Fatemeh Rezaeibagha

dblp:177/6209 · DBLP profile ↗
← Back
34ranked-venue papers
9as first author
26since 2021 · last 2026
0000-0002-1368-016XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 first-author · 8 since 2021Computer networks · 8 · 2 first-author · 7 since 2021Systems, architecture and hardware · 6 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Lightweight distributed data sharing with dual anonymity for accident traceability in VANETs
Leyou Zhang, Qing Wu 0005, Fatemeh Rezaeibagha
J. Inf. Secur. Appl.4
2026 Time Updatable Policy-Based Chameleon Hash for Traceable and Accountable Redactable Blockchain
abstract
Ateniese et al. (EuroS&P 2017) proposed the notion of redactable blockchains (RBs), in which a designated party uses a secret key to modify blockchain history without causing a hard fork. Nevertheless, redactions may be performed mistakenly or maliciously due to misbehavior or operational errors. From a regulatory perspective, any RB design must therefore incorporate accountability and traceability mechanisms to ensure that redactions are non-abusive and publicly verifiable. As a countermeasure, we propose the notion of time-updatable policy-based chameleon hash (TPCH). This construction addresses regulatory concerns by enabling publicly verifiable proofs of redaction and traceable user identities. Our basic building block, termed time-updatable chameleon hash (TUCH), provides redaction accountability through an intrinsic property formalized as Type-2 Trapdoor Collisions. TUCH is functionally versatile and achieves acceptably efficient performance compared to peer chameleon hash schemes. Following the heuristics of Camenisch et al. (PKC 2017) and Derler et al. (NDSS 2019), we further extend TUCH by integrating attribute-based encryption (ABE) to obtain a time-updatable, policy-based variant, namely TPCH. The resulting scheme overcomes the limitations of coarse-grained redaction and the impracticality of specifying the exact modifier in advance. Overall, TPCH provides a secure, efficient, and comprehensive solution for accountable and traceable redactable blockchains under practical regulatory requirements. Our systematic analysis further demonstrates the suitability of TPCH for small scale deployment.
Ke Huang 0002, Xiong Li 0002, Fatemeh Rezaeibagha, Linghao Zhang, Xiaosong Zhang 0001
IEEE Trans. Inf. Forensics Secur.3
2025 Traceable and Verifiable Authorized Cloud-Assisted PSI-CA Protocol for Blockchain-Enabled Intelligent Logistics
abstract
Amid the rapid development of e-commerce and logistics, enterprises urgently require advanced digital technologies to achieve modernization and intelligent transformation, thereby meeting the fast-changing market demands. Within the logistics Internet of Things (IoT), companies face numerous scenarios that necessitate quantifying the degree of data overlap, where only acquiring statistical information suffices. The Private Set Intersection Cardinality (PSI-CA) technology offers an almost ideal solution. However, an effective approach must not only safeguard privacy but also enable companies to demonstrate their data protection capabilities to consumers. Existing PSI-CA solutions neglect the sustainable development needs of enterprises in terms of data correctness, integrity, management transparency, and user retention. Therefore, this paper proposes, for the first time, a trackable and verifiable authorized cloud-assisted PSI-CA (TVACPSI-CA) protocol, upon which a multi-threaded intelligent logistics system (ILS) is designed to harmonize data privacy protection with operational efficiency in logistics enterprises. The protocol employs accumulators, oblivious pseudorandom function (OPRF), zero-knowledge proof, digital signatures and blockchain technology to achieve objectives such as data privacy protection, access control, correctness verification of delegated computation, data integrity protection, abuse resistance, and traceability. This facilitates enterprises in mitigating security risks and enhancing customer trust. We rigorously analyze and prove the security of our solution. Finally, a comparative analysis with existing approaches demonstrates that the proposed scheme balances between high security and low communication/computational overhead. This provides the logistics industry with a secure, efficient, and scalable data-sharing solution, thereby enabling operational optimization.
Qing Wu 0005, Yue Lei, Leyou Zhang, Xijia Dong, Fatemeh Rezaeibagha
IEEE Internet Things J.5
2025 Authenticable Distributed Homomorphic Private Counter and its application in data analysis of edge computing
abstract
The rapid proliferation of advanced technologies, including the Internet of Things (IoT), cloud computing , and edge computing , has led to an exponential growth in structured and unstructured data, generated and collected across diverse applications. It is important to develop secure techniques that can efficiently process large volumes of data while preserving privacy. Privacy-preserving data analytics on encrypted data have gained popularity for performing essential calculations within cloud storage servers . However, applying these techniques to fully homomorphic encryption introduces inefficiencies and computational overheads. While homomorphic encryption allows for delegated execution of arithmetic operations directly on ciphertexts via cloud services, ensuring both efficiency and correctness in data computations remains a challenging endeavor. Most existing studies overlook simultaneous data aggregation while maintaining integrity and privacy for analytical purposes. In response, we propose an Authenticable Distributed Homomorphic Private Counter Scheme (ADHPC) for privacy-preserving data analysis in cloud computing. Our scheme securely and efficiently aggregates encrypted data within distributed edge computing environments, subsequently allowing authorized parties to decrypt and validate it. To authenticate the encrypted data, we employ an authenticable additive homomorphic encryption scheme based on online and offline setup stages. We demonstrate the applicability and efficiency of our proposed approach through implementation results and a comprehensive security analysis.
Fatemeh Rezaeibagha, Leyou Zhang, Ke Huang 0002, Lanxiang Chen
J. Inf. Secur. Appl.1
2024 Blockchain-Aided Anonymous Traceable and Revocable Access Control Scheme With Dynamic Policy Updating for the Cloud IoT
abstract
The Internet of Things has been applied in various fields of industry, which has promoted the intelligent development of the industry and improved efficiency in industrial production. The devices involved in the IoT have generated useful and sensitive data over time and upload the data to the cloud to realize real-time data sharing. To ensure the confidentiality of data, many systems use attribute-based encryption primitive to encrypt data. However, there are still some security and privacy problems in this mode, such as the lack of identification of malicious users who leaked private keys, performance bottleneck caused by excessive reliance on a single central authority (CA), and vulnerability because a single CA holds the private keys of all users in the system. In this article, white-box tracking is used to identify malicious users. The alliance chain is introduced to support multiauthority environments, where the consensus nodes are managed by different authorities and assist CA in generating partial private keys. To protect users’ privacy, users remain anonymous at all times during their interactions with blockchain consensus. The security analysis and simulation results show that the proposed scheme outperformed other comparable schemes, indicating that it is a preferable scheme.
Leyou Zhang, Qing Wu 0005, Fatemeh Rezaeibagha
IEEE Internet Things J.4
2024 Enhanced Secure Attribute-Based Dynamic Data Sharing Scheme With Efficient Access Policy Hiding and Policy Updating for IoMT
abstract
The application of 5G makes the medical Internet of Things(IoMT) bring many opportunities to the medical industry. It is expected to improve the quality and efficiency of medical services and improve people’s quality of life. However, a large number of data and users are generated by smart devices in IoMT. How to access and share securely the dynamic data and manage the dynamic users has been a challenging problem at present. Many various methods were introduced to solve it. However, collusion attacks, privacy leakage, and high computational costs are not solved or only partly solved. In this paper, we analyze the most recent work at first and point out their drawbacks. Additionally, the user revocation method adopted by these schemes can not prevent revoked users from colluding with unrevoked users or the cloud to obtain shared data. Subsequently, we propose an efficient policy hiding and policy updating attribute-based data sharing scheme. The proposals support user revocation, which solves the collusion between the revoked users and unrevoked users or the cloud. Under this scheme, attributes are divided into attribute names and attribute values, and sensitive information attribute values are hidden in access policies to protect user privacy. We reduce user computational overhead by using outsourced techniques and policy update methods. The scheme is proved to be fully secure which is stronger than most of the existing works. The comparison and simulation results confirm the advantages of the proposed scheme over the available in the IoMT.
Leyou Zhang, Shuwei Xie, Qing Wu 0005, Fatemeh Rezaeibagha
IEEE Internet Things J.4
2024 Flexibly expressive and revocable multi-authority KP-ABE scheme from RLWE for Internet of Medical Things
Shuwei Xie, Leyou Zhang, Qing Wu 0005, Fatemeh Rezaeibagha
J. Syst. Archit.4
2024 Monero With Multi-Grained Redaction
abstract
Monero is a privacy-centric cryptocurrency that allows users to obscure their transactions with multiple input and output addresses. Current research on Monero mainly focuses on identifying design vulnerabilities or optimizing towards stronger privacy, security, etc. For example, improving the design of ring confidential transaction (RingCT) protocol proposed by Noether et al. As revealed by Ali et al. in USENIX 2016, new blockchains have inadequate nodes and network computing resources to resist powerful attack (e.g., 51% attack). Obviously, Monero blockchain is not an exception. Ateniese et al. proposed the notion of redactable blockchain in EuroS$ \& amp;$P 2017, which begins the trend of formalizing blockchain with extra cryptographic primitives. The motivation is to turn an immutable blockchain into a mutable ledger by adapting the blockchain design and integrating with new cryptographic schemes. In such a setting, users could use their private keys to perform the secure multi-party computation to reverse blockchain history. The idea of redactable blockchain has attracted many researchers to pursuit this topic. However, few works have considered the privacy-preserving setting. Even fewer have practised their designs in an actual cryptocurrency. In this paper, we seek to adapt the RingCT protocol with several building blocks. Our proposal achieves most of the desired properties for blockchain redaction. It allows multiple tracing authorities to collaboratively trace users’ identities, and a system manager to perform multi-grained (including block-level, transaction-level, accumulator-level and commitment-level) redaction on block contents. Our proposal can be seen as an extension of RingCT protocol. We give rigorous security requirements and comprehensive analysis of our scheme. The performance evaluation suggested that our scheme suffers from some unscalabilities in large-scale implementations. A more elegant design to achieve stronger security and ideal scalability is deemed as a challenging and interesting future work.
Ke Huang 0002, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaosong Zhang 0001, Xiong Li 0002
IEEE Trans. Dependable Secur. Comput.3
2023 Toward Secure Data Computation and Outsource for Multi-User Cloud-Based IoT
abstract
Cloud computing has promoted the success of Internet of Things (IoT) with offering abundant storage and computation resources where the data from IoT sensors can be remotely outsourced to the cloud servers, whereas storing, exchanging and processing data collected through IoT sensors via centralised or decentralised cloud servers make cloud-based IoT systems prone to internal or external attacks. To protect IoT data against potential malicious users and adversaries, some cryptographic schemes have been applied to ensure confidentiality and integrity of IoT data. It is however a challenging task to perform any arithmetical computations once data items are encrypted. Fully-homomorphic encryption which is based on lattices can, in principle, provide a solution, but it is unfortunately inefficient in computation and hence cannot be applied to IoT. Fully-homomorphic encryption is feasible when we allow the involvement of a semi-trusted server. However, it is challenging to provide such a system in the situation of distributed environments for shared IoT data. We solve this problem and provide a fully-homomorphic encryption scheme for cloud-based IoT applications. We introduce a new method with the aid of a semi-trusted server that can help compute the homomorphic multiplications without gaining any useful information of the encrypted data. We show how our scheme is applied to multi-user IoT security and prove its semantic security. We also conduct experiments to justify its efficiency and applicability to multi-user cloud-based IoT systems.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang
IEEE Trans. Cloud Comput.1
2023 Authenticable Data Analytics Over Encrypted Data in the Cloud
abstract
Statistical analytics on encrypted data requires a fully-homomorphic encryption (FHE) scheme. However, heavy computation overheads make FHE impractical. In this paper we propose a novel approach to achieve privacy-preserving statistical analysis on an encrypted database. The main idea of this work is to construct a privacy-preserving calculator to calculate attributes’ count values for later statistical analysis. To authenticate these encrypted count values, we adopt an authenticable additive homomorphic encryption scheme to construct the calculator. We formalize the notion of an authenticable privacy-preserving calculator that has properties of broadcasting and additive homomorphism. Further, we propose a cryptosystem based on binary vectors to achieve complex logic expressions for statistical analysis on encrypted data. With the aid of the proposed cryptographic calculator, we design several protocols for statistical analysis including conjunctive, disjunctive and complex logic expressions to achieve more complicated statistical functionalities. Experimental results show that the proposed scheme is feasible and practical.
Lanxiang Chen, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.4
2023 BE-TRDSS: Blockchain-Enabled Secure and Efficient Traceable-Revocable Data-Sharing Scheme in Industrial Internet of Things
abstract
As an important component of the Industrial Internet of Things (IIoT), the smart factory uses IIoT and equipment-monitoring technology to collect data to reasonably arrange the production. A large number of data is collected and uploaded to the IIoT cloud platform. However, the IIoT cloud platform is semitrusted and has structural limitations and vulnerability, which makes it necessary to realize data dynamic security sharing and malicious users' tracking. In this article, we show that the most recent work on this issue is still vulnerable to security threats at first. Then, a blockchain-enabled dynamic and traceable data-sharing scheme for a smart factory is proposed. Blockchain performs the user authentication and stores the ciphertext index and public keys to avoid tampering with shared data. The tracking algorithm tracks malicious users and adds them to a revocation list embedded in the ciphertext. And the authority can flexibly select domain or user revocation as required. The LSSS access policy is hidden to protect user privacy, and the cloud server uses the match test algorithm to detect whether users meet the hidden access policy. Additionally, online–offline encryption and outsourced decryption improve the efficiency of the scheme where the ciphertext and the pairing operations required for decryption achieve constant size. A performance analysis shows that the scheme can resist a variety of collusion attacks, and simulations show that it outperforms current schemes.
Ruonan Ma, Leyou Zhang, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
IEEE Trans. Ind. Informatics5
2023 CASE-SSE: Context-Aware Semantically Extensible Searchable Symmetric Encryption for Encrypted Cloud Data
abstract
Traditional searchable symmetric encryption (SSE) schemes rarely support context-aware semantic extension, and then lead to the searched results being incomplete or deviating from the user’s query intention. To address this problem, a new context-aware semantically extensible searchable symmetric encryption based on Word2vec model (CASE-SSE) is proposed to achieve context-aware semantic extension in this article. The proposed scheme utilizes outsourced datasets as corpora to extract all keywords for training the Word2vec model, and the trained results is the ontology knowledge base that can be used to extend the semantics of query keywords directly. Further, to facilitate multi-keyword search using the extended query vector, we use the$k$-means clustering algorithm to classify outsourced datasets. We then construct an AVL-tree index and an inverted index based on the classified results, thereby achieving efficient context-aware semantically extensible SSE. The security analysis indicates it is secure and effective. The experimental results show that our scheme is superior in both efficiency and accuracy.
Lanxiang Chen, Yujie Xue, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng
IEEE Trans. Serv. Comput.5
2023 Authenticable Additive Homomorphic Scheme and its Application for MEC-Based IoT
abstract
The integration of Internet of Things (IoT) and cloud computing are always seen as promising technologies to enhance streamlined data collection, share and exchange. Although the advances in edge computing, particularly mobile edge computing (MEC), could enhance the performance of data collection and computation via computing offloading, security and privacy impediments have made new challenges to data integrity and confidentiality, in particular when multiple edges or nodes at different locations collect IoT data. Homomorphic encryption therefore has shown promising advantages for cloud computing, offering arithmetic operations to be carried out on the encrypted data without revealing the secret key. While fully homomorphic encryption introduced by Gentry, in 2009, allows both additive and multiplicative operations, it has shown significant implementation drawbacks due to the parameters generation and memory consumption. In this work, we focus on partially homomorphic encryption, which can be efficiently computed. However, it is challenging to add authentication feature for the verification and aggregation capability. We propose a novel secure and privacy preserving authenticable homomorphic encryption (AHEC) scheme. We demonstrate an application of our AHEC scheme for MEC-based IoT systems and provide security analysis to prove that our scheme is secure against chosen plaintext attack (IND-CPA) and unforgeability (UNF) under DDH-ZN2 and Lift-DH-ZN2 assumptions. Experimental results show that our proposed scheme is efficient for practical applications.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang
IEEE Trans. Serv. Comput.1
2022 Blockchain-based random auditor committee for integrity verification
Lanxiang Chen, Qingxiao Fu, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Min-Shiang Hwang
Future Gener. Comput. Syst.5
2022 Blockchain-based deduplication with arbitration and incentives
abstract
Abstract Cloud storage is an ideal platform to accommodate massive data. However, with the increasing number of various devices and improved processing power, the amount of generated data is becoming gigantic. Therefore, this calls for a cost‐effective way to outsource massively generated data to a remote server. Cloud service providers utilise deduplication technique which deduplicates redundant data by aborting identical uploading requests and deleting redundant files. However, current deduplication mechanisms mainly focus on the storage saving of the server, and ignore the sustainable and long‐term financial interests of servers and users. This is not helpful to expand outsourcing and deduplication services. Blockchain is an ideal solution to achieve an economical and incentive‐driven deduplication system. Though some current research studiess have integrated deduplication with blockchain, they did not utilise blockchain as a financial tool. Meanwhile, it lacks an arbitration mechanism to settle disputes between the server and the user, especially in a Bitcoin payment where the payment is not confirmed immediately and a dispute may occur. This creates a burden to achieve fair and transparent incentive‐based deduplication service. In this work, we construct a deduplication system with financial incentives for the server and the user based on Bitcoin. The data owner will pay money via Bitcoin to the server for outsourcing the file, but this fee can be compensated by charging deduplication users with some fees to acquire the deduplication service. The server and the user can receive revenues using deduplication service. Disputes on the fair distribution of incentives can be settled by our arbitration protocol with chameleon hashes as arbitration tags. We give concrete construction and security requirements for our proposed . The security analysis shows that our is theoretically secure. The performance evaluation shows that our proposed is acceptably efficient for the deduplication. Meanwhile, we evaluate and conclude that 1% of outsourcing fee (or less) is a reasonable and preferable price for each deduplication user to pay as compensation for data owner.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Yongcheng Gong
IET Inf. Secur.4
2022 Secure Decentralized Attribute-Based Sharing of Personal Health Records With Blockchain
abstract
Personal health records (PHRs) are located in a patient-centered electronic health system in which users can store and share medical information. However, PHRs have recently been plagued by security issues, such as the leakage of personal health information, illegal access to patient data, and data tampering. Recent security developments, such as introducing an access control policy with attribute-based encryption (ABE) or utilizing blockchain, have only been partially successful in solving these issues. Ongoing challenges to PHR sharing include single points of failure, node cheating attacks, and fair keyword search issues. In this article, we tackle these challenges by introducing a distributed PHR-sharing scheme based on blockchain and ciphertext policy ABE (CP-ABE), which allows for fast and efficient encryption and decryption. Blockchain maintains the integrity and the tracing source of the data while also recording all operations on the data in the form of transactions. In addition, the blockchain nodes act as attribute authorities to construct the CP-ABE cryptosystem. The tracing of malicious blockchain nodes is realized by tracing cryptography algorithms. Furthermore, the fair retrieval of ciphertext is achieved by employing smart contracts. To overcome the limited storage capacity of blockchain, we adopt both the on-chain and off-chain storage modes in our new system. Security analysis indicates that our new scheme remains intact when threatened by an indistinguishable chosen plaintext attack (IND-CPA) and an indistinguishable chosen keywords attack (IND-CKA). As such, we conclude that our proposed approach is feasible and efficient.
Leyou Zhang, Tianshuai Zhang, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
IEEE Internet Things J.5
2022 A Secure and Efficient Decentralized Access Control Scheme Based on Blockchain for Vehicular Social Networks
abstract
The vehicular social network (VSN) is an emerging mobile communication system combining a vehicle ad hoc network (VANET) with a social network. It provides a new means of sharing, disseminating, and delivering data for passengers, drivers, and vehicles. However, a VSN may expose users’ private information, such as identities, location information, and trajectories, and tampering with shared data may lead to security and safety problems in vehicle systems. Considering the security and privacy preservation of shared data, we propose a lightweight decentralized multiauthority access control scheme based on ciphertext-policy attribute-based encryption (CP-ABE) and blockchain, by which a decentralized multiauthorization node supports vehicle users by performing lightweight calculations with the assistance of the vehicle cloud service provider (VCSP). We use blockchain to record storage and access transactions, achieving self-verification by users and tamper-resistance of ciphertexts. An improved smart contract reduces the workload of verification by users and achieves privacy preservation by hiding the policy. It supports user revocation and outsourced decryption, enabling more flexibility and better performance. A security and performance analysis shows that our scheme has clear advantages over existing schemes.
Leyou Zhang, Ye Zhang 0026, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
IEEE Internet Things J.5
2022 Structured encryption for knowledge graphs
Yujie Xue, Lanxiang Chen, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng
Inf. Sci.5
2022 Controllable software licensing system for sub-licensing
Manli Yuan, Yi Mu 0001, Fatemeh Rezaeibagha, Li Xu 0002, Xinyi Huang 0001
J. Inf. Secur. Appl.3
2022 Blockchain-enabled multi-authorization and multi-cloud attribute-based keyword search over encrypted data in the cloud
Qing Wu 0005, Taotao Lai, Leyou Zhang, Yi Mu 0001, Fatemeh Rezaeibagha
J. Syst. Archit.5
2022 A traceable and revocable multi-authority access control scheme with privacy preserving for mHealth
Leyou Zhang, Chuchu Zhao, Qing Wu 0005, Yi Mu 0001, Fatemeh Rezaeibagha
J. Syst. Archit.5
2022 Bidirectional and Malleable Proof-of-Ownership for Large File in Cloud Storage
abstract
Cloud storage is a cost-effective platform to accommodate massive data at low cost. However, advances of cloud services propel data generation, which pushes storage servers to its limit. Deduplication is a popular technique enjoyed by most current cloud servers, which detects and deletes redundant data to save storage and bandwidth. For security concerns, proof-of-ownership (PoW) can be used to guarantee ownership of data such that no malicious user could pass deduplication easily or utilize such mechanism for malicious purposes. Generally, PoW is implemented in static data archive where the data file is supposed to be read-only. However, to satisfy users’ needs for dynamical manipulation on data and support real-time data services, it is required to devise efficient PoW for dynamic archive. Inspired by malleable signature, which offers authentication even after its committed message changes, we propose the notion of bidirectional and malleable proof-of-ownership ($\sf {BM\mbox{-}PoW}$) for the above challenge. Our proposed$\sf {BM\mbox{-}PoW}$consists of bidirectional PoW (${\mbox{B-PoW}}$), malleable PoW (${\mbox{M-PoW}}$) and dispute arbitration protocol$\sf {DAP}$. While our${\mbox{B-PoW}}$is proposed for a static setting, the${\mbox{M-PoW}}$caters specifically for dynamic manipulation of data. In addition, our proposed arbitration protocol$\sf {DAP}$achieves accountable redaction which can arbitrate the originality of file ownership. We provide the security analysis of our proposal, and performance evaluation that suggests our proposed${\mbox{B-PoW}}$is secure and efficient for large file in static data archive. In addition, our proposed${\mbox{M-PoW}}$achieves acceptable performance under dynamic setting where data is supposed to be outsourced first and updated later in dynamic data archive.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du
IEEE Trans. Cloud Comput.4
2021 Enhanced bitcoin with two-factor authentication
abstract
Bitcoin transactions rely on digital signatures to prove the ownership of bitcoin. The private signing key of the bitcoin owner is the key component to enable a bitcoin transaction. If the signing key of a bitcoin is stolen, the theft who possesses the key can make a transaction of the bitcoin. In this paper, based on the distance-based encryption (DBE), we propose an enhanced version of bitcoin in order to protect the signing key. Our approach is based on our two-factor authentication, where the signing key cannot be retrieved without being identified via the password and biometric authentication scheme, and the user is only required to enter his password and fingerprint (or other biometric information such as a factual image) to retrieve the key. By doing this, we can effectively improve the bitcoin security and provide stronger authentication. An attractive feature of our scheme is that one of encryption schemes is asymmetric, in the sense that the decryption key (biometric information) is not stored in the device. We also provide the security model and proof to justify the security of our scheme.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Leyou Zhang
Int. J. Inf. Comput. Secur.1
2021 Secure and Efficient Data Aggregation for IoT Monitoring Systems
abstract
The proliferation of Internet of Things (IoT) as a promising paradigm has contributed enormously to modern technology design. The wireless body sensor network (WBSN) technology is an application of IoT in healthcare, whereas data security and privacy impediments have raised some concerns. The collected data via IoT wireless body sensors is vulnerable to a variety of internal and external attacks. One solution is to encrypt or sign the collected data to provide confidentiality and integrity, but the computational complexity hinders the application in the real IoT-based healthcare devices. Although there have been some attempts to provide secure and efficient IoT schemes, there is a lack of achieving secure data analysis in modern healthcare. The aggregated data statistics about the patient's medical status is useful to doctors and healthcare providers. However, the dynamic data continually updating over time is challenging. In this article, we present an efficient and provably secure scheme, which is the first step toward secure data analysis for handling the data collection and analysis for IoT wireless body sensors. The main contribution of our work is a novel cryptographic accumulator based on our novel authenticated additive homomorphic encryption which can collect and accumulate data from IoT wireless wearable devices. These encrypted data can be used for analysis in an encrypted form so that the information is not revealed. To validate security and efficiency, we present security analysis and performance evaluations of our proposed scheme for IoT wireless body sensors.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen
IEEE Internet Things J.1
2021 Secure and Privacy-Preserved Data Collection for IoT Wireless Sensors
abstract
The captured data from smart devices via Internet of Things (IoT) wireless sensors are vulnerable to numerous online and offline attacks and unauthorized accesses, hence, some digital signature and encryption solutions have been designed to ensure public verifiability, data integrity, and confidentiality. However, there are still some issues to be addressed. For example, the data source is revealed to the public due to the public verifiability of digital signatures, in which authentication is transferrable. Moreover, computation of these data can only be done after decryption, restricting outsourced computation, such as a computing facility from a cloud. The best approach of private computation, which supports outsourced computation, is based on homomorphic encryption. However, significant computational overhead is a concern. To deal with these issues, in this article, we propose an efficient and provably secure scheme based on designated-verifier proofs, deniable authentication and homomorphic encryption for secure and lightweight data collection, batch verification, and data analysis in the privacy-preserved IoT wireless sensors applications. The main contribution of our work is the privacy-preserved IoT wireless sensors system along with a novel deniable authenticated homomorphic encryption scheme that can securely aggregate data from IoT wireless sensors for secure outsourced applications. To prove the security and efficiency of our proposed scheme, we provide formal security analysis and performance comparisons for IoT wireless sensors.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Leyou Zhang, Xinyi Huang 0001
IEEE Internet Things J.1
2021 Scalable and redactable blockchain with update and anonymity
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du
Inf. Sci.4
2020 EVA: Efficient Versatile Auditing Scheme for IoT-Based Datamarket in Jointcloud
abstract
Cloud storage offers convenient outsourcing services to users, and it serves as a basic platform to drive Internet-of-Things (IoT) where massive devices are connected to the cloud storage and interact with each other. However, cloud storage is more than a data warehouse. In the literature, data market was proposed as a novel model to empower IoT, where data are circulated as merchandise in the digital marketplace with financial activities. When storing IoT data in cloud storage, security and efficiency rules should be applied. Meanwhile, data dynamics is counted as a critical factor to the feasibility of datamarket as data are supposed to be manipulated through circulation and exploitation for IoT. Another issue is the single-point-of-failure (SPoF) of cloud server in which the initiative of jointcloud was suggested. Since providing data security, efficiency, and dynamics simultaneously is challenging, in this article, we propose a versatile auditing scheme (EVA) as a solution to problems. Our proposal ensures that data are securely, efficiently, and dynamically stored in the jointcloud meanwhile supported by data trades via blockchain. We give a comprehensive security analysis based on our security definitions and experiments to support our claims. The evidence has shown that our EVA is efficient for processing large files when proper parameters are chosen.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Jingwei Li 0001, Qi Xia 0001, Jing Qin 0002
IEEE Internet Things J.4
2020 HUCDO: A Hybrid User-centric Data Outsourcing Scheme
abstract
Outsourcing helps relocate data from the cyber-physical system (CPS) for efficient storage at low cost. Current server-based outsourcing mainly focuses on the benefits of servers. This cannot attract users well, as their security, efficiency, and economy are not guaranteed. To solve with this issue, a hybrid outsourcing model that exploits both cloud server and edge devices to store data is needed. Meanwhile, the requirements of security and efficiency are different under specific scenarios. There is a lack of a comprehensive solution that considers all of the above issues. In this work, we overcome the above issues by proposing the first hybrid user-centric data outsourcing (HUCDO) scheme. It allows users to outsource data securely, efficiently, and economically via different CPSs. Brielly, our contributions consist of theories, implementations, and evaluations. Our theories include the first homomorphic collision-resistant chameleon hash (HCCH) and homomorphic designated-receiver signcryption (HDRS). As implementations, we instantiate how to use our proposals to outsource small- or large-scale data through distinct CPS, respectively. Additionally, a blockchain with proof-of-discrete-logarithm (B-PoDL) is instantiated to help improve our performance. Last, as demonstrated by our evaluations, our proposals are secure, efficient, and economic for users to implement while outsourcing their data via CPSs.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Guangquan Xu, Hao Wang 0003, James Xi Zheng, Guomin Yang, Qi Xia 0001, Xiaojiang Du
ACM Trans. Cyber Phys. Syst.5
2020 Achieving Intelligent Trust-Layer for Internet-of-Things via Self-Redactable Blockchain
abstract
The advances of artificial intelligence (AI) propels big data processing and transmission for Internet of Things (IoT), by capturing and structuring big data produced by heterogeneous devices. While applying blockchain to manage IoT devices and associated big data, the blockchain itself suffers from abuse of decentralization from anonymous users. Specifically, it has been utilized to facilitate black market trades and illegal activities. Ateniese et al. proposed using the chameleon hash (CH) to derive redactable blockchain (EuroS&P), which works by embedding a trapdoor in the basic hash function so that block content can be rewritten without causing major hard forks. In short, the redacted block hash remains unchanged. However, there is lacking intelligent design where any mistakes observed in the chain can be corrected universally and automatically. This creates disincentives to use redactable blockchain (RB) for managing big data or any data-driven business mainly due to ineffective chain redaction. To solve this problem, in this article, we propose the notion of the self-redactable blockchain (SRB) to support intelligent execution of chain redaction. Specifically, we propose the first revocable chameleon hash (RCH) to power RB. It enables an ephemeral trapdoor for finding collision without any co-operation. Periodical expiration is applied to committed hash and an ephemeral trapdoor to prevent any abuses of redaction power. We instantiate how to use our RCH to build SRB as an intelligent trust-layer for IoT. We also give a rigorous analysis as well as comprehensive experiments to validate our proposals. The evidence showed that our proposal is secure and acceptably efficient for IoT devices.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Fatemeh Rezaeibagha, Xiaojiang Du, Nadra Guizani
IEEE Trans. Ind. Informatics4
2020 Policy-Driven Blockchain and Its Applications for Transport Systems
abstract
Blockchains offer opportunities for developing advanced digital services. While current research on this topic is still growing, various security concerns have been raised and the security of blockchains has been becoming the most important issue which must be well addressed. Blockchain transactions are based on digital signatures, where the public key is associated with the ownership of the digital coin. User management of public or permissionless blockchain is ad hoc, i.e., any user can join and leave the blockchain network and participate in the Proof of Work (PoW). However, in a private blockchain and a permissioned blockchain, there are usually some constraints for users. In this paper, we investigate a scenario which provides a blockchain network with a set of policies where every user's signing key is associated with a policy set. It is particularly interesting while users are working in different sectors. We call our scheme as “policy-driven”, since policies in our scheme restrict users' rights. Our system is featured with a novel and lightweight policy-driven signature (PDS) scheme whose security has been proven formally. To justify our scenario, we provide experimental results and an example for the railway management services.
Yi Mu 0001, Fatemeh Rezaeibagha, Ke Huang 0002
IEEE Trans. Serv. Comput.2
2019 Efficient Micropayment of Cryptocurrency from Blockchains
abstract
Cryptocurrencies based on blockchain infrastructures have shown their advantages such as double-spending resistance and decentralization. Each transaction of cryptocurrency requires a certain amount of computation and attracts transaction fees. Often, in practice, many transactions are small; therefore, they add computation and transmission overheads to the system. In this paper, we introduce a cost-saving approach, which significantly reduces transaction time and storage for small amount of payment, i.e. micropayment. In our approach, with the notion of ‘transaction commitment’, the computation of each transaction is much more efficient. Therefore, our approach has advantages in comparison of other cryptocurrency systems such as the bitcoin system. Our approach can be applied to other existing cryptocurrency systems.
Fatemeh Rezaeibagha, Yi Mu 0001
Comput. J.1
2019 Building Redactable Consortium Blockchain for Industrial Internet-of-Things
abstract
Applying consortium blockchain as a trust layer for heterogeneous industrial Internet-of-Things devices is cost-effective. However, with an increase in computing power, some powerful attacks (e.g., the 51% attack) are inevitable and will cause severe consequences. Recent studies also confirm that anonymity and immutability of blockchain have been abused to facilitate black market trades, etc. To operate controllable blockchain for IIoT devices, it is necessary to rewrite blockchain history back to a normal state once the chain is breached. Ateniese et al. proposed redactable blockchain by using chameleon hash (CH) to replace traditional hash function, it allows blockchain history to be written when needed (EuroS&P 2017). However, we cannot apply this idea directly to IIoT without solving the following problems: (1) achieve a decentralized design of CH; (2) update the signatures accordingly to authenticate the redacted contents; (3) satisfy the low-computing need of the individual IIoT device. In this paper, we overcome the above issues by proposing the first threshold chameleon hash (TCH) and accountable-and-sanitizable chameleon signature (ASCS) schemes. Based on them, we build a redactable consortium blockchain which is efficient for IIoT devices to operate. It allows a group of authorized sensors to write and rewrite blockchain without causing any hard forks. Basically, TCH is the first TCH and ASCS is a public-key signature supporting file-level and block-level modifications of signatures without impairing authentications. Additionally, ASCS achieves accountability to avoid abuse of redaction. While security analysis validates our proposals, the simulation results show that redaction is acceptably efficient if it is executed at a small scale or if we adopt a coarse-grained redaction while sacrificing some securities.
Ke Huang 0002, Xiaosong Zhang 0001, Yi Mu 0001, Guomin Yang, Xiaojiang Du, Fatemeh Rezaeibagha, Qi Xia 0001, Mohsen Guizani
IEEE Trans. Ind. Informatics7
2018 Practical and secure telemedicine systems for user mobility
Fatemeh Rezaeibagha, Yi Mu 0001
J. Biomed. Informatics1
2017 Provably Secure Homomorphic Signcryption
Fatemeh Rezaeibagha, Yi Mu 0001, Shiwei Zhang 0003
ProvSec1