Yudi Zhang 0001

dblp:202/8656-1 · DBLP profile ↗
← Back
18ranked-venue papers
7as first author
14since 2021 · last 2026
0000-0002-7830-5133ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 6 since 2021Computer networks · 5 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 LRC-DPoR: Efficient Data Integrity Auditing with Local Repair and Dynamic Updates
Yumei Li 0003, Willy Susilo, Fuchun Guo, Yudi Zhang 0001, Mingwu Zhang
ACISP (3)4
2026 KeyChaser: Unveiling API Keys in Browser Extensions
Shijin Chen, Willy Susilo, Yudi Zhang 0001, Fuchun Guo
SP3
2026 Practical Private Set Operation via Secret Sharing for Lightweight Clients
abstract
The rapid growth of sensitive cross-domain data, such as electronic health records and genomic sequences in healthcare, presents significant opportunities for large-scale, multi-institutional collaborative analysis. Meeting stringent privacy regulations while utilizing data has become a critical challenge. Private set operations (PSO) play a crucial role to address this challenge. PSO protocols enable privacy-preserving data alignment across parties (such as interinstitutional data matching based on private set intersection (PSI)) and secure data aggregation (such as federated data aggregation through private set union (PSU)), providing fundamental support for cross-domain data collaboration. This type of technology is not only applicable to multi-center medical research but also has broad value in other scenarios requiring confidential data sharing. However, existing delegated/outsourced PSO schemes face two key limitations: (1) high client-side preprocessing overhead, requiring clients to expensively mask private data before uploading; (2) performance and single-point dependency bottlenecks in client-assisted computation where one client must act as a computational leader. To address these issues, we propose a secret-shared PSO framework for lightweight clients. In our scheme, the clients can go offline while servers perform all computations, significantly reducing clients’ burden. Notably, our protocol can be extended to support multi-party settings, making it well-suited for collaborative research across multiple institutions. In addition, we prove the security of all constructions under the semi-honest model. Experiments show that when the set sizen≥ 216, our protocol has a significant advantage and is well-suited for lightweight client that holds a large set.
Ziyu Niu, Yudi Zhang 0001, Yumei Li 0003, Willy Susilo, Ye Su 0001, Hao Wang 0007
IEEE Trans. Inf. Forensics Secur.2
2026 Outsourced Cloud Storage and Dynamic Sharing: Efficient Time-Bound Access Control
abstract
Cloud storage has become the most attractive way to achieve data sharing by setting flexible access policies. Cryptographic tools are considered the most popular approach to protecting the privacy of data stored on the cloud. Dividing data into different classes plays a significant role in cloud storage, making data organization more methodical and data sharing more expressive and efficient. Unfortunately, current data sharing solutions either neglect data classification or suffer from data leakage. Specifically, shared keys can decrypt newly added encrypted data within the same class, and have key abuse issues where shared keys are untraceable once sold. In this work, we propose a time-bound data sharing system that addresses all these issues simultaneously. In our scheme, data is divided into different classes and encrypted according to its class and associated time period. Decryption keys for a set of chosen data classes can be aggregated into a single key, allowing users to decrypt multiple ciphertexts whose classes are within the set. While other encrypted data with classes outside the set remain confidential. Moreover, the aggregate key is time-bound which can only decrypt the ciphertexts generated before the embedded time period, ensuring it cannot access newly added encrypted data. The key size is independent of the chosen class set size and is only logarithmic in the bit length of the time period used. For each sharing, the shared aggregate key is different. In the event of data leakage or key selling, the data provider can identify the responsible users. We provide formal security analysis of our system and evaluate its performance through experiments. The results demonstrate that our system is highly efficient in terms of shared keys. It provides a practical solution for achieving efficient and dynamic data sharing in cloud storage.
Willy Susilo, Jianchang Lai, Fuchun Guo, Yudi Zhang 0001
IEEE Trans. Inf. Forensics Secur.4
2026 TSFlow: Time-Aware Secure Flow Control for Fine-Grained Data Sharing in Mobile Edge-Cloud
abstract
The rise of edge-cloud computing has accelerated data sharing among mobile users. To resist malicious senders within organizations from leaking sensitive data, access control encryption (ACE) schemes have been employed to secure data f lows, in which each sender obtains an encryption key according to the access control policy to encrypt the data, and a sanitizer (i.e., the edge node) inspects all shared data between the sender and receiver. Although attribute-based ACE schemes have been put forward to support fine-grained data sharing, they lack temporal constraints on write control, which is crucial in mobile data sharing scenarios, and have high sanitization overhead at the edge node. In addition, they only provide selective security and are therefore vulnerable to adaptive adversaries. To this end, we propose TSFlow, a time-aware secure flow control framework in mobile edge-cloud that regulates which senders can transmit data to which receivers during the authorized time interval, preventing malicious sending by expired senders. At its core is TA-ACE, a time-aware attribute-based ACE that issues each sender an encryption key tied to an expressive access structure and a time interval. Encrypted data can be sanitized at the edge only if it is well-formed with a valid encryption key and encrypted within the time interval, and any legitimate receiver satisfying the access structure can decrypt the sanitized ciphertext. We formally prove that TA-ACE satisfies the adaptive no-read and no-write rules, and demonstrate the reasonable efficiency of TSFlow through experiments for secure flow control in mobile edge-cloud.
Qinlong Huang, Caiqun Shi, Yudi Zhang 0001, Willy Susilo
IEEE Trans. Mob. Comput.4
2025 DynaKiteQuery: Top-K Closest-Vertex Queries on Dynamic Attributed Knowledge Graphs for IIoT Applications
Weixiao Wang, Yudi Zhang 0001, Liehuang Zhu
KSEM (3)5
2025 Outsourced Secure Cross-Modal Retrieval Based on Secret Sharing for Lightweight Clients
abstract
Cross-modal retrieval is a technique that uses one modality to query another modality in multimedia data (e.g., retrieving images based on text, or retrieving text based on images). It can break down the barriers between different modalities and achieve seamless information connection. Secure cross-modal retrieval focuses on privacy issues in cross-modal retrieval, including private data of data owners and private query requests of users. Current work on secure cross-modal retrieval protects private information through homomorphic encryption, which makes the efficiency of the retrieval phase not ideal. Therefore, the conflict between retrieval efficiency and security has become an important issue that needs to be resolved in secure cross-modal retrieval. We propose a scheme to achieve secure cross-modal retrieval in the form of secret sharing in the IoT environment. In the scheme, the data owner (DO) can secretly divide all the original data into two parts and upload them to two non-collusive cloud servers respectively. The servers store the data and provide cross-modal retrieval for users. The security of the scheme is proved under semi-honest model, and the experiments show that our scheme is more efficient than previous work in the search phase. When the query dimension is 512 and the number of latent factors is 500, the search time is reduced by more than half compared with previous work.
Ziyu Niu, Hao Wang 0007, Zhi Li 0056, Ye Su 0001, Lijuan Xu 0001, Yudi Zhang 0001, Willy Susilo
IEEE Internet Things J.6
2025 Bilinear-Pairing-Free Universal Designated Verifier Signatures for Private Access in Zero Trust Network
abstract
Zero Trust networks provide an innovative cybersecurity architecture that effectively incorporates “never trust, always verify" principles to address traditional network security threats. Universal Designated Verifier Signature (UDVS) can protect the clients’ privacy in Zero Trust networks, preventing malicious gateways from leaking clients access information to third parties. However, existing UDVS schemes suffer from computational overhead due to their reliance on bilinear pairing operations. This paper primarily focuses on the general transformation method from Identity-Based Key Encapsulation Mechanism (ID-KEM) to UDVS proposed by Steinfeld et al. We first propose ID-KEM based on the SM2 algorithm and prove that it satisfies the EK and Separable properties required by the transformation. Then, we obtain the first UDVS scheme without bilinear pairing through transformation. In terms of performance analysis, the computational overhead of our scheme is 144.36 milliseconds, which is at least 74.39% lower than the previous UDVS schemes. The communication cost is 96 bytes, which is at least 88.89% lower than other schemes, including the first UDVSP scheme without bilinear pairing. To show the utility of our UDVS scheme, we finally apply it into a Zero Trust-based Software Defined Perimeter (SDP) environment, which reaps privacy-preserving authentication for single packet authorization.
Chao Lin 0003, Wei Wu 0001, Xu Yang 0002, Yudi Zhang 0001
IEEE Internet Things J.5
2025 Content-Moderated Bilateral Access Control for Privacy-Preserving Cloud Data Sharing Services
abstract
Cloud computing facilitates scalable data sharing across multiple organizations and users, but also raises concerns about data privacy. Matchmaking encryption (ME) is a prominent technique that enforces bilateral access control in cloud services such as cloud marketplace, allowing both senders and receivers to specify policies for the encrypted data to be revealed. However, receivers may be at risk of being exposed to malicious or harmful content, thus undermining their trust in cloud service platforms. To this end, we introduce MBAC, a content-moderated bilateral access control framework for privacy-preserving cloud data sharing services, which allows receivers to acquire data from authentic senders while preserving their anonymity, and report malicious content in a verifiable manner, i.e., empowering the service provider to hold senders accountable. MBAC is built upon a novel primitive called franking broadcast ME (FBME), which generates a franking signature for the data by designating the service provider as the moderator to ensure accountability and deniability, and encrypts both the data and its franking signature while embedding the sender secret key for privacy and authenticity. We then present a concrete construction of FBME from key-private public key encryption, strongly unforgeable one time signature and non-interactive zero-knowledge proof. Formal security analysis and extensive experiments demonstrate that MBAC provides efficient bilateral access control and content moderation for cloud data sharing services.
Willy Susilo, Yudi Zhang 0001, Yumei Li 0003, Qinlong Huang
IEEE Trans. Cloud Comput.3
2024 OEIBS: A Secure Obfuscation for Encrypted Identity-Based Signatures Scheme in NB-IoT
Yudi Zhang 0001, Yumei Li 0003, Mingwu Zhang, Willy Susilo
ISPEC1
2024 An Efficient Multiparty Threshold ECDSA Protocol against Malicious Adversaries for Blockchain-Based LLMs
abstract
Large language models (LLMs) have brought significant advancements to artificial intelligence, particularly in understanding and generating human language. However, concerns over management burden and data security have grown alongside their capabilities. To solve the problem, we design a blockchain‐based distributed LLM framework, where LLM works in the distributed mode and its outputs can be stored and verified on a blockchain to ensure integrity, transparency, and traceability. In addition, a multiparty signature‐based authentication mechanism is necessary to ensure stakeholder consensus before publication. To address these requirements, we propose a threshold elliptic curve digital signature algorithm that counters malicious adversaries in environments with three or more participants. Our approach relies on discrete logarithmic zero‐knowledge proofs and Feldman verifiable secret sharing, reducing complexity by forgoing multiplication triple protocols. When compared with some related schemes, this optimization speeds up both the key generation and signing phases with constant rounds while maintaining security against malicious adversaries.
Jing Wang 0036, Yudi Zhang 0001
IET Inf. Secur.4
2023 Balancing Privacy and Flexibility of Cloud-Based Personal Health Records Sharing System
abstract
The Internet of Things and cloud services have been widely adopted in many applications, and personal health records (PHR) can provide tailored medical care. The PHR data is usually stored on cloud servers for sharing. Weighted ABE is a practical and flexible technique to protect PHR data. Under a weighted ABE policy, the data user's attributes will be “scored”, if and only if the score reaches the threshold value, they can access the data. However, while this approach offers a flexible access policy, the data owners have difficulty controlling their privacy, especially sharing PHR data in collaborative e-health systems. This paper aims to find a balance between privacy and flexibility and proposes an AND-weighted ABE scheme in cloud-based personal health records sharing systems. The proposed scheme can meet both privacy and flexibility. Only when the data user satisfies the scored-based policy and is in the specified organization(s), can the data user access the PHR data. Besides, we give the security proof and the performance evaluation of the proposed scheme. The security proof and performance analysis show that the proposed scheme can efficiently and securely share PHR data in cloud service.
Yudi Zhang 0001, Fuchun Guo, Willy Susilo, Guomin Yang
IEEE Trans. Cloud Comput.1
2023 PPDF: A Privacy-Preserving Cloud-Based Data Distribution System With Filtering
abstract
Cloud computing has emerged as a popular choice for distributing data among both individuals and companies. Ciphertext-policy attribute-based encryption (CP-ABE) has been extensively used to provide data security and enable fine-grained access control. With this encryption technique, only users whose attributes satisfy the access policy can access the plaintext. In order to mitigate the computational overhead on users, particularly on lightweight devices, partial decryption has been introduced, where the cloud assists in performing the decryption computations without revealing sensitive information. However, in this process, the cloud obtains the user's attributes, thus infringing on the user's privacy. To address this issue, this article proposes a privacy-preserving cloud-based data distribution system with filtering (PPDF) to enable partial decryption without revealing the user's attributes. The proposed system also employs an edge server to assist the user in filtering out invalid ciphertexts, i.e., ciphertexts where the user's attributes do not satisfy the access policy, and transmit only the valid partially decrypted ciphertexts to the data receiver. Consequently, the proposed PPDF scheme achieves constant decryption cost for the data receiver. We provide a security proof and a performance evaluation of the proposed scheme, which confirms its effectiveness and practicality in various real-world applications.
Yudi Zhang 0001, Willy Susilo, Fuchun Guo, Guomin Yang
IEEE Trans. Serv. Comput.1
2021 Efficient Identity-Based Distributed Decryption Scheme for Electronic Personal Health Record Sharing System
abstract
The rapid development of the Internet of Things (IoT) has led to the emergence of more and more novel applications in recent years. One of them is the e-health system, which can provide people with high-quality and convenient health care. Meanwhile, it is a key issue and challenge to protect the privacy and security of the user's personal health record. Some cryptographic methods have been proposed such as encrypt user's data before sharing it. However, it is complicated to share the data with multiple parties (doctors, health departments, etc.), due to the fact that data should be encrypted under each recipient's keys. Although several (t, n) threshold secret sharing schemes can share the data only need one encryption operation, there is a limitation that the decryption private key has to be reconstructed by one party. To offset this shortcoming, in this paper, we propose an efficient identity-based distributed decryption scheme for personal health record sharing system. It is convenient to share their data with multiple parties and does not require to reconstruct the decryption private key. We prove that our scheme is secure under chosen-ciphertext attack (CCA). Moreover, we implement our scheme by using the Java pairing-based cryptography (JPBC) library on a laptop and an Android phone. The experimental results show that our system is practical and effective in the electronic personal health record system.
Yudi Zhang 0001, Debiao He, Mohammad S. Obaidat, Pandi Vijayakumar, Kuei-Fang Hsiao
IEEE J. Sel. Areas Commun.1
2020 An Efficient Blind Signature Scheme Based on SM2 Signature Algorithm
Yudi Zhang 0001, Debiao He, Fangguo Zhang, Xinyi Huang 0001
Inscrypt1
2020 A provable-secure and practical two-party distributed signing protocol for SM2 signature algorithm
Yudi Zhang 0001, Debiao He, Mingwu Zhang, Kim-Kwang Raymond Choo
Frontiers Comput. Sci.1
2020 Secure and Efficient Two-Party Signing Protocol for the Identity-Based Signature Scheme in the IEEE P1363 Standard for Public Key Cryptography
abstract
Mobile device and application (app) security are increasingly important, partly due to the constant and fast-paced cyberthreat evolution. To ensure the security of communication (e.g., data-in-transit), a number of identity-based signature schemes have been designed to facilitate authorization identification and validation of messages. However, in many of these schemes, a user's private key may leak when a new signature is generated since the private keys are stored on the device. Seeking to improve the security of the private key, we propose the first two-party distributed signing protocol for the identity-based signature scheme in the IEEE P1363 standard. This protocol requires that two devices separately store one part of the user's private key, and allows these two devices to generate a valid signature without revealing the entire private key of the user. We formally prove that the security of the protocol in the random oracle model. Then, we implement the protocol using the MIRACL library and evaluate the protocol on two mobile devices. Compared with the protocol of Lindell (CRYPTO'17) that uses the zero-knowledge proof for its security, our protocol is more suitable for deployment in the mobile environment.
Debiao He, Yudi Zhang 0001, Ding Wang 0002, Kim-Kwang Raymond Choo
IEEE Trans. Dependable Secur. Comput.2
2018 Efficient and Provably Secure Distributed Signing Protocol for Mobile Devices in Wireless Networks
abstract
Rapid advances in wireless communications, hardware/software, and Internet technologies have contributed to an exponential growth in the number of users accessing the Internet using mobile, wearable or other Internet of Things devices. Identity-based signature schemes have been widely applied to enforce user authorization and validate user messages in mobile wireless networks. However, the user’s private key used to generate signatures is prone to leakage because the key is being stored on the mobile device. Several (t, n) threshold secret sharing schemes have been proposed to address the issue. One limitation is that the private keys in most of those schemes have to be recovered on a single device when generating signatures, so that the user who holds the device can sign any message without the participation of other users. To address the recovery limitation, we propose an efficient and secure two-party distributed signing protocol for the identity-based signature scheme in the IEEE P1363 Standard, where two users can generate a valid signature without recovering the whole private key. We formally prove its security under a nonstandard assumption. We also implemented our proposed protocol using the MIRACL Cryptographic software development kit. The experimental results obtained show that the time it takes for two general Android devices to generate a signature is about 709.53 ms.
Yudi Zhang 0001, Debiao He, Sherali Zeadally, Ding Wang 0002, Kim-Kwang Raymond Choo
IEEE Internet Things J.1