Hong-Yen Tran

dblp:251/7444 · DBLP profile ↗
← Back
8ranked-venue papers
6as first author
7since 2021 · last 2024
0000-0003-3308-3378ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-author · 5 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2024 On Sealed-Bid Combinatorial Auction with Privacy-Preserving Dynamic Programming
Hong-Yen Tran, Jiankun Hu, Shabnam Kasra Kermanshahi
ProvSec (2)1
2024 Securely sharing outsourced IoT data: A secure access and privacy preserving keyword search scheme
abstract
The rapid progress in the field of IoT and its wide-ranging applications emphasize the criticality of robust security measures for effectively sharing, storing, and managing sensitive data generated by IoT devices. Regulations such as the Consumer Data Rights (CDR) highlight the need for the seamless sharing of sensitive data with authorized third parties while ensuring confidentiality and privacy. To enable such secure sharing, a data storage and sharing scheme should fulfill the following core requirements: (a) support multi-client data sharing settings, allowing IoT data owners to authorize multiple clients; (b) a dynamic storage environment permitting IoT owners to add or remove files with minimal privacy leak; (c) decentralized storage for distributing data across servers or Cloud Service Providers (CSPs) for greater security; and (d) efficient privilege revocation mechanism which incurs less computation and communication overhead. To address these requirements, we have proposed a novel keyword search scheme using computationally lightweight cryptographic primitives. Our scheme empowers IoT data owners to securely share, store and manage encrypted data in the CSPs, providing better security and privacy. We have provided formal security proof for our scheme as well as validated its efficiency via extensive experiments on the Docker platform. On a database of 12 million keyword/document pairs (with 105 documents and 103 keywords), our scheme took about 18 ms to return all matched documents.
Nazatul Haque Sultan, Shabnam Kasra Kermanshahi, Hong-Yen Tran, Shangqi Lai, Vijay Varadharajan, Surya Nepal, Xun Yi
Ad Hoc Networks3
2024 Biometrics-Based Authenticated Key Exchange With Multi-Factor Fuzzy Extractor
abstract
Existing fuzzy extractor and similar methods provide an effective way for extracting a secret key from a user’s biometric data, but are susceptible to impersonation attack: once a valid biometric sample is captured, the scheme is no longer secure. We propose a novel multi-factor fuzzy extractor that integrates both a user’s secret (e.g., a password) and a user’s biometrics in the generation and reconstruction process of a cryptographic key. We then employ this multi-factor fuzzy extractor to construct personal identity credentials, which can be used in a new multi-factor authenticated key exchange protocol that possesses multiple important features. First, the protocol provides mutual authentication. Second, the user and service provider can authenticate each other without the involvement of the identity authority. Third, the protocol can prevent user impersonation from a compromised identity authority. Finally, even when both a biometric sample and the secret are captured, the user can re-register to create a new credential using a new secret (renewable biometrics-based identity credentials). Most existing works on multi-factor authenticated key exchange only have a subset of these features. We formally prove that the proposed protocol is semantically secure. Our experiments carried out on the finger vein dataset SDUMLA achieved a low equal error rate (EER) of 0.04%, a reasonable computation time of 0.93 seconds for the user and service provider to authenticate and establish a shared session key, and a small communication overhead of 448 bytes.
Hong-Yen Tran, Jiankun Hu, Wen Hu 0001
IEEE Trans. Inf. Forensics Secur.1
2023 Committed Private Information Retrieval
Quang Cao, Hong-Yen Tran, Son Hoang Dau, Xun Yi, Emanuele Viterbo, Chen Feng 0001, Yu-Chih Huang, Jingge Zhu, Stanislav Kruglik, Han Mao Kiah
ESORICS (1)2
2023 A Privacy-Preserving State Estimation Scheme for Smart Grids
abstract
With the appearance of electric energy market deregulation, there exists a growing concern over the potential privacy leakage of commercial data among competing power companies where data sharing is essential in the applications such as smart grid state estimation. Most of the existing solutions are either perturbation-based or conventional cryptography-based where a trusted central 3rd party would often be required. This paper proposes privacy-preserving state estimation protocols for DC and AC models. The proposed idea is to distribute the overall task of the system state estimation into sub-tasks which can be performed by local sub-grid operators with their private data. A masking method is designed inside a homomorphic encryption scheme which is then used to ensure both the input and output data privacy during the collaboration process among individual sub-task players. Security is achieved via the computationally indistinguishable post-quantum security guaranteed by a levelled homomorphic encryption scheme over real numbers and the differential privacy of the output estimated states provided by the Laplace mechanism perturbation integrated into the masking linear transformation. Simulation results are presented to demonstrate the validity of our proposed privacy-preserving system state estimation protocols.
Hong-Yen Tran, Jiankun Hu, Hemanshu Roy Pota
IEEE Trans. Dependable Secur. Comput.1
2023 An Efficient Privacy-Enhancing Cross-Silo Federated Learning and Applications for False Data Injection Attack Detection in Smart Grids
abstract
Federated Learning is a prominent machine learning paradigm which helps tackle data privacy issues by allowing clients to store their raw data locally and transfer only their local model parameters to an aggregator server to collaboratively train a shared global model. However, federated learning is vulnerable to inference attacks from dishonest aggregators who can infer information about clients’ training data from their model parameters. To deal with this issue, most of the proposed schemes in literature either require a non-colluded server setting, a trusted third-party to compute master secret keys or a secure multiparty computation protocol which is still inefficient over multiple iterations of computing an aggregation model. In this work, we propose an efficient cross-silo federated learning scheme with strong privacy preservation. By designing a double-layer encryption scheme which has no requirement to compute discrete logarithm, utilizing secret sharing only at the establishment phase and in the iterations when parties rejoin, and accelerating the computation performance via parallel computing, we achieve an efficient privacy-preserving federated learning protocol, which also allows clients to dropout and rejoin during the training process. The proposed scheme is demonstrated theoretically and empirically to provide provable privacy against an honest-but-curious aggregator server and simultaneously achieve desirable model utilities. The scheme is applied to false data injection attack detection (FDIA) in smart grids. This is a more secure cross-silo FDIA federated learning resilient to the local private data inference attacks than the existing works.
Hong-Yen Tran, Jiankun Hu, Xuefei Yin, Hemanshu Roy Pota
IEEE Trans. Inf. Forensics Secur.1
2022 Smart Meter Data Obfuscation With a Hybrid Privacy-Preserving Data Publishing Scheme Without a Trusted Third Party
abstract
Smart electricity meters as a prominent instance of the Internet of Things (IoT) have driven more efficient energy services in smart grids but also created growing concerns of consumer privacy. Homomorphic encryption of consumption data is a conventional solution for privacy protection, but it incurs a high computational burden to the resource-restrained smart meters (SMs) due to the encryption of high-frequency consumption readings. Perturbation is another major approach in providing the privacy protection of SM readings which is highly efficient. However, most existing perturbation-based works inadequately balance the tradeoff between the need of hiding individual consumption profiles and the need of retaining utility’s quality. This article proposes a hybrid privacy-preserving electricity consumption data publishing scheme without a trusted third party which utilizes the desirable properties of both perturbation and cryptography for better privacy-utility tradeoff and efficiency. The proposed scheme for fine-grained SM consumption data consists of two phases, which are noise generation and noise distribution. In the first phase, a distributed perturbation method is designed to provide differential privacy protection for high-frequency consumption while retaining the accuracy of energy services like regional load forecasting. In the second phase, a private noise distribution protocol,$nn$-PND, securely distributes$n$noise elements generated by an energy distribution operator to$n$SMs in a semihonest adversarial model. Formal proofs of correctness and privacy of the scheme are provided. Experiments of regional short-term electricity consumption forecast using real-world data sets demonstrate the preservation of the utility over the masked data of this scheme.
Hong-Yen Tran, Jiankun Hu, Hemanshu Roy Pota
IEEE Internet Things J.1
2019 Privacy-preserving big data analytics a comprehensive survey
Hong-Yen Tran, Jiankun Hu
J. Parallel Distributed Comput.1