Yinghui Zhang 0002

dblp:31/3845-2 · also Ying-Hui Zhang 0002 · DBLP profile ↗
← Back
86ranked-venue papers
29as first author
42since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 30 · 10 first-author · 14 since 2021Computer networks · 22 · 7 first-author · 11 since 2021Systems, architecture and hardware · 14 · 2 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 3 first-author · 5 since 2021Databases, data management, data science and information retrieval · 5 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-author
YearPublicationVenuePosition
2026 Fuzzy Matching Data Sharing With Equality Test for Internet of Medical Things
abstract
The contemporary healthcare ecosystem is being radically reshaped by the burgeoning deployment of Internet of Medical Things (IoMT) technologies; however, this ubiquity inevitably expands the attack surface regarding data confidentiality and user privacy. To mitigate the risk of sensitive physiological data leakage, this paper introduces a novel cryptographic primitive: Fuzzy Matching Data Sharing with Equality Test (FMDS-ET), optimized for the constraints of IoMT environments. Distinct from traditional approaches, our construction enforces a bilateral fine-grained access control mechanism. Specifically, decryption is authorized if and only if the cardinality of the intersection between the attribute sets and access policies of both the transmitter and the recipient surpasses a predefined threshold. This design not only bolsters the resilience of mutual authentication but also facilitates secure data dissemination and ciphertext equality test. Furthermore, it provides a viable solution for privacy-preserving data classification and record linkage. We provide a formal definition of the system syntax and prove its semantic security in the random oracle model. Comprehensive performance evaluations confirm that the proposed scheme maintains low computational overhead, rendering it highly feasible for resource-constrained medical sensors.
Yinghui Zhang 0002, Yong Yu 0002, Qiuxia Zhao, Dong Zheng 0001
IEEE Internet Things J.2
2026 Bilateral-verifiable and robust secure aggregation via TEE for asynchronous federated learning
Wei Liu 0149, Yinghui Zhang 0002, Axin Wu, Jin Cao 0001, Yunling Wang, Yangguang Tian
J. Inf. Secur. Appl.2
2026 Secure aggregation with verifiability and robustness for privacy-preserving federated learning
Yinghui Zhang 0002, Wei Liu 0149, Jin Cao 0001, Yangguang Tian
Knowl. Based Syst.1
2026 Anonymous and Byzantine-Robust Federated Learning With Secure and Efficient Aggregation
abstract
Federated learning (FL) serves as a distributed machine learning framework that addresses the challenges of data silos while preserving data privacy. Specifically, FL enables multiple participants to collaboratively train a global model by sharing local updates without exposing their raw local data. Although FL achieves physical data isolation through local update sharing mechanisms, it still faces emerging security threats. On the one hand, adversaries may reconstruct sensitive data features or infer client attributes by analyzing local updates. On the other hand, clients might upload malicious updates to disrupt global model aggregation, causing performance degradation. To solve these issues, we propose an anonymous and Byzantine-robust FL scheme with secure and efficient aggregation. First, we propose a single-masking protocol that not only preserves data privacy but also enhances aggregation efficiency. Second, we eliminate client message metadata, such as source IP addresses and timestamps, through secure shuffling, achieving client anonymity in conjunction with the single-masking protocol. Additionally, we implement a baffle mechanism to resist the impact of malicious updates on the global model, thereby ensuring Byzantine robustness. Security analysis demonstrates that our scheme simultaneously preserves data privacy and identity anonymity. Experimental results show that our scheme can effectively resist poisoning attacks, even if 50% of the fog nodes are contaminated by malicious clients. Moreover, the aggregation efficiency of the proposed scheme is improved by over 20%.
Wei Liu 0149, Yinghui Zhang 0002, Axin Wu, Jin Cao 0001, Yangguang Tian
IEEE Trans. Dependable Secur. Comput.2
2025 NSAA: A Network Slice Access Authentication and Service Authorization Scheme for Integrated Satellite-Terrestrial Network
abstract
Introducing slicing into integrated satellite-terrestrial networks enables the flexible deployment of network resources and being adaptable for more new applications. However, the heterogeneity of integrated satellite-terrestrial network poses challenges to network resource access control. To ensure users can securely and efficiently access service across multiple management domains, we propose a network slice access authentication and service authorization scheme based on a sharding permissioned blockchain. Slice tenants and wireless network operators with management control act as consortium blockchain nodes, which are divided into shards, and the blockchain is maintained in parallel by multiple shards. First, an efficient public ledger is constructed to establish decentralized trust and manage user identity and service authorization information. Second, utilizing the trapdoor collision resistance of the chameleon hash, users can fully self-select their secret key and generate authentication credentials to register on the blockchain without key escrow problem. When users move into a new network domain, the mutual authentication between users and the visited network can be quickly completed. The session key is negotiated based on the Diffie-Hellman ephemeral protocol with perfect forward secrecy. Then, the editable transaction blocks, storing network slice authorization information and slice templates, are linked using chameleon hashes. This allows the access permissions of slice resources to be dynamically adjusted and easily queried by the service-providing wireless network operators. Performance evaluation and security simulations demonstrate the correctness of the scheme, showing that it can achieve secure access to integrated satellite-terrestrial network slice services with low computational and communication overhead.
Yurong Luo, Jin Cao 0001, Ruhui Ma, Ben Niu 0001, Yinghui Zhang 0002, Hui Li 0006
IEEE Internet Things J.6
2025 A Formal Analysis of 5G ProSe AKA Protocols for U2N Relay Communication
abstract
5G Proximity-based Service (ProSe) UE-to-Network (U2N) Relay can help a remote 5G User Equipment (UE) out of coverage connect with the network. The 3GPP committee has provided the standard Authentication and Key Agreement (AKA) protocols to achieve secure access for a Remote UE and establish a secure link between a Remote UE and a U2N Relay. However, the security of these AKA protocols is a remaining issue. At first, we present two detailed 5G ProSe AKA protocols over Control Plane (CP) and User Plane (UP) for U2N Relay communication referring to multiple related standards, then transform the security requirements for 5G ProSe U2N Relay communication as formal security properties, and provide two formal faithful security models for the 5G ProSe AKA protocols. We adopt the state-of-the-art formal verification tool Tamarin to achieve automated security analysis on two models through new proof strategies, and then find some significant and unexpected flaws. Finally, we propose corresponding measures that have least impact on standards based on the analysis on the attacks. Given that the version of Release 17 (R17) of the 3GPP standard has just been frozen, our work can provide a reference for the subsequent evolution of the protocols in 5G ProSe.
Xiongpeng Ren, Jin Cao 0001, Ben Niu 0001, Yinghui Zhang 0002, Lihui Xiong, Yurong Luo, Hui Li 0006
IEEE Trans. Dependable Secur. Comput.5
2025 AotmAuth: Atomic Function Module-Based 6G Authentication Protocol Combination Framework
abstract
Over the years, various mobile communication technologies have been developed and operated simultaneously, which made the mobile communication networks evolved from single-mode access to complex heterogeneous integration. The current 5 G has already accommodated diverse terminals through multiple access paths, but the upcoming 6 G ambitiously aims to achieve ubiquitous connectivity through space-air-ground-sea integrated networks. However, traditional authentication and management protocols, such as EPS-AKA and 5G-AKA, are designed for specific networks and lack the flexibility to adapt to the diverse and dynamic requirements of 6G. This limitation will inevitably result in complex management, enormous overhead, and unmanageable security risks. In this paper, we present an atomic functional module-based 6G authentication protocol combination framework (AotmAuth) to decompose the existing authentication protocols into reusable basic modules, and by combining these modules, flexible authentication protocols can be constructed to meet specific security and performance requirements. The proposed approach can significantly improve the robustness, extensibility and dependability of protocols cobmination, by simplify protocol design, enhance adaptability across diverse scenarios and facilitate quick improvements by replacing or adjusting specific modules. To validate the effectiveness of the proposed solution, we design and develop a 6G heterogeneous access security testbed. The experimental results show that the proposed framework can achieve higher authentication efficiency while ensuring security compared to traditional authentication methods.
Wei Yi 0001, Jin Cao 0001, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006
IEEE Trans. Dependable Secur. Comput.4
2025 Efficient Vehicle Secure Scheduling and Access Authentication Scheme for 5G-Integrated Emergency Rescue Scenario
abstract
With urban population density on the rise, emergency incidents are increasing in both frequency and complexity, placing growing pressure on existing rescue systems. Meanwhile, issues such as slow response times, inadequate coordination mechanisms, and inefficient information exchange further exacerbate the challenges faced by these systems. The integration of Vehicle-to-Everything (V2X) communication and 5G technology offers unprecedented capabilities, such as ultra-low latency and high data throughput, which are critical for real-time coordination and decision-making in emergency rescue scenarios. To establish secure and efficient vehicle communication in 5G and V2X-enabled emergency rescue scenarios, we propose an efficient vehicle secure scheduling and access authentication scheme based on certificateless cryptography and multireceiver signcryption. In this scheme, the command and control center can securely dispatch rescue fleets based on disaster conditions. By enabling mutual authentication and key agreement between rescue vehicles and roadside units, the scheme ensures the reliable and swift exchange of rescue information and instructions. In addition, to address unexpected situations such as traffic congestion, we design a route-switching mechanism. Furthermore, in order to mitigate potential malicious behavior, a vehicle legitimacy revocation mechanism is implemented to ensure the normal operation of the system. The security of the scheme is verified through formal analysis and informal analysis. Performance analysis demonstrates that the scheme offers significant advantages over existing ones in terms of signaling overhead, communication overhead, computational overhead, and energy efficiency.
Jin Cao 0001, Yiqing Xiong, Ruhui Ma, Yinghui Zhang 0002, Ben Niu 0001, Peijie Yin, Hui Li 0006
IEEE Trans. Intell. Transp. Syst.6
2024 UAVA: Unmanned Aerial Vehicle Assisted Vehicular Authentication Scheme in Edge Computing Networks
abstract
In the pursuit of autonomous driving and intelligent traffic management, the core goal of 5G Vehicle-to-Everything (V2X) communication is to enhance the safety and efficiency of transportation systems. Modern transportation networks have evolved into 3-D structures, including bridges and tunnels from traditional 2-D ones, which poses a challenge to fixed base stations-based networks reliant on supporting continuous and seamless coverage. Against this backdrop, unmanned aerial vehicles (UAVs) play a crucial role in developing multidimensional wireless networks due to their flexibility and functionality. This article proposes a UAV-assisted vehicle authentication (UAVA) scheme. It harnesses the efficiency of edge computing and the security of zero-trust architecture, focusing on enhancing the safety and efficiency of V2X communications. The UAVA scheme employs Chebyshev chaotic mapping and elliptic curve cryptography to strengthen communication security, adapting to the dynamic interactions between vehicles and UAVs. We validate the security using BAN logic and the Scyther tool and assess performance through experiments in a real hardware environment. The results indicate that UAVA offers higher security and lower communication overhead in serverless scenarios compared to existing solutions. These comprehensive evaluations show the potential of UAVA for application in intelligent transportation systems, especially in ensuring secure communications.
Zhenyang Guo, Jin Cao 0001, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006
IEEE Internet Things J.4
2024 Efficient public-key searchable encryption against inside keyword guessing attacks for cloud storage
Axin Wu, Fagen Li, Xiangjun Xin 0002, Yinghui Zhang 0002, Jianhao Zhu
J. Syst. Archit.4
2024 Hierarchal Bilateral Access Control With Constant Size Ciphertexts for Mobile Cloud Computing
abstract
Mobile cloud computing (MCC) integrates the advantages of mobile networks and cloud computing, enabling users to enjoy personalized services without constraints and restrictions of time and place. While this brings convenience, it also comes with risks such as privacy breaches and unauthorized access to outsourced data. Bilateral access control is a promising technique for addressing these issues. However, the current bilateral access control schemes cannot solve problems such as single point failure. To further enhance and enrich the existing schemes, we propose hierarchical bilateral access control. In the proposed scheme, the permission of generating encryption keys and decryption keys can be delegated to its child nodes, which alleviates the computation and communication overheads of the parent nodes and weaken the potential risks of single-point failure. Additionally, the ciphertext size remains constant, reducing the costs of transmitting and storing ciphertext and relieving resource limitations on devices. We then prove the privacy and authenticity of the scheme in the random oracle model. Finally, the comprehensive performance comparison and analysis demonstrate the efficiency of the proposed scheme.
Axin Wu, Yinghui Zhang 0002, Jianhao Zhu, Qiuxia Zhao, Yu Zhang 0201
IEEE Trans. Cloud Comput.2
2024 CEAMP: A Cross-Domain Entity Authentication and Message Protection Framework for Intra-Vehicle Network
abstract
Controller Area Network (CAN) is the most wide-used bus system in Intra-Vehicle Networks(IVN). However, the nature of broadcast communication and the lack of security mechanisms make the CAN bus extremely fragile against malicious attacks. Although there are works protecting IVN, most of them are not feasible when applied to real vehicles because they do not consider the IVN node capability. In this paper, we propose a security framework for the CAN bus, covering ECU entity identity management and authentication, symmetric key generation and update, intra-domain, cross-domain secure transmission, and sensitivity-based security classification methods. We formally verify our protocols using the up-to-date tool Tamarin and simulate real attacks in a simulation environment and the results show that the proposed protocol can resist these attacks. By the use of speck encryption and the Chaskey MAC algorithm in our schemes, the analysis results show that the increased time of a frame for a single ECU in our proposed intra-domain scheme is$2.09~ms$to$2.78~ms$on Arduino Mega, and$121.65 \mu s$to$152.15 \mu s$on Arduino DUE, which takes up$6.08\%$to$7.61\%$of a 10ms cyclic time frame. And in the cross-domain scheme is$2.55~ms$to$3.24~ms$on Arduino Mega, and$134.30 \mu s$to$164.80 \mu s$on Arduino DUE, which takes up$6.72\%$to$8.24\%$of a 10ms frame. To the best of our knowledge, this is the first time an IVN cross-domain secure transmission protocol has been proposed without changing the IVN network topology or the CAN protocol. Our work brings practical protection to IVN.
Jin Cao 0001, Jiajia Liu 0001, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006
IEEE Trans. Intell. Transp. Syst.4
2024 An Anonymous and Secure Data Transmission Mechanism With Trajectory Tracking for D2D Relay Communication in 3GPP 5G Networks
abstract
Device-to-device (D2D) communication, as a traffic offloading technology in the fifth-generation (5G) network, can be widely used in several scenarios to provide 5G characteristics of higher speed, lower latency, and larger capacity. D2D data transmission over wireless channels among mobile devices is vulnerable to security threats and privacy violations from third parties and relay nodes. However, academia and industry have yet to propose relevant schemes or standards for D2D relay data transmission scenarios. We first propose a generic construction for D2D relay communication in this paper. Then, a concrete anonymous and secure D2D data transmission scheme with trajectory tracking is presented based on Chebyshev polynomials, hash-based message authentication code, and symmetric encryption. We employ a formal verification tool -Tamarin, modal logic analysis -BAN logic, and informal security analysis to demonstrate the security features of the proposed scheme. The performance evaluation shows that the proposed scheme can achieve desirable efficiency compared with other related schemes. Finally, we developed an APP‘, D2DWatchmen’, to simulate the whole protocol and test its robustness and real execution time, where the result shows good availability and effectiveness.
Yunqing Sun, Jin Cao 0001, Xiongpeng Ren, Canhui Tang, Ben Niu 0001, Yinghui Zhang 0002, Hui Li 0006
IEEE Trans. Intell. Transp. Syst.6
2024 A UAV-Assisted UE Access Authentication Scheme for 5G/6G Network
abstract
Unmanned Aircraft Vehicles (UAVs) equipped with base stations can assist ground User Equipments (UEs) in accessing the 5G/6G network. Due to the UAV’s high autonomy, easy configuration, and strong dynamic deployment capabilities, UAV-assisted ground UEs to access the 5G/6G network can effectively expand the communication network coverage. However, some vulnerabilities exist, such as eavesdropping attack, impersonation attack, etc. In addition, the 3rd Generation Partnership Project (3GPP) committee has proposed that the UAV can employ the primary authentication mechanism (i.e., 5G-AKA) to connect to the network. Nevertheless, the primary authentication mechanism 5G-AKA has some security problems. In this paper, we first improve the existing 5G-AKA, which resists quantum attack and traceability attack and consumes moderate signaling overhead and short running time. Then, based on the improved 5G-AKA protocol, we propose a UAV-assisted UE access authentication scheme for the 5G/6G network. In the proposed scheme, the UAV can perform the service access authentication process to access the 5G/6G core network and then execute the UAV-assisted UE access authentication process to assist UE in obtaining network services. Additionally, the ground UE can perform a fast and secure handover process with the target UAV to ensure continuous network services. The automation verification tool Tamarin is employed to verify the security of the proposed scheme. Additionally, we implement the improved 5G-AKA protocol and the existing 5G-AKA protocol on Field Programmable Gate Array (FPGA) to test their running time. The security and performance evaluation results show that the proposed scheme provides robust security with moderate efficiency.
Ruhui Ma, Jin Cao 0001, Shiyang He, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006
IEEE Trans. Netw. Serv. Manag.4
2024 Efficient Bilateral Privacy-Preserving Data Collection for Mobile Crowdsensing
abstract
Mobile crowdsensing (MCS) utilizes ubiquitous mobile devices to collect massive amounts of data and offer various high-quality services. During the data collection and upload process, bilateral access control is implemented to recruit qualified data providers and prevent unauthorized access to collected data. However, the efficiency of existing bilateral access control schemes applicable in the data collection phase is dissatisfactory, as their ciphertext sizes are linear with the number of attributes. Additionally, data confidentiality and authenticity, as well as lightweight encryption and decryption processes, are crucial for the deployment of MCS since the former eliminate the risks of data abuse and false data injection, and the latter are typically limited in their computation and communication resources. To reduce the resource consumption of these devices, we present EBAC-CC, an efficient bilateral access control with constant-size ciphertexts that ensures data confidentiality and authenticity and allows for flexible threshold bilateral access control. Besides, offline/online techniques and outsourced decryption are employed to quickly generate ciphertexts and recover perceptual data, which also alleviates their computation burdens. We also prove its privacy and authenticity in the standard model and evaluate its efficacy theoretically and experimentally, demonstrating its superiority over other bilateral access control schemes.
Axin Wu, Weiqi Luo 0002, Anjia Yang, Yinghui Zhang 0002, Jianhao Zhu
IEEE Trans. Serv. Comput.4
2023 DP-Loc: A Differential Privacy-Based Indoor Localization Scheme with Bilateral Privacy Protection
Yinghui Zhang 0002, Hao Du 0006, Jin Cao 0001, Dong Zheng 0001
Inscrypt (2)1
2023 LK-AKA: A lightweight location key-based authentication and key agreement protocol for S2S communication
Jin Cao 0001, Xiongpeng Ren, Ben Niu 0001, Yinghui Zhang 0002, Hui Li 0006
Comput. Commun.5
2023 A fine-grained medical data sharing scheme based on federated learning
abstract
Abstract With the rapid development of smart health, the privacy problem of medical data has become more prominent. Aiming at the problem of mining the potential value of medical data and realizing secure sharing, a fine‐grained medical data sharing scheme based on federated learning is proposed. The scheme uses collaboration‐oriented attribute‐based encryption technologies to formulate fine‐grained access strategies, allowing medical institutions or doctors to decrypt individually or collaboratively with certain conditions to achieve the purpose of accurately screening the required medical data. In the proposed scheme, the model parameters are shared such that the screened medical data is modeled and analyzed based on federated learning, which allows more people to enjoy top medical resources. In addition, a blockchain‐based incentive mechanism is used to reward medical institutions which are either honest with high‐quality or helpful in decryption. Hence, the enthusiasm of various medical institutions to screen data and participate in federal learning is improved. Finally, security analysis shows that the scheme is secure, and theoretical analysis and simulation test show the practicability of the scheme.
Wei Liu 0149, Yinghui Zhang 0002, Dong Zheng 0001
Concurr. Comput. Pract. Exp.2
2023 Secure and Efficient Smart Healthcare System Based on Federated Learning
abstract
The rapid development of smart healthcare system in the Internet of Things (IoT) has made the early detection of many chronic diseases more convenient, quick, and economical. However, when healthcare organizations collect users’ health data through deployed IoT devices, there are issues of compromising users’ privacy. In view of this situation, this paper introduces federated learning technology to solve the problem of data security. In this paper, we consider the two main problems of federated learning applications in IoT smart healthcare system: (1) how to reduce the time overhead of system running and (2) how to authenticate that the user device uploading data is deployed by the system itself. To solve the above problems, we propose the first federated learning scheme based on full dynamic secret sharing. First, we use a two‐mask protocol to keep the user’s local model parameters confidential during federated learning. Then, based on homogeneous linear recursive equation, homomorphic hash function, and elliptic curve cryptosystem, the full dynamic secret sharing and user identity authentication are realized. In addition, our scheme allows users to join or quit during training. Finally, we have carried out simulation test on this scheme. The experimental results show that the efficiency of our scheme is improved by about 60% on average in the case of no user dropping and by about 30% in the case of some users dropping.
Wei Liu 0149, Yinghui Zhang 0002, Jin Cao 0001, Hui Cui 0001, Dong Zheng 0001
Int. J. Intell. Syst.2
2023 Multi-Keyword Searchable and Verifiable Attribute-Based Encryption Over Cloud Data
abstract
In cloud data sharing systems, Searchable Encryption (SE) schemes ensure data confidentiality with retrieving, but it faces several issues in practice. First, most of the previous Ciphertext-Policy Attribute-Based Keyword Search (CP-ABKS) systems enable users to initiate search requests with a single keyword, which results in many inaccurate results to be returned, thereby wasting computing and bandwidth resources. Second, untrusted cloud servers may return a small portion of incomplete search results to compress communication overhead. Besides, most CP-ABKS schemes only support an unshared multi-owner setting, which incurs a large amount of computational and storage overhead. Furthermore, when the keyword space is a polynomial, most of the previous schemes suffer from offline keyword guessing attacks. To address these issues, we focus on a multi-keyword search scheme which supports the verification of search results without losing efficiency by combining Ciphertext Policy Attribute-Based Encryption (CP-ABE) technology under the shared multi-owner mechanism. We show the security of our scheme, which achieves selective security against offline keyword guessing attacks and guarantees the unforgeability of signatures. The comparison of experimental results illustrates that our scheme is effective and enjoys superior functionalities than the most relevant solutions.
Yinghui Zhang 0002, Rui Guo 0005, Shengmin Xu, Hui Cui 0001, Jin Cao 0001
IEEE Trans. Cloud Comput.1
2023 A Software-Based Remote Attestation Scheme for Internet of Things Devices
abstract
With the rapid development of intelligent applications, many Internet of Things (IoT) devices are deployed in various application scenarios, playing an extremely important role. Remote attestation is an important method to ensure the software integrity of these devices and protect them from several attacks. Due to the lack of security hardware and no support of hardware extensions for Class-1 IoT devices, it is particularly important to design a suitable remote attestation scheme for these devices. In this paper, we first propose the delayed observation mechanism to alleviate the problem that the software-based remote attestation scheme is not suitable for wireless networks. At the same time, we propose a ”filling memory at attestation-time” mechanism, which solves the problem that attackers hide malicious code through return-oriented programming. Finally, we introduce a reputation mechanism to assist our attestation, and adopt the principle of ”making higher-performance verification nodes take on more work” to greatly reduce the time-consuming attestation. We analyze the security of the scheme and implement it on a UNO-R3 development board to prove its practicability and effectiveness. Compared with traditional software-based attestation schemes, our scheme can reduce the attestation time and resist proxy attacks.
Jin Cao 0001, Ruhui Ma, Zhenyang Guo, Yinghui Zhang 0002, Hui Li 0006
IEEE Trans. Dependable Secur. Comput.5
2023 A Novel Authentication Scheme Supporting Multiple User Access for 5G and Beyond
abstract
The deployment of ultra-dense networks in the fifth-generation (5 G) network architecture can significantly improve the quality of wireless links, but this will cause frequent handovers of mobile users and increase authentication delays. Furthermore, the simultaneous influx of a large number of mobile users may cause serious network congestion. Aiming at these problems, this article proposes a novel authentication scheme supporting multi-user access, which fully considers the scenarios of intra-domain handover and inter-domain handover across AMF. Using the characteristics of the network architecture integrated with mobile edge computing (MEC) and software-defined networks (SDN), the user's moving path can be predicted in advance to speed up the handover process. Most importantly, the proposed scheme can perform secure, efficient and flexible mutual authentication and key agreement between the group and the core network by using aggregated message authentication codes with detecting functionality (AMAD) and contributory broadcast encryption technique. Through the use of BAN Logic and Scyther tool verification, the proposed scheme can not only realize multiple user authentication and key agreement, but also fulfill various security goals. Performance evaluations demonstrate that the proposed scheme has moderate computational and communication overhead, and lower transmission overhead compared with existing schemes, which can effectively reduce authentication delay.
Chengzhe Lai, Rongxing Lu, Yinghui Zhang 0002, Dong Zheng 0001
IEEE Trans. Dependable Secur. Comput.4
2023 A Secure EMR Sharing System With Tamper Resistance and Expressive Access Control
abstract
To reduce the cost of human and material resources and improve the collaborations among medical systems, research laboratories and insurance companies for healthcare researches and commercial activities, electronic medical records (EMRs) have been proposed to shift from paperwork to friendly shareable electronic records. To take advantage of EMRs efficiently and reduce the cost of local storage, EMRs are usually outsourced to the remote cloud for sharing medical data with authorized users. However, cloud service providers are untrustworthy. In this paper, we propose an efficient, secure, and flexible EMR sharing system by introducing a novel cryptosystem called dual-policy revocable attribute-based encryption and tamper resistance blockchain technology. Our proposed system enables EMRs to be shared at a fine-grained level and allows data users to detect any unauthorized manipulation. Moreover, the key generation center can revoke malicious users without affecting the honest users. We provide the formal security model as well as the concrete scheme with security analysis. The experimental simulation and experimental analysis of our proposed scheme demonstrate that our proposed system has superior performances to the most relevant solutions.
Shengmin Xu, Jianting Ning, Yingjiu Li, Yinghui Zhang 0002, Guowen Xu, Xinyi Huang 0001, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.4
2023 A Novel Access and Handover Authentication Scheme in UAV-Aided Satellite-Terrestrial Integration Networks Enabling 5G
abstract
As an outlook of the terrestrial network, the flexible Unmanned Aerial Vehicle (UAV)-aided satellite-terrestrial integration network would have numerous prospective applications such as service enhancement, maritime communication, military, and emergency communication, which is getting significant attention. However, the public and open-access network must result in various imperative risks including impersonation, sensitive data, and privacy disclosure. Due to several unique characteristics including long transmission distance, unstable communication environment, resource-limited and highly dynamic characteristics of UAVs, diversified terminals that lack the ability of accessing the satellite and may be resource-limited, there are new challenges for the access authentication process in the UAV-Aided Satellite-Terrestrial Integration Networks with 5G. In this paper, we present a novel Physically Unclonable Function (PUF)-based access authentication scheme consisting of two access authentication protocols for the UAV and the ground terminals like 5G User Equipments (UEs), respectively. Two access authentication protocols for the drone and the terminals can both achieve mutual authentication, key agreement, and privacy protection with distinct advantages of no need to store secret key and supporting physical attack resistance. Finally, we propose an efficient handover authentication protocol executed by the ground terminals when the UAV is required to switch. We employ different security analysis tools to analyze the security of all proposed protocols, as well as present informal security analysis on various security properties. The performance comparison and evaluations show our protocols have better advantages.
Xiongpeng Ren, Jin Cao 0001, Ruhui Ma, Yurong Luo, Yinghui Zhang 0002, Hui Li 0006
IEEE Trans. Netw. Serv. Manag.6
2022 A Novel PUF-Based Group Authentication and Data Transmission Scheme for NB-IoT in 3GPP 5G Networks
abstract
With the gradual commercialization of the fifth-generation (5G) network, the narrowband Internet of Things (NB-IoT) system would have potential and prospective applications in future relying on the infrastructure. Meanwhile, predictably, there are several security requirements to be satisfied, including concurrent access authentication for massive devices, identity privacy protection, physical attack resistance, application traffic security, etc. In this article, we present a novel group authentication and data transmission scheme using the physically unclonable function (PUF) for NB-IoT in which the output of PUF is viewed as shared root key to achieve the mutual authentication along with key agreement. By this scheme, a Group Leader is employed to aggregate and relay authentication information and, thus, it reduces the signaling cost and communication cost followed by activating attach request messages from a sea of devices. The network side as well can surely find fake ones through individual truncated authentication code and detect honest devices with high probability when aggregated authentication code is invalid. Furthermore, the revised security model and the formal verification tool Scyther are employed to evaluate the security of the scheme. Finally, performance analysis results show that our solution has the desired efficiency.
Xiongpeng Ren, Jin Cao 0001, Maode Ma, Hui Li 0006, Yinghui Zhang 0002
IEEE Internet Things J.5
2022 An Efficient Certificateless Ring Signcryption Scheme With Conditional Privacy-Preserving in VANETs
Rui Guo 0005, Xiong Li 0002, Yinghui Zhang 0002, Xuelei Li
J. Syst. Archit.4
2022 Secure Similarity Search Over Encrypted Non-Uniform Datasets
abstract
Searchable symmetric encryption (SSE) enables a user to outsource a private dataset to a cloud server in encrypted form while retaining the ability to search over the encrypted outsourced data. The existing SSE schemes improve the search and safety performances from different perspectives. However, almost none of the existing SSE schemes considers the data distribution issues. We find that when the dataset is not distributed uniformly, the search quality based on the conventional methods decreases. Therefore, the existing SSE schemes cannot guarantee high search quality when faced with non-uniform datasets. In addition, most existing SSE solutions cannot hide the distribution of the query set. In this article, we design a S\ecure similarity search over Encrypted Non-uniform and high-dimensional Datasets (SEND) with a novel way to enhance security. The basic idea is to combine SSE with locality-sensitive hashing (LSH). Unlike earlier schemes, SEND uses selective hashing, which has better performance for non-uniform datasets. Also, we present a novel approach to hide the distribution of the query set, which makes SEND more secure. Our experimental results indicate SEND achieves a high search quality of recall and precision, and it is proven secure against adaptively chosen query attacks in the standard model.
Cheng Guo 0001, Wanping Liu, Ximeng Liu, Yinghui Zhang 0002
IEEE Trans. Cloud Comput.4
2022 Lightweight and Expressive Fine-Grained Access Control for Healthcare Internet-of-Things
abstract
Healthcare Internet-of-Things (IoT) is an emerging paradigm that enables embedded devices to monitor patients vital signals and allows these data to be aggregated and outsourced to the cloud. The cloud enables authorized users to store and share data to enjoy on-demand services. Nevertheless, it also causes many security concerns because of the untrusted network environment, dishonest cloud service providers and resource-limited devices. To preserve patients’ privacy, existing solutions usually apply cryptographic tools to offer access controls. However, fine-grained access control among authorized users is still a challenge, especially for lightweight and resource-limited end-devices. In this paper, we propose a novel healthcare IoT system fusing advantages of attribute-based encryption, cloud and edge computing, which provides an efficient, flexible, secure fine-grained access control mechanism with data verification in healthcare IoT network without any secure channel and enables data users to enjoy the lightweight decryption. We also define the formal security models and present security proofs for our proposed scheme. The extensive comparison and experimental simulation demonstrate that our scheme has better performance than existing solutions.
Shengmin Xu, Yingjiu Li, Robert H. Deng, Yinghui Zhang 0002, Xiangyang Luo 0001, Ximeng Liu
IEEE Trans. Cloud Comput.4
2022 Dual Access Control for Cloud-Based Data Storage and Sharing
abstract
Cloud-based data storage service has drawn increasing interests from both academic and industry in the recent years due to its efficient and low cost management. Since it provides services in an open network, it is urgent for service providers to make use of secure data storage and sharing mechanism to ensure data confidentiality and service user privacy. To protect sensitive data from being compromised, the most widely used method is encryption. However, simply encrypting data (e.g., via AES) cannot fully address the practical need of data management. Besides, an effective access control over download request also needs to be considered so that Economic Denial of Sustainability (EDoS) attacks cannot be launched to hinder users from enjoying service. In this article, we consider thedual access control, in the context of cloud-based storage, in the sense that we design a control mechanism over both data access and download request without loss of security and efficiency. Two dual access control systems are designed in this article, where each of them is for a distinct designed setting. The security and experimental analysis for the systems are also presented.
Jianting Ning, Xinyi Huang 0001, Willy Susilo, Kaitai Liang, Ximeng Liu, Yinghui Zhang 0002
IEEE Trans. Dependable Secur. Comput.6
2022 EAP-DDBA: Efficient Anonymity Proximity Device Discovery and Batch Authentication Mechanism for Massive D2D Communication Devices in 3GPP 5G HetNet
abstract
Device-to-device (D2D) communication as direct communication technology has many application scenarios and plays a very important role in the fifth-generation (5G) era. Using D2D communication in third generation partnership project (3GPP) 5G Heterogeneous Network (HetNet) can effectively relieve the network traffic pressure and reduce the energy consumption of the base station. However, there are numerous security threats in D2D applications since the D2D communication remains in the early stage. The existing standards and solutions rarely consider device discovery, efficient authentication, mutual authentication, and key negotiation with privacy protection for D2D user equipment (UE) in heterogeneous access scenarios. In this article, we present a unified efficient anonymity proximity device discovery and batch authentication mechanism for heterogeneous D2D UEs based on a new proposed efficient pairing-free certificateless batch signature (CLBS), the identity-based prefix encryption and Chinese remainder theorem (CRT). Our proposed scheme can be applied to all the 5G heterogeneous access scenarios of D2D communication. The security analysis and performance results show that our scheme can achieve mutual authentication, key agreement, identity privacy protection, batch verification, and resist several protocol attacks with ideal efficiency.
Yunqing Sun, Jin Cao 0001, Maode Ma, Yinghui Zhang 0002, Hui Li 0006, Ben Niu 0001
IEEE Trans. Dependable Secur. Comput.4
2022 Match in My Way: Fine-Grained Bilateral Access Control for Secure Cloud-Fog Computing
abstract
Cloud-fog computing is a novel paradigm to extend the functionality of cloud computing to provide a variety of on-demand data services via the edge network. Many cryptographic tools have been introduced to preserve data confidentiality against the untrustworthy network and cloud servers. However, how to efficiently identify and retrieve useful data from a large number of ciphertexts without a costly decryption mechanism remains a challenging problem. In this article, we introduce a cloud-fog-device data sharing system (CFDS) with data confidentiality and data source identification simultaneously based on a new cryptographic primitive named matchmaking attribute-based encryption (MABE) by extending matchmaking encryption in CRYPTO’19. Our solution offers a secure fine-grained bilateral access control that includes (1) fine-grained sender access control, (2) fine-grained receiver access control, (3) sender privacy, and (4) performance optimization via outsourcing data source identification to fog nodes. We give the formal definition and security models of MABE, and present a concrete construction with formal security proofs. We also offer a detailed security analysis of our proposed CFDS against real-world security threats. The extensive comparison and experimental simulation demonstrate that, by immigrating heavy workload to fog nodes, our scheme has better functionalities and performances than the most related solutions.
Shengmin Xu, Jianting Ning, Yingjiu Li, Yinghui Zhang 0002, Guowen Xu, Xinyi Huang 0001, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.4
2022 TRAC: Traceable and Revocable Access Control Scheme for mHealth in 5G-Enabled IIoT
abstract
Mobile healthcare (mHealth) enables people to collect and share their personal health records (PHRs) and gain rapid medical treatment via mobile 5G-enabled Industrial Internet of Things (IIoT) devices, which also brings the challenge of keeping the PHRs confidentiality and preventing unauthorized access. By the emerging ciphertext-policy attribute-based encryption (CP-ABE), the PHR owner can encrypt his/her PHR data under self-defined access policies. However, existing CP-ABE schemes are suffering from either heavy computation cost and storage overhead or traitor tracing and direct revocation. In this article, we propose an efficient, traceable, and revocable access control scheme named TRAC for mHealth in 5G-enabled IIoT. In TRAC, the ciphertext is composed of the attribute-relevant ciphertext encrypted under anand-gate access structure and the identity-relevant ciphertext associated with some potential receivers. The malicious user who leaks his/her privilege to unauthorized entities will be precisely tracked and added in the revocation list, by which the cloud server can update the identity-relevant ciphertext by itself. The length of final ciphertext and the time of bilinear pairing operations used in decryption are constant. The security analysis and performance evaluation indicate the security, efficiency, and practicality of TRAC.
Qi Li 0011, Bin Xia 0003, Haiping Huang, Yinghui Zhang 0002, Tao Zhang 0029
IEEE Trans. Ind. Informatics4
2022 A Group-Based Multicast Service Authentication and Data Transmission Scheme for 5G-V2X
abstract
5G Vehicular to everything (5G-V2X) has grown more vigorously than ever before, and services massive vehicles can obtain provided by content providers via the network in all fields are widely acknowledged, such as listening to news channels and traffic channels. In the 5G-V2X network, content providers can provide service messages to a group of vehicles belonging to a specific area in point-to-multipoint transmission mode. However, various challenges are in front of the way when vehicles obtain multicast services due to the unique features of 5G-V2X, such as massive vehicles and strong mobility. In this paper, we present a typical vehicle multicast service model in 5G-V2X and propose a group-based multicast service authentication and data transmission scheme based on this model. In the scheme, massive vehicles within the same RAN coverage are constructed into a group and connected to the content provider to gain access to a multicast service using the distributed keys securely by the 5G home network. Subsequently, the multicast service key for protecting the multicast service data is distributed to each vehicle so that the multicast service data can be securely transmitted to vehicles in point-to-multipoint mode. The security analysis results using the formal verification tool and informal security analysis show that the proposed scheme supports the multicast services authentication and authorization, multicast service data protection, key distribution protection, anonymity, unlinkability, and protocol attack resistance. The performance analysis results regarding signaling, computational and communication overheads show that the proposed scheme outperforms other related schemes.
Ruhui Ma, Jin Cao 0001, Yinghui Zhang 0002, Lihui Xiong, Hui Li 0006
IEEE Trans. Intell. Transp. Syst.3
2021 Flexible and anonymous network slicing selection for C-RAN enabled 5G service authentication
Yinghui Zhang 0002, Axin Wu, Dong Zheng 0001, Jin Cao 0001, Xiaohong Jiang 0001
Comput. Commun.1
2021 Secure Collaborative Deep Learning Against GAN Attacks in the Internet of Things
abstract
Deep learning makes the Internet-of-Things (IoT) devices more attractive, and in turn, IoT facilitates the resolution of the contradiction between data collection and privacy concerns. IoT devices with small-scale computing power can contribute to model training without sharing data in collaborative learning. However, collaborative learning is susceptible to generative adversarial network (GAN) attack, where an adversary can pretend to be a participant engaging in the model training and learn other participants' data. In this article, we propose a secure collaborative deep learning model which resists GAN attacks. We isolate the participants from the model parameters, and realize the local model training of participants via the interaction mode, ensuring that neither the participants nor the server would have access to each other's data. In particular, we target convolutional neural networks, the most popular network, design specific algorithms for various functionalities in different layers of the network, making it suitable for deep learning environments. To our best knowledge, this is the first work designing specific protocol against GAN attacks in collaborative learning. The results of our experiments on two real data sets show that our protocol can achieve good accuracy, efficiency, and image processing adaptability.
Zhenzhu Chen, Anmin Fu, Yinghui Zhang 0002, Zhe Liu 0001, Fanjian Zeng, Robert H. Deng
IEEE Internet Things J.3
2021 O3-R-CP-ABE: An Efficient and Revocable Attribute-Based Encryption Scheme in the Cloud-Assisted IoMT System
abstract
With the processes of collecting, analyzing, and transmitting the data in the Internet of Things (IoT), the Internet of Medical Things (IoMT) comprises the medical equipment and applications connected to the healthcare system and offers an entity with real time, remote measurement, and analysis of healthcare data. However, the IoMT ecosystem deals with some great challenges in terms of security, such as privacy leaking, eavesdropping, unauthorized access, delayed detection of life-threatening episodes, and so forth. All these negative effects seriously impede the implementation of the IoMT ecosystem. To overcome these obstacles, this article presents an efficient, outsourced online/offline revocable ciphertext policy attribute-based encryption scheme with the aid of cloud servers and blockchains in the IoMT ecosystem. Our proposal achieves the characteristics of fine-grained access control, fast encryption, outsourced decryption, user revocation, and ciphertext verification. It is noteworthy that based on the chameleon hash function, we construct the private key of the data user with collision resistance, semantically secure, and key-exposure free to achieve revocation. To the best of our knowledge, this is the first protocol for a revocation mechanism by means of the chameleon hash function. Through formal analysis, it is proven to be secure in a selectively replayable chosen-ciphertext attack (RCCA) game. Finally, this scheme is implemented with the Java pairing-based cryptography library, and the simulation results demonstrate that it enables high efficiency and practicality, as well as strong reliability for the IoMT ecosystem.
Rui Guo 0005, Huixian Shi, Yinghui Zhang 0002, Dong Zheng 0001
IEEE Internet Things J.4
2021 Secure and verifiable outsourced data dimension reduction on dynamic data
Zhenzhu Chen, Anmin Fu, Robert H. Deng, Ximeng Liu, Yang Yang 0026, Yinghui Zhang 0002
Inf. Sci.6
2021 Efficient privacy-preserving authentication for V2G networks
Yinghui Zhang 0002, Rui Guo 0005
Peer-to-Peer Netw. Appl.1
2021 Robust and Universal Seamless Handover Authentication in 5G HetNets
abstract
The evolving fifth generation (5G) cellular networks will be a collection of heterogeneous and backward-compatible networks. With the increased heterogeneity and densification of 5G heterogeneous networks (HetNets), it is important to ensure security and efficiency of frequent handovers in 5G wireless roaming environments. However, existing handover authentication mechanisms still have challenging issues, such as anonymity, robust traceability and universality. In this paper, we address these issues by introducing RUSH, a Robust and Universal Seamless Handover authentication protocol for 5G HetNets. In RUSH, anonymous mutual authentication with key agreement is enabled for handovers by exploiting the trapdoor collision property of chameleon hash functions and the tamper-resistance of blockchains. RUSH achieves universal handover authentication for all the diverse mobility scenarios, as exemplified by the handover between 5G new radio and non-3GPP access regardless of the trustworthiness of non-3GPP access and the consistency of the core network. RUSH also achieves perfect forward secrecy, master key forward secrecy, known randomness secrecy, key escrow freeness and robust traceability. Our formal security proofs based on the BAN-logic and formal verification based on AVISPA indicate that RUSH resists various attacks. Comprehensive performance evaluation and comparisons show that RUSH outperforms other schemes in both computation and communication efficiencies.
Yinghui Zhang 0002, Robert H. Deng, Elisa Bertino, Dong Zheng 0001
IEEE Trans. Dependable Secur. Comput.1
2021 CPPHA: Capability-Based Privacy-Protection Handover Authentication Mechanism for SDN-Based 5G HetNets
abstract
Ultra-dense Heterogeneous network (HetNet) technique can significantly improve wireless link quality, spectrum efficiency and system capacity, and satisfy different requirements for coverage in hotspots, which has been viewed as one of the key technologies in fifth Generation (5G) network. Due to the existence of many different types of base stations (BSs) and the complexity of the network topology in the 5G HetNets, there are a lot of new challenges in security and mobility management aspects for this multi-tier 5G architecture including insecure access points and potential frequent handovers among several different types of base stations. In this paper, we integrate user capability and Software Defined Network (SDN) technique, and propose a capability-based privacy protection handover authentication mechanism in SDN-based 5G HetNets. Our proposed scheme can achieve the mutual authentication and key agreement between User Equipments (UEs) and BSs in 5G HetNets at the same time largely reduce the authentication handover cost. We demonstrate that our proposed scheme indeed can provide robust security protection by employing several security analysis methods including the BAN logic and the formal verification tool Scyther. In addition, the performance evaluation results show that our scheme outperforms other existing schemes.
Jin Cao 0001, Maode Ma, Hui Li 0006, Yinghui Zhang 0002
IEEE Trans. Dependable Secur. Comput.5
2021 On the Security of Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-Owner Setting
abstract
Recently in the IEEE Transactions on Dependable and Secure Computing (doi: 10.1109/TDSC.2019.28976752019), Miao et al. proposed a novel construction of Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-owner Setting (ABKS-SM), which can delegate keyword search tasks to cloud server provider (CSP) without revealing any useful information. Although the authors claimed that the offline keyword guessing attacks can be resisted in ABKS-SM scheme, we show that this scheme indeed suffers from four types of offline keyword guessing attacks and hence fails to gain the claimed security property, which is an important goal to be achieved in searchable encryption schemes. Specifically, given the concrete attacks, we demonstrate that the underlying keyword information can be extracted from both encrypted keyword indexes and trapdoors by any malicious user and any adversarial CSP. We hope that the similar security vulnerabilities could be avoided in the future design of related searchable encryption schemes.
Jianfei Sun, Hu Xiong, Xuyun Nie, Yinghui Zhang 0002, Pengfei Wu 0003
IEEE Trans. Dependable Secur. Comput.4
2021 Outsourcing Service Fair Payment Based on Blockchain and Its Applications in Cloud Computing
abstract
As a milestone in the development of outsourcing services, cloud computing enables an increasing number of individuals and enterprises to enjoy the most advanced services from outsourcing service providers. Because online payment and data security issues are involved in outsourcing services, the mutual distrust between users and service providers may severely impede the wide adoption of cloud computing. Nevertheless, most existing solutions only consider a specific type of services and rely on a trusted third-party to realize fair payment. In this paper, to realize secure and fair payment of outsourcing services in general without relying on any third-party, trusted or not, we introduce BPay, an outsourcing service fair payment framework based on blockchain in cloud computing. We first propose the system architecture, adversary model and design goals of BPay, then describe the design details. Our security and compatibility analysis indicates that BPay achieves soundness and robust fairness and it is compatible with the Bitcoin blockchain and the Ethereum blockchain. The key to the robust fairness and compatibility lies in an all-or-nothing checking-proof protocol and a top-down checking method. In addition, our experimental results show that BPay is computationally efficient. Finally, we present the applications of BPay in outsourcing services.
Yinghui Zhang 0002, Robert H. Deng, Ximeng Liu, Dong Zheng 0001
IEEE Trans. Serv. Comput.1
2020 Catch You If You Deceive Me: Verifiable and Privacy-Aware Truth Discovery in Crowdsensing Systems
abstract
Truth Discovery (TD) is to infer truthful information by estimating the reliability of users in crowdsensing systems. To protect data privacy, many Privacy-Preserving Truth Discovery (PPTD) approaches have been proposed. However, all existing PPTD solutions do not consider a fundamental issue of trust. That is, if the data aggregator (e.g., the cloud server) is not trustworthy, how can an entity be convinced that the data aggregator has correctly performed the PPTD? A "lazy" cloud server may partially follow the deployed protocols to save its computing and communication resources, or worse, maliciously forge the results for some shady deals. In this paper, we propose V-PATD, the first Verifiable and Privacy-Aware Truth Discovery protocol in crowdsensing systems. In V-PATD, a publicly verifiable approach is designed enabling any entity to verify the correctness of aggregated results returned from the server. Since most of the computation burdens are carried by the cloud server, our verification approach is efficient and scalable. Moreover, users' data is perturbed with the principles of local differential privacy. Security analysis shows that the proposed perturbation mechanism guarantees a high aggregation accuracy even if large noises are added. Compared to existing solutions, extensive experiments conducted on real crowdsensing systems demonstrate the superior performance of V-PATD in terms of accuracy, computation and communication overheads.
Guowen Xu, Hongwei Li 0001, Shengmin Xu, Hao Ren 0001, Yinghui Zhang 0002, Jianfei Sun, Robert H. Deng
AsiaCCS5
2020 Revocable and certificateless public auditing for cloud storage
Yinghui Zhang 0002, Shengmin Xu, Guowen Xu, Dong Zheng 0001
Sci. China Inf. Sci.1
2020 LSAA: A Lightweight and Secure Access Authentication Scheme for Both UE and mMTC Devices in 5G Networks
abstract
As a development of the next generation of mobile communication networks and systems (5G), the Third-Generation Partnership Project (3GPP) committee has standardized a new 5G authentication and key-agreement (5G-AKA) protocol to ensure the access security of a mobile equipment. However, there are still some security vulnerabilities in the 5G-AKA protocol, and there is no authentication protocol proposed for massive device concurrent connection by the 3GPP working groups. In this article, we propose a novel lightweight and secure access authentication scheme named lightweight secure access authentication (LSAA) that contains two lightweight extended Chebyshev chaotic maps-based access authentication protocols for two types of 3GPP standard mobile devices: 1) common user equipment (UE) and 2) massive machine-type communication (mMTC) devices. Our proposed protocols can achieve several security functionalities, including mutual authentication, session-key establishment, identity privacy protection, and perfect forward/backward secrecy (PFS/PBS). In addition, the proposed protocols are lightweight in nature compared with the 5G-AKA. In order to comprehensively and accurately evaluate LSAA, we carry out formal security analysis by employing two formal verification tools Proverif and Scyther, and informal security analysis on the proposed protocols. We further evaluate the performance of the proposed protocols with regard to authentication signaling cost, authentication communication cost, authentication computational cost, and authentication storage cost. The security evaluation and performance analysis results show that our proposed protocols can provide advanced security and high efficiency.
Jin Cao 0001, Zheng Yan 0002, Ruhui Ma, Yinghui Zhang 0002, Hui Li 0006
IEEE Internet Things J.4
2020 Lightweight and Privacy-Aware Fine-Grained Access Control for IoT-Oriented Smart Health
abstract
With the booming of Internet of Things (IoT), smart health (s-health) is becoming an emerging and attractive paradigm. It can provide an accurate prediction of various diseases and improve the quality of healthcare. Nevertheless, data security and user privacy concerns still remain issues to be addressed. As a high potential and prospective solution to secure IoT-oriented s-health applications, ciphertext policy attribute-based encryption (CP-ABE) schemes raise challenges, such as heavy overhead and attribute privacy of the end users. To resolve these drawbacks, an optimized vector transformation approach is first proposed to efficiently transform the access policy and user attribute set into respective vectors of shorter length while other approaches result in redundant and longer vectors. Our transformation approach can greatly relieve the costly overheard of key generation, encryption, and decryption phases. Then, based on the transformation approach and the offline/online computation technology, we propose a lightweight policy-hiding CP-ABE scheme for the IoT-oriented s-health application. With our proposed scheme, data users in the s-health system can perform lightweight encryption and decryption without leaking any sensitive privacy about the attributes of the user. Finally, the formal security analysis, the theoretic performance evaluation and experiment results indicate that the solution is secure and efficient.
Jianfei Sun, Hu Xiong, Ximeng Liu, Yinghui Zhang 0002, Xuyun Nie, Robert H. Deng
IEEE Internet Things J.4
2020 Efficient ciphertext-policy attribute-based encryption with blackbox traceability
Shengmin Xu, Jiaming Yuan, Guowen Xu, Yingjiu Li, Ximeng Liu, Yinghui Zhang 0002, Zuobin Ying
Inf. Sci.6
2020 An attribute-based encryption scheme with multiple authorities on hierarchical personal health record in cloud
Rui Guo 0005, Xiong Li 0002, Dong Zheng 0001, Yinghui Zhang 0002
J. Supercomput.4
2019 ObliDC: An SGX-based Oblivious Distributed Computing Framework with Formal Proof
abstract
Data privacy is becoming one of the most critical concerns in cloud computing. Several proposals based on Intel SGX such as VC3 [1] and M2R [2] have been introduced in the literature to protect data privacy during job execution in the cloud. However, a comprehensive formal proof of their security guarantees is still lacking. In this paper, we propose ObliDC, a general UC-secure SGX-based oblivious distributed computing framework. First, we model the life-cycle of a distributed computing job as data-flow graphs. Under the assumption of malicious, adaptive adversaries in the cloud, we then formally define data privacy of a distributed computing job by introducing a notion named ODC-privacy, which encompasses both semantic security (to protect data confidentiality during computation and transmission) and oblivious traffic (to prevent data leakage from traffic analysis). ObliDC is composed of four two-party protocols -- job deployment, job initialization, job execution, and results return, which allow for modular construction of concrete privacy-preserving job protocols in different distributed computing frameworks. Finally, inspired by a formal abstraction for trusted processors proposed by R. Pass et al. [3], we formally prove the security of ObliDC under the universal composability (UC) framework.
Pengfei Wu 0003, Qingni Shen, Robert H. Deng, Ximeng Liu, Yinghui Zhang 0002, Zhonghai Wu
AsiaCCS5
2019 Validation of MODIS and GEOV2 Leaf Area Index (LAI) Products over Croplands in Northeastern China
abstract
The objective of this study is to validate the recent moderate resolution leaf area index (LAI) products generated by MODIS collection 6 (C6) and Geoland2/BioPar project (GEOV2) over major agricultural croplands. Field campaigns were conducted and seasonal continuous LAI measurements were obtained over rice, maize, soybean, and sorghum fields in the Honghe farm (2012 and 2013) and Hailun city (2016) in northeastern China. High resolution 30 m LAI maps were first derived from HJ-1 and Landsat with a look-up table (LUT) method and evaluated with ground-based measurements (R2≥0.67 and RMSE≤0.90). Consequently, the high resolution LAI was upscaled and compared with the moderate resolution LAI products. The results indicate that both MODIS and GEOV2 capture a consistent seasonal pattern of the crop LAI variation. The moderate resolution LAI products are very closed related to the upscaled high resolution reference LAI.
Hongliang Fang, Yinghui Zhang 0002, Shanshan Wei, Yongchang Ye, Weiwei Liu 0005
IGARSS2
2019 Generic Construction of ElGamal-Type Attribute-Based Encryption Schemes with Revocability and Dual-Policy
Shengmin Xu, Yinghui Zhang 0002, Yingjiu Li, Ximeng Liu, Guomin Yang
SecureComm (2)2
2019 PPSHA: Privacy preserving secure handover authentication scheme for all application scenarios in LTE-A networks
Ruhui Ma, Jin Cao 0001, Dengguo Feng, Hui Li 0006, Yinghui Zhang 0002, Xixiang Lv
Ad Hoc Networks5
2019 SybSub: Privacy-Preserving Expressive Task Subscription With Sybil Detection in Crowdsourcing
abstract
The past decade has witnessed the rise of crowdsourcing, and privacy in crowdsourcing has also gained rising concern in the meantime. Task matching or task subscription is one of indispensable services in crowdsourcing, but few mechanisms can achieve the expressive task subscription while protecting the privacy. In this paper, we focus on the privacy leaks and attacks during task subscription in crowdsourcing, and propose a privacy-preserving task subscription scheme with sybil detection, called SybSub. The SybSub scheme achieves the expressiveness of task subscription in the multisubscriber and multipublisher crowdsourcing while protecting the privacy of both subscribers and publishers against the semi-honest crowdsourcing service provider, and meanwhile supports the sybil attack detection against greedy subscribers. We implement the SybSub scheme and evaluate it thoroughly. Performance results validate that the SybSub scheme is efficient and feasible.
Jiangang Shu, Ximeng Liu, Kan Yang 0001, Yinghui Zhang 0002, Xiaohua Jia, Robert H. Deng
IEEE Internet Things J.4
2019 Comments on "A Large-Scale Concurrent Data Anonymous Batch Verification Scheme for Mobile Healthcare Crowd Sensing"
abstract
As an important application of the Internet of Things technologies, mobile healthcare crowd sensing (MHCS) still has challenging issues, such as privacy protection and efficiency. Quite recently in the IEEE Internet of Things Journal (DOI: 10.1109/JIOT.2018.2828463), Liuet al.proposed a large-scale concurrent data anonymous batch verification scheme for MHCS, claiming to provide batch authentication, nonrepudiation, and anonymity. However, after a close look at the scheme, we point out that the scheme suffers two types of signature forgery attacks and hence fails to achieve the claimed security properties. In addition, a reasonable and rigorous probability analysis indicates that the security reduction from the security of the scheme to the hardness of the computational Diffie–Hellman problem is invalid. We hope that similar design flaws can be avoided in future design of anonymous batch verification schemes for MHCS.
Yinghui Zhang 0002, Jiangang Shu, Ximeng Liu, Jin Li 0002, Dong Zheng 0001
IEEE Internet Things J.1
2019 DABKE: Secure deniable attribute-based key exchange framework
abstract
We introduce the first deniable attribute-based key exchange (DABKE) framework that is resilient to impersonation attacks. We define the formal security models for DABKE framework, and propose a generic compiler that converts any attribute-based key exchanges into deniable ones. We prove that it can achieve session key security and user privacy in the standard model, and strong deniability in the simulation-based paradigm. In particular, the proposed generic compiler ensures: 1) a dishonest user cannot impersonate other user’s session participation in conversations since implicit authentication is used among authorized users; 2) an authorized user can plausibly deny his/her participation after secure conversations with others; 3) the strongest form of deniability is achieved using one-round communication between two authorized users.
Yangguang Tian, Yingjiu Li, Guomin Yang, Willy Susilo, Yi Mu 0001, Hui Cui 0001, Yinghui Zhang 0002
J. Comput. Secur.7
2019 Efficient and Robust Certificateless Signature for Data Crowdsensing in Cloud-Assisted Industrial IoT
abstract
With the digitalization of various industries, the combination of cloud computing and the industrial Internet of Things (IIoT) has become an attractive data processing paradigm. However, the cloud-assisted IIoT still has challenging issues, including authenticity of data, untrustworthiness of third parties, and system robustness and efficiency. Recently, a lightweight certificateless signature (CLS) scheme for the cloud-assisted IIoT, that was claimed to address both authenticity of data and untrustworthiness of third parties, has been proposed by Karati et al. (2018). In this paper, we demonstrate that the CLS scheme fails to achieve the claimed security properties by presenting four types of signature forgery attacks. We also propose a robust certificateless signature (RCLS) scheme to address the aforementioned challenges. Our RCLS only needs public channels and is proven secure against both public key replacement attacks and malicious-but-passive third parties in the standard model. Performance evaluation indicates that the RCLS scheme outperforms other CLS schemes and is suitable for the IIoT.
Yinghui Zhang 0002, Robert H. Deng, Dong Zheng 0001, Jin Li 0002, Pengfei Wu 0003, Jin Cao 0001
IEEE Trans. Ind. Informatics1
2018 SybMatch: Sybil Detection for Privacy-Preserving Task Matching in Crowdsourcing
abstract
The past decade has witnessed the rise of crowdsourcing, and privacy in crowdsourcing has also gained rising concern in the meantime. In this paper, we focus on the privacy leaks and sybil attacks during the task matching, and propose a privacy-preserving task matching scheme, called SybMatch. The SybMatch scheme can simultaneously protect the privacy of publishers and subscribers against semi-honest crowdsourcing service provider, and meanwhile support the sybil detection against greedy subscribers and efficient user revocation. Detailed security analysis and thorough performance evaluation show that the SybMatch scheme is secure and efficient.
Jiangang Shu, Ximeng Liu, Kan Yang 0001, Yinghui Zhang 0002, Xiaohua Jia, Robert H. Deng
GLOBECOM4
2018 Smart Grid Power Trading Based on Consortium Blockchain in Internet of Things
Dong Zheng 0001, Kaixin Deng, Yinghui Zhang 0002, Jiangfan Zhao, Xinwei Ma
ICA3PP (3)3
2018 Privacy-Aware Data Collection and Aggregation in IoT Enabled Fog Computing
Yinghui Zhang 0002, Jiangfan Zhao, Dong Zheng 0001, Kaixin Deng, Fangyuan Ren
ICA3PP (4)1
2018 Efficient Traceable Oblivious Transfer and Its Applications
Weiwei Liu 0005, Yinghui Zhang 0002, Yi Mu 0001, Guomin Yang, Yangguang Tian
ISPEC2
2018 DSH: Deniable Secret Handshake Framework
Yangguang Tian, Yingjiu Li, Yinghui Zhang 0002, Nan Li 0007, Guomin Yang, Yong Yu 0002
ISPEC3
2018 Secure attribute-based data sharing for resource-limited users in cloud computing
Jin Li 0002, Yinghui Zhang 0002, Xiaofeng Chen 0001, Yang Xiang 0001
Comput. Secur.2
2018 Efficient and robust attribute-based encryption supporting access policy hiding in Internet of Things
Yinghui Zhang 0002, Hui Li 0006
Future Gener. Comput. Syst.2
2018 Secure and fine-grained access control on e-healthcare records in mobile cloud computing
Yi Liu 0029, Yinghui Zhang 0002, Jie Ling 0002, Zhusong Liu
Future Gener. Comput. Syst.2
2018 Security and Privacy in Smart Health: Efficient Policy-Hiding Attribute-Based Access Control
abstract
With the rapid development of the Internet of Things and cloud computing technologies, smart health (s-health) is expected to significantly improve the quality of health care. However, data security and user privacy concerns in s-health have not been adequately addressed. As a well-received solution to realize fine-grained access control, ciphertext-policy attribute-based encryption (CP-ABE) has the potential to ensure data security in s-health. Nevertheless, direct adoption of the traditional CP-ABE in s-health suffers two flaws. For one thing, access policies are in cleartext form and reveal sensitive health-related information in the encrypted s-health records (SHRs). For another, it usually supports small attribute universe, which places an undesirable limitation on practical deployments of CP-ABE because the size of its public parameters grows linearly with the size of the universe. To address these problems, we introduce PASH, a privacy-aware s-health access control system, in which the key ingredient is a large universe CP-ABE with access policies partially hidden. In PASH, attribute values of access policies are hidden in encrypted SHRs and only attribute names are revealed. In fact, attribute values carry much more sensitive information than generic attribute names. Particularly, PASH realizes an efficient SHR decryption test which needs a small number of bilinear pairings. The attribute universe can be exponentially large and the size of public parameters is small and constant. Our security analysis indicates that PASH is fully secure in the standard model. Performance comparisons and experimental results show that PASH is more efficient and expressive than previous schemes.
Yinghui Zhang 0002, Dong Zheng 0001, Robert H. Deng
IEEE Internet Things J.1
2018 Blockchain based efficient and robust fair payment for outsourcing services in cloud computing
Yinghui Zhang 0002, Robert H. Deng, Ximeng Liu, Dong Zheng 0001
Inf. Sci.1
2018 Dual-side privacy-preserving task matching for spatial crowdsourcing
Jiangang Shu, Ximeng Liu, Yinghui Zhang 0002, Xiaohua Jia, Robert H. Deng
J. Netw. Comput. Appl.3
2018 Secure smart health with privacy-aware aggregate authentication and access control in Internet of Things
Yinghui Zhang 0002, Robert H. Deng, Dong Zheng 0001
J. Netw. Comput. Appl.1
2018 Privacy-preserving communication and power injection over vehicle networks and 5G smart grid slice
Yinghui Zhang 0002, Jin Li 0002, Dong Zheng 0001, Ping Li 0018, Yangguang Tian
J. Netw. Comput. Appl.1
2018 A Secure and Privacy-Aware Smart Health System with Secret Key Leakage Resilience
abstract
With the development of the smart health (s-health), data security and patient privacy are becoming more and more important. However, some traditional cryptographic schemes can not guarantee data security and patient privacy under various forms of leakage attacks. To prevent the adversary from capturing the part of private keys by leakage attacks, we propose a secure leakage-resilient s-health system which realizes privacy protection and the safe transmission of medical information in the case of leakage attacks. The key technique is a promising public key cryptographic primitive called leakage-resilient anonymous Hierarchical Identity-Based Encryption. Our construction is proved to be secure against chosen plaintext attacks in the standard model under the Diffie-Hellman exponent assumption and decisional linear assumption. We also blind the public parameters and ciphertexts by using double exponent technique to achieve the recipient anonymity. Finally, the performance analysis shows the practicability of our scheme, and the leakage rate of the private key approximates to 1/6.
Yinghui Zhang 0002, Pengzhen Lang, Dong Zheng 0001, Menglei Yang, Rui Guo 0005
Secur. Commun. Networks1
2018 Secure Deduplication Based on Rabin Fingerprinting over Wireless Sensing Data in Cloud Computing
abstract
The rapid advancements in the Internet of Things (IoT) and cloud computing technologies have significantly promoted the collection and sharing of various data. In order to reduce the communication cost and the storage overhead, it is necessary to exploit data deduplication mechanisms. However, existing data deduplication technologies still suffer security and efficiency drawbacks. In this paper, we propose two secure data deduplication schemes based on Rabin fingerprinting over wireless sensing data in cloud computing. The first scheme is based on deterministic tags and the other one adopts random tags. The proposed schemes realize data deduplication before the data is outsourced to the cloud storage server, and hence both the communication cost and the computation cost are reduced. In particular, variable-size block-level deduplication is enabled based on the technique of Rabin fingerprinting which generates data blocks based on the content of the data. Before outsourcing data to the cloud, users encrypt the data based on convergent encryption technologies, which protects the data from being accessed by unauthorized users. Our security analysis shows that the proposed schemes are secure against offline brute-force dictionary attacks. In addition, the random tag makes the second scheme more reliable. Extensive experimental results indicate that the proposed data deduplication schemes are efficient in terms of the deduplication rate, the system operation time, and the tag generation time.
Yinghui Zhang 0002, Haonan Su, Menglei Yang, Dong Zheng 0001, Fang Ren 0004, Qinglan Zhao
Secur. Commun. Networks1
2018 Efficient and secure big data storage system with leakage resilience in cloud computing
Yinghui Zhang 0002, Menglei Yang, Dong Zheng 0001, Pengzhen Lang, Axin Wu
Soft Comput.1
2017 Ensuring attribute privacy protection and fast decryption for outsourced data security in mobile cloud computing
Yinghui Zhang 0002, Xiaofeng Chen 0001, Jin Li 0002, Duncan S. Wong, Hui Li 0006, Ilsun You
Inf. Sci.1
2017 Towards privacy protection and malicious behavior traceability in smart health
Yinghui Zhang 0002, Jin Li 0002, Dong Zheng 0001, Xiaofeng Chen 0001, Hui Li 0006
Pers. Ubiquitous Comput.1
2016 Accountable Large-Universe Attribute-Based Encryption Supporting Any Monotone Access Structures
Yinghui Zhang 0002, Jin Li 0002, Dong Zheng 0001, Xiaofeng Chen 0001, Hui Li 0006
ACISP (1)1
2016 Efficient attribute-based data sharing in mobile clouds
Yinghui Zhang 0002, Dong Zheng 0001, Xiaofeng Chen 0001, Jin Li 0002, Hui Li 0006
Pervasive Mob. Comput.1
2016 Anonymous attribute-based proxy re-encryption for access control in cloud computing
abstract
Abstract As a public key cryptographic primitive, attribute‐based encryption (ABE) is promising in implementing fine‐grained access control in cloud computing. However, before ABE comes into practical applications, two challenging issues have to be addressed, that is, users' attribute privacy protection and access policy update. In this paper, we tackle the aforementioned challenge for the first time by formalizing the notion of anonymous ciphertext‐policy attribute‐based proxy re‐encryption (anonymous CP‐ABPRE) and giving out a concrete construction. We propose a novel technique called match‐then‐re‐encrypt, in which a matching phase is additionally introduced before the re‐encryption phase. This technique uses special components of the proxy re‐encryption key and ciphertext to anonymously check whether the proxy can fulfill a proxy re‐encryption or not. Theoretical analysis and simulation results demonstrate that our anonymous CP‐ABPRE scheme is secure and efficient. Copyright © 2016 John Wiley & Sons, Ltd.
Yinghui Zhang 0002, Jin Li 0002, Xiaofeng Chen 0001, Hui Li 0006
Secur. Commun. Networks1
2016 Online/offline unbounded multi-authority attribute-based encryption for data sharing in mobile cloud computing
abstract
In order to realize attribute-based data sharing in cloud computing, multi-authority attribute-based encryption (MA-ABE) is extremely attractive. However, most of the existing MA-ABE schemes cannot support a fully large attribute universe and are not suitable for resource-constrained mobile data owners in that the computation cost in secret key generation and encryption is extremely heavy. To tackle the earlier challenges, we propose an online/offline MA-ABE scheme, which realizes both the online/offline secret key generation and the online/offline encryption while supporting a fully large attribute universe. In the offline phase, one global-identity authority and multiple attribute authorities do the majority of the work to issue attribute secret keys before knowing users' global identity and attributes. The data owner can perform most of the encryption computation tasks before knowing the actual message and access structure. Furthermore, the online phase can rapidly assemble the final decryption key and ciphertexts when related specifications become known. Particularly, global-identity authority and attribute authorities need not to cooperate in the whole process. Our online/offline MA-ABE scheme allows the access policies encoded in linear secret sharing schemes. The formal selective security proof and extensive performance analysis indicate that our scheme is very suitable for data sharing in mobile cloud computing. Copyright © 2016 John Wiley & Sons, Ltd.
Yinghui Zhang 0002, Dong Zheng 0001, Qi Li 0011, Jin Li 0002, Hui Li 0006
Secur. Commun. Networks1
2015 Privacy-aware attribute-based PHR sharing with user accountability in cloud computing
Fatos Xhafa, Jianglang Feng, Yinghui Zhang 0002, Xiaofeng Chen 0001, Jin Li 0002
J. Supercomput.3
2014 Computationally Efficient Ciphertext-Policy Attribute-Based Encryption with Constant-Size Ciphertexts
Yinghui Zhang 0002, Dong Zheng 0001, Xiaofeng Chen 0001, Jin Li 0002, Hui Li 0006
ProvSec1
2014 Generic construction for secure and efficient handoff authentication schemes in EAP-based wireless networks
Yinghui Zhang 0002, Xiaofeng Chen 0001, Jin Li 0002, Hui Li 0006
Comput. Networks1
2014 Efficient and robust identity-based handoff authentication for EAP-based wireless networks
abstract
SUMMARY The Extensible Authentication Protocol (EAP) framework aims to realize a flexible authentication for wireless networks. However, a full EAP authentication needs several round trips between a mobile node and the EAP server, and hence is unacceptable in a process of handoff authentication because of inefficient performance. Considering the advantage of the identity‐based cryptography, it is attractive to realize handoff authentication efficiently in the identity‐based setting. In this work, we propose a new identity‐based handoff authentication scheme in which a special double‐trapdoor chameleon hash function is used. Compared with the existing identity‐based handoff authentication construction, the main advantage of the proposed scheme eliminates the assumption that the private key generator is fully trusted. Besides, the detailed security analysis shows that the proposed scheme not only satisfies robust security properties but also enjoys desirable efficiency for the real‐world applications. Copyright © 2013 John Wiley & Sons, Ltd.
Yinghui Zhang 0002, Xiaofeng Chen 0001, Hui Li 0006, Jiaxiang Quan
Concurr. Comput. Pract. Exp.2
2013 Anonymous attribute-based encryption supporting efficient decryption test
abstract
Attribute-based encryption (ABE) has been widely studied recently to support fine-grained access control of shared data. Anonymous ABE, which is a relevant notion to ABE, further hides the receivers' attribute information in ciphertexts because many attributes are sensitive and related to the identity of eligible users. However, in existing anonymous ABE work, a user knows whether the attributes and the policy match or not only after repeating decryption attempts. And, the computation overhead of each decryption is high as the computational cost grows with the complexity of the access formula, which usually requires many pairings in most of the existing ABE schemes. As a result, this direct decryption method in anonymous ABE will suffer a severe efficiency drawback.
Yinghui Zhang 0002, Xiaofeng Chen 0001, Jin Li 0002, Duncan S. Wong, Hui Li 0006
AsiaCCS1
2013 Key-Evolving Hierarchical ID-Based Signcryption
abstract
Key-evolving cryptography is intended to mitigate the damage in case of a secret key compromise, one of the severest security threats to actual cryptographic schemes. In the public-key setting, the essential idea of key-evolving lies in updating the private key with time, while maintaining the same public key. Key evolution in encryption and signing has been well studied, especially in the identity-based (ID-based) setting where an entity's public key can be derived from that entity's identity information. From a more practical standpoint, however, one would like to use the primitive signcryption in the hierarchical ID-based setting. In this paper, we propose the first key-evolving hierarchical ID-based signcryption scheme that is scalable and joining-time-oblivious and allows secret keys to be updated autonomously. The security proofs of our construction depend on the bilinear Diffie–Hellman assumption and the computational Diffie–Hellman assumption in the random oracle model. To be specific, our proposal not only achieves the fundamental goals of confidentiality and authenticity, but also enjoys desirable properties of non-repudiation, ciphertext anonymity and strong forward security. Compared with the conventional sign-then-encrypt approach, our construction provides better efficiency in terms of the computation cost and the communication overhead.
Yinghui Zhang 0002, Xiaofeng Chen 0001, Hui Li 0006
Comput. J.1
2012 Efficient and Robust Identity-Based Handoff Authentication in Wireless Networks
Yinghui Zhang 0002, Xiaofeng Chen 0001, Hui Li 0006, Jiaxiang Quan
NSS2
2012 Identity-based construction for secure and efficient handoff authentication schemes in wireless networks
abstract
ABSTRACT With the rapid development of computer networks, wireless technologies find important applications in roaming communication. In this scenario, practical needs initiate the demand for a secure and efficient handoff authentication scheme. To the best of our knowledge, however, there exists no scheme that can simultaneously provide robust security properties and enjoy desirable efficiency. In this paper, we first examines the security of the scheme proposed in International Conference on Communications 2007 by Kim et al. and demonstrates that the scheme of Kim et al. fails to achieve perfect forward/backward secrecy. Furthermore, we propose a new identity‐based construction for secure and efficient handoff authentication schemes, in which an identity‐based online/offline encryption scheme is the primary ingredient. Compared with the scheme of Kim et al., our construction enjoys desirable efficiency in terms of the computation cost and the communication cost. To be specific, the developed scheme not only realizes a seamless handoff with key agreement, but also provides perfect forward/backward secrecy, which has never been achieved in any existing handoff‐related schemes. Therefore, our construction is more suitable for handoff authentication in the wireless applications environment. Copyright © 2012 John Wiley & Sons, Ltd.
Yinghui Zhang 0002, Xiaofeng Chen 0001
Secur. Commun. Networks1