EDBT 2026 Demo / reviewers in the wild / expert
Jianan Hong
dblp:178/4910
· DBLP profile ↗
38ranked-venue papers
3as first author
25since 2021 · last 2026
0009-0000-1452-5252ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 18 · 13 since 2021Security and privacy · 15 · 1 first-author · 10 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ZkChainDB: A Verifiable and Privacy-Preserving SQL Query Engine for Off-Chain Database Using zk-SNARKs and Blockchain
Wei Wang 0030, Jianan Hong |
ICBC | 3 |
| 2026 | Joint Design of Coding and Modulation for Digital Over-the-Air ComputationabstractInternational audience Cunqinq Hua, Jianan Hong, Yuejun Wei, Pengwenlong Gu |
IEEE Internet Things J. | 3 |
| 2026 | FairRelay: Fair Off-Chain Incentives for Decentralized Physical Infrastructure NetworksabstractDecentralized Physical Infrastructure Networks (DePINs) utilize token incentives to construct permissionless physical infrastructure, but face challenges in ensuring fair compensation for resource contributors. Focusing on bandwidth provision in decentralized data delivery, existing decentralized incentive mechanisms incur prohibitive on-chain costs or employ oversimplified network topologies. We proposeFairRelay, a protocol enablingfair,cost-efficientpayments incomplex multi-hop data delivery. We design two cryptographic primitives: 1)Accountable Multi-hop Data Delivery (AMDD)guaranteeing either correct data receipt or verifiable proof of misbehavior, reducing fair compensation to fee-for-secret exchange; and 2)Enforceable Accumulative HTLC (Enforceable A-HTLC)enabling atomic settlement across multiple off-chain payments via Payment Channel Networks (PCNs). FairRelay's fairness is formally proven within the Universal Composability (UC) framework. Evaluations demonstrate that FairRelay achieveszeroon-chain costs in optimistic execution. Pessimistic scenarios incur constant-cost disputes (O(1) complexity), achieving 13.5% lower overhead than FDE (CCS'24), the state-of-the-art simplified two-party exchange solution (no relays). FairRelay achieves over$95\%$encoding efficiency in 10-hop transmissions. Yingjie Xue, Zifan Peng, Chao Lin 0003, Jianan Hong, Xinyi Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | TG-Transformer: A Graph Transformer for Token Transaction Risk Detection with Bi-Level AttentionabstractThis paper presents a novel approach for detecting fraudulent tokens in blockchain transactions using an enhanced Graphs of Graphs model. By leveraging blockchain’s inherent transparency and immutability, our method enables precise tracking of transactional patterns, enhancing fraud detection capabilities and market forecast within decentralized ecosystems. We introduce a self-attention mechanism, Transaction-To-Token Attention (T2T-Attention), which captures both wallet-level and token-level information by maintaining detailed node and cluster interactions. Unlike traditional graph coarsening, T2T-Attention enables a fine-grained analysis of token transfer activities, preserving transaction-level details while also modeling inter-token relationships at a cluster level. To address computational complexity, we use kernelized softmax for efficient processing. Our model outperforms existing methods in detecting fraud and classifying token-related risks, offering a scalable solution to enhance blockchain security and DeFi risk management. Jiayue Zhou, Jianan Hong, Cunqing Hua |
IJCNN | 3 |
| 2025 | TrustMFA: A Privacy-Preserving Multi-Factor Authentication Scheme with Anonymous CredentialabstractMulti-Factor Authentication (MFA) has emerged as a widely adopted and robust authentication mechanism across various scenarios. Whereas, existing methods suffer serious threats, because of their sacrifice of privacy protection, identity provider offline, or other critical features. In theorem, the above threats come from the technical challenge of the combination of biometric and secret key factors. To solve these problems and achieve a reliable access system, this paper introduces TrustMFA, a hybrid authentication framework that leverages anonymous credentials and fuzzy extractors to construct a unified and secure authentication scheme. TrustMFA transforms multiple factors, including biometric factors, into attributes in the anonymous credential, thereby fully guaranteeing the trust and privacy of user. To enhance the practicality, we propose ECC-LSH, an Error-Correcting Code compatible Locality-Sensitive Hashing, which ensures that Hamming distances between biometric features extracted from the same person remain within the error-correcting capability. Comprehensive security analysis and implementation results demonstrate TrustMFA’s effectiveness, showing acceptable computational and communication overhead while maintaining high security levels. Jianan Hong, Kunling Li, Kun He 0008 |
TrustCom | 2 |
| 2025 | A Privacy-Preserving and Highly Fault-Tolerant Cross-Chain Atomic Swap SchemeabstractAs the blockchain ecosystem continues to diversify, the lack of interoperability among heterogeneous blockchain systems has become a critical bottleneck, leading to fragmented data silos and limited collaboration. Although numerous cross-chain protocols—such as atomic swaps, sidechains, and relay-based mechanisms—have been introduced to address this issue, they often face significant challenges related to privacy, security, and decentralization. In this paper, we propose a novel cross-chain protocol that enhances traditional hash-locking mechanisms by integrating zero-knowledge proofs and chameleon hash functions. Our approach ensures strong path confidentiality, such that reconstructing the payment path is computationally infeasible under the discrete logarithm assumption, even in partially compromised networks. Additionally, we introduce a multi-path atomic swap framework that supports concurrent routing and preserves transactional autonomy, enabling users to flexibly select preferred payment paths. We evaluate the performance through theoretical analysis and simulation. Comparative results demonstrate that our solution achieves secure atomicity with minimal trust assumptions and improved latency compared to existing methods. Jianan Hong, Yingjie Xue, Jiayue Zhou |
TrustCom | 2 |
| 2025 | Receiver-Agnostic Radio Frequency Fingerprint Identification for Zero-Trust Wireless NetworksabstractZero-trust has emerged as a promising security paradigm for next-generation networks (NGN). However, conventional cryptographic schemes struggle with continuous and dynamic authentication due to their coarse granularity and cumbersome processes. Radio frequency fingerprint identification (RFFI), as a prospective solution, enables physical-layer user-transparent identity authentication. Whereas, facing the dynamic topology and device mobility of NGN, such as Internet of Vehicles (IoV), Drone networks, etc., there exists a current deficiency in addressing the significant performance degradation across different receivers. In this paper, we propose a novel RFFI scheme for zero-trust continuous authentication in dynamic NGN environments, enabling unified high-performance cross-receiver identification. A two-stage unsupervised domain adaptation model is designed to extract receiver-independent transmitter-specific features. The receiver-side impact on RFFI, modeled as domain shift, is addressed through adversarial training for global alignment and local maximum mean discrepancy (LMMD)-based subdomain adaptation for eliminating subdomain confusion. Moreover, we further optimize RFFI through data augmentation to enhance robustness, multi-sample fusion inference to handle dynamic uncertainties, and an adaptive few-sample selection strategy for efficient fine-tuning. Extensive experiments on public datasets demonstrate the excellent performance of our proposed scheme in cross-receiver zero-trust wireless networks. Kunling Li, Jiazhong Bao, Jianan Hong, Cunqing Hua |
IEEE J. Sel. Areas Commun. | 4 |
| 2025 | FedPHE: A Secure and Efficient Federated Learning via Packed Homomorphic EncryptionabstractCross-silo federated learning (FL) enables multiple institutions (clients) to collaboratively build a global model without sharing private data. To prevent privacy leakage during aggregation, homomorphic encryption (HE) is widely used to encrypt model updates, yet incurs high computation and communication overheads. To reduce these overheads,packedHE (PHE) has been proposed to encrypt multiple plaintexts into a single ciphertext. However, the original design of PHE assumes all clients share a single private key, making the system vulnerable to security threats of ciphertexts being intercepted and decrypted byhonest-but-curious clients. Also, it does not consider theheterogeneityamong different clients, resulting in undermined training efficiency with slow convergence and stragglers. To address these challenges, we propose FedPHE, a secure and efficient FL framework with PHE by jointly exploiting contribution-aware secure aggregation and straggler-resistant client selection. Using CKKS with sparsification and blinding, FedPHE achieves efficient secure aggregation that allows clients to only provideobscuredencrypted updates while the server can perform aggregation by accounting forcontributionsof local updates. To mitigate the straggler effect, we devise aperturbed sketch-based selection to cherry-pick representative clients withheterogeneous models and computing capabilitiesin a communication-efficient and privacy-preserving manner. We show, through rigorous security analysis and extensive experiments, that FedPHE can efficiently safeguard clients' privacy, achieve$2.45-6.56\times$training speedup, cut the communication overhead by$1.32-24.85\times$, and reduce straggler effects by$1.89-2.78\times$. Yuqing Li 0001, Nan Yan 0001, Jing Chen 0003, Xiong Wang 0006, Jianan Hong, Kun He 0008, Wei Wang 0030, Bo Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | EtherCloak: Enabling Multi-Level and Customized Privacy on Account-Model BlockchainsabstractThe lack of privacy-preserving capabilities hinders the further development of blockchains and smart contracts. While numerous privacy solutions have been proposed, limitations persist. First, most existing solutions focus on specific privacy protections such as anonymous payments, private data, or multi-party computation tasks. However, these solutions lack a general privacy ability, allowing users to deploy applications with diverse privacy requirements. Second, existing solutions have limited customizability, which means users cannot easily customize and adapt the privacy policies according to their specific demands or preferences. In this article, we present EtherCloak, which adopts trusted execution environments (TEEs) to achieve a general and customizable privacy policy on account model blockchains, enabling users to conceal any on-chain information. To address the security issues caused by the unreliability of the host the TEE runs on, we design the enclave state check and crash recovery mechanisms and employ them in the block generation process. In addition, we propose an access control mechanism for privacy policy management and data query. We prove that EtherCloak offers general and customizable privacy protection with a minimal increase in transaction size (less than triple) and communication overhead (approximately 10%) compared to Ethereum. Kaiping Xue, Mingrui Ai, Jianan Hong, Xianchao Zhang 0002, Qibin Sun, Jun Lu 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Solving Data Contamination in DDoS Detection: A Method Based on Hierarchical Federated Learning
Jiaping Gui, Ruiwen Ji, Haishi Huang, Jianan Hong, Cunqing Hua |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Communication Efficient Ciphertext-Field Aggregation in Wireless Networks via Over-the-Air ComputationabstractAggregating metadata in the ciphertext field is an attractive property brought by homomorphic encryption (HE) for privacy-sensitive computing tasks, therefore, research on the next-generation wireless networks has treated it as one of the promising cryptographic techniques for various scenarios. However, existing schemes are far from being deployed in various computing scenarios due to their high computational complexity and ciphertext expansion, especially for bandwidth-limited and latency-sensitive wireless scenarios. In this paper, we propose the AirHE scheme to achieve homomorphic evaluation via the over-the-air computation in the physical layer. Moreover, we propose a new encryption scheme that can be integrated with the physical layer procedure. A new error control mechanism for ciphertext is further proposed to solve the error accumulation problem. The novelty of the AirHE scheme is to take advantage of the intrinsic superposition characteristic of the wireless channel, such that the communication and computation cost is greatly reduced by achieving homomorphic evaluation and error control of ciphertext in the physical layer. We implement the AirHE scheme based on the LTE system and validate its feasibility. Simulation results are also presented to show the performance of the AirHE scheme under different channel conditions. Jianan Hong, Cunqing Hua, Yanhong Xu 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Zero-Determinant Incentive Strategy for Transaction Trading in Blockchain SystemabstractBlockchain has been widely applied in many industries to provide secure and reliable services, in which the activities of the participating nodes are recorded as transactions. Although the original design assumes nodes disseminate the transactions voluntarily, they may be reluctant to provide transactions for others due to the lack of cooperative incentives. To fill the gap, we study the transaction collecting process in the blockchain system under the leader-based consensus protocol. Specifically, we design an incentive scheme to reward the followers if they provide unique transactions to the leader. Considering the selfish nature of different nodes, we model the transaction trading process between nodes as an Iterated Prisoner’s Dilemma (IPD), and a modified zero-determinant (ZD) strategy is proposed such that the follower could correlate the leader’s payoff with the leader’s cooperation probability. We theoretically prove the effectiveness of our proposed algorithm. Simulation results show the leader’s payoff changes under the follower’s different control functions. The proposed scheme can regulate the behavior of blockchain nodes during the transaction trading process. Liang Feng 0002, Cunqing Hua, Jianan Hong |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Quality and Diversity Balanced Neighbor Selection Against Eclipse Attack in Blockchain System
Liang Feng 0002, Cunqing Hua, Lingya Liu, Jianan Hong |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | A Secure and Private Authentication Based on Radio Frequency FingerprintingabstractThe technology development of wireless communication has brought about the rapid growth of various wireless devices, but also brings in many security threats. This paper focuses on the security and privacy problems in wireless authentication and proposes a novel authentication scheme based on the design of reusable fuzzy extractor (RFE) for device's radio frequency (RF) fingerprinting. Firstly, unlike the traditional authentication protocol, our scheme can accomplish the mutual authentication without the storage of long-term secret key, thus tackles with the key-compromise threats. Furthermore, although the scheme authenticates devices based on their RF fingerprint, it does not store RF fingerprinting information explicitly to safeguard it from eavesdroppers who may use it to impersonate the identity of valid users. Finally, our designed protocol relies on the correspondent peer to measure the fingerprint, rather than the device itself, thus is more secure against various adversaries. The security analysis shows the resiliency against theft of secret keys, wireless channel attacks and privacy disclosure. And the performance evaluation demonstrates that the design of RFE for device's RF fingernrinting is efficient in terms of recognition accuracy. Chengchen Zhu, Kunling Li, Jianan Hong, Cunqing Hua, Futai Zou |
ICC | 3 |
| 2024 | AcBF: A Revocable Blockchain-Based Identity Management Enabling Low-Latency AuthenticationabstractBlockchain-based identity brings in great evolution due to its decentralized deployment, transparent and tamper-free ledger. Specification groups of B5G/6G are exploring into integrate the technology to future network systems, e.g., Internet of Things, vehicular network, industrial communications. However, devices in these systems often have storage constraints and unstable channels, which necessitates lightweight node deployment. The security issue arises: revoked identity can forge a legitimate authentication, since the lightweight verifier does not maintain the revocation transactions. This paper hence proposes AcBF, a novel revocable identity management scheme, that enables extremely low authentication latency by allowing the lightweight node to query the certificate's status locally. To realize this feature trustfully, we design a revocation transaction based on accumulator-assisted Bloom filter to minimize the storage of certificate status structure. Secondly, we construct the blockchain protocol to ensure that no revocation event slips on any lightweight ledger, even in an insecure or unstable communication environment. In addition, different from other revocation mechanisms, AcBF minimizes the impact on valid users during the revocation process. Through security and performance analysis, AcBF has shown strong security and advantageous efficiency on both lightweight verifiers and certificate owners, thus suits identity management systems with low-latency constraints. Jianan Hong, Jiayue Zhou, Yuqing Li 0001, Cunqing Hua |
ICDCS | 1 |
| 2024 | Efficient and Straggler-Resistant Homomorphic Encryption for Heterogeneous Federated LearningabstractCross-silo federated learning (FL) enables multiple institutions (clients) to collaboratively build a global model without sharing their private data. To prevent privacy leakage during aggregation, homomorphic encryption (HE) is widely used to encrypt model updates, yet incurs high computation and communication overheads. To reduce these overheads, packed HE (PHE) has been proposed to encrypt multiple plaintexts into a single ciphertext. However, the original design of PHE does not consider the heterogeneity among different clients, an intrinsic problem in cross-silo FL, often resulting in undermined training efficiency with slow convergence and stragglers. In this work, we propose FedPHE, an efficiently packed homomorphically encrypted FL framework with secure weighted aggregation and client selection to tackle the heterogeneity problem. Specifically, using CKKS with sparsification, FedPHE can achieve efficient encrypted weighted aggregation by accounting for contributions of local updates to the global model. To mitigate the straggler effect, we devise a sketching-based client selection scheme to cherry-pick representative clients with heterogeneous models and computing capabilities. We show, through rigorous security analysis and extensive experiments, that FedPHE can efficiently safeguard clients’ privacy, achieve a training speedup of 1.85 − 4.44×, cut the communication overhead by 1.24 − 22.62× , and reduce the straggler effect by up to 1.71 − 2.39×. Nan Yan 0001, Yuqing Li 0001, Jing Chen 0003, Xiong Wang 0006, Jianan Hong, Kun He 0008, Wei Wang 0030 |
INFOCOM | 5 |
| 2024 | HFL-AD: A Hierarchical Federated Learning Framework for Solving Data Contamination in DDoS DetectionabstractDistributed denial-of-service (DDoS) attacks can cause significant damage to network applications. A crucial step in combating these attacks lies in promptly and accurately detecting DDoS attack traffic. However, due to data insufficiency (imbalance) and contamination, existing solutions fail to yield satisfactory results for DDoS detection. Furthermore, current methods typically require access to raw data for training, posing a significant privacy risk. To tackle these challenges, we propose HFL-AD, a hierarchical federated learning framework specifically designed for detecting DDoS attack traffic. In our approach, a federation of lower layer clients train local anomaly detection models using diverse raw data. A selected few clients, possessing a small supplementary dataset, serve as upper layer clients, responsible for excluding model updates trained on contaminated datasets. Experimental results demonstrate that HFL-AD outperforms baseline solutions in DDoS detection, particularly when some training datasets are contaminated. Haishi Huang, Jiaping Gui, Jianan Hong, Cunqing Hua |
TrustCom | 3 |
| 2024 | Detection and Analysis of Broken Access Control Vulnerabilities in App-Cloud Interaction in IoTabstractAt present, there is less research on the detection of broken access control vulnerabilities in IoT systems, mostly using state machines to analyze abnormal state transitions, and no systematic tools have been developed. The main challenges include the inaccessibility of communication messages, a lack of effective detection for broken access control vulnerabilities, and excessive manual involvement. Moreover, due to the existence of encryption, signatures, and other fields, it is challenging to directly port web-based detection tools to IoT. In response to these challenges, we propose a framework for detecting broken access control vulnerabilities based on the interaction between applications and cloud platforms. The framework employs man-in-the-middle techniques to obtain communication messages between the two entities, enabling fast and effective fuzz testing through keyword extraction, database-guided fuzzing, and response-based detection algorithms. In addition, a combination of dynamic and static reverse analysis techniques are used to overcome anti-tampering measures, such as encryption and signatures. Following the detection framework, we implemented the semi-automated BACDetector system and tested it on six applications from four manufacturers. BACDetector discovered nine broken access control vulnerabilities, including risks of device hijacking and privacy leakage. This validated its effectiveness in detecting vulnerabilities in IoT. Futai Zou, Jianan Hong, Libo Chen 0001, Ping Yi |
IEEE Internet Things J. | 3 |
| 2024 | AirCon: Over-the-Air Consensus for Wireless Blockchain NetworksabstractBlockchain has been deemed as a promising solution for providing security and privacy protection in the next-generation wireless networks. Large-scale concurrent access for massive wireless devices to accomplish the consensus procedure may consume prohibitive communication and computing resources, and thus may limit the application of blockchain in wireless conditions. As most existing consensus protocols are designed for wired networks, directly apply them for wireless users equipment (UEs) may exhaust their scarce spectrum and computing resources. In this paper, we propose AirCon, a byzantine fault-tolerant (BFT) consensus protocol for wireless UEs via the over-the-air computation. The novelty of AirCon is to take advantage of the intrinsic characteristic of the wireless channel and automatically achieve the consensus in the physical layer while receiving from the UEs, which greatly reduces the communication and computational cost that would be caused by traditional consensus protocols. We implement the AirCon protocol integrated into an LTE system and provide solutions to the critical issues for over-the-air consensus implementation. Experimental results are provided to show the feasibility of the proposed protocol, and simulation results to show the performance of the AirCon protocol under different wireless conditions. Cunqing Hua, Jianan Hong, Pengwenlong Gu, Wenchao Xu 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Optimal Power Control and CSI Acquisition for Over-the-Air Computation in OFDM SystemabstractOver-the-air computation (AirComp) is a novel technology that utilizes the superposition characteristic of the wireless multiple-access channel to accomplish communication and computation tasks simultaneously, which can be used to achieve efficient data fusion in wireless networks. However, the performance of AirComp can be compromised due to non-ideal conditions in practical systems, such as limited transmitting power budget, receiving noise, etc. In this paper, we first propose a joint transmitting-receiving power control scheme for over-the-air computation in the OFDM-based multicarrier wireless system, which can minimize the mean square error (MSE) of the received signal by taking into account of limited transmitting power budget and receiving noise. Based on the special structure of the problem, which depends on the set of users that either use up their power budget or not, we decompose the problem into two sub-problems, one deals with the power allocation at the transmitters, the other deals with the power scaling at the receiver. The optimal results are obtained by searching the set of users with used up power budget and solving these two sub-problems accordingly. We then propose an efficient channel state information (CSI) acquisition and feedback scheme for the AirComp power control scheme, and the effect of imperfect CSI is also considered accordingly. We provide extensive simulation results to demonstrate the performance of the proposed scheme under different network conditions. Cunqing Hua, Jianan Hong, Wenchao Xu 0001 |
IEEE Trans. Wirel. Commun. | 3 |
| 2023 | Receiver-Agnostic Radio Frequency Fingerprinting Based on Two-stage Unsupervised Domain Adaptation and Fine-tuningabstractRadio frequency fingerprint identification (RFFI) has been widely studied as a physical layer security scheme for device identification and authentication in wireless scenarios, such as Internet of Things (IoTs), industrial wireless networks, Internet of Vehicles (IoV), etc. Typical RFFI approaches train a model at the receiver to extract hardware defects of the transmitter RF front-end using a deep learning-based method and achieve classification. However, few works have taken into account its shortage in multiple-receiver scenarios, where the identification accuracy significantly decreases when migrating a model trained on the known receivers to the new ones, directly. In this paper, we propose a novel cross-receiver RFFI scheme to improve the performance and the generalization of the fingerprinting classification tasks on new receivers. This scheme tackles the shortage by two means: 1) we extract receiver- independent features using global domain adaptation based on adversarial training and relevant subdomain adaptation based on local maximum mean discrepancy (LMMD); 2) The performance is further improved by fine-tuning on few labeled samples when domain adaptation is not effective. The second mechanism brings in significant performance advantage, without a large amount of labeled data on new receivers. Experimental results on public datasets show the outstanding performance of the proposed scheme in cross-receiver scenarios. Jiazhong Bao, Zhaoyi Lu 0001, Jianan Hong, Cunqing Hua |
GLOBECOM | 4 |
| 2023 | Fine-Grained Data Rights Governance in Blockchain-Based Cloud-Edge CommunicationsabstractNowadays, cloud-edge communication has emerged as a promising communication paradigm, which leverages edge devices to provide a series of advantages, such as a fast response for end devices. However, considering complicated communication environments, a practical requirement is improving security by constructing decentralized and traceable communications. Currently, blockchains have been widely applied in cloud-edge communications to ensure decentralization and traceability by consensus. Despite these promising benefits, existing transparent and immutable blockchains inevitably introduce two limitations to data rights governance in blockchain-based cloud-edge communications. The first limitation is that transparent blockchains can hardly guarantee data confidentiality since data is accessible to all users, especially unauthorized users. The second limitation is that immutable blockchains can hardly support improper content redaction, which violates the right to be forgotten in GDPR. This paper proposes FDRG, the first fine-grained data rights governance scheme in blockchain-based cloud-edge communications. FDRG cryptographically ensures the right downward compatibility and user collusion resistance. Specifically, based on attributes and policies, FDRG partitions users into three roles (i.e., unauthorized user, readable user, and editable user) and ensures that editable users are compatible with the rights of readable users. The punchline is that FDRG leverages the linear secret sharing matrix-based secret sharing to govern the distribution of data decryption keys and chameleon hashes trapdoors. Formal security analysis proves the security of FDRG under the chosen-plaintext attack in the random oracle model. A full implementation on the FISCO blockchain platform shows that FDRG achieves competitive efficiency compared to state-of-the-art related schemes. Weilin Gan, Mingyang Zhao 0002, Hongchen Guo, Chuan Zhang 0003, Jianan Hong, Liehuang Zhu |
GLOBECOM | 5 |
| 2022 | Joint Power Control for Over-the-Air Computation in Multicarrier Wireless SystemabstractOver-the-air computation (AirComp) is a novel technology that utilizes the superposition characteristic of the wireless multiple-access channel to accomplish the communication and computation tasks simultaneously, which can achieve efficient data fusion in large-scale wireless networks. However, in practice, the performance of AirComp is distorted by some non-ideal factors, including limited transmit power budget, receiving noise, and imperfect channel estimation. In this paper, we propose an optimal transmitting-receiving power control scheme for over-the-air computation in the multicarrier system with these non-ideal factors. We optimize the over-the-air computation system by minimizing the mean square error (MSE) of receiving signal. The results show that when a user needs to use up all power budget, the optimal power allocation policy among sub-carriers is a proportional fairness scheme and whether the user needs to use up all power budget depends on its channel compensation capability and receiving scaling policy. We also provide computation simulation results to demonstrate the optimum of the proposed scheme. Cunqing Hua, Jianan Hong |
GLOBECOM | 3 |
| 2022 | Forward Private Multi-Client Searchable Encryption with Efficient Access Control in Cloud StorageabstractThrough Searchable Symmetric Encryption (SSE), a user can make search over encrypted documents that are stored on an untrusted cloud server. Multi-client SSE schemes require that one client can search documents contributed by other clients and upload documents. Nevertheless, existing multi- client SSE schemes implement the fine-grained access control with high complexity. Although fine-grained access control adapts to complex scenarios, it is not necessary anytime and may cause heavy costs over computation in SSE schemes. Moreover, it is crucial to support documents updating and forward privacy. To combat that, we design a multi-client SSE scheme with efficient access control over dynamic encrypted documents. Specifically, we first modify Symmetric Hidden Vector Encryption (SHVE) and utilize Bloom filter to implement the access control, which reduces much of computation overhead. We then employ Oblivious Dynamic Cross-Tag (ODXT) protocol to preserve the forward privacy of our scheme. Finally, the corresponding security and experimental evaluation demonstrate both security and practicality of our scheme, respectively. Jinjiang Yang, Feng Liu 0059, Jianan Hong, Jian Li 0031, Kaiping Xue |
GLOBECOM | 4 |
| 2022 | Efficient and Secure Attribute-Based Access Control With Identical Sub-Policies Frequently Used in Cloud StorageabstractUnder the assumption of honest-but-curious cloud service provider, various cryptographic techniques have been used to address the issues of data access control and confidentiality in public cloud storage. Among which, attribute-based encryption (ABE) has been shown to be an attractive scheme. Although the technique of ABE brings in various benefits, its onerous overhead should not be ignored. In this article, based on an improved LSSS (linear secret sharing scheme) matrix expression integrated in CP-ABE (Ciphertext-Policy Attribute-Based Encryption) algorithm, we present an efficient and secure attribute-based access control scheme for the scenarios where multiple data are shared and encrypted with frequently used sub-policies. In the scheme, a user can store the parameters about a specific sub-policy in his/her first decryption, which can be reused in the subsequent data decryptions whose embedded access policies include the same sub-policy so as to significantly reduce the computation cost. Our proposed scheme is proved to be semantically secure under chosen plaintext attacks and can well preserve the confidentiality of the data sharing system. Our analysis and experimentation also show that our scheme does significantly reduce the decryption time and while trades in only very little storage overhead, and thus effectively promotes the efficiency. Kaiping Xue, Na Gai, Jianan Hong, David S. L. Wei, Peilin Hong, Nenghai Yu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Service Outsourcing in F2C Architecture with Attribute-based Anonymous Access Control and Bounded Service NumberabstractF2C (fog-to-cloud) enables service providers to rent the low-cost cloud/fog resources to publish their services, and the fog nodes, which are deployed at the edge, can provide short-latency service to users. However, new security threats come along with this new computing paradigm, where the access control and trusted payment are concerned in this work. We propose a privacy-preserving authentication scheme. By integrating k-times anonymous authentication (k-TAA) and attribute-based access control, in our proposed scheme, service providers can autonomously determine a fine-grained access policy and the maximal access times for authorized users. Thus, users who satisfy the access policy can receive benefits of this service for certain number of times without leaking any private information. Our authentication phase has a low latency because it is offloaded to the fog as what the service does. This paper presents a lightweight and trusted billing mechanism using Merkle Hash Tree (MHT), which can detect the cloud's service forgery with high probability, without costing too much of service provider's bandwidth and computation. Rigorous security analysis proves that the proposed scheme is secure against malicious users, fogs, and cloud, and the experimental results show the significant performance advantage on both the delay reduction and service providers' cost saving. Jianan Hong, Kaiping Xue, Na Gai, David S. L. Wei, Peilin Hong |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | TAFC: Time and Attribute Factors Combined Access Control for Time-Sensitive Data in Public CloudabstractThe new paradigm of outsourcing data to the cloud is a double-edged sword. On the one hand, it frees data owners from the technical management, and is easier for data owners to share their data with intended users. On the other hand, it poses new challenges on privacy and security protection. To protect data confidentiality against the honest-but-curious cloud service provider, numerous works have been proposed to support fine-grained data access control. However, till now, no schemes can support both fine-grained access control and time-sensitive data publishing. In this paper, by embedding timed-release encryption into Ciphertext-Policy Attribute-based Encryption (CP-ABE), we propose a new time and attribute factors combined access control on time-sensitive data for public cloud storage (named TAFC). Based on the proposed scheme, we further propose an efficient approach to design access policies faced with diverse access requirements for time-sensitive data. Extensive security and performance analysis shows that our proposed scheme is highly efficient and satisfies the security requirements for time-sensitive data storage in public cloud. Jianan Hong, Kaiping Xue, Yingjie Xue, Weikeng Chen, David S. L. Wei, Nenghai Yu, Peilin Hong |
IEEE Trans. Serv. Comput. | 1 |
| 2019 | Healthchain: A Blockchain-Based Privacy Preserving Scheme for Large-Scale Health DataabstractWith the dramatically increasing deployment of the Internet of Things (IoT), remote monitoring of health data to achieve intelligent healthcare has received great attention recently. However, due to the limited computing power and storage capacity of IoT devices, users' health data are generally stored in a centralized third party, such as the hospital database or cloud, and make users lose control of their health data, which can easily result in privacy leakage and single-point bottleneck. In this paper, we propose Healthchain, a large-scale health data privacy preserving scheme based on blockchain technology, where health data are encrypted to conduct fine-grained access control. Specifically, users can effectively revoke or add authorized doctors by leveraging user transactions for key management. Furthermore, by introducing Healthchain, both IoT data and doctor diagnosis cannot be deleted or tampered with so as to avoid medical disputes. Security analysis and experimental results show that the proposed Healthchain is applicable for smart healthcare system. Jie Xu 0031, Kaiping Xue, Shaohua Li 0002, Hangyu Tian, Jianan Hong, Peilin Hong, Nenghai Yu |
IEEE Internet Things J. | 5 |
| 2019 | An Attribute-Based Controlled Collaborative Access Control Scheme for Public Cloud StorageabstractIn public cloud storage services, data are outsourced to semi-trusted cloud servers which are outside of data owners' trusted domain. To prevent untrustworthy service providers from accessing data owners' sensitive data, outsourced data are often encrypted. In this scenario, conducting access control over these data becomes a challenging issue. Attribute-based encryption (ABE) has been proved to be a powerful cryptographic tool to express access policies over attributes, which can provide a fine-grained, flexible, and secure access control over outsourced data. However, the existing ABE-based access control schemes do not support users to gain access permission by collaboration. In this paper, we explore a special attribute-based access control scenario where multiple users having different attribute sets can collaborate to gain access permission if the data owner allows their collaboration in the access policy. Meanwhile, the collaboration that is not designated in the access policy should be regarded as a collusion and the access request will be denied. We propose an attribute-based controlled collaborative access control scheme through designating translation nodes in the access structure. Security analysis shows that our proposed scheme can guarantee data confidentiality and has many other critical security properties. Extensive performance analysis shows that our proposed scheme is efficient in terms of storage and computation overhead. Yingjie Xue, Kaiping Xue, Na Gai, Jianan Hong, David S. L. Wei, Peilin Hong |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2018 | LASA: Lightweight, Auditable and Secure Access Control in ICN with Limitation of Access TimesabstractInformation Centric Networking (ICN), a future network architecture candidate, aims to alleviate the problem of insufficient bandwidth in traditional IP network. In ICN, contents are distributed in the whole network, so access control becomes more intractable. As we know, almost all of existing solutions consider it as a "Yes or No" problem, where a user either has the permission to access the corresponding content or not. However, in many practical situations, a content provider doesn't expect a single authorized user has the ability to access its repertory without times limitation when taking copyright protection into account. In this paper, we propose LASA, a lightweight, auditable and secure solution where legitimate users are limited to access a content provider's data within pre-designate times. In LASA, each content provider sets maximum access times for each legitimate user and edge routers perform authentication and audit based on users' signatures attached to interest packets. Once a legitimate user attempts to exceed his/her limited access times, his/her secret key will be leaked and the dishonest behavior will be detected. Our security analysis shows that LASA can provide signature unforgeability, data confidentiality and other security features. Experiment results show that our scheme LASA brings a little computational cost. Peixuan He, Yinxin Wan, Qiudong Xia, Shaohua Li 0002, Jianan Hong, Kaiping Xue |
ICC | 5 |
| 2018 | Low-Latency Authentication Against Satellite Compromising for Space Information NetworkabstractWith an advancement of mobile communication technology, the space information network (SIN) has been proposed to meet the increasing demands of mobile communication due to its advantage of providing great expanding access services. In SIN, authentication is significant for the security to prevent the network resource from unauthorized access. However, the features of highly exposed links and extremely high propagation delay make it difficult to design a secure and fast authentication scheme for SIN. Although some existing researches have tried to design authentication protocols for SIN, they haven't taken the intolerable authentication delay and the risk of satellite compromising into consideration. Faced with these problems, we design a proxy signature-based authentication scheme for SIN, in which, the interaction process of authentication can be only implemented between the mobile user and the satellite node, thus reducing the long authentication implementation delay. Furthermore, we utilize the proxy signature to mitigate the risk of satellites being attacked. The results of security and performance analysis show that the proposed scheme can provide the required security and largely reduce the authentication latency. Kaiping Xue, Jie Xu 0031, Jianan Hong, Nenghai Yu |
MASS | 4 |
| 2018 | Combining Data Owner-Side and Cloud-Side Access Control for Encrypted Cloud StorageabstractPeople endorse the great power of cloud computing, but cannot fully trust the cloud providers to host privacy-sensitive data, due to the absence of user-to-cloud controllability. To ensure confidentiality, data owners outsource encrypted data instead of plaintexts. To share the encrypted files with other users, ciphertext-policy attribute-based encryption (CP-ABE) can be utilized to conduct fine-grained and owner-centric access control. But this does not sufficiently become secure against other attacks. Many previous schemes did not grant the cloud provider the capability to verify whether a downloader can decrypt. Therefore, these files should be available to everyone accessible to the cloud storage. A malicious attacker can download thousands of files to launch economic denial of sustainability (EDoS) attacks, which will largely consume the cloud resource. The payer of the cloud service bears the expense. Besides, the cloud provider serves both as the accountant and the payee of resource consumption fee, lacking the transparency to data owners. These concerns should be resolved in real-world public cloud storage. In this paper, we propose a solution to secure encrypted cloud storages from EDoS attacks and provide resource consumption accountability. It uses CP-ABE schemes in a black-box manner and complies with arbitrary access policy of the CP-ABE. We present two protocols for different settings, followed by performance and security analysis. Kaiping Xue, Weikeng Chen, Jianan Hong, Peilin Hong |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2017 | A privacy-preserving and real-time traceable power request scheme for smart gridabstractSmart grid facilitates reliable and efficient power generation and transmission by integrating information and communication technologies. By collecting users' power demands in advance, the control center (power operator) can adjust the amount of electricity generated to reduce the excess power, which can increase the profit of the power operator. However, on the one hand, user's privacy becomes a critical issue, since it may leak out a user's life habits, which may make user's safety and belongings under threat. On the other hand, the system needs to arm the capability to avoid diverse adversaries' attacks and trace misbehaving users (who request power irresponsibly). In this paper, we propose a privacy-preserving and real-time traceable power request scheme to fulfill the security requirements. We utilize aggregator as a proxy between users and the control center, which verifies the messages and aggregates multiple users' requests together to preserve their privacy. More importantly, this privacy-preserving mechanism has no effect for the control center to whether charge each user, or trace the misbehaving users in real time. The performance analysis shows that our scheme is efficient in terms of computation and storage overhead. Qingyou Yang, Jianan Hong, Kaiping Xue, Weikeng Chen, Hao Yue 0001 |
ICC | 2 |
| 2017 | CABE: A New Comparable Attribute-Based Encryption Construction with 0-Encoding and 1-EncodingabstractAttribute-based encryption (ABE) has opened up a popular research topic in cryptography over the past few years. It can be used in various circumstances, as it provides a flexible way to conduct fine-grained data access control. Despite its great advantages in data access control, current ABE based access control system cannot satisfy the requirement well when the system judges the access behavior according to attribute comparison, such as “greater than x” or “less than x”, which are called comparable attributes in this paper. In this paper, based on a set of well-designed sub-attributes representing each comparable attribute, we construct a comparable attribute-based encryption scheme (CABE for short) to address the aforementioned problem. The novelty lies in that we provide a more efficient construction based on the generation and management of the sub-attributes with the notion of 0-encoding and 1-encoding. Extensive analysis shows that: Compared with the existing schemes, our scheme drastically decreases the storage, communication and computation overheads, and thus is more efficient in dealing with the applications with comparable attributes. Kaiping Xue, Jianan Hong, Yingjie Xue, David S. L. Wei, Nenghai Yu, Peilin Hong |
IEEE Trans. Computers | 2 |
| 2017 | Two-Cloud Secure Database for Numeric-Related SQL Range Queries With Privacy PreservingabstractIndustries and individuals outsource database to realize convenient and low-cost applications and services. In order to provide sufficient functionality for SQL queries, many secure database schemes have been proposed. However, such schemes are vulnerable to privacy leakage to cloud server. The main reason is that database is hosted and processed in cloud server, which is beyond the control of data owners. For the numerical range query (“>,” “<;,” and so on), those schemes cannot provide sufficient privacy protection against practical challenges, e.g., privacy leakage of statistical properties, access pattern. Furthermore, increased number of queries will inevitably leak more information to the cloud server. In this paper, we propose a two-cloud architecture for secure database, with a series of intersection protocols that provide privacy preservation to various numeric-related range queries. Security analysis shows that privacy of numerical information is strongly protected against cloud providers in our proposed scheme. Kaiping Xue, Shaohua Li 0002, Jianan Hong, Yingjie Xue, Nenghai Yu, Peilin Hong |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | RAAC: Robust and Auditable Access Control With Multiple Attribute Authorities for Public Cloud StorageabstractData access control is a challenging issue in public cloud storage systems. Ciphertext-policy attribute-based encryption (CP-ABE) has been adopted as a promising technique to provide flexible, fine-grained, and secure data access control for cloud storage with honest-but-curious cloud servers. However, in the existing CP-ABE schemes, the single attribute authority must execute the time-consuming user legitimacy verification and secret key distribution, and hence, it results in a single-point performance bottleneck when a CP-ABE scheme is adopted in a large-scale cloud storage system. Users may be stuck in the waiting queue for a long period to obtain their secret keys, thereby resulting in low efficiency of the system. Although multi-authority access control schemes have been proposed, these schemes still cannot overcome the drawbacks of single-point bottleneck and low efficiency, due to the fact that each of the authorities still independently manages a disjoint attribute set. In this paper, we propose a novel heterogeneous framework to remove the problem of single-point performance bottleneck and provide a more efficient access control scheme with an auditing mechanism. Our framework employs multiple attribute authorities to share the load of user legitimacy verification. Meanwhile, in our scheme, a central authority is introduced to generate secret keys for legitimacy verified users. Unlike other multi-authority access control schemes, each of the authorities in our scheme manages the whole attribute set individually. To enhance security, we also propose an auditing mechanism to detect which attribute authority has incorrectly or maliciously performed the legitimacy verification procedure. Analysis shows that our system not only guarantees the security requirements but also makes great performance improvement on key generation. Kaiping Xue, Yingjie Xue, Jianan Hong, Hao Yue 0001, David S. L. Wei, Peilin Hong |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | LABAC: A Location-Aware Attribute-Based Access Control Scheme for Cloud StorageabstractData access control is a challenging issue in cloud storage. Ciphertext-Policy Attribute-based Encryption (CP-ABE) is a potential cryptographic technique to address the above issue, which is able to enforce data access control based on users' permanent characteristics. However, in some scenarios, access policies are associated with users' temporary conditions (such as access time and location) as well as their permanent ones. CP-ABE cannot deal with such situations commendably. In this paper, we focus on the scenario where users' access privilege is determined by their attributes, together with their locations. To cope with this data access control requirement, we propose a location-aware attribute-based access control mechanism (LABAC) for cloud. In LABAC, we uniquely integrate CP-ABE with location trapdoors to make up access policies. In this way, data owners can flexibly combine both users' attributes and locations to implement a fine-grained control of their data. A competitive advantage of LABAC is that it requires no any additional revocation mechanisms to revoke location-aware access privilege when user location changes. Security and performance analysis are presented which show the security and efficiency of LABAC for practical implementations. Yingjie Xue, Jianan Hong, Kaiping Xue, Peilin Hong |
GLOBECOM | 2 |
| 2016 | TMACS: A Robust and Verifiable Threshold Multi-Authority Access Control System in Public Cloud StorageabstractAttribute-based Encryption (ABE) is regarded as a promising cryptographic conducting tool to guarantee data owners’ direct control over their data in public cloud storage. The earlier ABE schemes involve only one authority to maintain the whole attribute set, which can bring a single-point bottleneck on both security and performance. Subsequently, some multi-authority schemes are proposed, in which multiple authorities separately maintain disjoint attribute subsets. However, the single-point bottleneck problem remains unsolved. In this paper, from another perspective, we conduct a threshold multi-authority CP-ABE access control scheme for public cloud storage, named TMACS, in which multiple authorities jointly manage a uniform attribute set. In TMACS, taking advantage of ($t,n$) threshold secret sharing, the master key can be shared among multiple authorities, and a legal user can generate his/her secret key by interacting with any$t$authorities. Security and performance analysis results show that TMACS is not only verifiable secure when less than$t$authorities are compromised, but also robust when no less than$t$authorities are alive in the system. Furthermore, by efficiently combining the traditional multi-authority scheme with TMACS, we construct a hybrid one, which satisfies the scenario of attributes coming from different authorities as well as achieving security and system-level robustness. Kaiping Xue, Yingjie Xue, Jianan Hong |
IEEE Trans. Parallel Distributed Syst. | 4 |