EDBT 2026 Demo / reviewers in the wild / expert
Shucheng Yu
dblp:21/5356
· DBLP profile ↗
56ranked-venue papers
7as first author
12since 2021 · last 2026
0000-0001-6484-4382ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 32 · 3 first-author · 7 since 2021Security and privacy · 14 · 3 first-author · 2 since 2021Systems, architecture and hardware · 7 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Asynchronous Concurrent Wireless Power Transfer in Sustainable 6G Networks: A Systematic Analysisabstract6G networks require a sustainable and dependable power supply to ubiquitous space–air–ground connectivity infrastructures. Wireless power transfer (WPT) offers a promising path to sustainable energy delivery; however, concurrent transmitters can experience destructive interference when operating asynchronously. Most existing studies focus on centralized or synchronized WPT systems, leaving the asynchronous regime largely unexplored. In contrast to 5G’s tightly coordinated and slowly varying links, 6G WPT must function under non-stationary mobility, higher carrier frequencies, and dense power transmitter deployments. To bridge this gap, we translate key 6G stressors into design laws and probability guarantees. Specifically, we present a new systematic framework for asynchronous concurrent WPT, featuring a unified kernel that captures frequency, timing, and phase dispersions as a single retention term across instantaneous, short-time, and long-time scales. Further, we provide closed-form ppm/time budgets for a target retention, a retention cumulative distribution function that tightens asO(N−2), and a Doppler time-to-null scheduler coupled to the harvester. Finally, we perform deterministic and Monte Carlo analyses, together with experimental studies. Ye Liu 0004, Mikael Gidlund, Honggang Wang 0001, Shucheng Yu |
IEEE J. Sel. Areas Commun. | 4 |
| 2025 | Uplink Secrecy in RIS-Aided MIMO-NOMA Networks with User-Centric Artificial NoiseabstractThis paper investigates the uplink secrecy performance of a reconfigurable intelligent surface (RIS)-aided multiple-input multiple-output non-orthogonal multiple access (MIMO-NOMA) network. In the proposed system model, users communicate with the base station (BS) via a strategically partitioned RIS. However, a silent passive eavesdropper overhears the data through a direct link. As part of the proposed security design, we propose a user-centric artificial noise (AN) transmission strategy that degrades the decoding ability of the eavesdropper without sacrificing the power budget. The AN is nullified in the composite channel utilizing singular value decomposition. After analyzing the channel statistics, which consider all channels experiencing Nakagami-$m$fading, we derive theoretical closed-form expressions for the ergodic secrecy rate (ESR) for each user in the NOMA pair using Gauss-Chebyshev quadrature and Taylor-Maclaurin expansions. Monte Carlo simulations validate the correctness of our analysis. The numerical results confirm that our proposed scheme consistently achieves a positive ESR. We also explore the impact of channel fading and RIS-partitioning ratio on the uplink ESR and comment on optimal power allocation. Notably, the results also confirm that the proposed system outperforms the benchmark MIMOorthogonal multiple access-based scheme. Moh. Khalid Hasan, Shucheng Yu, Min Song 0002 |
ICC | 2 |
| 2024 | Integrity Verifiable Privacy-preserving Federated Learning for Healthcare-IoTabstractIn Healthcare Internet of Things, federated learning has emerged as a promising distributed machine learning paradigm, enabling multiple clients to collaboratively train models with huge amounts of medical data while preserving the privacy of sensitive information. Despite its advantages, federated learning faces significant challenges in maintaining the integrity of the global model due to the potential for data and model poisoning attacks. These attacks are exacerbated by the lack of direct oversight in the local training processes, allowing malicious participants to manipulate model updates. This paper introduces Integrity Verifiable Federated Learning (IV-FED), a novel framework that leverages trusted execution environments (TEEs) to ensure the integrity of the training process without compromising privacy. IV-FED employs an accumulator-based integrity verification protocol, allowing the central server to verify the correctness of local training without reproducing the entire training process. Additionally, the framework incorporates an adversarial perturbation-based detection mechanism to prevent the injection of poisoned data by malicious participants. Shucheng Yu |
HealthCom | 2 |
| 2024 | GridSE: Towards Practical Secure Geographic Search via Prefix Symmetric Searchable Encryption
Ruoyang Guo, Shucheng Yu |
USENIX Security Symposium | 3 |
| 2023 | Over-the-Air Federated Learning with Enhanced PrivacyabstractFederated learning (FL) has emerged as a promising learning paradigm in which only local model parameters (gradients) are shared. Private user data never leaves the local devices thus preserving data privacy. However, recent research has shown that even when local data is never shared by a user, exchanging model parameters without protection can also leak private information. Moreover, in wireless systems, the frequent transmission of model parameters can cause tremendous bandwidth consumption and network congestion when the model is large. To address this problem, we propose a new FL framework with efficient over-the-air parameter aggregation and strong privacy protection of both user data and models. We achieve this by introducing pairwise cancellable random artificial noises (PCR-ANs) on end devices. As compared to existing over-the-air computation (AirComp) based FL schemes, our design provides stronger privacy protection. We analytically show the secrecy capacity and the convergence rate of the proposed wireless FL aggregation algorithm. Xiaochan Xue, Moh. Khalid Hasan, Shucheng Yu, Laxima Niure Kandel, Min Song 0002 |
ICC | 3 |
| 2023 | Secure Device Trust Bootstrapping Against Collaborative Signal Modification AttacksabstractBootstrapping security among wireless devices without prior-shared secrets is frequently demanded in emerging wireless and mobile applications. One promising approach for this problem is to utilize in-band physical-layer radio-frequency (RF) signals for authenticated key establishment because of the efficiency and high usability. However, existing in-band authenticated key agreement (AKA) protocols are mostly vulnerable to Man-in-the-Middle (MitM) attacks, which can be launched by modifying the transmitted wireless signals over the air. By annihilating legitimate signals and injecting malicious signals, signal modification attackers are able to completely control the communication channels and spoof victim wireless devices. State-of-the-art (SOTA) techniques addressing such attacks require additional auxiliary hardware or are limited to single attackers. This paper proposes a novel in-band security bootstrapping technique that can thwart colluding signal modification attackers. Different from SOTA solutions, our design is compatible with commodity devices without requiring additional hardware. We achieve this based on the internal randomness of each device that is unpredictable to attackers. Any modification to RF signals will be detected with high probabilities. Extensive security analysis and experimentation on the USRP platform demonstrate the effectiveness of our design under various attack strategies. Xiaochan Xue, Shucheng Yu, Min Song 0002 |
INFOCOM | 2 |
| 2023 | Uplink Secrecy Analysis for UAV-enabled PD-NOMA-based Underlay Spectrum Sharing NetworksabstractEffective sharing of spectrum resources is essential in forthcoming sixth-generation (6G) wireless networks to deploy massive Internet-of-Things (IoT) terminals. Unmanned aerial vehicles (UAVs) can significantly support IoT devices, especially in remote or disaster areas. Recently, power-domain non-orthogonal multiple access (PD-NOMA) utilized with underlay spectrum sharing has been proposed as a promising solution to enhance spectral efficiency. However, in a UAV-enabled multi-user spectrum sharing network, the risk of wiretapping in uplink signaling should be studied to ensure secured communications. This article investigates the uplink secrecy performance of a UAV-supported PD-NOMA-based underlay spectrum sharing (PDN-USS) network. The system is principally comprised of a secondary network with a pair of IoT terminals and a UAV receiver, where imperfect successive interference cancellation is carried out to decode data. Considering a transmission power constraint imposed at the secondary transmitters, we derive the closed-form expressions of the secrecy outage probability (SOP) for both IoT terminals. All the analytical expressions are obtained considering all the links undergo Nakagami-m fading. The simulation results validate the accuracy of the analysis and confirm that the PDN-USS system outperforms the benchmark OMA-based USS scheme in terms of the SOP. The results also provide valuable insights into the impact of the interference temperature and residual interference on the uplink SOP. Moh. Khalid Hasan, Shucheng Yu, Min Song 0002 |
WCNC | 2 |
| 2023 | SAFELearning: Secure Aggregation in Federated Learning With Backdoor DetectabilityabstractFor model privacy, local model parameters in federated learning shall be obfuscated before sent to the remote aggregator. This technique is referred to assecure aggregation. However, secure aggregation makes model poisoning attacks such as backdooring more convenient given that existing anomaly detection methods mostly require access to plaintext local models. This paper proposes a new federated learning technique SAFE-Learning to support backdoor detection for secure aggregation. We achieve this through two new primitives -oblivious random grouping (ORG)andpartial parameter disclosure (PPD). ORG partitions participants into one-time random subgroups with group configurations oblivious to participants; PPD allows secure partial disclosure of aggregated subgroup models for anomaly detection without leaking individual model privacy. ORG is based on our construction of several new primitives including tree-based random subgroup generation, oblivious secure aggregation, and randomized Diffie-Hellman key exchange. ORG can thwart colluding attackers from knowing each other’s group membership assignment with non-negligible advantage than random guess. Backdoor attacks are detected based on statistical distributions of the subgroup aggregated parameters of the learning iterations. SAFELearning can significantly reduce backdoor model accuracy without jeopardizing the main task accuracy under common backdoor strategies. Extensive experiments show SAFELearning is robust against malicious and faulty participants, whilst being more efficient than the state-of-art secure aggregation protocol in terms of both communication and computation costs. Zhuosheng Zhang 0003, Shucheng Yu, Christian Makaya |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Indirect Revocable KP-ABE With Revocation Undoing ResistanceabstractLately, many cloud-based applications proposed attribute-based encryption (ABE) as an all-in-one solution for achieving confidentiality and access control. Within this paradigm, data producers store the encrypted data on a semi-trusted cloud server, and users, holding decryption keys issued by a key authority, can decrypt data according to some access control policy. To be used in practical cases, any ABE scheme should implement a key revocation mechanism which assures that a compromised decryption key cannot be used anymore to decrypt data. Yuet al.(2010) introduced an ABE scheme with revocation capabilities that enjoys several unique advantages, such as reactivity and efficiency. In the scheme, the cloud server is entitled to update keys and ciphertexts in order to achieve revocation. Unfortunately, the cloud server retains the power to undo the revocation of a key (revocation undoing attack) so endangering confidentiality. In this article, we propose a revocable ABE scheme that still ensures the advantages of Yuet al.’s scheme, but it also resists to the revocation undoing attack. We formally prove the security of our scheme and show through simulations that the user experiences a slightly higher computational cost with respect to Yuet al.’s scheme. Marco Rasori, Pericle Perazzo, Gianluca Dini, Shucheng Yu |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | Efficient Parameter Aggregation in Federated Learning with Hybrid ConvergecastabstractIn federated learning, workers train local models with their private data sets and only upload local gradients to the remote aggregator. Data privacy is well preserved and parallelism is achieved. In large-scale deep learning tasks, however, frequent interactions between workers and the aggregator to transmit parameters can cause tremendous degradation of system performance in terms of communication costs, the needed number of iterations, the latency of each iteration and the accuracy of the trained model because of system “churns” (i.e., devices frequently joining and leaving the network). Existing research leverages different network topologies to improve the performance of federated learning. In this paper, we propose a novel hybrid network topology design that integrates ring (R) and n-ary tree (T) to provide flexible and adaptive convergecast in federated learning. Specifically, multiple participated peers within one-hop are formed as a local ring to adapt to device dynamics (i.e., “churns”) and carry out local cooperation shuffling; an n-ary convergecast tree is formed from local rings to the aggregator to assure the communication efficiency. Theoretical analysis shows the superiority of the proposed hybrid (R+T) convergecast design in terms of system latency as compared to existing topologies. Prototype-based simulation on CloudLab shows that the hybrid (R+T) design is able to reduce the rounds of iterations while achieving the best model accuracy under system “churns” as compared to the state of the art. Yangyang Tao, Junxiu Zhou, Shucheng Yu |
CCNC | 3 |
| 2021 | K-Group Random Channel Hopping (K-RCH) Rendezvous for Cognitive Radio NetworksabstractThe channel-hopping (CH) based rendezvous is an important technique in next-generation wireless cognitive radio networks (CRNs) where spectrum efficiency is desired. It allows unlicensed secondary users (SUs) to dynamically schedule rendezvous channels using their assigned CH sequence. Rendezvous is an essential operation for radios in CRNs to meet and establish a communication link, or find a common channel. Thus, radios can exchange information and communicate on a channel.In this paper, we propose a rendezvous protocol called K-Group Random Channel Hopping (K-RCH) which is based on the symmetric-role model. K-RCH assigns nodes into groups. Each group contains at least two nodes, which means our model is general and can fit both pairwise or multi-user rendezvous. K-RCH increases the chance of rendezvous by synchronizing channel hopping patterns of nodes in the same group and allowing for multi-round rendezvous. K-RCH considers a heterogeneous channel availability model and is suitable for complicated communication environments. Our simulation results show that K-RCH achieves a much shorter rendezvous time than most existing rendezvous protocols. The expected time to rendezvous (ETTR) is reduced by more than 85% as compared to the Jump-Stay strategy and the TENOR protocol. The ETTR decreases with an increasing number of SUs. Xiaochan Xue, Shucheng Yu, Min Song 0002, Chunsheng Xin |
ICC | 2 |
| 2021 | Low-Latency Privacy-Preserving Outsourcing of Deep Neural Network InferenceabstractEfficiently supporting inference tasks of deep neural network (DNN) on the resource-constrained Internet-of-Things (IoT) devices has been an outstanding challenge for emerging smart systems. To mitigate the burden on IoT devices, one prevalent solution is to outsource DNN inference tasks to the public cloud. However, this type of “cloud-backed” solutions can cause privacy breach since the outsourced data may contain sensitive information. For privacy protection, the research community has resorted to advanced cryptographic primitives to support DNN inference over encrypted data. Nevertheless, these attempts are limited by the real-time performance due to the heavy IoT computational overhead brought by cryptographic primitives. In this article, we proposed an edge computing-assisted framework to boost the efficiency of DNN inference tasks on IoT devices, which also protects the privacy of IoT data to be outsourced. In our framework, the most time-consuming DNN layers are outsourced to edge computing devices. The IoT device only processes compute-efficient layers and fast encryption/decryption. Thorough security analysis and numerical analysis are carried out to show the security and efficiency of the proposed framework. Our analysis results indicate a 99%+ outsourcing rate of DNN operations for IoT devices. Experiments on AlexNet show that our scheme can speed up DNN inference for 40.6× with a 96.2% energy saving for IoT devices. Yifan Tian, Laurent Njilla, Shucheng Yu |
IEEE Internet Things J. | 4 |
| 2020 | ELVMC: A Predictive Energy-Aware Algorithm for Virtual Machine Consolidation in Cloud Computing
Da-Ming Zhao, Jiantao Zhou 0002, Shucheng Yu |
ICA3PP (2) | 3 |
| 2019 | Flexibly and Securely Shape Your Data Disclosed to OthersabstractThis work is to enhance existing fine-grained access control to support a more expressive access policy over arithmetic operation results. We aim to enable data owners to flexibly bind a user's identity with his/her authorized access target according to a given access control policy, which indicates how a piece of data obfuscated by different noises. To this end, we design a cryptographic primitive that decouples the noisy data to two components, one associated with user identity, and the other one shared and dynamically changes, with the composite of these two components evaluated and revealed at user sides. The security of our scheme is formally proven using game based approach. We implement our system on a commercial cloud platform and use extensive experiments to validate its functionality and performance. Qing-Qing Xie, Yantian Hou, Ke Cheng 0001, Gaby G. Dagher, Liangmin Wang 0001, Shucheng Yu |
AsiaCCS | 6 |
| 2019 | Edge-Assisted Learning for Real-Time UAV Imagery via Predictive OffloadingabstractReal-time decision making with unmanned aerial vehicles (UAVs) imagery is desired in many applications. Deep learning (DL) is a promising enabler for such applications thanks to its recent advancements. However, direct execution of DL models on UAVs, especially small and micro ones, would not only introduce severe delay but also significantly shorten the flight time of UAVs due to the high energy consumption. Realtime transmission of UAV images to ground edge devices for deep analysis can mitigate the computational complexity but may introduce severe interference to ground devices, in addition unpredictable delays due to the dynamic network conditions. To minimize real-time image transmission, this paper designs a new offloading prediction algorithm which first estimates nearfuture need for DL of each UAV and transmit images only when necessary. Holistic resource allocation is made at the edge based on the offloading likelihood analysis of multiple UAVs as well as available resources. Experimental results on real UAV video clips show that our design can save 92% of the communication costs with less than 4% false positive rate. Zhuosheng Zhang 0003, Laurent Njilla, Shucheng Yu |
GLOBECOM | 3 |
| 2019 | Exploiting CSI-MIMO for Accurate and Efficient Device IdentificationabstractDue to the inherent broadcast nature of the wireless medium, Wireless Local Area Networks (WLANs) are targets of a variety of malicious attacks, for example, MAC identity spoofing, rogue AP attack, and network freeloading. These attacks invite security and privacy threats and hinder the worry-free deployment of WLAN networks. To thwart these attacks, existing research has proposed to use hardware-specific imperfections as a unique unforgeable fingerprint for the APs and/or clients. Unfortunately, existing solutions are limited to static and stable environments or use customized hardware preventing their wide-scale adoption. To overcome the limitations, in this work, we propose to use the distribution of relative phase differences between MIMO-radio transmitter oscillators as a distinguishing trait or fingerprint. More specifically, we show that the nonidealities of the multiple RF chains on a single MIMO-OFDM (Multiple Input Multiple Output-Orthogonal Frequency Division Multiplexing) transmitter can be extracted and utilized as a reliable device fingerprint. Each transmitter RF chain has a random initial phase offset, and their difference relative to one another is stable over time, differs uniquely for each transmitter device and cannot be altered by the adversary without significant effort and cost. Our functional prototype measures these unknown phase differences using PHY-layer Channel State Information (CSI) of the in-band channel obtained from off-the-shelf hardware. Our design eliminates expensive custom-built hardware, is invariant to environmental variations and supports device mobility making it practical and deployable in real indoor settings. Experimental evaluation using 17 Intel Network Interface Cards (NICs) resulted in 97 % and 92 % device identification accuracy for static and mobile device states respectively. Such promising results with identical model and manufacturer devices wherein underlying manufacturing variations are typically low showcase the effectiveness of our design and suggest even higher accuracy across multi-model and multi-manufacturer cards because of the higher manufacturing variations. Laxima Niure Kandel, Zhuosheng Zhang 0003, Shucheng Yu |
GLOBECOM | 3 |
| 2019 | Enabling Blockchain Applications Over Named Data NetworkingabstractBlockchain can be used to ensure trust in a decentralized environment in which no trusted authority is available. Its original idea is to collect transactions in a block, and to chain the blocks together in such a way that attackers cannot forge the chain if the majority of the network is honest. Since its creation in 2008, blockchain technology has been used broadly in Internet to support decentralized payments, cloud computing, publishing, etc. This work focuses on public permissionless blockchain which neither guards against bad actors nor enforces access control. Named data networking (NDN) uses name-based routing and in-networking caching to support efficient content delivery, making it a promising future Internet architecture as well as a great network technology which can improve blockchain data delivery. Therefore, it is a very necessary task to enable deployment of blockchain applications over NDN. However, NDN is not immediately compatible with typical blockchain, since (permissionless) blockchain applications usually require broadcasting transactions and blocks in real time, which is not supported by the “pull” design of NDN. In this work, we propose BoNDN which enables blockchain applications over NDN. Unlike previous work, BoNDN follows the core design of NDN. We treat each type of blockchain data needed to be broadcast individually. Specifically, we rely on Interest broadcasting to support real-time broadcasting of blockchain transactions, which is small in size and can be brought by an Interest packet. In addition, we propose a subscription-push approach to support broadcasting of blockchain blocks, in which each miner performs subscription, and once a block is generated, the subscribed miner will receive the block. Miao Wang 0007, Bo Chen 0028, Shucheng Yu, Hanwen Zhang 0001, Yujun Zhang 0001 |
ICC | 4 |
| 2019 | QoS-Aware Power Management with Deep Learning
Junxiu Zhou, Yangyang Tao, Shucheng Yu |
IM | 4 |
| 2019 | Edge-Assisted CNN Inference over Encrypted Data for Internet of Things
Yifan Tian, Shucheng Yu, Yantian Hou, Houbing Song |
SecureComm (1) | 3 |
| 2017 | Making Wireless Body Area Networks Robust Under Cross-Technology InterferenceabstractWireless body area networks (BANs) demand high-quality service. However, as BANs will be widely deployed in densely populated areas, they inevitably face RF cross-technology interference (CTI) from non-protocol-compliant wireless devices operating in the same spectrum range. The main challenges to defending against such a strong CTI come from the scarcity of spectrum resources, the uncertainty of the CTI sources and BAN channel status, and the stringent hardware constraints. In this paper, we first experimentally characterize the adverse effect on BAN reliability caused by the non-protocol-compliant CTI. Then, we formulate a joint routing and power control (JRPC) problem, which aims at minimizing energy consumption under strong CTI while satisfying node reachability and delay constraints. We reformulate our problem into a mixed integer linear programing problem and then derive the optimal results through IBM's CPLEX. A practical protocol, including a heuristic JRPC algorithm, is then proposed, in which we address the challenge of fast link-quality measurement by proposing a passive link-quality estimation and prediction method. Through experiments and simulations, we show that our protocol can assure the robustness of BAN even when the CTI sources are in very close vicinity, using a small amount of energy on commercial-off-the-shelf sensor devices. Yantian Hou, Ming Li 0003, Shucheng Yu |
IEEE Trans. Wirel. Commun. | 3 |
| 2016 | Protecting Your Right: Verifiable Attribute-Based Keyword Search with Fine-Grained Owner-Enforced Search Authorization in the CloudabstractSearch over encrypted data is a critically important enabling technique in cloud computing, where encryption-before-outsourcing is a fundamental solution to protecting user data privacy in the untrusted cloud server environment. Many secure search schemes have been focusing on the single-contributor scenario, where the outsourced dataset or the secure searchable index of the dataset are encrypted and managed by a single owner, typically based on symmetric cryptography. In this paper, we focus on a different yet more challenging scenario where the outsourced dataset can be contributed from multiple owners and are searchable by multiple users, i.e., multi-user multi-contributor case. Inspired by attribute-based encryption (ABE), we present the first attribute-based keyword search scheme with efficient user revocation (ABKS-UR) that enables scalable fine-grained (i.e., file-level) search authorization. Our scheme allows multiple owners to encrypt and outsource their data to the cloud server independently. Users can generate their own search capabilities without relying on an always online trusted authority. Fine-grained search authorization is also implemented by the owner-enforced access policy on the index of each file. Further, by incorporating proxy re-encryption and lazy re-encryption techniques, we are able to delegate heavy system update workload during user revocation to the resourceful semi-trusted cloud server. We formalize the security definition and prove the proposed ABKS-UR scheme selectively secure against chosen-keyword attack. To build confidence of data user in the proposed secure search system, we also design a search result verification scheme. Finally, performance evaluation shows the efficiency of our scheme. Wenhai Sun, Shucheng Yu, Wenjing Lou, Y. Thomas Hou 0001, Hui Li 0006 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2015 | SEISA: Secure and efficient encrypted image search with access controlabstractImage search has been widely deployed in many applications for the rich content that images contain. In the era of big data, image search engines have to be hosted in data centers. As a viable solution, outsourcing the image search to public clouds is an economic choice for many small organizations. However, as many images contain sensitive information, e.g., healthcare information and personal faces/locations, directly outsourcing image search services to public clouds obviously raises privacy concerns. With this observation, several attempts are made towards secure image search over encrypted dataset, but they are limited by either search accuracy or search efficiency. In this paper, we propose a lightweight secure image search scheme over encrypted data, namely SEISA. Compared with image search techniques over plaintexts, SEISA only increases about 9% search cost and sacrifices about 3% on search accuracy. SEISA also efficiently supports search access control by employing a novel polynomial based design, which enables data owners to define who can search a specific image. Furthermore, we design a secure k-means outsourcing algorithm that significantly saves the data owner's cost. To demonstrate SEISA's performance, we implement a prototype of SEISA on Amazon EC2 cloud over a dataset with 10 million images. Shucheng Yu, Linke Guo |
INFOCOM | 2 |
| 2015 | MASK-BAN: Movement-Aided Authenticated Secret Key Extraction Utilizing Channel Characteristics in Body Area NetworksabstractRecently, most wireless network security schemes merely based on physical layer characteristics tackle the two fundamental issues-device authentication and secret key extraction separately. It remains an open problem to simultaneously achieve device authentication and fast secret key extraction merely using wireless physical layer characteristics, without the help of advanced hardware or out-of-band channel. In this paper, we answer this open problem in the setting of wireless body area networks (BANs). We propose MASK-BAN, a lightweight fast authenticated secret key extraction scheme for intra-BAN communication. Our scheme neither introduces advanced hardware nor relies on out-of-band channels. To perform device authentication and fast secret key extraction at the same time, we exploit the heterogeneous channel characteristics among the collection of on-body channels during body motion. On one hand, MASK-BAN achieves authentication through multihop stable channels, which greatly reduces the false positive rate as compared to existing work. On the other hand, based on dynamic channels, key extraction between two on-body devices with multihop relay nodes is modeled as a max-flow problem, and a novel collaborative secret key generation algorithm is introduced to maximize the key generation rate. Extensive real-world experiments on low-end commercial-off-the-shelf sensor devices validate MASK-BAN's great authentication capability and high-secret key generation rate. Shucheng Yu, Ming Li 0003 |
IEEE Internet Things J. | 3 |
| 2015 | PCPOR: Public and constant-cost proofs of retrievability in cloudabstractAbstract For data storage outsourcing services, it is important to allow users to efficiently and securely verify that cloud storage servers store their data correctly. To address this issue, a number of Proof of Retrievability (POR) and Proof of Data Possession (PDP) schemes have been proposed wherein servers must prove to a verifier that data are stored correctly. While existing POR and PDP schemes offer decent solutions addressing various practical issues, they either have non-trivial (linear or quadratic) communication and computational complexity, or only consider private verification. In this paper, we propose the first POR scheme with public verifiability, constant communication and computational costs on users. In our scheme, messages exchanged between cloud servers and users are composed of a constant number of group elements and random numbers; computational tasks required on users are also constant; batch auditing of multiple tasks is also efficiently supported. We achieved these by a unique design based on our novel polynomial-based authenticators. Extensive experiments on Amazon EC2 cloud and different client devices (contemporary and mobile devices) show that our design allows a user to audit the integrity of a file of any size with a constant computational cost of 150 ms on PC (2.11 s on mobile device) and a communication cost of 2.34 kB for 99% error detection probability when employing an erasure coding with 1% fault tolerance rate. We prove the security of our scheme based on the Computational Diffie–Hellman problem, the t-Strong Diffie–Hellman problem and the Static Diffie–Hellman problem. Shucheng Yu |
J. Comput. Secur. | 2 |
| 2015 | Public Integrity Auditing for Dynamic Data Sharing With Multiuser ModificationabstractIn past years, the rapid development of cloud storage services makes it easier than ever for cloud users to share data with each other. To ensure users' confidence of the integrity of their shared data on cloud, a number of techniques have been proposed for data integrity auditing with focuses on various practical features, e.g., the support of dynamic data, public integrity auditing, low communication/computational audit cost, and low storage overhead. However, most of these techniques consider that only the original data owner can modify the shared data, which limits these techniques to client read-only applications. Recently, a few attempts started considering more realistic scenarios by allowing multiple cloud users to modify data with integrity assurance. Nevertheless, these attempts are still far from practical due to the tremendous computational cost on cloud users, especially when high error detection probability is required by the system. In this paper, we propose a novel integrity auditing scheme for cloud data sharing services characterized by multiuser modification, public auditing, high error detection probability, efficient user revocation as well as practical computational/communication auditing performance. Our scheme can resist user impersonation attack, which is not considered in existing techniques that support multiuser modification. Batch auditing of multiple tasks is also efficiently supported in our scheme. Extensive experiments on Amazon EC2 cloud and different client devices (contemporary and mobile devices) show that our design allows the client to audit the integrity of a shared file with a constant computational cost of 340 ms on PC (4.6 s on mobile device) and a bounded communication cost of 77 kB for 99% error detection probability with data corruption rate of 1%. Shucheng Yu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | Protecting your right: Attribute-based keyword search with fine-grained owner-enforced search authorization in the cloudabstractSearch over encrypted data is a critically important enabling technique in cloud computing, where encryption-before-outsourcing is a fundamental solution to protecting user data privacy in the untrusted cloud server environment. Many secure search schemes have been focusing on the single-contributor scenario, where the outsourced dataset or the secure searchable index of the dataset are encrypted and managed by a single owner, typically based on symmetric cryptography. In this paper, we focus on a different yet more challenging scenario where the outsourced dataset can be contributed from multiple owners and are searchable by multiple users, i.e. multi-user multi-contributor case. Inspired by attribute-based encryption (ABE), we present the first attribute-based keyword search scheme with efficient user revocation (ABKS-UR) that enables scalable fine-grained (i.e. file-level) search authorization. Our scheme allows multiple owners to encrypt and outsource their data to the cloud server independently. Users can generate their own search capabilities without relying on an always online trusted authority. Fine-grained search authorization is also implemented by the owner-enforced access policy on the index of each file. Further, by incorporating proxy re-encryption and lazy re-encryption techniques, we are able to delegate heavy system update workload during user revocation to the resourceful semi-trusted cloud server. We formalize the security definition and prove the proposed ABKS-UR scheme selectively secure against chosen-keyword attack. Finally, performance evaluation shows the efficiency of our scheme. Wenhai Sun, Shucheng Yu, Wenjing Lou, Y. Thomas Hou 0001, Hui Li 0006 |
INFOCOM | 2 |
| 2014 | Privacy-preserving multi-keyword fuzzy search over encrypted data in the cloudabstractEnabling keyword search directly over encrypted data is a desirable technique for effective utilization of encrypted data outsourced to the cloud. Existing solutions provide multi-keyword exact search that does not tolerate keyword spelling error, or single keyword fuzzy search that tolerates typos to certain extent. The current fuzzy search schemes rely on building an expanded index that covers possible keyword misspelling, which lead to significantly larger index file size and higher search complexity. In this paper, we propose a novel multi-keyword fuzzy search scheme by exploiting the locality-sensitive hashing technique. Our proposed scheme achieves fuzzy matching through algorithmic design rather than expanding the index file. It also eliminates the need of a predefined dictionary and effectively supports multiple keyword fuzzy search without increasing the index or search complexity. Extensive analysis and experiments on real-world data show that our proposed scheme is secure, efficient and accurate. To the best of our knowledge, this is the first work that achieves multi-keyword fuzzy search over encrypted cloud data. Bing Wang 0005, Shucheng Yu, Wenjing Lou, Y. Thomas Hou 0001 |
INFOCOM | 2 |
| 2014 | Efficient public integrity checking for cloud data sharing with multi-user modificationabstractIn past years a body of data integrity checking techniques have been proposed for securing cloud data services. Most of these works assume that only the data owner can modify cloud-stored data. Recently a few attempts started considering more realistic scenarios by allowing multiple cloud users to modify data with integrity assurance. However, these attempts are still far from practical due to the tremendous computational cost on cloud users. Moreover, collusion between misbehaving cloud servers and revoked users is not considered. This paper proposes a novel data integrity checking scheme characterized by multi-user modification, collusion resistance and a constant computational cost of integrity checking for cloud users, thanks to our novel design of polynomial-based authentication tags and proxy tag update techniques. Our scheme also supports public checking and efficient user revocation and is provably secure. Numerical analysis and extensive experimental results show the efficiency and scalability of our proposed scheme. Shucheng Yu |
INFOCOM | 2 |
| 2014 | Privacy Preserving Back-Propagation Neural Network Learning Made Practical with Cloud ComputingabstractTo improve the accuracy of learning result, in practice multiple parties may collaborate through conducting joint Back-Propagation neural network learning on the union of their respective data sets. During this process no party wants to disclose her/his private data to others. Existing schemes supporting this kind of collaborative learning are either limited in the way of data partition or just consider two parties. There lacks a solution that allows two or more parties, each with an arbitrarily partitioned data set, to collaboratively conduct the learning. This paper solves this open problem by utilizing the power of cloud computing. In our proposed scheme, each party encrypts his/her private data locally and uploads the ciphertexts into the cloud. The cloud then executes most of the operations pertaining to the learning algorithms over ciphertexts without knowing the original private data. By securely offloading the expensive operations to the cloud, we keep the computation and communication costs on each party minimal and independent to the number of participants. To support flexible operations over ciphertexts, we adopt and tailor the BGN "doubly homomorphic" encryption algorithm for the multiparty setting. Numerical analysis and experiments on commodity cloud show that our scheme is secure, efficient, and accurate. Shucheng Yu |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | SybilShield: An agent-aided social network-based Sybil defense among multiple communitiesabstractLacking trusted central authority, distributed systems have received serious security threats from Sybil attack, where an adversary forges identities of more than one node and attempts to control the system. By utilizing the real-world trust relationships between users, social network-based defense schemes have been proposed to mitigate the impact of Sybil attacks. These solutions are mostly built on the assumption that the social network graph can be partitioned into two loosely linked regions - a tightly connected non-Sybil region and a Sybil region. Although such an assumption may hold in certain settings, studies have shown that the real-world social connections tend to divide users into multiple inter-connected small worlds instead of a single uniformly connected large region. Given this fact, the applicability of existing schemes would be greatly undermined for inability to distinguish Sybil users from valid ones in the small non-Sybil regions. This paper addresses this problem and presents SybilShield, the first protocol that defends against Sybil attack utilizing multi-community social network structure in real world. Our scheme leverages the sociological property that the number of cutting edges between a non-Sybil community and a Sybil community, which represent human-established trust relationships, is much smaller than that among non-Sybil communities. With the help of agent nodes, SybilShield greatly reduces false positive rate of non-Sybils among multiple communities, while effectively identifying Sybil nodes. Analytical results prove the superiority of SybilShield. Our experiments on a real-world social network graph with 100,000 nodes also validate the effectiveness of SybilShield. Shucheng Yu, Wenjing Lou, Y. Thomas Hou 0001 |
INFOCOM | 2 |
| 2013 | Efficient privacy-preserving biometric identification in cloud computingabstractBiometric identification is a reliable and convenient way of identifying individuals. The widespread adoption of biometric identification requires solid privacy protection against possible misuse, loss, or theft of biometric data. Existing techniques for privacy-preserving biometric identification primarily rely on conventional cryptographic primitives such as homomorphic encryption and oblivious transfer, which inevitably introduce tremendous cost to the system and are not applicable to practical large-scale applications. In this paper, we propose a novel privacy-preserving biometric identification scheme which achieves efficiency by exploiting the power of cloud computing. In our proposed scheme, the biometric database is encrypted and outsourced to the cloud servers. To perform a biometric identification, the database owner generates a credential for the candidate biometric trait and submits it to the cloud. The cloud servers perform identification over the encrypted database using the credential and return the result to the owner. During the identification, cloud learns nothing about the original private biometric data. Because the identification operations are securely outsourced to the cloud, the realtime computational/communication costs at the owner side are minimal. Thorough analysis shows that our proposed scheme is secure and offers a higher level of privacy protection than related solutions such as kNN search in encrypted databases. Real experiments on Amazon cloud, over databases of different sizes, show that our computational/communication costs at the owner side are several magnitudes lower than the existing biometric identification schemes. Shucheng Yu |
INFOCOM | 2 |
| 2013 | Surviving the RF smog: Making Body Area Networks robust to cross-technology interferenceabstractWireless Body Area Networks (BANs) demand for highly robust communication due to the criticality and time-sensitivity of the medical monitoring data. However, as BANs will be widely deployed in densely populated areas, they inevitably face the RF cross-technology interference (CTI) from non-protocol-compliant wireless devices operating in the same spectrum range, which are persistent, high power, and broadband in nature. The main challenges to defend such strong CTI come from the scarcity of spectrum resources, the uncertainty of the CTI sources and BAN channel status, and the stringent hardware constraints. Existing methods fail because of their need for extra spectrum resources or advanced hardware. In this paper, we first experimentally characterize the adverse effect on BAN reliability caused by the non-protocol-compliant CTI. Then we propose a CTI-aware joint routing and power control (JRPC) approach to ensure desired reliability goals using minimum energy resources even under strong co-channel CTI. To cope with channel uncertainty, we propose a passive link quality estimation method which exploits prediction. Through extensive experiments and simulations, we show that our proposed protocol can assure the robustness of BAN even when the CTI sources are in very close vicinity, using little overall energy and spectrum resources, and can be easily implemented on commercial-off-the-shelf (COTS) devices. Yantian Hou, Ming Li 0003, Shucheng Yu |
SECON | 3 |
| 2013 | ASK-BAN: authenticated secret key extraction utilizing channel characteristics for body area networksabstractRecently there has been an increasing interest on bootstrapping security for wireless networks merely using physical layer characteristics. In particular, the focus has been on two fundamental security issues - device authentication and secret key extraction. While most existing works emphasize on tackling the two issues separately, it remains an open problem to simultaneously achieve device authentication and fast secret key extraction merely using wireless physical layer characteristics, without the help of advanced hardware or out-of-band channel. Shucheng Yu, Ming Li 0003 |
WISEC | 3 |
| 2013 | BANA: Body Area Network Authentication Exploiting Channel CharacteristicsabstractIn wireless body area network (BAN), node authentication is essential for trustworthy and reliable gathering of patient's critical health information. Traditional authentication solutions depend on prior trust among nodes whose establishment would require either key pre-distribution or non-intuitive participation by inexperienced users. Most existing non-cryptographic authentication schemes require advanced hardware or significant modifications to the system software, which are impractical for BANs. In this paper, for the first time, we propose a lightweight body area network authentication scheme BANA. Different from previous work, BANA does not depend on prior-trust among nodes and can be efficiently realized on commercial off-the-shelf low-end sensors. We achieve this by exploiting a unique physical layer characteristic naturally arising from the multi-path environment surrounding a BAN, i.e., the distinct received signal strength (RSS) variation behaviors among on-body channels and between on-body and off-body communication channels. Based on distinct RSS variations, BANA adopts clustering analysis to differentiate the signals from an attacker and a legitimate node. We also make use of multi-hop on-body channel characteristics to enhance the robustness of our authentication mechanism. The effectiveness of BANA is validated through extensive real-world experiments under various scenarios. It is shown that BANA can accurately identify multiple attackers with minimal amount of overhead. Ming Li 0003, Shucheng Yu |
IEEE J. Sel. Areas Commun. | 3 |
| 2013 | Secure ad hoc trust initialization and key management in wireless body area networksabstractThe body area network (BAN) is a key enabling technology in e-healthcare. An important security issue is to establish initial trust relationships among the BAN devices before they are actually deployed and generate necessary shared secret keys to protect the subsequent wireless communications. Due to the ad hoc nature of the BAN and the extreme resource constraints of sensor devices, providing secure as well as efficient and user-friendly trust initialization is a challenging task. Traditional solutions for wireless sensor networks mostly depend on key predistribution, which is unsuitable for a BAN in many ways. In this article, we propose group device pairing (GDP), a user-aided multi-party authenticated key agreement protocol. Through GDP, a group of sensor devices that have no pre-shared secrets establish initial trust by generating various shared secret keys out of an unauthenticated channel. Devices authenticate themselves to each other with the aid of a human user who performs visual verifications. The GDP supports fast batch deployment, addition and revocation of sensor devices, does not rely on any additional hardware device, and is mostly based on symmetric key cryptography. We formally prove the security of the proposed protocols, and we implement GDP on a sensor network testbed and report performance evaluation results. Ming Li 0003, Shucheng Yu, Joshua D. Guttman, Wenjing Lou, Kui Ren 0001 |
ACM Trans. Sens. Networks | 2 |
| 2013 | Scalable and Secure Sharing of Personal Health Records in Cloud Computing Using Attribute-Based EncryptionabstractPersonal health record (PHR) is an emerging patient-centric model of health information exchange, which is often outsourced to be stored at a third party, such as cloud providers. However, there have been wide privacy concerns as personal health information could be exposed to those third party servers and to unauthorized parties. To assure the patients' control over access to their own PHRs, it is a promising method to encrypt the PHRs before outsourcing. Yet, issues such as risks of privacy exposure, scalability in key management, flexible access, and efficient user revocation, have remained the most important challenges toward achieving fine-grained, cryptographically enforced data access control. In this paper, we propose a novel patient-centric framework and a suite of mechanisms for data access control to PHRs stored in semitrusted servers. To achieve fine-grained and scalable data access control for PHRs, we leverage attribute-based encryption (ABE) techniques to encrypt each patient's PHR file. Different from previous works in secure data outsourcing, we focus on the multiple data owner scenario, and divide the users in the PHR system into multiple security domains that greatly reduces the key management complexity for owners and users. A high degree of patient privacy is guaranteed simultaneously by exploiting multiauthority ABE. Our scheme also enables dynamic modification of access policies or file attributes, supports efficient on-demand user/attribute revocation and break-glass access under emergency scenarios. Extensive analytical and experimental results are presented which show the security, scalability, and efficiency of our proposed scheme. Ming Li 0003, Shucheng Yu, Yao Zheng 0004, Kui Ren 0001, Wenjing Lou |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | Privacy-Preserving Distributed Profile Matching in Proximity-Based Mobile Social NetworksabstractMaking new connections according to personal preferences is a crucial service in mobile social networking, where an initiating user can find matching users within physical proximity of him/her. In existing systems for such services, usually all the users directly publish their complete profiles for others to search. However, in many applications, the users' personal profiles may contain sensitive information that they do not want to make public. In this paper, we propose FindU, a set of privacy-preserving profile matching schemes for proximity-based mobile social networks. In FindU, an initiating user can find from a group of users the one whose profile best matches with his/her; to limit the risk of privacy exposure, only necessary and minimal information about the private attributes of the participating users is exchanged. Two increasing levels of user privacy are defined, with decreasing amounts of revealed profile information. Leveraging secure multi-party computation (SMC) techniques, we propose novel protocols that realize each of the user privacy levels, which can also be personalized by the users. We provide formal security proofs and performance evaluation on our schemes, and show their advantages in both security and efficiency over state-of-the-art schemes. Ming Li 0003, Shucheng Yu, Ning Cao 0001, Wenjing Lou |
IEEE Trans. Wirel. Commun. | 2 |
| 2012 | Authenticated secret key extraction using channel characteristics for body area networksabstractSimultaneously realizing device authentication and fast secret key extraction is a challenging issue in wireless networks. Most existing works solve this problem by utilizing either advanced hardware or out-of-band channel, which is not always available for commercial-off-the-shelf wireless devices. In this work, we solve this challenging issue under the setting of Wireless Body Area Network (BAN) and propose a lightweight authenticated secret key extraction scheme, namely ASK-BAN. The proposed scheme is just based on wireless channel measurement and does not introduce any advanced hardware or rely on any out-of-band channel. Experimental results show that our proposed scheme can offer a high secret key extraction rate while providing effective device authentication simultaneously. Shucheng Yu, Ming Li 0003 |
CCS | 3 |
| 2012 | LT codes-based secure and reliable cloud storage serviceabstractWith the increasing adoption of cloud computing for data storage, assuring data service reliability, in terms of data correctness and availability, has been outstanding. While redundancy can be added into the data for reliability, the problem becomes challenging in the “pay-as-you-use” cloud paradigm where we always want to efficiently resolve it for both corruption detection and data repair. Prior distributed storage systems based on erasure codes or network coding techniques have either high decoding computational cost for data users, or too much burden of data repair and being online for data owners. In this paper, we design a secure cloud storage service which addresses the reliability issue with near-optimal overall performance. By allowing a third party to perform the public integrity verification, data owners are significantly released from the onerous work of periodically checking data integrity. To completely free the data owner from the burden of being online after data outsourcing, this paper proposes an exact repair solution so that no metadata needs to be generated on the fly for repaired data. The performance analysis and experimental results show that our designed service has comparable storage and communication cost, but much less computational cost during data retrieval than erasure codes-based storage solutions. It introduces less storage cost, much faster data retrieval, and comparable communication cost comparing to network coding-based distributed storage systems. Ning Cao 0001, Shucheng Yu, Zhenyu Yang 0007, Wenjing Lou, Y. Thomas Hou 0001 |
INFOCOM | 2 |
| 2012 | Achieving usable and privacy-assured similarity search over outsourced cloud dataabstractAs the data produced by individuals and enterprises that need to be stored and utilized are rapidly increasing, data owners are motivated to outsource their local complex data management systems into the cloud for its great flexibility and economic savings. However, as sensitive cloud data may have to be encrypted before outsourcing, which obsoletes the traditional data utilization service based on plaintext keyword search, how to enable privacy-assured utilization mechanisms for outsourced cloud data is thus of paramount importance. Considering the large number of on-demand data users and huge amount of outsourced data files in cloud, the problem is particularly challenging, as it is extremely difficult to meet also the practical requirements of performance, system usability, and high-level user searching experiences. In this paper, we investigate the problem of secure and efficient similarity search over outsourced cloud data. Similarity search is a fundamental and powerful tool widely used in plaintext information retrieval, but has not been quite explored in the encrypted data domain. Our mechanism design first exploits a suppressing technique to build storage-efficient similarity keyword set from a given document collection, with edit distance as the similarity metric. Based on that, we then build a private trie-traverse searching index, and show it correctly achieves the defined similarity search functionality with constant search time complexity. We formally prove the privacy-preserving guarantee of the proposed mechanism under rigorous security treatment. To demonstrate the generality of our mechanism and further enrich the application spectrum, we also show our new construction naturally supports fuzzy search, a previously studied notion aiming only to tolerate typos and representation inconsistencies in the user searching input. The extensive experiments on Amazon cloud platform with real data set further demonstrate the validity and practicality of the proposed mechanism. Cong Wang 0001, Kui Ren 0001, Shucheng Yu, Karthik Mahendra Raje Urs |
INFOCOM | 3 |
| 2012 | Privacy Preserving Back-Propagation Learning Made Practical with Cloud Computing
Shucheng Yu |
SecureComm | 2 |
| 2012 | BANA: body area network authentication exploiting channel characteristicsabstractWireless body area network (BAN) is a promising technology for real-time monitoring of physiological signals to support medical applications. In order to ensure the trustworthy and reliable gathering of patient's critical health information, it is essential to provide node authentication service in a BAN, which prevents an attacker from impersonation and false data/command injection. Although quite fundamental, the authentication in BAN still remains a challenging issue. On one hand, traditional authentication solutions depend on prior trust among nodes whose establishment would require either key pre-distribution or non-intuitive participation by inexperienced users, while they are vulnerable to key compromise. On the other hand, most existing non-cryptographic authentication schemes require advanced hardware capabilities or significant modifications to the system software, which are impractical for BANs. Ming Li 0003, Shucheng Yu |
WISEC | 3 |
| 2011 | Authorized Private Keyword Search over Encrypted Data in Cloud ComputingabstractIn cloud computing, clients usually outsource their data to the cloud storage servers to reduce the management costs. While those data may contain sensitive personal information, the cloud servers cannot be fully trusted in protecting them. Encryption is a promising way to protect the confidentiality of the outsourced data, but it also introduces much difficulty to performing effective searches over encrypted information. Most existing works do not support efficient searches with complex query conditions, and care needs to be taken when using them because of the potential privacy leakages about the data owners to the data users or the cloud server. In this paper, using on line Personal Health Record (PHR) as a case study, we first show the necessity of search capability authorization that reduces the privacy exposure resulting from the search results, and establish a scalable framework for Authorized Private Keyword Search (APKS) over encrypted cloud data. We then propose two novel solutions for APKS based on a recent cryptographic primitive, Hierarchical Predicate Encryption (HPE). Our solutions enable efficient multi-dimensional keyword searches with range query, allow delegation and revocation of search capabilities. Moreover, we enhance the query privacy which hides users' query keywords against the server. We implement our scheme on a modern workstation, and experimental results demonstrate its suitability for practical usage. Ming Li 0003, Shucheng Yu, Ning Cao 0001, Wenjing Lou |
ICDCS | 2 |
| 2011 | FindU: Privacy-preserving personal profile matching in mobile social networksabstractMaking new connections according to personal preferences is a crucial service in mobile social networking, where the initiating user can find matching users within physical proximity of him/her. In existing systems for such services, usually all the users directly publish their complete profiles for others to search. However, in many applications, the users' personal profiles may contain sensitive information that they do not want to make public. In this paper, we propose FindU, the first privacy-preserving personal profile matching schemes for mobile social networks. In FindU, an initiating user can find from a group of users the one whose profile best matches with his/her; to limit the risk of privacy exposure, only necessary and minimal information about the private attributes of the participating users is exchanged. Several increasing levels of user privacy are defined, with decreasing amounts of exchanged profile information. Leveraging secure multi-party computation (SMC) techniques, we propose novel protocols that realize two of the user privacy levels, which can also be personalized by the users. We provide thorough security analysis and performance evaluation on our schemes, and show their advantages in both security and efficiency over state-of-the-art schemes. Ming Li 0003, Ning Cao 0001, Shucheng Yu, Wenjing Lou |
INFOCOM | 3 |
| 2011 | Dependable and Secure Sensor Data Storage with Dynamic Integrity AssuranceabstractRecently, distributed data storage has gained increasing popularity for efficient and robust data management in wireless sensor networks (WSNs). The distributed architecture makes it challenging to build a highly secure and dependable yet lightweight data storage system. On the one hand, sensor data are subject to not only Byzantine failures, but also dynamic pollution attacks, as along the time the adversary may modify/pollute the stored data by compromising individual sensors. On the other hand, the resource-constrained nature of WSNs precludes the applicability of heavyweight security designs. To address the challenge, in this article we propose a novel dependable and secure data storage scheme with dynamic integrity assurance. Based on the principle of secret sharing and erasure coding, we first propose a hybrid share generation and distribution scheme to achieve reliable and fault-tolerant initial data storage by providing redundancy for original data components. To further dynamically ensure the integrity of the distributed data shares, we then propose an efficient data integrity verification scheme exploiting the techniques of algebraic signature and spot-checking. The proposed scheme enables individual sensors to verify in one protocol execution the correctness of all the pertaining data shares simultaneously in the absence of the original data. Extensive security analysis shows that the proposed scheme has strong resistance against various data pollution attacks. The efficiency of the scheme is demonstrated by experiments on sensor platforms Tmote Sky and iMote2. Qian Wang 0002, Kui Ren 0001, Shucheng Yu, Wenjing Lou |
ACM Trans. Sens. Networks | 3 |
| 2011 | FDAC: Toward Fine-Grained Distributed Data Access Control in Wireless Sensor NetworksabstractDistributed sensor data storage and retrieval have gained increasing popularity in recent years for supporting various applications. While distributed architecture enjoys a more robust and fault-tolerant wireless sensor network (WSN), such architecture also poses a number of security challenges especially when applied in mission-critical applications such as battlefield and e-healthcare. First, as sensor data are stored and maintained by individual sensors and unattended sensors are easily subject to strong attacks such as physical compromise, it is significantly harder to ensure data security. Second, in many mission-critical applications, fine-grained data access control is a must as illegal access to the sensitive data may cause disastrous results and/or be prohibited by the law. Last but not least, sensor nodes usually are resource-constrained, which limits the direct adoption of expensive cryptographic primitives. To address the above challenges, we propose, in this paper, a distributed data access control scheme that is able to enforce fine-grained access control over sensor data and is resilient against strong attacks such as sensor compromise and user colluding. The proposed scheme exploits a novel cryptographic primitive called attribute-based encryption (ABE), tailors, and adapts it for WSNs with respect to both performance and security requirements. The feasibility of the scheme is demonstrated by experiments on real sensor platforms. To our best knowledge, this paper is the first to realize distributed fine-grained data access control for WSNs. Shucheng Yu, Kui Ren 0001, Wenjing Lou |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2010 | Attribute based data sharing with attribute revocationabstractCiphertext-Policy Attribute Based Encryption (CP-ABE) is a promising cryptographic primitive for fine-grained access control of shared data. In CP-ABE, each user is associated with a set of attributes and data are encrypted with access structures on attributes. A user is able to decrypt a ciphertext if and only if his attributes satisfy the ciphertext access structure. Beside this basic property, practical applications usually have other requirements. In this paper we focus on an important issue of attribute revocation which is cumbersome for CP-ABE schemes. In particular, we resolve this challenging issue by considering more practical scenarios in which semi-trustable on-line proxy servers are available. As compared to existing schemes, our proposed solution enables the authority to revoke user attributes with minimal effort. We achieve this by uniquely integrating the technique of proxy re-encryption with CP-ABE, and enable the authority to delegate most of laborious tasks to proxy servers. Formal analysis shows that our proposed scheme is provably secure against chosen ciphertext attacks. In addition, we show that our technique can also be applicable to the Key-Policy Attribute Based Encryption (KP-ABE) counterpart. Shucheng Yu, Cong Wang 0001, Kui Ren 0001, Wenjing Lou |
AsiaCCS | 1 |
| 2010 | Group Device Pairing based Secure Sensor Association and Key Management for Body Area NetworksabstractBody Area Networks (BAN) is a key enabling technology in E-healthcare such as remote health monitoring. An important security issue during bootstrap phase of the BAN is to securely associate a group of sensor nodes to a patient, and generate necessary secret keys to protect the subsequent wireless communications. Due to the the ad hoc nature of the BAN and the extreme resource constraints of sensor devices, providing secure, fast, efficient and user-friendly secure sensor association is a challenging task. In this paper, we propose a lightweight scheme for secure sensor association and key management in BAN. A group of sensor nodes, having no prior shared secrets before they meet, establish initial trust through group device pairing (GDP), which is an authenticated group key agreement protocol where the legitimacy of each member node can be visually verified by a human. Various kinds of secret keys can be generated on demand after deployment. The GDP supports batch deployment of sensor nodes to save setup time, does not rely on any additional hardware devices, and is mostly based on symmetric key cryptography, while allowing batch node addition and revocation. We implemented GDP on a sensor network testbed and evaluated its performance. Experimental results show that that GDP indeed achieves the expected design goals. Ming Li 0003, Shucheng Yu, Wenjing Lou, Kui Ren 0001 |
INFOCOM | 2 |
| 2010 | Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud ComputingabstractCloud computing is an emerging computing paradigm in which resources of the computing infrastructure are provided as services over the Internet. As promising as it is, this paradigm also brings forth many new challenges for data security and access control when users outsource sensitive data for sharing on cloud servers, which are not within the same trusted domain as data owners. To keep sensitive user data confidential against untrusted servers, existing solutions usually apply cryptographic methods by disclosing data decryption keys only to authorized users. However, in doing so, these solutions inevitably introduce a heavy computation overhead on the data owner for key distribution and data management when fine-grained data access control is desired, and thus do not scale well. The problem of simultaneously achieving fine-grainedness, scalability, and data confidentiality of access control actually still remains unresolved. This paper addresses this challenging open issue by, on one hand, defining and enforcing access policies based on data attributes, and, on the other hand, allowing the data owner to delegate most of the computation tasks involved in fine-grained data access control to untrusted cloud servers without disclosing the underlying data contents. We achieve this goal by exploiting and uniquely combining techniques of attribute-based encryption (ABE), proxy re-encryption, and lazy re-encryption. Our proposed scheme also has salient properties of user access privilege confidentiality and user secret key accountability. Extensive analysis shows that our proposed scheme is highly efficient and provably secure under existing security models. Shucheng Yu, Cong Wang 0001, Kui Ren 0001, Wenjing Lou |
INFOCOM | 1 |
| 2010 | Securing Personal Health Records in Cloud Computing: Patient-Centric and Fine-Grained Data Access Control in Multi-owner Settings
Ming Li 0003, Shucheng Yu, Kui Ren 0001, Wenjing Lou |
SecureComm | 2 |
| 2010 | Attribute-based on-demand multicast group setup with membership anonymity
Shucheng Yu, Kui Ren 0001, Wenjing Lou |
Comput. Networks | 1 |
| 2010 | PEACE: A Novel Privacy-Enhanced Yet Accountable Security Framework for Metropolitan Wireless Mesh NetworksabstractRecently, multihop wireless mesh networks (WMNs) have attracted increasing attention and deployment as a low-cost approach to provide broadband Internet access at metropolitan scale. Security and privacy issues are of most concern in pushing the success of WMNs for their wide deployment and for supporting service-oriented applications. Despite the necessity, limited security research has been conducted toward privacy preservation in WMNs. This motivates us to develop PEACE, a novel Privacy-Enhanced yet Accountable seCurity framEwork, tailored for WMNs. On one hand, PEACE enforces strict user access control to cope with both free riders and malicious users. On the other hand, PEACE offers sophisticated user privacy protection against both adversaries and various other network entities. PEACE is presented as a suite of authentication and key agreement protocols built upon our proposed short group signature variation. Our analysis shows that PEACE is resilient to a number of security and privacy related attacks. Additional techniques were also discussed to further enhance scheme efficiency. Kui Ren 0001, Shucheng Yu, Wenjing Lou |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2009 | FDAC: Toward Fine-Grained Distributed Data Access Control in Wireless Sensor NetworksabstractDistributed sensor data storage and retrieval has gained increasing popularity in recent years for supporting various applications. While distributed architecture enjoys a more robust and fault-tolerant wireless sensor network (WSN), such architecture also poses a number of security challenges especially when applied in mission-critical applications such as battle field and e-healthcare. First, as sensor data are stored and maintained by individual sensors and unattended sensors are easily subject to strong attacks such as physical compromise, it is significantly harder to ensure data security. Second, in many mission-critical applications, fine-grained data access control is a must as illegal access to the sensitive data may cause disastrous result and/or prohibited by the law. Last but not least, sensors usually are resource-scarce, which limits the direct adoption of expensive cryptographic primitives. To address the above challenges, we propose in this paper a distributed data access control scheme that is able to fulfill fine-grained access control over sensor data and is resilient against strong attacks such as sensor compromise and user colluding. The proposed scheme exploits a novel cryptographic primitive called attribute-based encryption (ABE), tailors, and adapts it for WSNs with respect to both performance and security requirements. The feasibility of the scheme is demonstrated by experiments on real sensor platforms. To our best knowledge, this paper is the first to realize distributed fine-grained data access control for WSNs. Shucheng Yu, Kui Ren 0001, Wenjing Lou |
INFOCOM | 1 |
| 2009 | Defending against Key Abuse Attacks in KP-ABE Enabled Broadcast Systems
Shucheng Yu, Kui Ren 0001, Wenjing Lou, Jin Li 0002 |
SecureComm | 1 |
| 2008 | Towards Secure Link Quality Measurement in Multihop Wireless NetworksabstractLink quality measurement (LQM), i.e. packet reception ratio (PRR) measurement, is becoming an indispensable component in multihop wireless networks. However, in all the existing LQM mechanisms, a common fact is that a node's knowledge about the forward PRR from itself to its neighbor is informed by the neighbor. On the one hand, this receiver- dependent measurement provides accurate and timely updates on the link quality. On the other hand, it opens up a door for a malicious node to easily report a false measurement result to mislead the routing decision and degrade the system performance. In this paper, we analyze the security vulnerabilities in the existing LQM mechanisms and propose an efficient broadcast- based secure LQM (SLQM) mechanism, which prevents the malicious receiver from reporting a higher PRR than the actual one. We analyze the security strength and the cost of the proposed mechanism. Simulation results show that even when there are only 10% malicious nodes in the network, the average end-to-end throughput can be degraded by 50% compared with the normally operated network, which demonstrates the importance of employing SLQM mechanisms. To the best of our knowledge, this is the first work addressing the SLQM problem in multihop wireless networks. Kai Zeng 0001, Shucheng Yu, Kui Ren 0001, Wenjing Lou |
GLOBECOM | 2 |
| 2008 | Attribute-based on-demand multicast group setup with membership anonymityabstractIn many applications, it is desired to dynamically establish temporary multicast groups for secure message delivery. It is also often the case that the group membership information itself is sensitive and needs to be well protected. However, existing solutions either fail to address the issue of membership anonymity or do not scale well for dynamically established groups. In this paper, we propose a highly scalable solution for dynamical multicast group setup and yet protecting group membership anonymity simultaneously. In the proposed solution, scalability and membership anonymity are achieved via a novel design that integrates both ciphertextpolicy attribute-based encryption (CP-ABE) and centralized flat table (CFT) techniques. In our design, multicast groups are specified through group member attributes represented through binary member ID only and thus achieves scalability. Also, high level of membership anonymity is guaranteed such that every group member knows nothing but his own group membership only. The proposed solution is also efficient in communication, that is, the ciphertext size is only O(n), where n is the length of a group member ID and independent to the group size. Shucheng Yu, Kui Ren 0001, Wenjing Lou |
SecureComm | 1 |