Xiaodong Yang 0006

dblp:19/1551-6 · DBLP profile ↗
← Back
15ranked-venue papers
13as first author
14since 2021 · last 2026
0000-0002-0382-5943ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 6 first-author · 7 since 2021Security and privacy · 4 · 3 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Decoupled and Privacy-Preserving Key Generation in ABE Under the Minimal Disclosure Principle
abstract
Attribute-Based Encryption (ABE) enables fine-grained access control over outsourced data, but its key generation process typically requires users to disclose their complete attribute sets, introducing significant privacy risks. Existing privacy-preserving approaches—such as those based on zero-knowledge proofs or tightly coupled interactive protocols—suffer from limited scalability, high communication costs, and insufficient support for selective attribute disclosure. To address these limitations, we propose a privacy-enhancing key generation protocol guided by the principle ofMinimal Disclosure, which ensures that users disclose only the minimally necessary subset of attributes required for authorization. Our protocol decouples attribute verification from key issuance: users first obtain cryptographically verifiable attribute tokens, and later issue blinded key requests over selectively chosen attributes. This design enables selective disclosure, supports reusable attribute credentials, and enhances user autonomy. To improve scalability, we introduce a lightweight batch verification mechanism that reduces computation and communication overhead for the attribute authority. We prove that our protocol achieves thebindingandhidingproperties under standard cryptographic assumptions, and we formally verify these guarantees in the symbolic model using the ProVerif tool. In addition, we propose two privacy metrics—AttributeInference Gain (AIG) andPrivacy Gain (PG)—alongside an entropy-based analysis to quantify resistance against attribute inference attacks. Experimental results show that our scheme effectively mitigates inference leakage while offering substantial efficiency gains compared to existing schemes.
Youwen Zhu, Xiaodong Yang 0006, Changhee Hahn, Jian Wang 0038, Junbeom Hur
IEEE Trans. Inf. Forensics Secur.3
2025 A Privacy-Preserving Aggregation Scheme Based on Dual-Masking and Threshold Signature in Computing Power Network
abstract
With the rapid development of computing power network (CPN), resource usage, data exchange, and data aggregation among edge computing nodes have become critical aspects of optimizing resource scheduling. However, such data contains sensitive information, including computational task characteristics and user behavior patterns, making it susceptible to privacy leakage risks. To address this challenge, we propose a privacy-preserving data aggregation (PPDA) scheme that integrates dual secret sharing and an improved threshold Schnorr signature. Our scheme realizes dual masking through Shamir’s Secret Sharing (SSS). It ensures data integrity and source authenticity via threshold signatures. Furthermore, we introduce blockchain smart contracts to enable dynamic updates of secret shares and verifiable publication of aggregation results. In addition to having fault tolerance, the scheme significantly improves the aggregation efficiency in large-scale CPN environments. Theoretical analysis demonstrates that our solution can effectively resist both internal/external attacks and collusion attacks, ensuring the confidentiality of single-node data. Performance evaluations further indicate its computational efficiency surpasses comparable schemes, particularly in large-scale CPN environments.
Xiaodong Yang 0006, Junru He, Duojia Wang, Yuanxin Zhang, Yatong Zhong
TrustCom1
2025 Decentralized and Anonymous Attribute-Based Searchable Encryption With Policy Update and Batch Revocation for Computing Power Network
abstract
computing power network (CPN) can possess powerful data computing capabilities and storage resources by equipping a host of computing nodes. However, data sharing in the CPN faces significant challenges, particularly in data security and access control. attribute-based searchable encryption (ABSE) is a feasible technology to tackle this problem. Nevertheless, CPNs typically contain a vast amount of sensitive data that requires strict fine-grained retrieval permissions. Hence, we construct a decentralized and anonymous ABSE scheme with policy update and batch revocation for CPN, highlighting the generation of keyword indexes based on access structure. Meanwhile, considering the limited computing power of users, we transfer the time-consuming calculation to the edge computing node. Besides, security analysis indicates that our scheme can achieve the security of chosen plaintext attack and chosen keyword attack, collusion resistance, forward and backward security. Experimental evaluations demonstrate that our scheme is trustworthy and applicable to CPNs.
Xiaodong Yang 0006, Shuqian Lian, Xiaoni Du, Caifen Wang
IEEE Internet Things J.1
2025 A CP-ABE-based access control scheme with cryptographic reverse firewall for IoV
Xiaodong Yang 0006, Xilai Luo, Zefan Liao, Xiaoni Du, Shudong Li
J. Syst. Archit.1
2025 Efficient and mutual heterogeneous signcryption schemes for VANETs
Xiaodong Yang 0006, Ke Yao, Songyu Li, Ningning Ren, Caifen Wang
Peer Peer Netw. Appl.1
2024 Heterogeneous Signcryption Scheme From PKI to IBC With Multi-Ciphertext Equality Test in Internet of Vehicles
abstract
With the arrival of the era of self-driving technology, 5G, and IoT technology, self-driving car Internet technology is gradually changing the way people travel. The existing signcryption scheme test scheme with equality can only compare two ciphertexts, which is not suitable for the complex network of Internet of vehicles. To address this challenge, we propose the heterogeneous signcryption scheme from public key infrastructure (PKI) to identity-based cryptosystem (IBC) with multi-ciphertext equality test in the Internet of vehicles (HSCPI-MET). This scheme enables to communicate from PKI cryptosystem to IBC cryptosystem in Internet of vehicles, at the same time excuting the equality test of multi-ciphertext. Our scheme protects inter-vehicle communication data from being illegally accessed, tampered, or forged by malicious vehicles. The proposed scheme satisfies confidentiality and unforgeability under the stochastic predictor model for the computational Diffie–Hellman assumption and the IDH assumption. In addition, we conduct a rigorous experimental evaluation of the scheme to prove that it is secure and effective in practical applications.
Xiaodong Yang 0006, Songyu Li, Muzi Li, Xiaoni Du, Caifen Wang
IEEE Internet Things J.1
2024 Backdoor-resistant certificateless-based message-locked integrity auditing for computing power network
Xiaodong Yang 0006, Lizhen Wei, Muzi Li, Xiaoni Du, Caifen Wang
J. Syst. Archit.1
2024 Proxy re-signature scheme with cryptographic reverse firewall for medical data security
Xiaodong Yang 0006, Lizhen Wei, Songyu Li, Xiaoni Du, Caifen Wang
Peer Peer Netw. Appl.1
2024 Cryptanalysis and Improvement of a Blockchain-Based Certificateless Signature for IIoT Devices
abstract
With the rapid development of the IIoT, security and privacy issues have become increasingly prominent when the data from IIoT devices are shared across public networks. Very recently, Wang et al. presented a blockchain-based CLS scheme for IIoT devices in order to achieve secure and lightweight communication (IEEE Transactions on Industrial Informatics, DOI: 10.1109/TII.2021.3084753). Wang et al. claimed that their CLS scheme is secure under the assumption of the elliptic curve discrete logarithm problem. Unfortunately, by providing two attack methods to analyze the security of Wang et al.’s CLS scheme, we find that it is insecure against universal forgery attacks. Without knowing any information about the target user's private key, the two categories of attackers can successfully forge the valid signature of any message. Hence, Wang et al.’s CLS scheme fails to achieve the claimed security goals. To fix the security flaws, we propose an enhanced blockchain-based and pairing-free CLS scheme, and prove its security in the random oracle model. Furthermore, the analysis results demonstrate that our revised scheme has higher security while keeping the performance of the original scheme.
Xiaodong Yang 0006, Caifen Wang
IEEE Trans. Ind. Informatics1
2024 Efficient and Security-Enhanced Certificateless Aggregate Signature-Based Authentication Scheme With Conditional Privacy Preservation for VANETs
abstract
Vehicular ad-hoc networks (VANETs) are integral to the evolution of intelligent transportation systems, offering substantial benefits in managing traffic flow, issuing warnings for potential accidents, and delivering information services to drivers. To ensure the authenticity and integrity of data exchanged within VANETs, numerous authentication schemes based on certificateless aggregate signature (CLAS) have been developed. However, state-of-the-art solutions often fail to be applicable in real-world VANETs due to security weaknesses and operational inefficiencies. Recently, Zhu et al. proposed an efficient CLAS-based authentication scheme with conditional privacy preservation (CPP) for VANETs (IEEE Transactions on Intelligent Transportation Systems, DOI: 10.1109/TITS.2023.3275077). Unfortunately, our analysis reveals that Zhu et al.’s scheme is incapable of withstanding coalition attacks from malicious RSUs and vehicles as well as public-key replacement attacks from dishonest vehicles. To facilitate secure communication in VANETs, we present a security-enhanced, pairing-free and energy-efficient CLAS-based authentication scheme with CPP for VANETs. This scheme has been rigorously proven to be secure against Type I, Type II and Type III attackers. Distinguished from other comparable schemes, our construction significantly reduces communication overhead and energy consumption while simultaneously fortifying security.
Xiaodong Yang 0006, Songyu Li, Xiaoni Du, Caifen Wang
IEEE Trans. Intell. Transp. Syst.1
2023 Improved Security of a Pairing-Free Certificateless Aggregate Signature in Healthcare Wireless Medical Sensor Networks
abstract
Recently, Zhan et al. presented a pairing-free certificateless aggregation signature scheme (ZH-CLAS) to address security issues in healthcare wireless medical sensor networks (HWMSNs) and proved that their scheme is secure against adaptive chosen message attacks. In this article, we analyze the security of the ZH-CLAS scheme by utilizing two types of concrete attacks. Unfortunately, we demonstrate that their scheme cannot withstand public key replacement attacks and is not secure against coalition attacks from malicious sensor nodes. To solve these security challenges, we further improve the security of the ZH-CLAS scheme. Our enhanced scheme has a fixed-length aggregate signature, which efficiently minimizes the transmission bandwidth. Additionally, our scheme outperforms related pairing-free certificateless aggregate signature schemes in terms of security and communication performance.
Xiaodong Yang 0006, Haoqi Wen, Runze Diao, Xiaoni Du, Caifen Wang
IEEE Internet Things J.1
2022 A blockchain-based keyword search scheme with dual authorization for electronic health record sharing
Xiaodong Yang 0006, Wanting Xi, Caifen Wang
J. Inf. Secur. Appl.1
2022 Blockchain-based multi-user certificateless encryption with keyword search for electronic health record sharing
Xiaodong Yang 0006, Caifen Wang
Peer-to-Peer Netw. Appl.1
2021 An efficient outsourcing attribute-based encryption scheme in 5G mobile network environments
Suzhen Cao, Xiaodong Yang 0006, Xueyan Liu 0005, Longbo Han
Peer-to-Peer Netw. Appl.3
2017 Cryptanalysis and Improvement of a Strongly Unforgeable Identity-Based Signature Scheme
Xiaodong Yang 0006, Faying An, Shudong Li, Caifen Wang, Dengguo Feng
Inscrypt1