Zhen Zhao 0005

dblp:29/1773-5 · DBLP profile ↗
← Back
24ranked-venue papers
6as first author
19since 2021 · last 2026
0000-0003-2654-624XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 5 since 2021Computer networks · 5 · 1 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Theory of computation · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 Secure Sealed-Bidding Networks via Conditional Time-Aware Access Authorization
Qi Liu 0068, Peng Jiang 0007, Yimin Liu 0002, Zhen Zhao 0005, Liehuang Zhu
ACISP (1)4
2026 A lattice-based linkable authentication scheme for privacy-preserving vehicular systems
Wen Gao 0010, Kuan-he Tan, Hao-yuan Yao, Simeng Ren, Zhen Zhao 0005, Xiaoli Dong
J. Syst. Archit.5
2026 Reinforcing Data Integrity for Smart Wearable Devices via Certificateless Signature With Enhanced Security
abstract
Due to the convenience of real time monitoring and feedback, eHealth system is gaining its popularity. With the wide adoption of electronic health records (EHRs), the security issues arise at the same time. Data integrity is one of the most fundamental security requirements and many techniques have been extensively studied to provide integrity guarantee, such as digital signature. Among various signature schemes, certificateless signature enjoys the advantages of there is neither complicated certificate management nor the key escrow problem. In this paper, we study the particular security threats in eHealth systems and analyze the limitations of traditional certificateless signature schemes if being directly applied to protect data integrity. We show that there is a gap between the traditional threat model and the security threats in practice. To improve the security, we define an enhanced notion for the “normal” type adversary in certificateless signature. Then, a concrete construction secure in the enhance model is presented, which can withstand more powerful but realistic attacks. In addition, we provide experimental simulations to analyze the efficiency and security of our proposed scheme. The results demonstrate its utility in eHealth systems and other similar scenarios.
Ge Wu 0001, Hua Shen 0002, Zhen Zhao 0005, Liquan Chen, Jinguang Han
IEEE Trans. Dependable Secur. Comput.3
2025 EPBNN: Efficient and Private Inference for Binary Neural Network
abstract
The progress of deep learning has facilitated the widespread adoption of neural network (NN) inference in real-word applications, particularly in the Internet of Things (IoT). IoT devices, such as smart home appliances and industrial sensors, increasingly rely on NN inference to process data. However, IoT devices usually collect sensitive information, and NN models may contain proprietary algorithms. Therefore, ensuring the privacy of both data and models is essential. In this context, the development of efficient and private NN inference frameworks becomes even more critical. Binary Neural Network (BNN) stands out as a promising solution due to its low computational requirements and energy efficiency, which align well with the resource-constrained nature of many IoT devices. Nevertheless, existing private BNN inference approaches still face challenges in terms of computational and communication overhead. In this paper, we introduce EPBNN, an efficient and private BNN inference framework against a semi-honest adversary in a dealer-based offline-online setting. Our construction relies on secret sharing and advanced cryptographic primitives including function secret sharing (FSS) and lookup table (LUT). Specifically, we propose an LUT-based tailored protocol for maxpool layer, as well as an FSS-based protocol for batch normalization and binary activation layers, which enables an efficient online inference phase and makes EPBNN well-suited for IoT environments. Extensive evaluations demonstrate that EPBNN outperforms the state-of-the-art solution in terms of runtime (1.8-9.3× improvement), communication (up to 3.2× improvement), and round complexity.
Baocang Wang, Zhen Zhao 0005
IEEE Internet Things J.3
2025 Identity-Based Encryption with Equality Test Supporting Accountable Authorization in Cloud Computing
Zhen Zhao 0005, Baocang Wang, Wen Gao 0010
J. Comput. Sci. Technol.1
2025 Verifiable and Privacy-Preserving $k$k-NN Query Scheme With Multiple Keys
abstract
As a basic primitive in spatial and multimedia databases, the$k$-nearest neighbors ($k$-NN) query has been widely used in electronic medicine, location-based services and so on. With the boom in cloud computing, it is currently a trend to upload massive data to the cloud server to enjoy its powerful storage and computing resources. Recently, research communities and commercial applications have proposed many schemes to support$k$-NN query on cloud data. However, most of the existing schemes were designed under the assumption that the query users (QUs) are fully trusted and hold the key of the data owner (DO). In this case, even if the queries were encrypted, the QUs can capture the query content from each other, leading to the query privacy leakage. Unfortunately, to the best of our knowledge, few$k$-NN query schemes can ensure data security and result verification under the key confidentiality condition. In this paper, we propose a verifiable and privacy-preserving$k$-NN query scheme with multiple keys (VP$k$NN), in which each QU's partial private key can only decrypt the encrypted query results belonging to its own, but not the encrypted database, the encrypted query data and query results of other QUs. Moreover, our proposal not only answers the query efficiently, but also ensures the privacy of the data, the query and the result, and the verification of the correctness of the results. Finally, the complexity and security are theoretically analyzed, and the practicality and efficiency of our proposed scheme are compared by simulation experiments.
Yunzhen Zhang 0001, Baocang Wang, Zhen Zhao 0005
IEEE Trans. Big Data3
2025 SVOC: Secure Aggregatable and Extractable System for Outsourced Cloud Computation
abstract
With the rapid advancement of technology, cloud computing has emerged as the most popular and promising service platform. A cloud user can delegate heavy computation tasks to cloud servers. To ensure the correctness of outsourced processing (e.g., machine learning and data mining), the cloud server must prove that the processing has been executed properly. However, even without malicious intent, it is possible for a cloud server to produce incorrect results. Consequently, clients may outsource the same task to multiple cloud servers and receive various results, aiding them in selecting the best outcome. To protect data privacy, the cloud server must encrypt the results before sending them back to the user. Yet, processing and verifying encrypted results remain significant challenges. To avoid the expensive computational overhead of decrypting ciphertexts from cloud servers one by one, clients prefer to use homomorphic encryption (HE) to obtain the combined output from a single server. However, existing schemes fall short of efficiently verifying the correctness of computations over encrypted data processed by multiple cloud servers, especially in extracting the results computed by each server. In this paper, we introduce a new framework for verifiable outsourced computing systems. In this system, each cloud server's computation result is protected by Paillier encryption, and the edge server can verify these results using zero-knowledge proofs and aggregate the verified ciphertexts. The client can extract the combined plaintext through the Base-3 conversion algorithm to identify each cloud server's results and any non-participating servers. We also prove the security of our scheme and analyze its performance from both theoretical and experimental aspects. Performance analysis shows that our system significantly reduces the client's workload and is userfriendly
Willy Susilo, Yumei Li 0003, Fuchun Guo, Zhen Zhao 0005, Yannan Li 0001, Chunpeng Ge 0001
IEEE Trans. Dependable Secur. Comput.4
2025 Conjunctive Keyword Search With Dynamic Group-User
abstract
In order to ensure data security and improve data usability, searchable encryption has been widely used in cloud computing systems. However, the evil single users with search privileges bring heavy privacy threats to the system. Threshold searchable encryption provides a collaborative search service for group users; a single user cannot search for ciphertext. However, the threshold searchable encryption based on the Shamir secret sharing mechanism cannot achieve flexible user dynamic since the Lagrange interpolation polynomial for recovering the secret value changes with the group user add or delete, resulting in the ciphertext or trapdoor containing Lagrange interpolation formula needs to be recreated. In this paper, the conjunctive keyword search with dynamic group-user scheme (CKSDGU) is proposed to realize group-user flexible addition and deletion. The proposed CKSDGU scheme can match successfully without the data owner resetting ciphertext and the original data user generating trapdoors. In addition, multi-keyword conjunctive retrieval is implemented in the CKSDGU scheme, and group users can search the target ciphertexts that contain all users’ query keyword sets. The security analysis illustrates that the CKSDGU scheme can resist chosen keyword attacks and keyword guessing attacks. The performance analysis presents that our scheme has considerable overhead and efficient computational cost in the user dynamic stage.
Nan Gao 0003, Kai Fan 0001, Zhen Zhao 0005, Willy Susilo, Zhoutong Xiong, Hui Li 0006
IEEE Trans. Inf. Forensics Secur.3
2024 Secure k-NN Query With Multiple Keys Based on Random Projection Forests
abstract
As a basic primitive in spatial and multimedia databases, the$k$-nearest neighbors$(k$-NN) query has been widely used in electronic medicine, location-based services, and so on. With the boom in cloud computing, it is currently a trend to upload massive data to the cloud server to enjoy its powerful storage and computing resources. Recently, research communities and commercial applications have proposed many schemes to support$k$-NN query on cloud data. However, most of the existing$k$-NN query schemes were designed under the assumption that the query users (QUs) are fully trusted and hold the key of the acrlong DO. In this case, even if the queries were encrypted, the QUs can capture the query content from each other, leading to the query privacy leakage. Unfortunately, to the best of our knowledge, few$k$-NN query schemes can ensure data privacy under the key-confidentiality condition. In this article, we propose a secure$k$-NN query with multiple keys based on random projection forests (SM$k$NN), in which each QU’s partial strong private key can only decrypt the encrypted query results belonging to its own, but not the encrypted database, the encrypted query data and query results of other QUs. Moreover, our proposal not only answers the query efficiently but also ensures the privacy of data, query, results, and access pattern, and the verification of the correctness of the results. Finally, the complexity and security are theoretically analyzed, and the practicality and efficiency of our proposed scheme are compared by simulation experiments.
Yunzhen Zhang 0001, Baocang Wang, Zhen Zhao 0005
IEEE Internet Things J.3
2024 Privacy-preserving medical diagnosis system with Gaussian kernel-based support vector machine
Baocang Wang, Zhen Zhao 0005
Peer Peer Netw. Appl.3
2023 PPeFL: Privacy-Preserving Edge Federated Learning With Local Differential Privacy
abstract
Since traditional federated learning (FL) algorithms cannot provide sufficient privacy guarantees, an increasing number of approaches apply local differential privacy (LDP) techniques to FL to provide strict privacy guarantees. However, the privacy budget heavily increases proportionally with the dimension of the parameters, and the large variance generated by the perturbation mechanisms leads to poor performance of the final model. In this article, we propose a novel privacy-preserving edge FL framework based on LDP (PPeFL). Specifically, we present three LDP mechanisms to address the privacy problems in the FL process. The proposed filtering and screening with exponential mechanism (FS-EM) filters out the better parameters for global aggregation based on the contribution of weight parameters to the neural network. Thus, we can not only solve the problem of fast growth of privacy budget when applying perturbation mechanism locally but also greatly reduce the communication costs. In addition, the proposed data perturbation mechanism with stronger privacy (DPM-SP) allows a secondary scrambling of the original data of participants and can provide strong security. Further, a data perturbation mechanism with enhanced utility (DPM-EU) is proposed in order to reduce the variance introduced by the perturbation. Finally, extensive experiments are performed to illustrate that the PPeFL scheme is practical and efficient, providing stronger privacy protection while ensuring utility.
Baocang Wang, Yange Chen, Zhen Zhao 0005
IEEE Internet Things J.4
2023 Public-Key Encryption With Tester Verifiable Equality Test for Cloud Computing
abstract
Public-key encryption with equality test (PKEET) provides cloud servers with an effective way to check the equality of outsourced encrypted data without decryption. This enables PKEET to attract much attention and be widely researched in cloud computing. However, we claim that the existing PKEET schemes suffer from an inherited problem, called message-consistency unverifiability of testers (MCUT). Applying the MCUT problem, outsourcers can fool cloud servers into outputting incorrect testing results of encrypted data, which negates the practicability of PKEET in cloud computing. We investigate the PKEET literature and find the main reason for the MCUT problem is the independence between the messages inserted in the decryption and testing modules in their ciphertexts. To bridge the technical gap between PKEET and its practical applications, we present a new notion, called PKE with tester verifiable equality test (PKE-TVET), which solves the MCUT problem by allowing testers to verify the message consistency in two modules. We then instantiate the PKE-TVET and give a specific construction in the standard model. In our PKE-TVET scheme, the testing module is integrated into the decryption module so that there is only one message inserted in the ciphertext for both decryption and testing. This special setting lets our scheme directly get rid of the MCUT problem. For better applications in actual scenarios, we further extend the scheme to support authorization and tester designation. Finally, we analyze the tradeoff of parameter sizes and computation costs for the security against MCUT attacks in our PKE-TVET scheme.
Zhen Zhao 0005, Willy Susilo, Baocang Wang
IEEE Trans. Cloud Comput.1
2023 EthereumX: Improving Signature Security With Randomness Preprocessing Module
abstract
Ethereum leverages ECDSA as the digital signature scheme to validate transactions. From the provable security standpoint, ECDSA built on an 80-bit security Elliptic Curve group can achieve at most 50-bit concrete security, rather than 80-bit security, due to its reduction loss for$2^{30}$signature queries in security analysis. The state-of-the-art ECDSA scheme comes with no de facto formal security guarantee. Although there have been many signatures with higher concrete security, their structures are quite different from ECDSA and a total replacement of the signature field in Ethereum will incur high deployment cost. In this work, we present EthereumX without compromising the signature structure in Ethereum while achieves better security. The security gain is built on top of a new technique named randomness preprocessing module (RPM), which can securely pre-generate and verify randomness with the help of Ethereum. Calling RPM allows to pre-select randomness, which will be used for the subsequent signature, and to verify the randomness, assuring that it is previously generated. We give an instantiation with formal security guarantee and prove that it can be improved to 80-bit concrete security under the same discrete logarithm assumption as ECDSA. From this instantiated scheme, we implement EthereumX via a deployment into a locally simulated network. Experiment results show that EthereumX costs 5 seconds for a block generation which is equal to Ethereum, and generates/verifies at least$17017/10623$transactions per second that is practical enough in application, even if they are slightly slower than Ethereum which generates/verifies at least$17908/11257$transactions per second. We also mention that RMP can be applied to other DL-based signatures for the security improvement.
Peng Jiang 0007, Fuchun Guo, Willy Susilo, Chao Lin 0003, Jiaxi Hu, Zhen Zhao 0005, Liehuang Zhu, Debiao He
IEEE Trans. Serv. Comput.6
2023 Secure Replication-Based Outsourced Computation Using Smart Contracts
abstract
The replication-Based Outsourced Computation (RBOC) mechanism allows a client to outsource the same computing job to multiple contractors and the honest contractors will get paid in the incentivized system based on the fact that a majority of contractors will honestly perform the computation. As self-executing contracts, smart contracts are utilized in the decentralized blockchain networks to execute coded programs automatically transparently, and publicly. It is natural to apply smart contracts to RBOC to improve performance by setting smart contracts as the converter between the client and contractors to reduce the load on the client. However, it is infeasible to directly combine these two blocks together because the data including returned computing results from contractors in the decentralized blockchain are in the form of plaintexts such that some lazy contractors could copy others’ results as their own and still get paid, which will compromise the security of RBOC. The existing public-key encryption with equality test (PKEET) is a promising candidate solution to stop the above lazy contractors, where the results are encrypted by PKEET and then transferred without hindering smart contracts to compare the equality of underlying results. Unfortunately, we found that the advanced lazy contractors can still compromise security by forging ciphertexts to pass the equality test only with the encrypted results of other contractors. In this paper, to achieve security against lazy contractors, we introduce the notion of PKEET against lazy encryptors (PKEET-LE). Besides the fundamental property of PKEET that performs equality test on ciphertexts without decryption, PKEET-LE additionally realizes the security against the lazy encryptors who aim to forge a ciphertext for a given one to pass the equality test between them without the knowledge of the underlying plaintext. We further propose a concrete and practical PKEET-LE construction along with formal security proof. Finally, we conduct a performance evaluation to demonstrate that our PKEET-LE scheme is efficient and practical in the RBOC system using smart contracts.
Willy Susilo, Fuchun Guo, Zhen Zhao 0005, Yinhao Jiang, Chunpeng Ge 0001
IEEE Trans. Serv. Comput.3
2022 Secure Infectious Diseases Detection System With IoT-Based e-Health Platforms
abstract
In a traditional health system, it merely depends on doctors’ initiative reports to discover infectious diseases, which causes late responses from the Center for Disease Control (CDC) and therefore may result in snowballed loss of lives and economy. Sometimes, the disease has spread when doctors realize it is infectious, and the CDC has to invest more human and material resources to control it. In this article, we propose a new secure infectious diseases detection system with the help of the IoT-based e-health platform. In our system model, the hospitals collect patients’ electronic health records (EHRs) and outsource the encrypted EHRs to the contracted cloud. The CDC can regularly send a test query to the cloud server to check whether there are patients who have similar symptoms or some increasing signs, which are regarded as signs of infectious diseases. With this system, the CDC can find the small signs of infectious diseases so that it can make appropriate and timely measures to save more lives. To enable the cloud server to perform the required test, we propose a new cryptographic notion, called public-key encryption with DFET (PKE-DFET), with which we can check whether the underlying messages of two ciphertexts are equal or not after ignoring the bits on designated positions without decryption. The cloud server can utilize the PKE-DFET to flexibly count the number of patients with similar symptoms following the CDC’s instructions. We first instantiate the PKE-DFET into a concrete construction, where anyone can be a tester to perform the DFET on ciphertexts. Finally, we extend our PKE-DFET construction to enable it to be flexible in different actual application scenarios.
Zhen Zhao 0005, Fuchun Guo, Ge Wu 0001, Willy Susilo, Baocang Wang
IEEE Internet Things J.1
2022 PKE-MET: Public-Key Encryption With Multi-Ciphertext Equality Test in Cloud Computing
abstract
Cloud computing enables users to remove the necessity of the need of local hardware architecture, which removes the burden of the users from high computation costs. Therefore, it has attracted much attention and research has been conducted heavily on it. To protect users’ privacy, data is usually encrypted prior to being sent to the cloud server. As the resulting system is unusable, since the cloud can no longer search throughout the data, new cryptographic primitive such as public-key encryption with equality test (PKEET) has been introduced. In PKEET, users can test whether the underlying messages of two ciphertexts encrypted under different public keys are equal or not without the need to decrypt those ciphertexts. This is a very useful tool, especially for the cloud database, since PKEET mainly focuses on the equality test between two ciphertexts. However, in practice, the cloud server may need to verify the equivalence among more than two ciphertexts. This leads to disclosing unnecessary information of users and redundant computation cost will also occur when using traditional PKEET schemes. How to make this more efficient and practical remains an interesting research problem. In this article, to solve the aforementioned problems by providing a novel concept of public-key encryption with multi-ciphertext equality test (PKE-MET). In PKE-MET, each ciphertext can designate a number$s$such that the cloud server can only perform equality test on this ciphertext with other$s-1$ciphertexts, where all their designated numbers are$s$. For PKE-MET, besides traditional OW-CPA and IND-CPA security, we specially define Number security. We instantiate PKE-MET to a concrete scheme and give its security proof. Furthermore, to enable the primitive to be more practical in applications, we extend it to the concept of PKE with flexible MET (PKE-FMET). In PKE-FMET, the cloud server can perform equality test on any number of ciphertexts as long as the maximum number of their designated numbers is less than or equal to the number of ciphertexts. We construct a PKE-FMET scheme based on our PKE-MET construction and prove its security under the defined security models. Besides, the performance analysis mainly of efficiency and security between our constructions and existing equality test schemes in cloud computing show that our proposed schemes are more efficient and secure in the multi-ciphertext scenario.
Willy Susilo, Fuchun Guo, Zhen Zhao 0005, Ge Wu 0001
IEEE Trans. Cloud Comput.3
2022 An Anonymous Authentication System for Pay-As-You-Go Cloud Computing$^*$*
abstract
Cloud computing offers on-demand availability of computing resources over the Internet. To attract users, cloud providers offer their resources as services at reasonable prices and provide various price models to reflect higher level of quality of service (QoS), which are referred as pricing schemes.$k$-times anonymous authentication ($k$-TAA) is an attractive approach to construct pricing schemes, providing access controllability, user anonymity and public traceability. In$k$-TAA schemes, authenticated users are permitted to anonymously access services from a provider at most$k$times, while the ones whose the number of access times exceeds$k$can be publicly traced. That is,$k$-TAA schemes offer a prepaid plan that charges users based on the amount of access times. Alternatively, pay-as-you-go (PAYG) is a pricing strategy that allows users to be charged based on the amount of usage, reducing the costs on unnecessary resources. Adopting$k$-TAA schemes to PAYG model, the access bound$k$is decided by the prepayment amount and the service usage is tracked by the number of access times. However, this approach is impractical, since existing$k$-TAA schemes only allow an one-time access in an authentication. This article aims to bridge this gap in the literature by designing an efficient and secure authentication system for PAYG cloud computing, supporting flexible access controllability, user anonymity and public traceability. To achieve this, we propose a new$k$-TAA primitive, called$k$-times anonymous pay-as-you-go authentication ($k$-TAA-PAYG), that allows users to access services for multiple times in an authentication as long as the number of their access times does not exceed$k$. We first formalize the definition and security model for$k$-TAA-PAYG scheme. Subsequently, we present a concrete construction of$k$-TAA-PAYG scheme, with the computational complexity as$O(1)$and the constant communicational cost. Finally, comparing with the most efficient$k$-TAA scheme proposed by Emuraet al., the experimental results show that our$k$-TAA-PAYG scheme is 2.5 to 3 times faster and saves up to 66 percent storage in grant processes. The time cost of an authentication of our$k$-TAA-PAYG scheme is constant (1.4-2.4 ms), while Emuraet al.’s scheme needs more than one second when the number of access time is greater than 1, 000.
Jianye Huang 0001, Willy Susilo, Fuchun Guo, Ge Wu 0001, Zhen Zhao 0005, Qiong Huang 0001
IEEE Trans. Dependable Secur. Comput.5
2021 Lightweight Public Key Encryption With Equality Test Supporting Partial Authorization in Cloud Storage
abstract
Abstract Public key encryption with equality test (PKEET) can check whether two ciphertexts are encrypted from the same message or not without decryption. This attribute enables PKEET to be increasingly utilized in cloud storage, where users store their encrypted data on the cloud. In traditional PKEET, the tester is authorized by the data receiver to perform equality test on its ciphertexts. However, the tester can only test one ciphertext or all ciphertexts of one receiver with one authorization. It means that the receiver cannot adaptively authorize the test right of any number of ciphertexts to the tester. A trivial solution is authorizing one ciphertext each time and repeating multiple times. The corresponding size of trapdoor in this method is linear with the number of authorized ciphertexts. This will incur storage burden for the tester. To solve the aforementioned problem, we propose the concept of PKEET supporting partial authentication (PKEET-PA). We then instantiate the concept to a lightweight PKEET-PA, which achieves constant-size trapdoor. Besides, we prove the security of our PKEET-PA scheme against two types of adversaries. Compared with other PKEET schemes that can be used in trivial solution, our PKEET-PA is more efficient in receivers’ computation and has lower trapdoor size.
Zhen Zhao 0005, Fei Gao 0001, Willy Susilo, Qiaoyan Wen, Fuchun Guo, Yijie Shi
Comput. J.2
2021 Generic construction for tightly-secure signatures from discrete log
Jianchang Lai, Ge Wu 0001, Peng Jiang 0007, Zhen Zhao 0005, Willy Susilo, Fuchun Guo
Theor. Comput. Sci.4
2020 On the General Construction of Tightly Secure Identity-Based Signature Schemes
abstract
Abstract A tightly secure scheme has a reduction, where the reduction loss is a small constant. Identity-based signature (IBS) is an important cryptographic primitive, and tightly secure IBS schemes enjoy the advantage that the security parameter can be optimal to achieve a certain security level. General constructions of IBS schemes (Bellare, M., Namprempre, C., and Neven, G. (2004) Security Proofs for Identity-Based Identification and Signature Schemes. In Proc. EUROCRYPT 2004, May 2–6, pp. 268–286. Springer, Berlin, Interlaken, Switzerland; Galindo, D., Herranz, J., and Kiltz, E. (2006) On the Generic Construction of Identity-Based Signatures With Additional Properties. In Proceedings of ASIACRYPT 2006, December 3–7, pp. 178–193. Springer, Berlin, Shanghai, China) and their security have been extensively studied. However, the security is not tight and how to generally construct a tightly secure IBS scheme remains unknown. In this paper, we concentrate on the general constructions of IBS schemes. We first take an insight into previous constructions and analyze the reason why it cannot achieve tight security. To further study possible tightly secure constructions, we propose another general construction, which could be seen as a different framework of IBS schemes. Our construction requires two traditional signature schemes, whereas the construction by Bellare et al. uses one scheme in a two-round iteration. There are no additional operations in our general construction. Its main advantage is providing the possibility of achieving tight security for IBS schemes in the random oracle model. Combining two known signature schemes, we present an efficient IBS scheme with tight security as an example.
Ge Wu 0001, Zhen Zhao 0005, Fuchun Guo, Willy Susilo, Futai Zhang
Comput. J.2
2020 Black-Box Accountable Authority Identity-Based Revocation System
abstract
Abstract Identity-based revocation system (IBRS) generates the ciphertext with a revoked identity list such that only the non-revoked identities can use their private keys to decrypt this ciphertext. IBRS can be efficiently applied in some practical applications, such as the pay-TV systems when the number of revoked identities are much less than the non-revoked ones. However, since IBRS is based on identity-based cryptography, it also suffers from the inherent key escrow problem where the private key generator (PKG) has full control of each user’s private key. As a consequence, it is hard to judge whether a pirated private key is generated by the PKG or the suspected user. There is no study on IBRS fulfilling accountability in literature to date. In this paper, we introduce the notion of accountable authority IBRS (A-IBRS), which provides accountability in IBRS schemes. In an A-IBRS, the aforementioned problem can be alleviated and resolved. Furthermore, a full black-box A-IBRS can distinguish the creator of a black box between the PKG and the associated user and the dishonest PKG is allowed to access the decryption results of the user private key. We formalize the definition and security models of the full black-box A-IBRS schemes. Then, we present a concrete full black-box A-IBRS scheme with constant-size master public key and private key. Finally, we prove the security of our scheme under the defined security models without random oracle.
Zhen Zhao 0005, Ge Wu 0001, Fuchun Guo, Willy Susilo, Yi Mu 0001, Baocang Wang, Yupu Hu
Comput. J.1
2020 Highly Secure Privacy-Preserving Outsourced k-Means Clustering under Multiple Keys in Cloud Computing
abstract
Data clustering is the unsupervised classification of data records into groups. As one of the steps in data analysis, it has been widely researched and applied in practical life, such as pattern recognition, image processing, information retrieval, geography, and marketing. In addition, the rapid increase of data volume in recent years poses a huge challenge for resource-constrained data owners to perform computation on their data. This leads to a trend that users authorize the cloud to perform computation on stored data, such as keyword search, equality test, and outsourced data clustering. In outsourced data clustering, the cloud classifies users’ data into groups according to their similarities. Considering the sensitive information in outsourced data and multiple data owners in practical application, it is necessary to develop a privacy-preserving outsourced clustering scheme under multiple keys. Recently, Rong et al. proposed a privacy-preserving outsourced k-means clustering scheme under multiple keys. However, in their scheme, the assistant server (AS) is able to extract the ratio of two underlying data records, and key management server (KMS) can decrypt the ciphertexts of owners’ data records, which break the privacy security. AS can even reduce all data records if it knows one of the data records. To solve the aforementioned problem, we propose a highly secure privacy-preserving outsourced k-means clustering scheme under multiple keys in cloud computing. In this paper, noncolluded cloud computing service (CCS) and KMS jointly perform clustering over the encrypted data records without exposing data privacy. Specifically, we use BCP encryption which has additive homomorphic property and AES encryption to double encrypt data records, where the former cryptosystem prevents CCS from obtaining any useful information from received ciphertexts and the latter one protects data records from being decrypted by KMS. We first define five protocols to realize different functions and then present our scheme based on these protocols. Finally, we give the security and performance analyses which show that our scheme is comparable with the existing schemes on functionality and security.
Ying Zou 0008, Zhen Zhao 0005, Sha Shi, Lei Wang 0031, Yuan Ping 0003, Baocang Wang
Secur. Commun. Networks2
2020 Accountable authority identity-based broadcast encryption with constant-size private keys and ciphertexts
Zhen Zhao 0005, Fuchun Guo, Jianchang Lai, Willy Susilo, Baocang Wang, Yupu Hu
Theor. Comput. Sci.1
2019 Accountable identity-based encryption with distributed private key generators
Zhen Zhao 0005, Ge Wu 0001, Willy Susilo, Fuchun Guo, Baocang Wang, Yupu Hu
Inf. Sci.1