Changsong Jiang

dblp:272/7193 · DBLP profile ↗
← Back
24ranked-venue papers
12as first author
24since 2021 · last 2026
0000-0002-6510-3380ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 8 first-author · 14 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 DAAPS: Distributed anonymous access control for pervasive edge computing services
Jie Chen 0093, Wenhao Li 0005, Shuai Wang 0079, Huamin Jin, Changsong Jiang
Comput. Secur.6
2026 Privacy-preserving electricity trading matching based on blockchain in smart grid
Zhao Zhang 0026, Chunxiang Xu, Changsong Jiang
Expert Syst. Appl.3
2025 Strong Federated Authentication With Password-Based Credential Against Identity Server Corruption
Changsong Jiang, Chunxiang Xu, Guomin Yang, Jing Wang 0036
ACISP (3)1
2025 LPbT-SSO: Password-Based Threshold Single-Sign-On Authentication From LWE
abstract
In networks, clients access various servers. Servers need to authenticate clients' identities and provide services to clients who pass the authentication. Password-based threshold single-sign-on authentication (PbT-SSO) delegates multiple identity servers to authenticate a client with the client's password, and issue a token for subsequent access. However, existing PbT-SSO schemes are based on conventional hardness problems, which are vulnerable to adversaries equipped with quantum computers in the near future. Once quantum computers are accessible, adversaries can retrieve passwords by off-line dictionary guessing attacks (DGA) from the credentials of clients' passwords. Moreover, quantum adversaries can derive identity servers' secret from public information and further forge tokens with the secret. Motivated by these issues, we propose a password-based threshold single-sign-on authentication from learning with errors problem (LWE), dubbed LPbT-SSO, which is resistant to quantum attacks. LPbT-SSO evaluates a one-way function of passwords, and takes the function outputs as credentials. Since the function is grounded on LWE problem intractable for quantum computation, quantum adversaries cannot recover passwords by off-line DGA. Additionally, LPbT-SSO leverages a lattice-based threshold signature scheme to issue tokens, and guarantees that no adversary can forge a valid token. The comprehensive performance evaluation demonstrates that LPbT-SSO is efficient in terms of computation, storage, and communication costs.
Chenchen Cao, Chunxiang Xu, Changsong Jiang, Zhao Zhang 0026, Kefei Chen
IEEE Trans. Dependable Secur. Comput.3
2025 An Efficient Privacy-Preserving Scheme for Weak Password Collection in Internet of Things Against Perpetual Leakage
abstract
Password-based authentication is widely applied in Internet of Things (IoT). It allows IoT devices to identify users with passwords to resist unauthorized access. However, choices of weak passwords, especially popular ones, might violate users’ privacy and lead to large-scale network attacks. Collection of popular passwords among IoT devices to establish blocklists via a service provider can prevent use of weak passwords. To protect unpopular passwords during collection, existing privacy-preserving schemes rely on expensive cryptographic primitives (e.g., garbled circuits and zero-knowledge proofs), which would impose heavy communication and computation burdens on constrained devices and hinder wide deployment of these schemes. In this paper, we propose EAGER+, an efficient privacy-preserving scheme for weak password collection in IoT against perpetual leakage. EAGER+ is mainly built on secret sharing and symmetric encryption, thereby enabling lightweight computation and communication on IoT devices. In EAGER+, we conceive a password-locked encryption with conditional decryption mechanism to efficiently identify popular passwords, where a password is essentially locked under itself in the encryption to guarantee its security, and the password can be revealed from the ciphertext by the service provider only if a sufficient number of devices exploit it. The mechanism is integrated with a servers-aided password-hardening mechanism to resist offline dictionary guessing attacks. Moreover, EAGER+ uses a key renewal mechanism to periodically update secrets for password hardening on key servers to thwart perpetual leakage towards the secrets. We formally analyze the security of EAGER+, and conduct experimental evaluations to show that EAGER+ is more efficient than existing schemes.
Changsong Jiang, Chunxiang Xu, Kefei Chen, Guomin Yang
IEEE Trans. Inf. Forensics Secur.1
2025 Threshold Password-Hardening Updatable Oblivious Key Management
abstract
We propose a threshold password-hardening updatable oblivious key management system dubbed TPH-UOKM for cloud storage. In TPH-UOKM, a group of key servers share a user-specific secret key for a user, and assist the user in producing her/his password-derived private key in a threshold and oblivious way, where the password is hardened to resist offline dictionary guessing attacks. Anyone can outsource data protected with the user’s password-derived public key to the cloud server, and merely the user holding the correct password can recover the password-derived private key for data access. TPH-UOKM can accomplish decryption ofNciphertexts with the complexityO(1) of communication between a user and the key servers, which outperforms existing schemes. TPH-UOKM supports password update. The cloud server can update all protected data of a user with an update token to be accessible only with the new password, which resists password leakage. We present a two-level proactivization mechanism to periodically update user-specific secret key shares and the key servers to thwart perpetual compromise of them, where the renewal of user-specific secret key shares reduces computation and communication costs compared to existing approaches. Provable security and high efficiency of TPH-UOKM are demonstrated by comprehensive analyses and performance evaluations.
Changsong Jiang, Chunxiang Xu, Wenzheng Zhang 0001
IEEE Trans. Inf. Forensics Secur.1
2025 Device-Enhanced Password-Based Threshold Single-Sign-On Authentication
abstract
Password-based threshold single-sign-on authentication (PbTA) allows multiple identity servers to in a threshold manner authenticate a user and issue a token, with which the user accesses relevant services. We analyze existing PbTA schemes and reveal a potential threat: vulnerability against perpetual credential leakage, in which “perpetual” adversaries could perpetually attempt to compromise long-lived credential databases maintained by identity servers. Compromising a threshold number of credential databases enables the adversaries to launch offline dictionary guessing attacks (DGA) or illegally obtain users’ tokens. To address these issues, we first propose a basic device-enhanced PbTA scheme (DE-PbTA), where an auxiliary device collaborates with identity servers in hardening a user’s password during authentication, such that perpetual adversaries cannot learn the password from compromised credentials via offline DGA. Using the hardened password, a private key can be derived to decrypt ciphertexts from identity servers for token construction, which protects the user’s tokens against perpetual adversaries. Then, we extend basic DE-PbTA to support dynamic usage of multiple devices, where a user can actively choose$t^{\prime } $devices out of$n^{\prime } $for authentication. Provable security and high efficiency of the basic/enhanced DE-PbTA scheme are demonstrated by comprehensive analysis and experimental evaluations.
Changsong Jiang, Chunxiang Xu, Guomin Yang, Zhao Zhang 0026, Jie Chen 0093
IEEE Trans. Inf. Forensics Secur.1
2025 AugSSO: Secure Threshold Single-Sign-On Authentication With Popular Password Collection
abstract
Single-sign-on authentication is widely deployed in mobile systems, which allows an identity server to authenticate a mobile user and issue her/him with a token, such that the user can access diverse mobile services. To address the single-point-offailure problem, threshold single-sign-on authentication (PbTA) is a feasible solution, where multiple identity servers perform user authentication and token issuance in a threshold way. However, existing PbTA schemes confront critical drawbacks. Specifically, these schemes are vulnerable to perpetual secret leakage attacks (PSLA): an adversary perpetually compromises secrets of identity servers (e.g., secret key shares or credentials) to break security. Besides, they fail to achieve popular password collection, which is an effective means of enhancing system security. In this paper, we propose a secure PbTA scheme with popular password collection, dubbed AugSSO. In AugSSO, we conceive an efficient key renewal mechanism that allows identity servers to periodically update secret key shares in batches, and require storage of hardened password-derived public keys in credentials for user authentication, thereby resisting PSLA. We also present a popular password collection mechanism, where an aggregation server is introduced to identify popular passwords without disclosing unpopular ones. We provide security analysis and performance evaluation to demonstrate security and efficiency of AugSSO
Changsong Jiang, Chunxiang Xu, Guomin Yang
IEEE Trans. Mob. Comput.1
2025 PCSE: Privacy-Preserving Collaborative Searchable Encryption for Group Data Sharing in Cloud Computing
abstract
Collaborative searchable encryption for group data sharing enables a consortium of authorized users to collectively generate trapdoors and decrypt search results. However, existing countermeasures may be vulnerable to a keyword guessing attack (KGA) initiated by malicious insiders, compromising the confidentiality of keywords. Simultaneously, these solutions often fail to guard against hostile manufacturers embedding backdoors, leading to potential information leakage. To address these challenges, we propose a novel privacy-preserving collaborative searchable encryption (PCSE) scheme tailored for group data sharing. This scheme introduces a dedicated keyword server to export server-derived keywords, thereby withstanding KGA attempts. Based on this, PCSE deploys cryptographic reverse firewalls to thwart subversion attacks. To overcome the single point of failure inherent in a single keyword server, the export of server-derived keywords is collaboratively performed by multiple keyword servers. Furthermore, PCSE extends its capabilities to support efficient multi-keyword searches and result verification and incorporates a rate-limiting mechanism to effectively slow down adversaries' online KGA attempts. Security analysis demonstrates that our scheme can resist KGA and subversion attack. Theoretical analyses and experimental results show that PCSE is significantly more practical for group data sharing systems compared with state-of-the-art works.
Yongliang Xu, Hang Cheng, Ximeng Liu, Changsong Jiang, Xinpeng Zhang 0001
IEEE Trans. Mob. Comput.4
2025 Privacy-Preserving Single-Sign-on With Fine-Grained Access Control for IoT Devices
abstract
IoT-based sharing economy is a win-win business model, where a transferor owns idle IoT devices and transfers the right to use a device to a user for a fee. Considering usage of multiple devices and privacy preservation, anonymous single-sign-on (ASSO) is a feasible solution for authentication. ASSO allows a user to access multiple devices with one token issued by the transferor and prevents the transferor from identifying the user. We also observe that in the scenario of IoT-based sharing economy, the token should (i) support attributes since a device should be available only to users with specific attributes (e.g., age) and (ii) avoid incurring significant communication/computation overhead as IoT devices are resource-constrained. In this paper, we proposed PILOT, a privacy-preserving single-sign-on with fine-grained access control for IoT devices. When a user attempts to access a device, he/she requests a token from the transferor. The token is actually a blind signature that cannot be tracked, and contains the user’s attributes which facilitate fine-grained access control on the device. Besides, the token consists of only four group elements and verification of the token involves only several exponentiation operations. This renders PILOT superior in terms of communication/computation overhead and suitable for IoT devices.
Zhao Zhang 0026, Chunxiang Xu, Man Ho Au, Changsong Jiang
IEEE Trans. Mob. Comput.4
2024 Device-Enhanced Secure Cloud Storage with Keyword Searchable Encryption and Deduplication
Changsong Jiang, Chunxiang Xu, Guomin Yang
ESORICS (4)1
2024 ScCGKA: Continuous Group Key Agreement With Smart Contract
abstract
Continuous Group Key Agreement (CGKA) is the core of a new generation of End-to-End secure (E2E) cryptographic multi-party applications. CGKA allows the members in a dynamic group to agree on the current state for continuous communicating. The first CGKA protocol deployed in practical E2E applications is Inside-Secure TreeKEM (ITK), in which members use flood broadcasting to transition to the same new state for subsequent communications. However, flood broadcasting requires spread of a large amount of messages, while only a small part of the messages is needed for one specific member. This would incur substantial communication costs. To reduce the communication costs, Server-Aided ITK (SAIK) was proposed. SAIK employs a server to split the whole uploaded messages into multiple pieces, and deliver each piece to a specific member, thereby saving bandwidth of members. However, SAIK relies on a central server and hence is vulnerable to the single-point-of-failure problem. The problem is that if the server is unavailable, it will cause a sharp reduction in efficiency and increasing cost. In this work, we first formalize CGKA with smart contract (ScCGKA), which replaces the central server with smart contracts to solve the single-point-of-failure problem. We give a concrete construction of ScCGKA, dubbed the improved ITK with smart contract (ScITK). ScITK is constructed on ITK and can be deployed in real-world E2E applications. In ScITK, participants collaboratively negotiate and deploy a smart contract on the Ethereum blockchain to perform the splitting-delivering procedure. We give a formal security model to capture security properties that CGKA needs to achieve and a correctness property. The comparison between our ScITK and existing approaches shows that ScITK not only reduces communication cost, but also removes the server’s costs.
Zhiqian Cai, Changsong Jiang, Chunxiang Xu
HPCC2
2024 Blockchain-based immunization against kleptographic attacks
Changsong Jiang, Chunxiang Xu, Kefei Chen
Sci. China Inf. Sci.1
2024 A portable blind cloud storage scheme against compromised servers
abstract
Applications (Apps) generate large amounts of data on users’ storage-limited local devices. To alleviate the burden of local storage, users can outsource their App-generated data to a remote cloud server. Secure data outsourcing needs data portability and blindness. The former enables users to access data from multiple devices using a single password, and the latter ensures data privacy against unauthorized individuals. Portable blind cloud storage (PBCS) can satisfy both requirements. However, existing PBCS schemes are vulnerable to offline password guessing attacks (OPGA) if both the App server and the cloud server are compromised: an adversary can learn users’ passwords from compromised registered information of users. In this paper, we propose a PBCS scheme called IPBCS that is secure against OPGA. In IPBCS, a user hardens her/his password with a secret key, which is stored in trusted execution environments (TEE). With the hardened password and a user-specific randomness, a token can be derived for user authentication . By adopting TEE to protect secret keys, IPBCS guarantees security against OPGA even if both servers are compromised. Moreover, IPBCS adopts a password-based authentication mechanism to support authentication over public channels. Security analysis and performance evaluation demonstrate that IPBCS is secure and efficient.
Zhen Liu 0062, Changsong Jiang, Chunxiang Xu
J. Syst. Archit.2
2024 A Secure Two-Factor Authentication Key Exchange Scheme
abstract
Two-factor authentication key exchange (AKE) is an effective way to strengthen the security of password-authenticated key exchange. Most two-factor AKE schemes using smart cards as the second factor require users to have the second factor with them any time, which causes users inconveniences. Biometrics provide a user-friendly manner to achieve two-factor AKE since they need not be carried. However, biometrics may have less entropy than expected and would suffer from offline guessing attacks. In this paper, we propose a secure two-factor authentication key exchange scheme TAKE that resists offline guessing attacks against biometrics and passwords. In TAKE, a user generates a combined factor of his/her biometrics and password. To protect the combined factor, the user and the server leverages secure two-party computation to blind it with a key which is protected in a trusted execution environment. Thus, TAKE prevents an adversary from eavesdropping on the combined factor, and simultaneously guarantees that he cannot recover the combined factor from blinded one to undertake offline guessing attacks even if he compromises the server and obtains the blinded combined factor. We provide the formal security proof of TAKE. The experiments show that TAKE is efficient in terms of storage, computation, and communication overhead.
Yunxia Han, Chunxiang Xu, Changsong Jiang, Kefei Chen
IEEE Trans. Dependable Secur. Comput.3
2024 TSAPP: Threshold Single-Sign-On Authentication Preserving Privacy
abstract
Single-sign-on (SSO) authentication enables a user to gain a token from the identity server, with which the user accesses multiple services. To address single-point-of-failure of SSO, threshold SSO, where a group of identity servers issue a user with a token in the threshold manner, is introduced. SSO including threshold schemes suffers from privacy disclosure. One can learn a user's identity and access pattern from her/his token. Recent works focus on privacy preservation of SSO. However, these works merely consider scenarios of one single identity server SSO. No works that address privacy preservation of threshold SSO have emerged. In this work, we propose TSAPP, a threshold SSO authentication scheme preserving privacy. Each identity server issues a user with a partial token which is a signature on the user's pseudonym. With a threshold number of partial tokens, the user constructs a token, blinds the token with random numbers and accesses services with blinded tokens. Such mechanism preserves the user's identity, simultaneously protects the user's access pattern since adversaries cannot link the user's accesses, even if identity servers are corrupted. Security analysis demonstrates that TSAPP satisfies properties of anonymity, unlinkability, unforgeability and password-safety. The performance evaluation demonstrates that TSAPP is efficient in practice.
Zhao Zhang 0026, Chunxiang Xu, Changsong Jiang, Kefei Chen
IEEE Trans. Dependable Secur. Comput.3
2024 Two-Factor Authenticated Key Exchange From Biometrics With Low Entropy Rates
abstract
Multi-factor authenticated key exchange (AKE) enables a user to be authenticated by a server using multiple factors and negotiate a shared session key to protect subsequent communications. Most existing multi-factor AKE schemes utilize biometrics as one factor due to their uniqueness and invariance properties. To support matching for noisy biometrics and protect them, fuzzy extractors are employed to extract a constant random string from varying biometric measurements without disclosing biometric data. However, the fuzzy extractors used in these schemes merely work on biometrics with an entropy rate greater than the error rate. Hence these schemes are unsuitable for biometrics with low entropy rates. In this paper, we propose a secure two-factor AKE scheme dubbed AHEAD from passwords and biometrics, which eliminates the limitation of biometric entropy rates. In AHEAD, we conceive a matching mechanism to simultaneously check whether an input biometric measurement with low entropy rates is close enough to the registered one, and whether an input password exactly matches the registered password. The mechanism allows a valid user to generate a secret element shared with the server in an oblivious way. By adopting a randomization technique, the secret element can be randomized for derivation of session keys. The security and efficiency of AHEAD are demonstrated by formal security proofs and experimental evaluations.
Changsong Jiang, Chunxiang Xu, Yunxia Han, Zhao Zhang 0026, Kefei Chen
IEEE Trans. Inf. Forensics Secur.1
2024 Practical Blockchain-Based Options Contract
abstract
Decentralized finance (DeFi) relies on crypto assets in blockchains to provide financial services. High volatility of crypto assets puts users at risk of financial loss. Options contracts address this issue by empowering a buyer to exchange his asset with that of a seller, which mitigates risks for both parties. Existing options contract protocols have the following two weaknesses: (i) The buyer have to lock his asset during the contract's lifespan, incurring heavy opportunity costs; (ii) Turing-completed smart contract (TCSC)/hash time lock contract (HTLC) is required to exchange assets, which restricts applicability as TCSC/HTLC is supported by a limited number of blockchains. In this paper, we propose UP-BLOC, a universal and practical blockchain-based options contract. We construct UP-BLOC using a buyer-pay-first design, and propose a blockchain-based secret storage mechanism to ensure the security of the assets involved. This allows the buyer to engage in an options contract without locking any asset and resulting opportunity costs, and thus is more practical than existing works. Besides, UP-BLOC achieves the exchange of assets using standard digital signatures instead of TCSC/HTLC. Hence, UP-BLOC is compatible with all blockchains and is universal. Security analysis and performance evaluation demonstrate that UP-BLOC is secure and efficient.
Zhao Zhang 0026, Chunxiang Xu, Changsong Jiang
IEEE Trans. Serv. Comput.3
2023 An Efficient Privacy-Preserving Scheme for Weak Password Collection in Internet of Things
Changsong Jiang, Chunxiang Xu, Kefei Chen
Inscrypt (2)1
2023 ttPAKE: Typo tolerance password-authenticated key exchange
Yunxia Han, Chunxiang Xu, Shanshan Li 0004, Changsong Jiang, Kefei Chen
J. Inf. Secur. Appl.4
2023 GAIN: Decentralized Privacy-Preserving Federated Learning
Changsong Jiang, Chunxiang Xu, Chenchen Cao, Kefei Chen
J. Inf. Secur. Appl.1
2023 SR-PEKS: Subversion-Resistant Public Key Encryption With Keyword Search
abstract
Public key encryption with keyword search (PEKS) provides secure searchable data encryption in cloud storage. Users can outsource encrypted data and keywords to a cloud server, and search target one without disclosing sensitive information. To achieve resistance against off-line keyword guessing attacks, existing practical PEKS schemes employ independent key server(s) to assist users in producing keywords to be encrypted (called server-derived keywords) in an online manner. In this article, we analyze server-aided PEKS schemes and reveal a potential threat: vulnerability against subversion attacks, where algorithms in server-aided PEKS might be maliciously implemented to undermine security. In a subverted encryption implementation, a subliminal channel is established to control randomness generation such that biased ciphertexts covertly leak plaintext information. We further present a specific subversion attack against generation of server-derived keywords to violate keywords’ confidentiality. To address these issues, we propose SR-PEKS, a subversion-resistant PEKS scheme based on cryptographic reverse firewalls (CRF). In SR-PEKS, CRF sanitizes messages transmitted in server-derived keyword generation to resist the presented subversion attack. CRF also participates in a collaborative randomness generation protocol to yield unbiased randomness for encryption, thereby eliminating the subliminal channel. Provable security and high efficiency of SR-PEKS are demonstrated by comprehensive analyses and performance evaluations.
Changsong Jiang, Chunxiang Xu, Zhao Zhang 0026, Kefei Chen
IEEE Trans. Cloud Comput.1
2021 PFLM: Privacy-preserving federated learning with membership proof
Changsong Jiang, Chunxiang Xu, Yuan Zhang 0006
Inf. Sci.1
2021 Security Analysis of a Path Validation Scheme With Constant-Size Proof
abstract
We analyze a path validation scheme with constant-size proof (published in IEEE Transactions on Information Forensics and Security) and demonstrate that this scheme fails to achieve unforgeability. An adversary can forge a valid proof with a non-negligible probability.
Changsong Jiang, Chunxiang Xu, Kefei Chen
IEEE Trans. Inf. Forensics Secur.2