety, business intelligence, and healthcare & life science, among others. However, cloud-centric video analytics requires that all video data must be preloaded to a centralized cluster or the cloud, which suffers from high response latency and high cost of data transmission, given the scale of zettabytes of video data generated by IoE devices. Moreover, video data is rarely shared among multiple stakeholders due to various concerns, which restricts the practical deployment of video analytics that takes advantages of many data sources to make smart decisions. Furthermore, there is no efficient programming interface for developers and users to easily program and deploy IoE applications across geographically distributed computation resources. In this paper, we present a new computing framework,Firework, which facilitates distributed data processing and sharing for IoE applications via a virtual shared data view and service composition. We designed an easy-to-use programming interface forFireworkto allow developers to program onFirework. This paper describes the system design, implementation, and programming interface of Firework. The experimental results of a video analytics application demonstrate thatFireworkreduces up to 19.52 percent of response latency and at least 72.77 percent of network bandwidth cost, compared to a cloud-centric solution. Quan Zhang 0001, Qingyang Zhang 0001, Weisong Shi, Hong Zhong 0001 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2017 | LAVEA: Latency-Aware Video Analytics on Edge Computing PlatformabstractWe present LAVEA, a system built for edge computing, which offloads computation tasks between clients and edge nodes, collaborates nearby edge nodes, to provide low-latency video analytics at places closer to the users. We have utilized an edge-first design to minimize the response time, and compared various task placement schemes tailed for inter-edge collaboration. Our results reveal that the client-edge configuration has task speedup against local or client-cloud configurations. Shanhe Yi, Zijiang Hao, Qingyang Zhang 0001, Quan Zhang 0001, Weisong Shi, Qun Li 0001 |
ICDCS | 3 |