EDBT 2026 Demo / reviewers in the wild / expert
Wenzheng Zhang 0001
dblp:20/889-1
· DBLP profile ↗
18ranked-venue papers
2as first author
14since 2021 · last 2026
0009-0002-3888-0229ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 5 since 2021Computer networks · 5 · 5 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Theory of computation · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GovLink: Auditable FPH-CP-ABE for Dynamic Revocation and Query Integrity in E-GovernmentabstractGovernment data sharing, a cornerstone of digital governance, is strategically vital for enhancing public services and maximizing data utility. While Ciphertext-Policy Attribute-Based Encryption (CP-ABE) offers a promising cryptographic solution for secure government data sharing due to its flexible access control, existing schemes face substantial limitations in policy privacy, dynamic permission management, and verifiability of query results, thus hindering real-world e-governance deployment. To address these challenges, we propose GovLink, an auditable, full policy hiding CP-ABE scheme that supports dynamic revocation and verifiable query results. Specifically, by integrating the matrix representation of a linear secret sharing scheme with hidden vector encryption, GovLink achieves fine-grained access control and robust policy hiding. Furthermore, we design an efficient dynamic revocation mechanism utilizing puncturable encryption and Lagrange interpolation, guaranteeing system forward security. To enhance auditability, GovLink introduces lightweight data update verification (using hash and XOR operations) and employs a multiset accumulator to ensure verifiable data update legitimacy and query result integrity. Security analysis confirms that GovLink meets stringent security requirements, including indistinguishability under chosen-plaintext attack and full policy indistinguishability. Empirical evaluations conducted using the JPBC cryptographic library demonstrate GovLink’s practical feasibility and efficiency in its core operations. Jingting Xue, Kangyi Liu, Fagen Li, Wenzheng Zhang 0001 |
IEEE Internet Things J. | 4 |
| 2025 | Attribute-Based Policy-Hiding Redactable Blockchain With Authorizable Verification for Energy InternetabstractThe goal of the energy internet is to enable communication between distributed energy endpoints to facilitate information exchange and trading matching. Blockchain, which ensures content consistency, bridges the gaps between multiple energy stakeholders and satisfies the need for universal trust. However, applying blockchain directly in peer-to-peer trading can result in the permanent inclusion of illegal or outdated data in blockchain databases, hindering efficient interaction. Driven by emerging application requirements and legal regulations, redactable blockchain (EuroS&P 2017) was introduced, allowing the block history to be rewritten via collisions in chameleon hash functions. Nevertheless, current solutions still face challenges, including trapdoor security risks, privacy leakage, and indefinite redactions. This paper presents a redactable energy blockchain scheme (REBS) with partially attribute-based policy hiding, which enables controlled multi-authority key generation and redactor attribute verification. To prevent the abuse of redaction permission, REBS employs time-updatable chameleon hash functions for redaction. Additionally, we design a delegation algorithm that adds dynamic flexibility to attribute verification nodes, permitting them to delegate key share distribution authority to other nodes on demand. The detailed security proofs and performance evaluations demonstrate the feasibility of REBS. Jingting Xue, Liang Liu 0018, Fagen Li, Ximin Jing, Wenzheng Zhang 0001, Yu Zhou 0012 |
IEEE Internet Things J. | 5 |
| 2025 | Incentive-assisted multi-keyword ranked searchable encryption with hidden attributes for community data sharing
Jingting Xue, Lusha Zeng, Wenzheng Zhang 0001, Fagen Li, Yu Zhou 0012, Liang Liu 0018 |
Peer Peer Netw. Appl. | 3 |
| 2025 | Towards Authorization and Batch Validation for NFTs: A Cryptographic Generic FrameworkabstractThe rapid growth in the NFT (Non-fungible token) market has offered a wide variety of opportunities for scammers, fraudsters, wash tradings, and so on. One of the most urgent security issues is how to efficiently authorize and validate the ownership to make the NFT ecosystem avoid infringement and counterfeiting. By exploiting linear homomorphic tagging and robust digital watermarking technologies, this article proposes a generic framework for ownership authorization and batch validation of NFTs. Within this framework, the digital artwork creators can authorize the ownership to a buyer before the NFT is minted in the public blockchain. Anytime in the future who questions the ownership of a claimant can initiate a validation procedure to get an auditing report by running a Challenge-Response protocol that supports efficient batch verification. The completeness and soundness of the proposed framework have been proven by assuming a secure homomorphic tag scheme and a robust watermarking scheme. We also present instantiations of the generic construction, especially with$\Pi _{Pub}$, one can outsource the validation procedure to the public blockchain to release local computation burden. A series of elaborated experiments have shown our proposed framework is practical and efficient. Tao Wang 0039, Keyong Hong, Bo Yang 0003, Qiliang Yang, Wenzheng Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Threshold Password-Hardening Updatable Oblivious Key ManagementabstractWe propose a threshold password-hardening updatable oblivious key management system dubbed TPH-UOKM for cloud storage. In TPH-UOKM, a group of key servers share a user-specific secret key for a user, and assist the user in producing her/his password-derived private key in a threshold and oblivious way, where the password is hardened to resist offline dictionary guessing attacks. Anyone can outsource data protected with the user’s password-derived public key to the cloud server, and merely the user holding the correct password can recover the password-derived private key for data access. TPH-UOKM can accomplish decryption ofNciphertexts with the complexityO(1) of communication between a user and the key servers, which outperforms existing schemes. TPH-UOKM supports password update. The cloud server can update all protected data of a user with an update token to be accessible only with the new password, which resists password leakage. We present a two-level proactivization mechanism to periodically update user-specific secret key shares and the key servers to thwart perpetual compromise of them, where the renewal of user-specific secret key shares reduces computation and communication costs compared to existing approaches. Provable security and high efficiency of TPH-UOKM are demonstrated by comprehensive analyses and performance evaluations. Changsong Jiang, Chunxiang Xu, Wenzheng Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Efficient Collaborative Data Cleaning Using Private Set Intersection and Encoding for Unbalanced DatasetsabstractData cleaning improves quality and consistency by detecting, localizing, and repairing “dirty” data without compromising sensitive information. Collaborative Data Cleaning employs a distributed model to avoid single points of failure and trust issues in centralized systems, although it incurs additional communication overhead. Blass et al. (S&P’23) were the first to implement CDC via balanced Private Set Intersection (PSI). Unbalanced PSI (e.g.,uPSI-CA, USENIX’23) does not address the localization of intersections within datasets and thus cannot be directly applied to CDC. uPSI-based data cleaning remains largely unexplored. In this paper, we propose an efficient CDC scheme for unbalanced datasets, nameduECDC.uECDCemploys oblivious key-value stores for slice matching, achieving: i) a reduction of 18% ~ 85% in offline phase runtime, and ii) a reduction of 8% ~ 43% in online phase runtime (under large-scale data settings on the server side), when compared to the slice-linking approach ofuPSI-CA. Moreover, we encode server-side data for fast localization of intersection data in unbalanced settings. Under the semi-honest adversary model,uECDCis provably secure. Implementation in Python and C++ demonstrates thatuECDCis practically feasible. Jingting Xue, Fagen Li, Wenzheng Zhang 0001, Yu Zhou 0012 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | A Small-Size FHE Scheme for Better Privacy Protection of IoTabstractFully homomorphic encryption (FHE) fundamentally solves the problems of confidentiality when data and operations are entrusted to third parties. It can play an important role in secure data computation for Internet of Things (IoT). However, the storage complexities of existing FHE schemes are still not friendly. Our work focuses on optimizing the storage complexity of FHE, in order to further promote the practical process of FHE in IoT. The FHE schemes based on learning with errors (LWE) have become the mainstream of FHE schemes due to its simplicity, security, and ease of efficient implementation. The key switching technology is the ingenious and crucial technique that led to LWE-based FHE. By proposing a low-noise key switching technology, and using Bin-LWE assumption twice (first on the public key, and then again on the ciphertext), we design a leveled FHE scheme with small parameters (without expensive bootstrapping technology). Meanwhile, a detailed analysis of noise growth for homomorphic evaluation is made, and the specific security parameters are given. Wenzheng Zhang 0001, Dianhua Tang |
IEEE Internet Things J. | 2 |
| 2024 | Attribute-Based Hierarchical Keyword Auditing With Batch Fault Localization Assisted by Smart ContractsabstractKeyword-based auditing (KA) provides a means for users to verify the integrity of only the outsourced data they are interested in. Existing KA schemes employ relation authentication labels to conduct targeted audits with keywords, which significantly improves the cost-effectiveness. However, such schemes typically support only a single-challenge scenario, which may not always be practical. To overcome this constraint, we introduce a hierarchical challenge mechanism grounded in user attributes. This mechanism leverages inequality and affiliation relationships to comply with a predefined tree structure for access policies. Incorporated during the challenge-response phase of the auditing model, it permits users to initiate cross-challenges. Expanding upon this hierarchical mechanism, we propose an attribute-based hierarchical keyword auditing scheme, abbreviated as$\mathcal{AHKA}$.$\mathcal{AHKA}$combines searchable encryption to conduct cross-targeted audits and benefits from the hash collision mapping of Bloom filters to safeguard against keyword guessing attacks. Moreover, we design a fault localization algorithm based on a variant of the binary search technique. It locates in batch the faulty cloud servers and damaged data blocks after an audit failure. As an integral part of$\mathcal{AHKA}$, the algorithm significantly enhances our scheme's practicability. Security analyses indicate that$\mathcal{AHKA}$can effectively withstand both forgery and replace attacks on audit proofs. The smart contract component ensures that our scheme's processes can be monitored and regulated. Experimental data corroborate that deploying$\mathcal{AHKA}$on the client side and on the blockchain is both efficient and feasible. Jingting Xue, Shuqin Luo, Fagen Li, Wenzheng Zhang 0001, Liang Liu 0018, Yu Zhou 0012 |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | An Efficient Identity Authentication Scheme With Dynamic Anonymity for VANETsabstractNowadays, as an essential technique for intelligent transportation, vehicular ad hoc networks (VANETs) has significantly improved people’s travel experience, providing richer, and smarter services for vehicles while ensuring driver safety. However, considering that VANETs are complex, some security challenges still remain, including but not restricted to privacy preserving of vehicles, authentication of messages, limited resources in computational power, and network bandwidth. To address these issues, many privacy-preserving identity authentication schemes for VANETs have been proposed recently. However, these schemes still suffer some limitations. First, their computational overheads are heavy due to the complex calculations. Second, some schemes are vulnerable to various security weaknesses, unable to resist normal attacks. Third, in some schemes, the same pseudonym keeps unchanged and it is linked to the corresponding private key of user. The consequence is that if the user wants to change its pseudonym, the corresponding private key must be changed. In order to further solve the above problems, we propose a novel privacy-preserving identity authentication protocol based on the certificateless aggregate signature scheme, allowing the user to generate a fuzzy identity to hide her real identity, and the private key can be kept unchanged even if the corresponding pseudonym is updated. Furthermore, to achieve efficiency in computation, bilinear mapping is avoided in our proposed scheme. We prove that our protocol satisfies unforgeability in the random oracle based on a classic complexity assumption. Finally, the security and efficiency analyses demonstrate that our construction enjoys more security features and better performance compared with the existing schemes. Yanwei Zhou, Zirui Qiao, Zhe Xia, Bo Yang 0003, Mingwu Zhang, Wenzheng Zhang 0001 |
IEEE Internet Things J. | 7 |
| 2023 | Public-key encryption scheme with optimal continuous leakage resilience
Yanwei Zhou, Ran Xu 0012, Wenzheng Zhang 0001, Zhe Xia, Bo Yang 0003, Meijuan Huang |
Inf. Process. Lett. | 3 |
| 2023 | ABCrowdMed: A Fine-Grained Worker Selection Scheme for Crowdsourcing Healthcare With Privacy-PreservingabstractCrowdsourcing for healthcare, which is an application of crowd intelligence, has become a novel and important auxiliary way for traditional healthcare, showing a huge application perspective. In a crowdsourcing platform for healthcare, patients can act as requesters who recruit workers, such as doctors, to provide professional advice by posting a task. However, privacy concerns pose a significant obstacle for patients willing to participate in crowdsourcing, as task data often contain sensitive personal information. To address this issue, we propose a novel attribute-based, lightweight, and dynamic fine-grained worker selection scheme, called ABCrowdMed, with privacy-preserving features. With this scheme, requesters can select workers in a non-interactive way by using a novel CP-ABE scheme that incorporates online/offline encryption, verifiable outsourcing decryption, revocation, and hidden policy properties. Additionally, requesters can revoke and update their tasks by withdrawing some workers’ decryption privileges. Participants can also release the computation burden with the aid of a third-party server. The proposed scheme’s security has been proven to be selectively secure under the decisional$ (q-1)$assumption and satisfies forward/backward security. The performance of ABCrowdMed has been evaluated and compared with state-of-art schemes, with the results demonstrating that our scheme achieves the lowest computation and is suitable for resource-constrained settings. Tao Wang 0039, Bo Yang 0003, Qiliang Yang, Wenzheng Zhang 0001, Keyong Hong |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | Continuous Leakage-Amplified Public-Key Encryption With CCA SecurityabstractAbstract Secret key leakage has become a security threat in computer systems, and it is crucial that cryptographic schemes should resist various leakage attacks, including the continuous leakage attacks. In the literature, some research progresses have been made in designing leakage resistant cryptographic primitives, but there are still some remaining issues unsolved, e.g. the upper bound of the permitted leakage is fixed. In actual applications, the leakage requirements may vary; thus, the leakage parameter with fixed size is not sufficient against various leakage attacks. In this paper, we introduce some novel idea of designing a continuous leakage-amplified public-key encryption scheme with security against chosen-ciphertext attacks. In our construction, the leakage parameter can have an arbitrary length, i.e. the length of the permitted leakage can be flexibly adjusted according to the specific leakage requirements. The security of our proposed scheme is formally proved based on the classic decisional Diffie–Hellman assumption. Wenzheng Zhang 0001, Zirui Qiao, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang |
Comput. J. | 1 |
| 2022 | A distributed privacy-preserving data aggregation scheme for smart grid with fine-grained access control
Wenzheng Zhang 0001, Zhe Xia |
J. Inf. Secur. Appl. | 1 |
| 2021 | On the Modified Transparency Order of n , m -FunctionsabstractThe concept of transparency order is introduced to measure the resistance of n , m -functions against multi-bit differential power analysis in the Hamming weight model, including the original transparency order (denoted by TO ), redefined transparency order (denoted by RTO ), and modified transparency order (denoted by MTO ). In this paper, we firstly give a relationship between MTO and RTO and show that RTO is less than or equal to MTO for any n , m -functions. We also give a tight upper bound and a tight lower bound on MTO for balanced n , m -functions. Secondly, some relationships between MTO and the maximal absolute value of the Walsh transform (or the sum-of-squares indicator, algebraic immunity, and the nonlinearity of its coordinates) for n , m -functions are obtained, respectively. Finally, we give MTO and RTO for (4,4) S-boxes which are commonly used in the design of lightweight block ciphers, respectively. Yu Zhou 0012, Yongzhuang Wei, Hailong Zhang 0001, Wenzheng Zhang 0001 |
Secur. Commun. Networks | 4 |
| 2016 | Provably secure and efficient leakage-resilient certificateless signcryption scheme without bilinear pairing
Yanwei Zhou, Bo Yang 0003, Wenzheng Zhang 0001 |
Discret. Appl. Math. | 3 |
| 2016 | CCA2 secure public-key encryption scheme tolerating continual leakage attacksabstractAbstract For a public‐key encryption scheme to be applied in practical applications, it should withstand various leakage attacks (e.g., side‐channel attacks and cold‐boot attacks). To this end, we present a way of construct the more practical CCA2 secure public‐key encryption scheme tolerating leakage attacks, and the scheme's security is based on the hardness of classical decisional Diffie–Hellman assumption and the target collision resistant of one‐way hash function. Additionally, our proposal enjoys better performance, for example, all of elements of ciphertext will be random from the adversary's view, and any probabilistic polynomial‐time adversary cannot obtain leakage on the secret key from the ciphertext, and so on. In the bounded‐leakage setting, for any leakage parameter λ⩽logq − ω(logk)(q is the prime order of the underlying group, and k denotes the security parameter.), our proposal is secure against leakage‐resilient chosen‐ciphertext attacks, where λ is independent of the plaintext space, and has the constant size. However, in the real world, an adversary can continuously learn information on the secret key through a variety of leakage attacks and can trivially break the security of public‐key encryption scheme under the continual leakage attacks. Thus, we will improve our method to resist the continual leakage attacks. Similarly, for any round leakage parameter λC⩽logq − ω(logk), we can prove the security of the improvement scheme based on the hardness of decisional Diffie–Hellman assuming and the target collision resistant of one‐way hash function. With this important performance, our proposal may have some significant value in the practical applications, such as our proposal can provide the leakage‐resilient security for outsourcing data in the cloud computing environment. Copyright © 2016 John Wiley & Sons, Ltd. Yanwei Zhou, Bo Yang 0003, Wenzheng Zhang 0001, Yi Mu 0001 |
Secur. Commun. Networks | 3 |
| 2009 | Analysis and Improvement of an ID-Based Anonymous Signcryption Model
Mingwu Zhang, Yusheng Zhong, Bo Yang 0003, Wenzheng Zhang 0001 |
ICIC (1) | 4 |
| 2008 | Assertions Signcryption Scheme in Decentralized Autonomous Trust Environments
Mingwu Zhang, Bo Yang 0003, Shenglin Zhu, Wenzheng Zhang 0001 |
ATC | 4 |