EDBT 2026 Demo / reviewers in the wild / expert
Zengpeng Li 0001
dblp:188/7735
· DBLP profile ↗
34ranked-venue papers
16as first author
25since 2021 · last 2026
0000-0003-0758-7230ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 6 first-author · 13 since 2021Computer networks · 7 · 3 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PADRE: Privacy-Aware Decentralized RandomnessabstractA Decentralized Randomness Beacon (DRB) is a powerful cryptographic tool that aims to generate fair, unpredictable, and publicly verifiable randomness. DRBs are gaining significant importance in distributed computing systems and decentralized network applications, where they serve as crucial sources of randomness for consensus protocols and other essential functions. While most existing DRBs prioritize core security attributes such as infeasibility and unpredictability, they often neglect participants' identity privacy. Traditional DRB protocols, such as GRandLine (CCS 2024) and RandFlash (TIFS 2025), typically expose participants' identities to potential attackers during the leader-election process and subsequent interactions. This exposure can disclose sensitive information, including blockchain stakes, rendering these protocols unsuitable for applications that require stringent privacy guarantees. In this work, we propose a privacy-aware DRB protocol, PADRE, that conceals participants' identities while generating randomness without compromising efficiency or basic security. To this end, we propose a new cryptographic primitive, the “anonymous threshold verifiable random function (ATVRF)”, that introduces both “threshold-capability” and “anonymity” on top of verifiable random functions (VRFs) under the Decisional Diffie-Hellman assumption (on elliptic curves). In addition, we integrate an “anonymous lottery” into the committee-based DRB, enhancing privacy protection and performance to a wide range of state-of-the-art DRBs. Our proof-of-concept implementation (102 beacons per minute on average across 64 nodes) indicates that PADRE is suitable for real-world deployments. Zengpeng Li 0001, Mei Wang 0003 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Bandwidth-Efficient Robust Threshold ECDSA in Three RoundsabstractThreshold ECDSA schemes distribute the capability of issuing signatures to multiple parties. They have been used in practical MPC wallets holding cryptocurrencies. However, most prior protocols are not robust, wherein even one misbehaving or non-responsive party would mandate an abort. Robust schemes have been proposed (Wong et al., NDSS ’23, ’24), but they do not match state-of-the-art number of rounds which is only three (Doerner et al., S&P ’24). In this work, we propose robust threshold ECDSA schemes RompSig-Q and RompSig-L that each take three rounds (where the first two are broadcasts, whereas the non-robust scheme of Doerner et al. uses no broadcasts). Building on the works of Wong et al. and further optimized towards saving bandwidth, they respectively take each signer (1.0t+ 1.6) KiB and 3.0 KiB outbound broadcast communication, and thus exhibit bandwidth efficiency that is competitive in practical scenarios where broadcasts are natively handled. RompSig-Q preprocesses multiplications and features fast online signing; RompSig-L leverages threshold CL encryption for scalability and dynamic participation. Yingjie Lyu, Zengpeng Li 0001, Hong-Sheng Zhou, Haiyang Xue, Mei Wang 0003, Shuchao Wang, Mengling Liu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | A Byzantine-Robust Secure Federated Learning Scheme in Heterogeneous Data
Ruijin Wang, Zengpeng Li 0001, Fengli Zhang, Jingwei Li 0001, Xiong Li 0002 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | Avatar: Securing Anonymous Communication With Relay AnonymityabstractOnion routing and mix networks are designed to provide users with anonymous Internet access and to prevent the disclosure of real IP addresses. In practice, anonymous networks serve various legitimate purposes, such as whistleblowing, circum-venting censorship, and safeguarding personal online privacy and security. These systems typically achieve anonymity by introducing a series of relays between the sender and the receiver. An anonymous path, or circuit, is usually composed of multiple relays (commonly three), and onion routing systems such as Tor rely on these circuits to relay traffic and ensure anonymity. Although Tor employs hidden relays (known as bridges) to resist censorship and blocking, most relays are publicly listed, and their identities are visible to circuit initiators during circuit construction, making them susceptible to surveillance and targeted attacks. A malicious relay deviating from the protocol (e.g.,injecting modified onions) poses serious threats to system security. An interesting question is how to preserve relay identity privacy while maintaining network functionality. In this paper, we introduce an innovative method for protecting relay privacy within circuits. This is achieved through the application of anonymous credentials, anonymous verifiable random functions (AVRFs), and signatures with key blinding. Additionally, if more than half of the directory authority servers within the current Tor network are compromised, the entire network could collapse. To mitigate this risk, our design distributes trust among more entities, enhancing the network’s resilience against potential adversaries. We have named this approach Avatar to enable users to navigate the online realm with the same freedom, privacy, and anonymity as an Avatar, allowing them to maintain full control over their digital identity. Furthermore, we provide a comprehensive analysis and evaluation of the Avatar framework. The findings indicate that, in comparison to the original Tor network’s onion routing protocol, our proposed protocol exhibits superior time efficiency in many network environments. Mei Wang 0003, Zengpeng Li 0001, Jing Chen 0003 |
IEEE Trans. Netw. | 3 |
| 2025 | Threshold ECDSA in Two RoundsabstractWe propose the first two-round multi-party signing protocol for the Elliptic Curve Digital Signature Algorithm (ECDSA) in the threshold-optimal setting, reducing the number of rounds by one compared to the state of the art (Doerner et al., S&P '24). We also resolve the security issue of presigning pointed out by Groth and Shoup (Eurocrypt '22), evading a security loss that increases with the number of pre-released, unused presignatures, for the first time among threshold-optimal schemes. Our construction builds on Non-Interactive Multiplication (NIM), a notion proposed by Boyle et al. (PKC '25), which allows parties to evaluate multiplications on secret-shared values in one round. In particular, we use the construction of Abram et al. (Eurocrypt '24) instantiated with class groups. The setup is minimal and transparent, consisting of only two class-group generators. The signing protocol is efficient in bandwidth, with a message size of 1.9 KiB at 128-bit security, and has competitive computational performance. Yingjie Lyu, Zengpeng Li 0001, Hong-Sheng Zhou |
CCS | 2 |
| 2025 | Improved Quantum Cryptanalysis on Generalized Feistel Structure
Yingkai Wei, Boyun Li, Zengpeng Li 0001 |
Inscrypt (1) | 4 |
| 2025 | StealthHub: Utxo-Based Stealth Address ProtocolabstractPrivacy remains a significant challenge in public blockchain ecosystems. Mainstream add-on privacy solutions, such as Stealth Address Protocols (SAPs) and Zero-Knowledge Proof (ZKP)-based mixers, have recently attracted considerable attention. However, existing SAPs offer only ephemeral anonymity for users' transaction data, and their implementation and evaluation within the highly concurrent Unspent Transaction Output (UTXO) model remain largely unexplored. ZKP-based mixers are limited to native coin transfers with fixed denominations and require additional security assumptions, employing out-of-band encrypted channels to transmit notes. To overcome these challenges, we unify the core principles underlying both SAPs and ZKP mixers and formally introduce StealthHub, a UTXObased SAP. Compared with the widely adopted dual-key-based Umbra protocol prevalent on Ethereum Virtual Machine (EVM)-compatible chains, StealthHub reduces computational overhead for the prepare and scan announcements stages by over 71% and 32%, respectively. Furthermore, by leveraging Merkle Mountain Range (MMR) commitments and off-chain batch aggregation, our StealthHub implementation lowers deposit and shielded transfer transaction costs to approximately 76% of those for a standard transfer, substantially improving practical usability. Hanze Guo, Yebo Feng, Cong Wu 0003, Zengpeng Li 0001, Jiahua Xu 0002 |
ICWS | 4 |
| 2025 | Authenticated and Incremental Single-Server Private Information Retrieval
Zengpeng Li 0001, Mei Wang 0003 |
ISPEC | 2 |
| 2025 | Purse: Post-Quantum Unique Ring Signature for Anonymous TransactionsabstractDistributed public ledger (e.g., Blockchain) has been proven to be a powerful technique that allows users to sign transactions in an untrusted environment, where identity-privacy disclosure is gaining attention in practice. Ring signatures can protect identities by providing anonymity property for users. However, a malicious anonymous user may generate multiple signatures on the same transaction, called double-spending attack. A unique ring signature avoids this attack by attaching a unique identifier to the transaction. In addition, future-proof cryptographic solutions are attracting attention in the quantum era. Thus, we aim to propose a post-quantum unique ring signature scheme for anonymous transactions, named . We initially provide verifiable random functions over lattices (L-VRF, in short) with tight security and optimize the proof size (compared with the work of Nguyen et al., ESORICS’ 22) using compression techniques. We then obtain from L-VRF inspired by the previous solution of Franklin-Zhang (FC’ 13) while enables to prevent of quantum computer attacks. Finally, is analyzed under the quantum random oracle model (QROM) while providing a prototype via C language. The performance evaluation shows offers a smaller communication load. Guangyu Liao, Zengpeng Li 0001, Guangsheng Feng, Mei Wang 0003, Hongwu Lv |
IEEE Internet Things J. | 2 |
| 2025 | Collusion-resistant multi-user searchable symmetric encryption with conjunctive query and suppressed pattern leakage
Yanpeng Ba, Yuan Ping 0003, Zengpeng Li 0001 |
J. Inf. Secur. Appl. | 3 |
| 2024 | F-FHEW: High-Precision Approximate Homomorphic Encryption with Batch Bootstrapping
Yuyue Chen, Rui Zong, Zengpeng Li 0001, Zoe Lin Jiang |
ACISP (1) | 4 |
| 2024 | Funder: Future-Proof Unbiased Decentralized RandomnessabstractA trustworthy source of randomness is a crucial component of many decentralized and crypto-based application systems, especially blockchain consensus. A decentralized random beacon (DRB) periodically outputs a new source of randomness generated using a distributed technique, such as publicly verifiable secret sharing (PVSS) or distributed verifiable random functions (VRFs). These protocols offer a variety of efficiency versus randomness quality tradeoffs, but guarantee security under a variety of configurations, assumptions, and adversarial models. This article aims to provide a future-proof unbiased decentralized randomness (abbreviated as Funder) via a post-quantum threshold VRF for sustainable proof-of-stake blockchain. We also provide a generic compiler for achieving post-quantum VRF from a classical VRF solution, but our approach makes use of symmetric-key primitives Our novel compiler is validated and evaluated using the ZKBoo and ZKB++ quantum-secure zero-knowledge systems, respectively. The implementation of the proof-of-concept demonstrates that the overheads introduced by our solution are acceptable for real-world deployments even in the present day. In addition, we demonstrate the protocol’s possible application in lottery-based proof-of-stake consensus protocols. Zengpeng Li 0001, Mei Wang 0003, Teik Guan Tan, Jianying Zhou 0001 |
IEEE Internet Things J. | 1 |
| 2024 | Controlled Search: Building Inverted-Index PEKS With Less Leakage in Multiuser SettingabstractThe public key encryption with keyword search (PEKS) schemes are mostly applied to small data sets in mail forwarding systems. When retrieving large databases, the typical search mechanism makes them inefficient and impractical. When designing a PEKS scheme, except for remedying the vulnerability of keyword guessing attacks (KGAs), other leakage issues, such as multipattern privacy and forward/backward security are rarely considered, which may lead to information leakage. Moreover, most existing PEKS only consider applications in single-user scenarios, and cannot be directly transferred to multiuser scenarios, which undermines the value of data utilization. To cope with the above concerns, we propose a PEKS scheme based on an inverted index where the bitmap is used to build the index for the first time in PEKS to meet some seemingly conflicting yet desirable characteristics. First, it has high search efficiency under multiwriter and multiuser. Through linear transformation, users quickly retrieve data and control other users’ access to their data without relying on a third party for authentication. Second, we prove its security in an enhanced security model that achieves multipattern privacy and forward and backward security. It can also resist KGA attacks without a designated tester, which makes it more practical. Finally, it can be extended to achieve search result verification. Compare to the scheme (Zhang et al. ICWS 2016), it has absolute advantages in security and computational cost where the search efficiency is improved by two orders of magnitude. Guiyun Qin, Pengtao Liu, Chengyu Hu 0001, Zengpeng Li 0001, Shanqing Guo |
IEEE Internet Things J. | 4 |
| 2023 | Sustainable and Round-Optimized Group Authenticated Key Exchange in Vehicle CommunicationabstractVehicle authentication is an essential component validating the vehicle’s identity and ensuring the integrity of transformed data for intelligent transport vehicles (ITS) in the vehicular ad hoc network (VANET). Easy to deploy and operate privacy-enhancing vehicle authentication mechanisms are the mainstay for the widespread ITS in the VANET. Very recently, VANET security architectures are constituting by IEEE 1609.2 group, NoW project, the SeVeCom project. However, these approaches heavily depend on the consuming public key infrastructure (PKI) and certification authorities (CA). In this work, walking along the research line, we attempt to design authentication protocols with two diverse factors for Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) networks, respectively, without depending on the stumbling block PKI/CA. In addition, a smooth projective hash function (SPHF) (a.k.a., a special case of the designated-verifier zero-knowledge proof system) guarantees any recipient can confirm the authenticity and integrity of the received messages without knowing the authentication factors. Thus, to optimize the communication round, SPHF is used to design a (group) two-factor authenticated key exchange (AKE) with low-interactive communication rounds. The proof-of-concept implementation indicates that the computation and communication overheads introduced by our solution are acceptable in real-world deployments. The security of the proposed approach is validated using Bellare-Pointcheval-Rogaway (BPR) model along with the experimental evaluation and the theoretical analysis. Zengpeng Li 0001, Mei Wang 0003, Vishal Sharma 0001, Prosanta Gope |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2022 | Reinshard: An Optimally Sharded Dual-Blockchain for Concurrency ResolutionabstractDecentralized control, low-complexity, flexible and efficient communications are the requirements of an architecture that aims to scale blockchains beyond the current state. Such properties are attainable by reducing ledger size and providing parallel operations in the blockchain. Sharding is one of the approaches that lower the burden of the nodes and enhance performance. However, the current solutions lack the features for resolving concurrency during cross-shard communications. With multiple participants belonging to different shards, handling concurrent operations is essential for optimal sharding. This issue becomes prominent due to the lack of architectural support and requires additional consensus for cross-shard communications. Relying on the advantages of hybrid Proof-of-Work/Proof-of-Stake (PoW/PoS), like Ethereum , hybrid consensus and 2-hop blockchain , we propose Reinshard , a new blockchain that inherits the properties of hybrid consensus for optimal sharding. Reinshard uses PoW and PoS chain-pairs with PoS sub-chains for all the valid chain-pairs where the hybrid consensus is attained through Verifiable Delay Function (VDF). Our architecture provides a secure method of arranging nodes in shards and resolves concurrency conflicts using the delay factor of VDF. The applicability of Reinshard is demonstrated through security and experimental evaluations. A practical concurrency problem is considered to show the efficacy of Reinshard in providing optimal sharding. Vishal Sharma 0001, Zengpeng Li 0001, Pawel Szalachowski, Teik Guan Tan, Jianying Zhou 0001 |
Distributed Ledger Technol. Res. Pract. | 2 |
| 2022 | PANDA: Lightweight non-interactive privacy-preserving data aggregation for constrained devices
Mei Wang 0003, Kun He 0008, Jing Chen 0003, Ruiying Du, Bingsheng Zhang, Zengpeng Li 0001 |
Future Gener. Comput. Syst. | 6 |
| 2022 | Quantum-Safe Round-Optimal Password Authentication for Mobile DevicesabstractPassword authentication is the dominant form of access control for the Web and mobile devices, and its practicality and ubiquity is unlikely to be replaced by other authentication approaches in the foreseeable future. To guarantee the security of data communication and mitigate the problem of password-cracking, aPassword Authenticated Key Exchange($\mathsf {PAKE}$) system can be deployed between two peer participants. The main drawback of traditional$\mathsf {PAKE}$is that passwords are exposed in plaintext when the remote server is compromised. To overcome this limitation, it is recommended by industry standards (such as SRP family RFC 5054, RFC6628, RFC7914, OPAQUE,etc) to useasymmetric-$\mathsf {PAKE}$protocols, which enable the server to store a hash of the user's password with a random salt, providing guarantees that the user's password is never transmitted in plain-text to the server when login. However, most of the existingasymmetric-$\mathsf {PAKE}$protocols either are based on traditional hash functions under random oracles, or depend on non-quantum-secure hardness assumptions and become insecure in the quantum era. To bridge the gap betweenasymmetric-$\mathsf {PAKE}$and quantum-security, in this article, we resort tosmooth projective hash functions($\mathsf {SPHF}$) andcommitment-basedpassword-hashing schemes($\mathsf {PHS}$) over lattice-based cryptography, and construct an asymmetric$\mathsf {PAKE}$protocol secure against quantum attacks. Our construction eliminates the costly non-interactive zero-knowledge (NIZK) method, bypasses assumptions of the random oracle model, and achieves quantum resistance. We also show that our asymmetric-$\mathsf {PAKE}$protocol can achieve security and efficiency under the Bellare-Pointcheval-Rogaway (BPR) model. Finally, we develop a prototype implementation of our instantiation and use it to evaluate its performance in realistic settings. Zengpeng Li 0001, Ding Wang 0002, Eduardo Morais |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Achieving One-Round Password-Based Authenticated Key Exchange over LatticesabstractPassword-based authenticated key exchange($\mathsf {PAKE}$PAKE) protocol, a widely used authentication mechanism to realize secure communication, allows protocol participants to establish a high-entropy session key by pre-sharing a low-entropy password. An open challenge in$\mathsf {PAKE}$PAKEis how to design a quantum-resistant round-optimal$\mathsf {PAKE}$PAKE. To solve this challenge, lattice-based cryptography is a promising candidate for post-quantum cryptography. In addition, Katz and Vaikuntanathan (ASIACRYPT’09) design the firstthree-round$\mathsf {PAKE}$PAKEprotocol by leveraging the smooth projective hash function ($\mathsf {SPHF}$SPHF) over lattices. Subsequently, Zhang and Yu (AISACRYPT’17) optimized Katz-Vaikuntanathan’s approximate$\mathsf {SPHF}$SPHFvia a splittable public key encryption. They then constructed atwo-round$\mathsf {PAKE}$PAKEby using the simulation-sound non-interactive zero-knowledge (NIZK) proofs, but how to construct a lattice-based simulation-sound NIZK remains an open research question. In other words, how to design a one-round$\mathsf {PAKE}$PAKEvia an efficient lattice-based$\mathsf {SPHF}$SPHFstill remains a challenge. In this work, we attempt to fill this gap by proposing a lattice-based$\mathsf {SPHF}$SPHFwith adaptive smoothness. We then obtain aone-round$\mathsf {PAKE}$PAKEprotocol over lattices with rigorous security analysis by integrating the proposed$\mathsf {SPHF}$SPHFinto the one-round framework proposed by Katz and Vaikuntananthan (TCC’11). Furthermore, we explore the possibilities of achieving two-round$\mathsf {PAKE}$PAKEand universal composable (UC) security from our$\mathsf {SPHF}$SPHF, and show the potential application of our$\mathsf {PAKE}$PAKEin Internet of Things (IoTs) where communication cost is the main consideration. Zengpeng Li 0001, Ding Wang 0002 |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | Group Time-based One-time Passwords and its Application to Efficient Privacy-Preserving Proof of LocationabstractTime-based One-Time Password (TOTP) provides a strong second factor for user authentication. In TOTP, a prover authenticates to a verifier by using the current time and a secret key to generate an authentication token (or password) which is valid for a short time period. Our goal is to extend TOTP to the group setting, and to provide both authentication and privacy. To this end, we introduce a new authentication scheme, called Group TOTP (GTOTP), that allows the prover to prove that it is a member of an authenticated group without revealing its identity. We propose a novel construction that transforms any asymmetric TOTP scheme into a GTOTP scheme. Our approach combines Merkle tree and Bloom filter to reduce the verifier’s states to constant sizes. Zheng Yang 0001, Chenglu Jin, Jianting Ning, Zengpeng Li 0001, Tien Tuan Anh Dinh, Jianying Zhou 0001 |
ACSAC | 4 |
| 2021 | Biometrics-Authenticated Key Exchange for Secure MessagingabstractSecure messaging heavily relies on a session key negotiated by an Authenticated Key Exchange (AKE) protocol. However, existing AKE protocols only verify the existence of a random secret key (corresponding to a certificated public key) stored in the terminal, rather than a legal user who uses the messaging application. In this paper, we propose a Biometrics-Authenticated Key Exchange (BAKE) framework, in which a secret key is derived from a user's biometric characteristics that are not necessary to be stored. To protect the privacy of users' biometric characteristics and realize one-round key exchange, we present an Asymmetric Fuzzy Encapsulation Mechanism (AFEM) to encapsulate messages with a public key derived from a biometric secret key, such that only a similar secret key can decapsulate them. To manifest the practicality, we present two AFEM constructions for two types of biometric secret keys and instantiate them with irises and fingerprints, respectively. We perform security analysis of BAKE and show its performance through extensive experiments. Mei Wang 0003, Kun He 0008, Jing Chen 0003, Zengpeng Li 0001, Wei Zhao 0054, Ruiying Du |
CCS | 4 |
| 2021 | LaKSA: A Probabilistic Proof-of-Stake Protocol
Daniël Reijsbergen, Pawel Szalachowski, Junming Ke, Zengpeng Li 0001, Jianying Zhou 0001 |
NDSS | 4 |
| 2021 | Ciphertext-policy attribute-based proxy re-encryption via constrained PRFs
Zengpeng Li 0001, Vishal Sharma 0001, Chunguang Ma, Chunpeng Ge 0001, Willy Susilo |
Sci. China Inf. Sci. | 1 |
| 2021 | Building Low-Interactivity Multifactor Authenticated Key Exchange for Industrial Internet of ThingsabstractIndustrial Internet of Things (IIoT) brings together computers, devices, advanced analytics, and people in industries, such as transportation, oil plant, and power grid that leads to major efficiency and productivity gains for almost any industrial procedures. Due to the interconnection of devices in IIoT, communication security has become a critical issue to address in many emerging industry standards that require the authentication and key exchange procedure to be done to guarantee the authorized machine access (e.g., from users) and secure the data transmission between machines. To overcome the shortcoming (i.e., low entropy) of the memorable password in user authentication, it is rightfully recommended by industry standards (such as IEC-62443 family) to use multifactor authentication (MFA) for higher security levels. Notably, latency is one of the main sources of inefficiency when a device is communicating with other machines on IIoT. To mitigate latency, a smooth projective hash function (SPHF) built from well-studied standard assumptions is used to achieve a lowinteractivity multifactor authenticated key exchange protocol (MFAKE) because SPHF allows each party to prove to the others that he knows the right authentication factor(s). In this article, we are, therefore, motivated to build a new MFAKE named “secure remote multifactor (SRMF)” to achieve the humaninvolved “machine-to-machine” secure communication in IIoT. That is, SRMF leverages multiple user-centric authentication factors (such as password, biometric fingerprints, and PIN), and it can synergistically support multifactor registration (MFR), MFA, and multifactor key exchange (MFKE). Furthermore, to prevent authentication factors stored at the server exposing to attackers, the password-harden service (i.e., Pythia-PRF and USENIX'15) inspires us to develop a multifactor hardening service (MFHS) utilizing an oblivious pseudorandom function (OPRF). The balanced security of the proposed protocol is proved under the model of Bellare-Pointcheval-Rogaway (EUROCRYPTO'00) along with theoretical and experimental evaluations. Zengpeng Li 0001, Zheng Yang 0001, Pawel Szalachowski, Jianying Zhou 0001 |
IEEE Internet Things J. | 1 |
| 2021 | Leakage Resilient Leveled FHE on Multiple Bits MessageabstractFully Homomorphic Encryption ($\mathsf {FHE}$) allows computing over encrypted data without decrypting the corresponding ciphertexts, and it constitutes a promising cryptographic primitive to preserve data privacy in the big data computing environments. In general,$\mathsf {FHE}$schemes can be constructed by using the standard Learning with Errors ($\mathsf {LWE}$) assumption, and the current crux lies in how to achieve efficient multi-bit$\mathsf {FHE}$encryption while being leakage-resistent against attackers who may capture the information of cryptographic secret keys via side channel attacks. Based on Berkoff-Liu’s work at TCC’14, we aim to address this issue by giving a new structure of public key matrix with any number of$\mathsf {LWE}$instances, thereby avoiding the use of a straightforward composition to achieve multi-bit$\mathsf {FHE}$encryption under standard$\mathsf {LWE}$. Particularly, our scheme attains provable security. Zengpeng Li 0001, Chunguang Ma, Ding Wang 0002 |
IEEE Trans. Big Data | 1 |
| 2021 | Towards Achieving Keyword Search over Dynamic Encrypted Cloud Data with Symmetric-Key Based VerificationabstractVerifiable Searchable Symmetric Encryption, as an important cloud security technique, allows users to retrieve the encrypted data from the cloud through keywords and verify the validity of the returned results. Dynamic update for cloud data is one of the most common and fundamental requirements for data owners in such schemes. To the best of our knowledge, the existing verifiable SSE schemes supporting data dynamic update are all based on asymmetric-key cryptography verification, which involves time-consuming operations. The overhead of verification may become a significant burden due to the sheer amount of cloud data. Therefore, how to achieve keyword search over dynamic encrypted cloud data with efficient verification is a critical unsolved problem. To address this problem, we explore achieving keyword search over dynamic encrypted cloud data with symmetric-key based verification and propose a practical scheme in this paper. In order to support the efficient verification of dynamic data, we design a novel Accumulative Authentication Tag (AAT) based on the symmetric-key cryptography to generate an authentication tag for each keyword. Benefiting from the accumulation property of our designed AAT, the authentication tag can be conveniently updated when dynamic operations on cloud data occur. In order to achieve efficient data update, we design a new secure index composed by a search table ST based on the orthogonal list and a verification list VL containing AATs. Owing to the connectivity and the flexibility of ST, the update efficiency can be significantly improved. The security analysis and the performance evaluation results show that the proposed scheme is secure and efficient. Xinrui Ge, Jia Yu 0003, Hanlin Zhang 0001, Chengyu Hu 0001, Zengpeng Li 0001, Zhan Qin, Rong Hao |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2020 | Achieving Multi-Hop PRE via Branching ProgramabstractProxy re-encryption (PRE) is a fundamental cryptographic primitive in secure data sharing and e-mail forwarding, etc. To our knowledge, most existing efficient lattice-based PRE schemes focus on the construction of single-hop, key-private, multi-bit and chosen-ciphertext attack (CCA), etc. Few works of literature discussed the detailed multi-hop construction over lattices. Very recently, Chandran et al. (PKC'14) proposed a lattice-based PRE scheme that builds upon the key switching mechanism of Brakerski (CRYPTO'12), and pointed out that their scheme can achieve multi-hop PRE scheme by the ideal circuit family for a directed graph G. In this paper, we are still working along this line and achieving multi-hop PRE via the branching program (BP), which is one type of NC1 circuit and can be used to compute encrypted data. To our knowledge, we proposed the first multi-hop PRE scheme via BP which supports homomorphic evaluation. We also analyze the security of our scheme under decisional learning with errors (LWE) assumption. Zengpeng Li 0001, Chunguang Ma, Ding Wang 0002 |
IEEE Trans. Cloud Comput. | 1 |
| 2018 | Two-Round PAKE Protocol over Lattices Without NIZK
Zengpeng Li 0001, Ding Wang 0002 |
Inscrypt | 1 |
| 2018 | Multi-key FHE for multi-bit messages
Zengpeng Li 0001, Chunguang Ma, Hong-Sheng Zhou |
Sci. China Inf. Sci. | 1 |
| 2018 | Oblivious Transfer via Lossy Encryption from Lattice-Based CryptographyabstractAuthenticationis the first defence line to prevent malicious entities to accesssmart mobile devices(or SMD). Essentially, there exist many available cryptographic primitives to design authentication protocols.Oblivious transfer() protocol is one of the important cryptographic primitives to design authentication protocols. The first lattice‐based framework under universal composability (UC) model was designed by dual mode encryption and promoted us to find an alternative efficient scheme. We note that “lossy encryption” scheme is an extension of the dual mode encryption and can be used to design UC‐secure protocol, but the investigations of via lossy encryption over the lattice are absent. Hence, in order to obtain an efficient authentication protocol by improving the performance of the UC‐secure protocol, in this paper, we first design a multibit lossy encryption under the decisional learning with errors () assumption and then design a new variant of UC‐secure protocol for authenticated protocol via lossy encryption scheme. Additionally, our protocol is secure against semihonest (static) adversaries in the common reference string (CRS) model and within the UC framework. Zengpeng Li 0001, Can Xiang, Chengyu Wang 0002 |
Wirel. Commun. Mob. Comput. | 1 |
| 2017 | An Uncertain Continuous Collaborative Users Finding Algorithm for Location Privacy ProtectionabstractThe centralized and distributed models are the main system architecture of privacy protection in location-based services (LBS). In the model of centralized, the trusted third party (TTP) is used to provide location privacy, but it is usually thought as the point of attack and the bottleneck of service, which makes the distributed model attract more attention. However, although a large number of algorithms were proposed under this model, they were mainly focussed on the protection of the snapshot query and difficult to provide privacy in the continuous query. Especially that, with the difference of anonymous users, the adversary can get rid of the anonymous users and identify the issuer, and then the privacy of the issuer will be revealed. In order to deal with this problem, we propose an uncertain continuous collaborative users finding algorithm (UCCUFA), which utilizes the uncertainty cells of region grid and the collaborative users to provide query results to make the issuer hiding behind the collaborative users. In this algorithm, all query results are provided by collaborative users, and no information interacted between the issuer and the LBS server during the procedure of continuous query. At last, we utilize the security analysis and experimental results further verify the effectiveness of location privacy protection and the performance efficiency of our proposed algorithm. Lei Zhang 0052, Chunguang Ma, Zengpeng Li 0001 |
MSWiM | 4 |
| 2017 | Toward single-server private information retrieval protocol via learning with errors
Zengpeng Li 0001, Chunguang Ma, Ding Wang 0002, Gang Du |
J. Inf. Secur. Appl. | 1 |
| 2016 | Multi-bit Leveled Homomorphic Encryption via \mathsf Dual.LWE -Based
Zengpeng Li 0001, Chunguang Ma, Eduardo Morais, Gang Du |
Inscrypt | 1 |
| 2016 | Dual LWE-Based Fully Homomorphic Encryption with Errorless Key SwitchingabstractCloud computing raises new challenges for how to protect user privacy. Fully homomorphic encryption is one way to solve the problem. In this paper, we show a useful property of Dual-LWE assumption to construct Key-Switching procedure compared with LWE assumption without extra error term. Hence, we propose to construct "Errorless Key Switching" fully homomorphic encryption (FHE) scheme based on dual learning with errors (Dual-LWE) assumption. Specifically, we compile the Dual-LWE problem proposed by Gentry et.al. at STOC2008 and First-is-errorless LWE (Ferr.LWE) problem proposed by Brakerski et al. at STOC2013 into Dual-First-is-errorless LWE (Dual-Ferr.LWE) problem. Then, utilizing Dual-Ferr.LWE assumption to construct a various GPV(vGPV) scheme, and we use vGPV scheme as the fundamental building block to construct FHE with errorless key switching scheme. Lastly, under the assumption of decisional learning with errors(DLWE), we prove that our scheme is CPA secure. Zengpeng Li 0001, Chunguang Ma, Gang Du, Weiping Ouyang |
ICPADS | 1 |
| 2016 | Preventing Adaptive Key Recovery Attacks on the GSW Levelled Homomorphic Encryption Scheme
Zengpeng Li 0001, Steven D. Galbraith, Chunguang Ma |
ProvSec | 1 |