Wenxiu Ding

dblp:162/5813 · DBLP profile ↗
← Back
27ranked-venue papers
9as first author
13since 2021 · last 2026
0000-0002-8531-9226ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 5 first-author · 9 since 2021Computer networks · 5 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Systems, architecture and hardware · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Extremal distance spectra of graphs and essential connectivity
Daoxia Zhang, Wenxiu Ding
Discret. Appl. Math.3
2026 Octopus: A Robust and Privacy-Preserving Scheme for Compressed Gradients in Federated Learning
abstract
Federated learning is a distributed machine learning framework that allows multiple parties to collaboratively train a shared model without the need to share their original data with a central server. This approach minimizes the risk of data leakage and effectively addresses the challenge of isolated data silos. However, it necessitates multiple rounds of interactions to transmit models or gradients between the client and the server, leading to a significant communication cost and private data leakage. Consequently, some schemes compress the transmitted models or gradients through model pruning or knowledge distillation. However, they often overlook the privacy implications of compressed gradients or models, potentially resulting in privacy breaches. Additionally, they are susceptible to client disconnections, resulting in incomplete or delayed model updates. To address these challenges, this paper proposes Octopus, a robust and privacy-preserving scheme for compressed gradients in federated learning. Octopus employs Sketch to compress gradients and embeds masks for the compressed gradients, thereby safeguarding the gradients while concurrently reducing communication overhead. Moreover, we propose an anti-disconnection strategy to support model updates even in situations where some clients are disconnected. Lastly, we carry out comprehensive security and convergence analyses, along with extensive performance evaluations, demonstrating Octopus's robustness, stability, and efficiency over existing schemes.
Wenxiu Ding, Yuxuan Xiao 0001, Zheng Yan 0002, Ciwei Chen, Xuyang Jing
IEEE Trans. Dependable Secur. Comput.1
2025 TardySketch: A Framework for Cardinality Estimation Adaptable to Sliding Windows
abstract
Sliding cardinality estimation is crucial in many data analysis scenarios, e.g., detecting abnormal network behav-iors by monitoring unique connections in real time, detecting fraud in online transactions by monitoring unique user behavior patterns, and improving inventory management in supply chains by analyzing unique buyer behaviors. However, existing sliding cardinality estimation methods suffer from a cardinality barrel-down problem caused by unexpired item elimination in advance and item excessive removal, which remains unresolved so far. In this paper, we propose TardySketch, a sketch framework to make sliding cardinality estimation accurate and efficient by solving the above problem. The cornerstone of TardySketch is a Bidirectional Pointer-based Bitmap (BP-Bitmap), which stores the arrival sequence of items without timestamps. To prevent the premature elimination of unexpired items, we propose a Gap mechanism to enhance the accuracy of BP-Bitmap for identifying truly expired items through intermittent monitoring. To ensure an appropriate number of items are eliminated as the window moves, we design a Slow-Down mechanism to slacken the reset rate of bucket in BP- Bitmap to prevent over removal of items. Experimental results based on real-world datasets demonstrate that TardySketch significantly outperforms state-of-the-art methods, achieving a performance improvement of 5–40 times. The source code of TardySketch is available on GitHub.
Xuyang Jing, Qinghua Cao, Zheng Yan 0002, Wenxiu Ding, Witold Pedrycz, Pu Wang 0003
ICDE5
2024 Secure Federated Learning Schemes Based on Multi-Key Homomorphic Encryption
abstract
Federated learning (FL) has effectively solved the dilemma of "data silos" and has been widely applied into various fields. However, in real-life, user data is often Not Independent and Identically Distributed (Non-IID), and eavesdroppers can still infer users’ private data from various parameters transmitted in FL. Nevertheless, few privacy-preserving FL schemes focus on data heterogeneity, and offline problem causes more accuracy loss under Non-IID. This paper introduces a multi-key homomorphic encryption algorithm to construct two privacy-preserving FL schemes based on FedProx and SCAFFOLD, namely EMKProx and EMKSCAF. The two schemes both incorporate an anti-offline mechanism and take diverse measures to mitigate Non-IID’s impact on convergence speed, where EMKProx inserts a proximal term into loss function which is more suitable for poor hardware condition and EMKSCAF adds control variate to meet higher model performance requirement. We give security analyses to prove their security. In addition, we conduct simulations and comparisons with FL schemes using other privacy protection mechanisms, which show that our schemes behave more efficient and gain higher accuracy than the others.
Wenxiu Ding, Hongjiang Guo, Zheng Yan 0002
TrustCom1
2024 Zephyr: A High-Performance Framework for Graph Attention Networks on Heterogeneous Data
abstract
The Graph Attention Network (GAT), based on the foundational principles of Graph Neural Network (GNN), represents a significant advancement in the accurate representation and in-depth understanding of complex data structures. However, GAT can’t proficiently handle heterogeneous data, which negatively affects model performance. Existing solutions incur substantial computational overhead when addressing these challenges, compromising efficiency and impeding practical deployment. In this paper, we propose Zephyr to enable GAT to efficiently process heterogeneous data with high performance. In Zephyr, we introduce Dynamic Multi-matrix Design and Spatial Multi-activation Design to eliminate the effects of finiteness of matrix representation capability and difference in heterogeneous spaces. Remarkably, Zephyr shows superior capability in processing heterogeneous data while requiring minimal storage space. Through comprehensive simulations and comparisons with existing schemes, Zephyr demonstrates a substantial performance improvement, increasing accuracy by over 8% on heterogeneous datasets and enhancing fitting speed by approximately 20%. Moreover, with heterogeneous data, it maintains memory overhead below 1.05x and curtails time overhead to 70%.
Wenxiu Ding, Muzhi Liu, Mingxin Chen, Zheng Yan 0002
TrustCom1
2024 AdaptFL: Adaptive Client Task Allocation-Based Synchronous Federated Learning
abstract
Federated learning is a privacy protection method for machine learning, enabling the maintenance of data localization and privacy during training. However, the system heterogeneity leads to different time consumption for each client to complete each round of local training, thereby causing a serious straggler effect and affecting the overall efficiency of federated learning. Existing work has addressed the system heterogeneity issue by proposing task allocation strategies based on client capabilities to solve the straggler effect. However, simply adjusting the training tasks based solely on client capabilities can cause a decrease in the accuracy of local models, affecting the global model’s accuracy. In this paper, we propose AdaptFL, an adaptive client task allocation-based synchronous federated learning algorithm. This algorithm selects clients with a high probability of participation in training in each round. It adjusts the number of local epochs for clients dynamically based on training speed and the loss of local model. AdaptFL can alleviate the straggler effect effectively without reducing model accuracy, thereby enhancing the overall training efficiency of federated learning. Finally, we evaluate AdaptFL using the CIFAR-10 and FMNIST datasets, and the results demonstrate that the convergence and efficiency of AdaptFL.
Xiaoshuang Li, Yilong Guo, Wenxiu Ding
TrustCom4
2024 SP2-RD2D: Secure and Privacy-Preserving Authentication and Key Agreement Protocol for D2D Relay Communication
abstract
As a new paradigm among various D2D communication applications and use cases, D2D relay communication is a powerful underlay for 5G/6G to extend network coverage and increase communication reliability at the edge of cells. Despite its benefits, new application scenarios and system architecture expose D2D relay communications to unique security and privacy threats. Existing works proposed by neither 3GPP specifications nor academic research literature adequately address the issues of system security, privacy, and efficiency. To fill this gap, we propose SP2-RD2D, a lightweight secure and privacy-preserving authentication and key agreement protocol in D2D relay communication. This protocol enables remote users located outside or at the edge of the cell to establish a secure connection to the service network through relays. Meanwhile, SP2-RD2D provides identity privacy preservation for remote users and relays. We analyze the security of SP2-RD2D and assess its performance from both theoretical analysis and experimental evaluations. The result indicates that the proposed protocol effectively meets security and privacy requirements, demonstrating high efficiency in both computational and communication aspects.
Wenxiu Ding
TrustCom3
2024 EDDAC: An Efficient and Decentralized Data Access Control Scheme With Attribute Privacy Preservation
abstract
The rapid development of the Internet of Things (IoT) has led to the generation and perception of large amounts of data from IoT devices. These data are outsourced to the cloud for flexible sharing and deep analytics, which can significantly enhance IoT applications. But this raises privacy concerns for IoT devices. Attribute-based encryption is applied to realize fine-grained access control, which offers data owners control capability over their outsourced data. However, the centralized infrastructure is susceptible to the single-point-of-failure problem and may not be suitable for highly distributed IoT applications due to high latency. To overcome this issue, blockchain technology is introduced to realize a distributed infrastructure and provide robust data services. Owing to the innate transparency characteristic of blockchain, challenges associated with privacy are amplified. Therefore, this article presents an efficient and decentralized data access control (EDDAC) scheme that preserves attribute privacy. The scheme utilizes chameleon hash to implement attribute hiding, providing resistance against dictionary attacks. Additionally, it includes blockchain-based decryption tests that reduce the decryption overhead on clients through the application of inner product predicate encryption. Furthermore, our scheme employs Shamir secret sharing to achieve decentralized authorization based on blockchain, thereby reducing the trust-building overhead on authorization nodes. Finally, we provide proof of the adaptive security of the proposed scheme and demonstrate its effectiveness and advantages through simulations and comparisons with existing literature.
Lanyan Wang, Wenxiu Ding, Zheng Yan 0002, Su Qiu, Zhiguo Wan
IEEE Internet Things J.2
2024 SecFed: A Secure and Efficient Federated Learning Based on Multi-Key Homomorphic Encryption
abstract
Federated Learning (FL) is widely used in various industries because it effectively addresses the predicament of isolated data island. However, eavesdroppers is capable of inferring user privacy from the gradients or models transmitted in FL. Homomorphic Encryption (HE) can be applied in FL to protect sensitive data owing to its computability over ciphertexts. However, traditional HE as a single-key system cannot prevent dishonest users from intercepting and decrypting the ciphertexts from cooperative users in FL. Guaranteeing privacy and efficiency in this multi-user scenario is still a challenging target. In this paper, we propose a secure and efficient Federated Learning scheme (SecFed) based on multi-key HE to preserve user privacy and delegate some operations to TEE to improve efficiency while ensuring security. Specifically, we design the first TEE-based multi-key HE cryptosystem (EMK-BFV) to support privacy-preserving FL and optimize operation efficiency. Furthermore, we provide an offline protection mechanism to ensure the normal operation of system with disconnected participants. Finally, we give their security proofs and show their efficiency and superiority through comprehensive simulations and comparisons with existing schemes. SecFed offers a 3x performance improvement over TEE-based scheme and a 2x performance improvement over HE-based solution.
Wenxiu Ding, Yuxuan Xiao 0001, Zheng Yan 0002, Ximeng Liu, Zhiguo Wan
IEEE Trans. Dependable Secur. Comput.2
2023 A Survey on Cross-chain Technologies
abstract
Blockchain has attracted more and more attention of academia, industry, and government in recent decades. Different usage demands have inspired various blockchain designs, forming different blockchain systems, which leads to information islands. Many cross-chain technologies have been proposed to link different blockchains together and expand the utility of blockchain. Nevertheless, the cross-chain technology is still in its infancy, which faces many problems that retard its wide application, for example, the issues related to security, privacy, and effectiveness. In order to further investigate cross-chain technologies, it is essential to understand its current state of arts. Although there are some surveys about cross-chain technologies driven by specific demands, the literature still lacks a comprehensive survey focusing on security, privacy, and effectiveness of cross-chain technologies. In this paper, we provide a review on existing cross-chain technologies based on a comprehensive set of criteria on security, privacy, and other performance. We first propose a blockchain interoperability architecture for the purpose of analyzing potential threats and problems regarding security, privacy, and effectiveness. We then summarize a set of criteria regarding these quality attributes. Next, we comprehensively review the representative works on cross-chain technologies according to a taxonomy based on applied types of techniques and cross-chain purposes. In each work review, we provide a serious discussion on its pros and cons by employing our proposed criteria. Finally, based on our review and analysis, we figure out a number of open issues and step ahead to direct future research directions on cross-chain technologies.
Panpan Han, Zheng Yan 0002, Wenxiu Ding, Shufan Fei, Zhiguo Wan
Distributed Ledger Technol. Res. Pract.3
2023 ESMAC: Efficient and Secure Multi-Owner Access Control With TEE in Multi-Level Data Processing
abstract
Traditional data access control schemes only prevent unauthorized access to private data with a single owner. They are not suitable for application in a Multi-Level Data Processing (MLDP) scenario, where data are processed by a series of parties who also insert new data. Hence, the accumulated dataset should be protected through access control handled by hierarchically-structured parties who are at least partial data owners in MLDP. Existing multi-owner access control schemes mainly focus on controlling access to co-owned data of multiple entities with the equal ownership, but seldom investigates how to apply access control in MLDP. In this paper, we base the off-the-shelf Trusted Execution Environment (TEE), Intel SGX, to propose an Efficient and Secure Multi-owner Access Control scheme (ESMAC) for access authorization in MLDP. Moreover, to prevent unauthorized data disclosure by non-root data owners aiming to gain extra profits, we further introduce undercover polices to supervise their behaviors. Specifically, we design a data protection scheme based on game theory to decide the payoffs and punishments of honest and dishonest data owners, which motivates data owners to behave honestly when claiming ownership over data. Through comprehensive security analysis and performance evaluation, we demonstrate ESMAC's security and effectiveness.
Zheng Yan 0002, Wenxiu Ding, Yaxing Chen, Zhiguo Wan
IEEE Trans. Dependable Secur. Comput.3
2022 An Efficient and Secure Scheme of Verifiable Computation for Intel SGX
abstract
Cloud computing offers resource-constrained users big-volume data storage and energy-consuming complicated computation. However, owing to the lack of full trust in the cloud, the cloud users prefer privacy-preserving data computation with correctness verification. However, cryptography-based schemes introduce high computational costs to both the cloud and its users for verifiable computation with privacy preservation, which makes it difficult to support complicated computations in practice. Intel Software Guard Extensions (SGX) as a trusted execution environment is widely researched in various fields, and is regarded as a promising way to achieve efficient outsourced data computation with privacy preservation over the cloud. But we find two types of threats towards the computation with SGX: Disarranging Data-Related Code threat and Output Tampering and Misrouting threat. In this paper, we depict these threats using formal methods and propose an efficient and secure scheme to resist the threats and realize verifiable computation for Intel SGX. We prove the security and show the efficiency and correctness of our proposed scheme through theoretic analysis and extensive experiments. Furthermore, we compare our scheme with some cryptography-based schemes to show its high efficiency.
Wenxiu Ding, Zheng Yan 0002, Robert H. Deng, Zhiguo Wan
TrustCom1
2022 Software Side Channel Vulnerability Detection Based on Similarity Calculation and Deep Learning
abstract
Software Side Channel Vulnerabilities (SSCVs) cause serious security threats, which introduces a big challenge to software development. With the sustaining growth of software complexity and scale, SSCV detection has become a tedious work. Existing methods suffer from efficiency, accuracy and generality problems, and ignore the detection of vulnerability variants. Applying machine learning is promising due to high efficiency and automation, but training an effective model is still an open issue due to the lack of side-channel vulnerability data. In this paper, we propose a novel two-stage SSCV detection method based on similarity calculation and deep learning. We target three types of vulnerability variants that have different degrees of similarity to original ones. The first detection stage applies Deterministic Finite Automata (DFA) and Trie tree to regularize software codes for detecting vulnerability Variants 1 and 2 through similarity calculation. The second stage uses Long Short-Term Memory and Neural Network Classifier (LSTM-NNClassifier) to discover vulnerability Variant 3. In addition, we offer a code augmentation method to construct a sufficient dataset to train the LSTM-NNClassifier for overcoming the problem of lacking training data. Extensive experiments based on real world data show the efficiency and accuracy of our detection method.
Zheng Yan 0002, Wenxiu Ding
TrustCom4
2020 Privacy-preserving Computation over Encrypted Vectors
abstract
Cloud computing allows users to outsource massive amounts of data to a cloud server for storage and analysis, which breaks the bottleneck of limited local resources. However, it makes user data exposed and possibly be accessed by unauthorized entities. Owing to privacy concern, users are inclined to upload encrypted data to a cloud server, but encryption limits operations over original data and affects access to a processing result. Though lots of schemes have been proposed to achieve some basic operations over encrypted data, it still lacks the research on the dot product of encrypted vectors. In this paper, we propose two privacy-preserving dot product schemes based on a dual server model, which can flexibly support single-user access and multiuser access to a final data processing result. Furthermore, we extend them to achieve privacy-preserving Support Vector Machine (SVM) prediction algorithm. Finally, we give security analysis of our proposed schemes and demonstrate their availability and practicality through simulation and comparison with existing works.
Wenxiu Ding, Zheng Yan 0002
GLOBECOM2
2020 Privacy-Preserving Data Processing with Flexible Access Control
abstract
Cloud computing provides an efficient and convenient platform for cloud users to store, process and control their data. Cloud overcomes the bottlenecks of resource-constrained user devices and greatly releases their storage and computing burdens. However, due to the lack of full trust in cloud service providers, the cloud users generally prefer to outsource their sensitive data in an encrypted form, which, however, seriously complicates data processing, analysis, as well as access control. Homomorphic encryption (HE) as a single key system cannot flexibly control data sharing and access after encrypted data processing. How to realize various computations over encrypted data in an efficient way and at the same time flexibly control the access to data processing results has been an important challenging issue. In this paper, we propose a privacy-preserving data processing scheme with flexible access control. With the cooperation of a data service provider (DSP) and a computation party (CP), our scheme, based on Paillier's partial homomorphic encryption (PHE), realizes seven basic operations, i.e., Addition, Subtraction, Multiplication, Sign Acquisition, Absolute, Comparison, and Equality Test, over outsourced encrypted data. In addition, our scheme, based on the homomorphism of attribute-based encryption (ABE), is also designed to support flexible access control over processing results of encrypted data. We further prove the security of our scheme and demonstrate its efficiency and advantages through simulations and comparisons with existing work.
Wenxiu Ding, Zheng Yan 0002, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.1
2020 An Extended Framework of Privacy-Preserving Computation With Flexible Access Control
abstract
Cloud computing offers various services based on outsourced data by utilizing its huge volume of resources and great computation capability. However, it also makes users lose full control over their data. To avoid the leakage of user data privacy, encrypted data are preferred to be uploaded and stored in the cloud, which unfortunately complicates data analysis and access control. In particular, few existing works consider the fine-grained access control over the computational results from ciphertexts. Though our previous work proposed a framework to support several basic computations (such as addition, multiplication and comparison) with flexible access control, privacy-preserving division calculations over encrypted data, as a crucial operation in many statistical processes and machine learning algorithms, is neglected. In this paper, we propose four privacy-preserving division computation schemes with flexible access control to fill this gap, which can adapt to various application scenarios. Furthermore, we extend a division scheme over encrypted integers to support privacy-preserving division over multiple data types including fixed-point numbers and fractional numbers. Finally, we give their security proof and show their efficiency and superiority through comprehensive simulations and comparisons with existing work.
Wenxiu Ding, Zheng Yan 0002, Xinren Qian, Robert H. Deng, Laurence T. Yang, Mianxiong Dong
IEEE Trans. Netw. Serv. Manag.1
2020 A survey on data provenance in IoT
abstract
Abstract Internet of Things (IoT), as a typical representation of cyberization, enables the interconnection of physical things and the Internet, which provides intelligent and advanced services for industrial production and human lives. However, it also brings new challenges to IoT applications due to heterogeneity, complexity and dynamic nature of IoT. Especially, it is difficult to determine the sources of specified data, which is vulnerable to inserted attacks raised by different parties during data transmission and processing. In order to solve these issues, data provenance is introduced, which records data origins and the history of data generation and processing, thus possible to track the sources and reasons of any problems. Though some related researches have been proposed, the literature still lacks a comprehensive survey on data provenance in IoT. In this paper, we first propose a number of design requirements of data provenance in IoT by analyzing the features of IoT data and applications. Then, we provide a deep-insight review on existing schemes of IoT data provenance and employ the requirements to discuss their pros and cons. Finally, we summarize a number of open issues to direct future research.
Zheng Yan 0002, Wenxiu Ding, Laurence T. Yang
World Wide Web3
2019 Computing Maximum and Minimum with Privacy Preservation and Flexible Access Control
abstract
With the fast development of Internet of Things, huge volume of data is being collected from various sensors and devices, aggregated at gateways, and processed in the cloud. Due to privacy concern, data are usually encrypted before being outsourced to the cloud. However, encryption seriously impedes both computation over the data and sharing of the computation results. Computing maximum and minimum among a data set are two of the most basic operations in machine learning and data mining algorithms. In this paper, we study how to compute maximum and minimum over encrypted data and control the access to the computation result in a privacy-preserving manner. We present four schemes to realize privacy-preserving maximum and minimum computations with flexible access control that can adapt to various application scenarios. We further analyze their security and show their efficiency through extensive evaluations and comparisons with existing work.
Wenxiu Ding, Zheng Yan 0002, Xinren Qian, Robert H. Deng
GLOBECOM1
2019 A Survey on Secure Data Analytics in Edge Computing
abstract
Internet of Things (IoT) is gaining increasing popularity. Overwhelming volumes of data are generated by IoT devices. Those data after analytics provide significant information that could greatly benefit IoT applications. Different from traditional applications, IoT applications, such as environmental monitoring, smart navigation, and smart healthcare come with new requirements, such as mobility, real-time response, and location awareness. However, traditional cloud computing paradigm cannot satisfy these demands due to centralized processing and being far away from local devices. Hence, edge computing was introduced to perform data processing and storage in the edge of networks, which is closer to data sources than cloud computing, thus efficient and location-aware. Unfortunately, edge computing brings new security and privacy challenges when applied to data analytics. The literature still lacks a thorough review on the recent advances in secure data analytics in edge computing. In this paper, we first introduce the concept and features of edge computing, and then propose a number of requirements for its secure data analytics by analyzing potential security threats in edge computing. Furthermore, we give a comprehensive review on the pros and cons of the existing works on data analytics in edge computing based on our proposed requirements. Based on our literature survey, we highlight current open issues and propose future research directions.
Zheng Yan 0002, Wenxiu Ding, Mohammed Atiquzzaman
IEEE Internet Things J.3
2019 Heterogeneous Data Storage Management with Deduplication in Cloud Computing
abstract
Cloud storage as one of the most important services of cloud computing helps cloud users break the bottleneck of restricted resources and expand their storage without upgrading their devices. In order to guarantee the security and privacy of cloud users, data are always outsourced in an encrypted form. However, encrypted data could incur much waste of cloud storage and complicate data sharing among authorized users. We are still facing challenges on encrypted data storage and management with deduplication. Traditional deduplication schemes always focus on specific application scenarios, in which the deduplication is completely controlled by either data owners or cloud servers. They cannot flexibly satisfy various demands of data owners according to the level of data sensitivity. In this paper, we propose a heterogeneous data storage management scheme, which flexibly offers both deduplication management and access control at the same time across multiple Cloud Service Providers (CSPs). We evaluate its performance with security analysis, comparison and implementation. The results show its security, effectiveness and efficiency towards potential practical usage.
Zheng Yan 0002, Wenxiu Ding
IEEE Trans. Big Data3
2017 Secure Encrypted Data Deduplication with Ownership Proof and User Revocation
Wenxiu Ding, Zheng Yan 0002, Robert H. Deng
ICA3PP1
2017 Encrypted data processing with Homomorphic Re-Encryption
Wenxiu Ding, Zheng Yan 0002, Robert H. Deng
Inf. Sci.1
2016 Two Schemes of Privacy-Preserving Trust Evaluation
Zheng Yan 0002, Wenxiu Ding, Valtteri Niemi, Athanasios V. Vasilakos
Future Gener. Comput. Syst.2
2016 Deduplication on Encrypted Big Data in Cloud
abstract
Cloud computing offers a new way of service provision by re-arranging various resources over the Internet. The most important and popular cloud service is data storage. In order to preserve the privacy of data holders, data are often stored in cloud in an encrypted form. However, encrypted data introduce new challenges for cloud data deduplication, which becomes crucial for big data storage and processing in cloud. Traditional deduplication schemes cannot work on encrypted data. Existing solutions of encrypted data deduplication suffer from security weakness. They cannot flexibly support data access control and revocation. Therefore, few of them can be readily deployed in practice. In this paper, we propose a scheme to deduplicate encrypted data stored in cloud based on ownership challenge and proxy re-encryption. It integrates cloud data deduplication with access control. We evaluate its performance based on extensive analysis and computer simulations. The results show the superior efficiency and effectiveness of the scheme for potential practical deployment, especially for big data deduplication in cloud storage.
Zheng Yan 0002, Wenxiu Ding, Xixun Yu, Haiqi Zhu, Robert H. Deng
IEEE Trans. Big Data2
2016 Privacy-Preserving Outsourced Calculation on Floating Point Numbers
abstract
In this paper, we propose a framework for privacy-preserving outsourced calculation on floating point numbers (POCF). Using POCF, a user can securely outsource the storing and processing of floating point numbers to a cloud server without compromising on the security of the (original) data and the computed results. In particular, we first present privacy-preserving integer processing protocols for common integer operations. We then present an approach to outsourcing floating point numbers for storage in a privacy-preserving way, and securely processing commonly used floating point number operations on-the-fly. We prove that the proposed POCF achieves the goal of floating point number processing without privacy leakage to unauthorized parties, and demonstrate the utility and the efficiency of POCF using simulations.
Ximeng Liu, Robert H. Deng, Wenxiu Ding, Rongxing Lu, Baodong Qin
IEEE Trans. Inf. Forensics Secur.3
2015 A Scheme to Manage Encrypted Data Storage with Deduplication in Cloud
Zheng Yan 0002, Wenxiu Ding, Haiqi Zhu
ICA3PP (3)2
2015 Improvement and optimized implementation of cryptoGPS protocol for low-cost radio-frequency identification authentication
abstract
Abstract In radio‐frequency identification (RFID) authentication technology, the authentication schemes between reader and tag based on public‐key cryptography (PKC) are much better than those based on symmetric‐key cryptography in terms of expanding the scale of RFID applications and the style of providing service, while the limitation of resource consumption and computation capability of RFID tags makes it difficult to apply traditional PKC to RFID authentications. The cryptoGPS protocol based on PKC proposed by Mcloone and Robshaw suits low‐cost RFID system well, but it just achieves one‐way authentication, and the authentication times are very limited, which makes it vulnerable to coupons‐exhausted DoS attacks. To solve these problems, cryptoGPS protocol is greatly improved to realize the mutual authentication between RFID reader and the tag. In the improved protocol, a readers' public key distribution scheme is proposed to support the mutual authentication and a coupons updating algorithm is presented to resist the aforementioned DoS attack. Moreover, a modified Rabin encryption algorithm and a parameter generation method based on Low Hamming Weight technology are proposed to optimize the implementation of the proposed authentication protocol. And a feasible hardware structure of the protocol is also given. The protocol's simulation results show that the scheme just needs 3232 equivalent gates, and the maximum time of single step is 3.3 ms (500 k clock). The scheme is suitable for the low‐cost tags. Copyright © 2014 John Wiley & Sons, Ltd.
Qingkuan Dong, Wenxiu Ding
Secur. Commun. Networks2