EDBT 2026 Demo / reviewers in the wild / expert
Zijian Bao
dblp:206/8665
· DBLP profile ↗
20ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0002-2145-9713ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 6 since 2021Computer networks · 6 · 1 first-author · 6 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Efficient Construction of Threshold BBS+ Signatures and Its Extensions
Yang Heng, Mengling Liu, Xingye Lu, Haiyang Xue, Zijian Bao, Man Ho Au |
PKC (3) | 5 |
| 2026 | Attribute-Based Credentials With Verifiable Human Binding: Toward Compactness and RevocabilityabstractDigital and physical identity authentications are often implemented concurrently to meet strict access control for online services. Although privacy-preserving digital credentials provide strong guarantees such as anonymity and minimal disclosure, these benefits are compromised if holders must simultaneously present physical identification (e.g., government issued IDs) to establish ownership. To securely bind digital credentials to their physical holders while preserving privacy, a new protocol called card-based anonymous credentials (cbAC) was proposed by Hesse et al. (USENIX Security'23). However, this approach faces two significant drawbacks: the size of the communication during credential presentation scales linearly with the number of disclosed attributes, and it lacks revocability, which is essential for internal governance, including identity management and accountability. In this paper, we bridge the above gap by first introducing a constant-size two-party proof of knowledge protocol in asymmetry settings, where there exists a disparity in storage and computational resources between the two parties. Furthermore, building upon this two-party proof of knowledge protocol and utilizing signatures with randomizable keys, we meticulously design a cbAC scheme that is both efficient and capable of supporting revocation. We formalize all notions and conduct a rigorous security proof of the proposed construction. Finally, we present benchmarks from our implementation to illustrate the better than-state-of-the-art performance and features of our solutions. Debiao He, Jianting Ning, Zijian Bao, Cong Peng 0005 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Tightly, Adaptively Secure Proxy Re-encryption in Multi-challenge Setting
Yunhao Ling, Jie Chen 0021, Zijian Bao, Man Ho Au, Luping Wang 0001, Haifeng Qian |
ASIACRYPT (6) | 3 |
| 2025 | A Framework for Efficient Enhanced Privacy ID from Group Actions
Ying Chen 0030, Debiao He, Zijian Bao, Cong Peng 0005, Min Luo 0002 |
Inscrypt (3) | 3 |
| 2025 | BECAAC: A Blockchain and Edge Computing-Assisted Access Control Scheme for Medical Data SharingabstractSecuring the sharing of medical data has become a critical issue in the field of medical informatics. Although existing IoMT-based medical data sharing systems prioritize data security, anonymity, and operational efficiency during transmission, they still exhibit significant shortcomings in preventing unauthorized access and establishing effective accountability mechanisms. Therefore, a solution is urgently needed to ensure fine-grained access control and accountability during data sharing. This paper proposes a novel data sharing system, BECAAC, which is based on blockchain and edge computing. By employing an edge computing-assisted, contract-based access control strategy and proxy re-encryption technology, the system reduces the computational overhead on hospitals and edge nodes while ensuring that only authorized entities can access medical data. Additionally, a blockchain-based verifiable and traceable anonymization scheme has been developed, utilizing group signature technology to ensure patient identity anonymity. By integrating the decentralization, transparency, and immutability features of a consortium blockchain, this approach enhances accountability for malicious behavior. Experiments conducted using Hyperledger Fabric and EdgeCloudSim were performed to evaluate the performance and simulate the proposed solution. The results indicate that BECAAC effectively meets the requirements of real-world medical data sharing environments. Kejie Zhao, Zijian Bao, Hong Lei 0001 |
IEEE Internet Things J. | 2 |
| 2025 | MISP: An Efficient Quantum-Resistant Misbehavior Preventing Scheme With Self-Enforcement for Vehicle-to-EverythingabstractIn the Vehicle-to-Everything (V2X) communication system, the presence of ambiguous warnings significantly increases the risk of severe accidents, posing a substantial threat to the safety of autonomous driving. It is crucial to detect such confusing warnings to avoid danger. Existing solutions to address this issue heavily rely on trust entities or are constructed based on number theory assumptions, leading to low efficiency and vulnerability to quantum attacks. In this paper, we leverage the double authentication-preventing signature scheme (DAPS) to present a revocable identity-based double-authentication preventing signature scheme (RIDAPS) and provides an instantiation from lattice. Furthermore, we propose a post-quantum secure misbehavior preventing scheme (Misp) based on our RIDAPS scheme. We give a detailed proof in the random oracle model (ROM) to demonstrate that our contribution achieves security requirements. Additionally, the efficiency evaluation results demonstrate that our scheme is suitable to be applied in V2X. Ying Chen 0030, Debiao He, Zijian Bao, Huaqun Wang, Min Luo 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | PEACS: A Privacy-Enhancing and Accountable Car Sharing SystemabstractCar sharing is gaining increased popularity in urban transportation which allows individuals to conveniently rent vehicles for short periods. Such systems, however, present considerable challenges to security such as unauthorized access and privacy data breaches, as service providers are able to track the precise mobility patterns of all customers. Nevertheless, efforts in solving the security and privacy concerns associated with car-sharing services are relatively few, in particular for a trade-off between privacy preservation and accountability of misbehaviors. In this work, we propose an efficient Privacy-Enhancing and Accountable Car Sharing System (PEACS), introduced to mitigate the aforementioned threats. PEACS primarily employs several key ingredients, including structure-preserving signatures on equivalence classes (J CRYPTOL’s 19), as well as two primitives designed in this paper, namely: signatures of knowledge and identity-based structure-preserving signatures with a tag on equivalence classes. Furthermore, we employ a bivariate polynomial function to establish a revocation mechanism that ensures accountability. We provide thorough security proof to demonstrate the security and privacy of PEACS. Comprehensive performance evaluation and comparison results point out that our proposed scheme is feasible in practical settings. Debiao He, Zijian Bao, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 3 |
| 2024 | PACTA: An IoT Data Privacy Regulation Compliance Scheme Using TEE and BlockchainabstractDespite the existence of data privacy regulations, such as the general data protection regulation (GDPR), data leaks in the Internet of Things (IoT) still occur and cause significant harm due to the noncompliance of data users. To address this issue, a notable solution involves recording the process in an open, immutable blockchain and utilizing the trusted execution environment (TEE) for reliable compliance verification. Although substantial progress has been made in designing compliance schemes in recent years, current approaches suffer from various limitations, including compliance incompleteness, regulation faultiness, and privacy leak. This article introduces PACTA, an IoT data privacy regulation compliance scheme that leverages TEE and blockchain technology. In the protocol, PACTA efficiently handles both dynamic and static consent of data owners and utilizes TEE for compliance analysis of requests and processes. By storing encrypted critical data, the blockchain facilitates privacy-preserving audits of the entire compliance process. Additionally, we have designed a challenge–response protocol to address the silent behavior of the TEE. We demonstrate that PACTA effectively enforces regulation compliance while safeguarding privacy. We thoroughly evaluate our implementation’s efficiency and effectiveness using Ethereum and Intel SGX platforms. Hong Lei 0001, Zijian Bao, Ning Lu 0005, Bangdao Chen |
IEEE Internet Things J. | 4 |
| 2024 | Constant-Size Verifiable Timed Signatures from RSA Group for Bitcoin-Based Voting ProtocolsabstractA verifiable timed signature (VTS) scheme allows a signature to be time-locked to a known message for a predetermined duration denoted as$\mathsf {T}$. Verifiability ensures that anyone can verify that the time-lock contains a valid signature without completing the computation. In this paper, we introduce a novel VTS construction method based on the RSA group, designed to maintain a constant level of size. This approach serves as an improvement over the previous linear level size construction method (CCS 2020). First, we construct it by using a commitment to a valid RSA signature. This commitment can only be opened to a regular RSA signature after a sequential computation period. Our scheme utilizes a trapdoor verifiable delay function, RSA signatures, and a specialized zero-knowledge proof to instantiate the proposed scheme. We also conduct proofs in three aspects: correctness, soundness, and security. Furthermore, we identify potential applications for VTS and present a simple Bitcoin voting protocol based on an open vote protocol by utilizing VTS. Experimental results show that our scheme is more efficient compared to the construction of VTS (CCS 2020), reducing the signature size by at least 90.5% and lowering computational costs by at least 77%. Zijian Bao, Debiao He, Min Luo 0002, Xiangyong Zeng |
IEEE Trans. Serv. Comput. | 1 |
| 2023 | Traceable Ring Signatures from Group Actions: Logarithmic, Flexible, and Quantum Resistant
Min Luo 0002, Zijian Bao, Cong Peng 0005, Debiao He |
SAC | 3 |
| 2023 | OWL: A data sharing scheme with controllable anonymity and integrity for group users
Zijian Bao, Qinghao Wang, Ning Lu 0005, Bangdao Chen, Hong Lei 0001 |
Comput. Commun. | 2 |
| 2023 | A Group Signature Scheme With Selective Linkability and Traceability for Blockchain-Based Data Sharing Systems in E-Health ServicesabstractRecently, with the rapid improvement of e-health technology, a large amount of precious medical data has been accumulated in different entities, such as hospitals, clinics, and medical institutions, promoting the development of data sharing in e-health services. However, most of them lacks fine-grained functionalities: selective linkability and traceability, which are critical in an e-health environment. Furthermore, we observe that existing schemes mostly rely on centralized storage centers, which will lead to a single point of failure and privacy disclosure. In this article, we first construct a group signature schemeSLTGSsuitable for a data sharing environment. It supports selectively linking two different message-signature pairs to the same signer. Further, it provides an algorithm to trace the signer. Then, based on theSLTGSscheme, we leverage distributed technology (i.e., interplanetary file system (IPFS) and blockchain) and attribute-based encryption to propose a distributed data sharing scheme. We claim that our scheme meets anonymity, accountability, linkability, traceability, fine-grained and efficient access control, and distributed storage. Moreover, the proposed data sharing scheme yields a practical performance making it suitable for e-health applications. Zijian Bao, Debiao He, Huaqun Wang, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 1 |
| 2023 | An identity-based dynamic group signature scheme for reputation evaluation systems
Haoyang An, Debiao He, Zijian Bao, Cong Peng 0005, Qin Liu 0003 |
J. Syst. Archit. | 3 |
| 2023 | LedgerMaze: An Efficient Privacy-Preserving Noninteractive Zero-Knowledge Scheme Over Account-Model BlockchainabstractThe prosperity of blockchain has pushed various decentralized applications, e.g., cross-regional finance, due to its advantages of openness, immutability, and decentralization. The feature of openness inevitably leads to a serious privacy breach. Recently, various privacy-enhanced works (e.g., Zcash, Monero) were proposed focusing on this problem. However, most existing solutions either aim for the unspent transaction output (UTXO) model, or fail to provide full privacy protection for the account-based model with efficient performance. In this paper, we put forwardLedgerMaze, an efficient privacy-preserving non-interactive zero-knowledge (NIZK) scheme over account-model blockchain. We design a novel scheme calledchequemechanism to cut the link between the sender/receiver relationship. Namely, a sender transfers money to a receiver's cheque, then the receiver can retrieve the cheque among a set of cheques for obfuscation without revealing the original one. We construct several efficient NIZK proofs for initializing the mechanism. Moreover, we further analyze the security properties ofLedgerMaze. Experimental results show thatLedgerMazeachieves comparable performance in communication and computation costs while retaining a full privacy guarantee, compared to previous similar constructions. Zijian Bao, Debiao He, Cong Peng 0005, Xinyi Huang 0001 |
IEEE Trans. Computers | 1 |
| 2023 | PBidm: Privacy-Preserving Blockchain-Based Identity Management System for Industrial Internet of ThingsabstractIndustrial Internet of Things (IIoT) is revolutionizing plenty of industrial applications by utilizing large-scale smart devices in manufacturing and industrial processes. However, IIoT is facing the disclosure of identity privacy. The identity information is precious and critical, thereby inspiring a line of follow-up privacy-preserving studies, i.e., anonymous credential protocols, or privacy-preserving identity management schemes. However, they are either too anonymous to be used in the IIoT environment, or the system is highly centralized, which implies the risk of a single point of failure. In this article, we proposePBidm, a privacy-preserving blockchain-based identity management scheme for IIoT. Specifically, by leveraging blockchain and diversified cryptographic tools,PBidmcan fully support the desirable properties, i.e., unforgeability, blindness, unlikability, traceability, revocability, and public verifiability. Then, we provide security analysis to ensure reasonable security assurance. Finally, we present a performance evaluation of the proposed scheme to demonstrate the practicability in IIoT applications. Zijian Bao, Debiao He, Muhammad Khurram Khan, Min Luo 0002, Qi Xie 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | SorTEE: Service-Oriented Routing for Payment Channel Networks With Scalability and Privacy ProtectionabstractPayment channel networks (PCNs) are emerged as the most widely deployed solution to mitigate the scalability problem of permissionless cryptocurrencies, allowing vast payments to be carried out off-chain. Routing, which finds feasible paths between the senders and receivers, is critical for PCNs. However, existing solutions either fail to achieve high scalability that can maintain low storage/computation/network communication overhead, or they are susceptible to privacy disclosure. In this paper, we propose SorTEE, a service-oriented routing solution for PCNs, which adopts a set of service nodes to alleviate the per-user burden of routing and achieves more comprehensive privacy guarantees than the state-of-the-art by leveraging trusted execution environments (TEEs). SorTEE demands users communicate with the TEE by the secure channel to protect the privacy of transaction value. Then, an oblivious path mechanism is designed to construct redundant paths with the pseudo senders and receivers generated by TEEs to confuse its untrusted controller. Further, we report a novel attack that allows malicious service nodes to drop the valid paths for profit, and design a feedback mechanism to relieve it. Moreover, SorTEE hides the identities of the senders/receivers for the intermediate nodes of payment paths by introducing a novel identity information transfer scheme called encrypted identity chain. Based on security analysis and performance evaluation, our results demonstrate that SorTEE is able to achieve sufficient privacy-preserving payment and low per-user overhead. Qinghao Wang, Zijian Bao, Hong Lei 0001, Han Liu 0010, Bangdao Chen |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | SDABS: A Secure Cloud Data Auditing Scheme Based on Blockchain and SGX
Hong Lei 0001, Zijian Bao, Qinghao Wang |
BlockSys | 2 |
| 2020 | A Survey on the Application of SGX in Blockchain Area
Hong Lei 0001, Qinghao Wang, Zijian Bao |
BlockSys | 4 |
| 2020 | Dredas: Decentralized, reliable and efficient remote outsourced data auditing scheme with blockchain smart contract for industrial IoT
Kuan Fan, Zijian Bao, Athanasios V. Vasilakos |
Future Gener. Comput. Syst. | 2 |
| 2017 | A privacy-preserving degree-matching multi-attribute auction scheme in smart grid auction market
Zijian Bao, Jiaqi Wang 0011, Ning Lu 0005, Jian Shen 0001 |
Pers. Ubiquitous Comput. | 2 |