EDBT 2026 Demo / reviewers in the wild / expert
Xiwen Wang 0001
dblp:187/3023-1
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2024
0000-0003-2013-0032ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Non-interactive Boolean Searchable Asymmetric Encryption With Bilateral Access ControlabstractAbstract Searchable asymmetric encryption (SAE) enables a client to search over a data owner’s encrypted data. Nevertheless, state-of-the-art SAE schemes allow a data owner to specify access control policy for a client, while they have not considered the threat case of a malicious data owner. To address the problem, this work presents a non-interactive SAE scheme with bilateral access control: (i) allowing data owner and client to both specify policies toward the other party; (ii) allowing client to perform arbitrary boolean queries with sub-linear search complexity. Technically, we extend Cash et al.’s highly scalable SSE into an asymmetric setting and introduce the property of data owner authenticity. By refining identity-based matchmaking encryption, we formalize the syntax and security definition of our SAE with identity-based bilateral access control. Moreover, the security of the proposed SAE can be reduced to discrete logistic assumption and decisional bilinear Diffie–Hellman assumption. As an enhanced extension, we present a non-interactive multi-client SAE scheme with fuzzy identity-based bilateral access control. In addition, we implement the proposed schemes in real cloud platform and evaluate their performance on a real-world dataset. The result confirms that our SAE schemes achieve bilateral access control for both data owner and client with highly acceptable efficiency. Xiwen Wang 0001, Kai Zhang 0016, Jinguo Li, Mi Wen, Shengmin Xu, Jianting Ning |
Comput. J. | 1 |
| 2024 | Updatable searchable symmetric encryption: Definitions and constructions
Xiwen Wang 0001, Kai Zhang 0016, Junqing Gong 0001, Shifeng Sun 0001, Jianting Ning |
Theor. Comput. Sci. | 1 |
| 2023 | Revocable identity-based matchmaking encryption in the standard modelabstractAbstract Identity‐based Matchmaking Encryption (IB‐ME) is an extension notion of matchmaking encryption (CRYPTO 2019), where a sender and a receiver can specify an access policy for the other party. In IB‐ME, data encryption is performed by not only a receiver identity but also a sender's encryption key. Nevertheless, previous IB‐ME schemes have not considered the problem of efficient revocation . Hence, the authors introduce a new notion of revocable IB‐ME (RIB‐ME) and formalise the syntax and security model of RIB‐ME. In particular, the authors give an effective and simple construction of RIB‐ME in the standard model, whose security is reduced to the hardness of decisional bilinear Diffie—Hellman problem and computational Diffie—Hellman problem. In addition, the authors show two extensions of our RIB‐ME scheme to consider chosen‐ciphertext security and forward privacy. Xiwen Wang 0001, Kai Zhang 0016, Junqing Gong 0001, Jie Chen 0021, Haifeng Qian |
IET Inf. Secur. | 2 |
| 2023 | Multi-Client Boolean File Retrieval With Adaptable Authorization Switching for Secure Cloud Search ServicesabstractSecure cloud search services provide a cost-effective way for resource-constrained clients to search encrypted files in the cloud, where data owners can customize search authorization. Despite providing fine-grained authorization, traditional attribute-based keyword search (ABKS) solutions generally support single keyword search. Towards expressive queries over encrypted data, multi-client searchable symmetric encryption (MC-SSE) was introduced. However, current search authorizations of existing MC-SSEs: (i) cannot support dynamic updating; (ii) are (semi-)black-box implementations of attribute-based encryption; (iii) incur significant cost during system initialization and file encryption. To address these limitations, we present AasBirch, an MC-SSE system with fast fine-grained authorization that supports adaptable authorization switching from one policy to any other one. AasBirch achieves constant-size storage and lightweight time cost for system initialization, file encryption and file searching. We conduct extensive experiments based on Enron dataset in real cloud environment. Compared to state-of-the-art MC-SSE with fine-grained authorization, AasBirch achieves 30$\sim 200\times$smaller public parameter and secret key size, with the assumed least frequent keyword in a query ($s$-term) as 21. Moreover, it runs 10$\sim 20\times$faster for file encryption and$>20\times$faster for file searching. In addition, AasBirch outperforms 80,000× (resp. 7,850×) faster with$s$-term=1 (resp. =21), as compared to classic dynamic ABKS system. Kai Zhang 0016, Xiwen Wang 0001, Jianting Ning, Mi Wen, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Secure Cloud-Assisted Data Pub/Sub Service With Fine-Grained Bilateral Access ControlabstractSecure cloud-assisted data publish/subscribe (Pub/Sub) service provides an asynchronous method for publishers and subscribers to non-interactively exchange encrypted messages. Besides performing conjunctive subscription policy, numerous data Pub/Sub systems have recently been proposed to provide dynamic access control enforced from the publisher side to the subscriber side. However, these solutions fail to consider the following properties: (i) bilateral access control for both publishers and subscribers; (ii) the anonymity of the publisher; (iii) high matching time cost between publication and subscription. Therefore, we present P/S-BiAC, a secure and boolean cloud-assisted data Pub/Sub system with attribute-based bilateral access control that achieves authenticity and anonymity of publishers. In particular, P/S-BiAC enables cloud-based brokers to use the subscriber’s trapdoor to match published data with sub-linear time complexity. Technically, we introduce a “BiAC-and-Hidden” technique to refine publication tuples and trapdoor in classic searchable symmetric encryption solutions. Moreover, we implement P/S-BiAC and evaluate its practical performance based on Enron dataset in real cloud environment. To deal with a conjunctive subscription policy, P/S-BiAC runs 27.8× faster for matching time cost (with s-term=10) compared to state-of-the-art solutions, which demonstrates its feasibility in practical data Pub/Sub services with strong security properties. Kai Zhang 0016, Xiwen Wang 0001, Jianting Ning, Junqing Gong 0001, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Dual-Server Boolean Data Retrieval for Highly-Scalable Secure File Sharing ServicesabstractSearchable encryption (SE) is a promising strategy for cloud-based file retrieval services, via structuring correspondences between files and keywords. Public key encryption with keyword search (PEKS) has been generally employed in file-sharing services, as compared to searchable symmetric encryption (SSE). However, PEKS is inherently vulnerable to keyword guessing attacks (KGA) launched by a malicious server. To resist such attacks, classic solutions are dual-server PEKS (DS-PEKS) [TIFS’2015] and server-aided PEKS (SA-PEKS) [TIFS’2016]. However, the query model in these two solutions only support single keyword search pattern, which inevitably limits their wide deployments in practice due to efficiency concern. In this work, we present DSB-SE, a new cloud-based file sharing & retrieval system that supports boolean queries while retaining KGA-resistance. Compared to DS-PEKS and SA-PEKS, the cost of documents searching in DSB-SE is 25, 000 times (resp. 6, 600 times) faster when$\#\text {keyword}=10$and$s\text {-term}=1$, where$s$-term is the least frequent keyword in the query pattern. Technically, the performance gain derives from revisiting traditional boolean SSE by: (i) introducing a pairing-free DDH-based transformation key modular that allows a data reader’s query pattern to be treated as a data writer’s; (ii) employing the dual-server methodology to support boolean query with efficient validity checks. In particular, the client-to-cloud communication cost for retrieving index of a single document is bounded to$10^{-2}s$, and the cost of sending a token ranges from$8\times 10^{-2}s\sim 13\times 10^{-2}s$. Nevertheless, DSB-SE is$1.5\times 10^{-2}s$slightly slower than DS-PEKS (but$1.35\times 10^{-2}s$faster than SA-PEKS) for key generation cost. Overall, the experiments show that the DSB-SE is practical and sufficient for real cloud applications, which is conducted over Enron dataset under a real-world cloud platform. Kai Zhang 0016, Xiwen Wang 0001, Jianting Ning, Xinyi Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |