Ye Su 0001

dblp:34/5909-1 · DBLP profile ↗
← Back
29ranked-venue papers
2as first author
27since 2021 · last 2026
0000-0002-4912-3197ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 1 first-author · 9 since 2021Security and privacy · 8 · 7 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Databases, data management, data science and information retrieval · 4 · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Multi-User Boolean Keyword Searchable Encryption With Fine-Grained Access Control for Cloud Storage
abstract
ABSTRACT Searchable Encryption (SE) enables users to perform searches on encrypted data while preserving data privacy. Since cloud servers are platforms that provide services for a large number of users, and data owners require access control over their data, SE schemes that support multi‐user settings and access control are therefore more suitable for cloud storage. However, in existing SE schemes that support multi‐user settings and access control, most only support single‐keyword or conjunctive keyword searches, and the search time grows linearly with the total amount of data. These limitations negatively impact both the accuracy and efficiency of search operations. This work proposes an SE scheme specifically designed for multi‐user settings. Data owners can enforce fine‐grained access control policies, while a specialized retrieval structure allows the cloud to assist users in performing Boolean keyword searches with improved efficiency. The search complexity of the proposed scheme is , where denotes the number of files relevant to the queried keyword. We demonstrate the scheme's effectiveness and practicality through performance analysis.
Xinyi Hou, Ye Su 0001, Jing Qin 0002, Jixin Ma 0001
Concurr. Comput. Pract. Exp.2
2026 QSDA: Quality-Aware Secure Multidimensional Data Aggregation With Location Privacy for HIoT
abstract
Data aggregation, as a data processing technique, facilitates accurate diagnosis in the Healthcare Internet of Things (HIoT) by integrating multi-source heterogeneous health data. However, achieving efficient and secure aggregation of multi-dimensional medical data remains challenging, particularly when simultaneously preserving location privacy and providing fair, quality-driven incentives. To address these issues, this paper proposes a Quality-Aware Secure Multi-Dimensional Data Aggregation scheme with Location Privacy for HIoT (QSDA). First, the scheme employs inner product encryption to support aggregation task matching without revealing users’ actual coordinates, and further integrates symmetric homomorphic encryption with super-increasing sequences to enable one-stop compressed aggregation of multi-dimensional data, thereby effectively supporting common statistical operations such as mean and variance. Second, it introduces a data quality incentive mechanism based on offset metrics, while leveraging blockchain auditing to ensure the traceability of the aggregation process and the verifiability of the aggregation results. Finally, security analysis and performance evaluation demonstrate the scheme’s effectiveness and efficiency.
Lei Wu 0011, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001, Zhiquan Liu 0001
IEEE Internet Things J.3
2026 SecOIR: Enhancing Privacy and Accuracy in Outsourced Image Retrieval via Function Secret Sharing and Deep Hashing
abstract
With the increasing prevalence of outsourcing images to cloud servers, privacy-preserving content-based image retrieval (CBIR) has attracted significant research attention. Existing privacy-preserving CBIR schemes often prioritize retrieval speed by adopting methods that provide weak privacy guarantees and low-dimensional image features, which inevitably compromises security and retrieval accuracy. Additionally, most solutions directly employ CNN models pre-trained on public datasets for feature extraction, neglecting domain adaptation problem. To address these limitations, we propose SecOIR, a secure outsourced image retrieval scheme based on deep hashing networks, which achieves provable security under the semi-honest adversary model while hiding access patterns. Furthermore, domain adaptation is resolved through fine-tuning of feature extraction models. Experimental results demonstrate that SecOIR outperforms state-of-the-art schemes by 11%-12% in accuracy under identical datasets and configurations, while maintaining practical efficiency. To achieve SecOIR, we propose two modified function secret sharing (FSS) schemes that overcome the limited compatibility of the original FSS schemes with replicated secret sharing (RSS). Then, building upon the modified FSS schemes and RSS, we design a series of efficient sub-protocols. Benchmark tests reveal that our sub-protocols surpass existing mainstream solutions in efficiency, which can also serve as independent contributions to secure multi-party computation protocol design.
Zhi Li 0056, Hao Wang 0007, Ye Su 0001, Xiaochao Wei, Lei Wu 0011
IEEE Trans. Dependable Secur. Comput.3
2026 Practical Private Set Operation via Secret Sharing for Lightweight Clients
abstract
The rapid growth of sensitive cross-domain data, such as electronic health records and genomic sequences in healthcare, presents significant opportunities for large-scale, multi-institutional collaborative analysis. Meeting stringent privacy regulations while utilizing data has become a critical challenge. Private set operations (PSO) play a crucial role to address this challenge. PSO protocols enable privacy-preserving data alignment across parties (such as interinstitutional data matching based on private set intersection (PSI)) and secure data aggregation (such as federated data aggregation through private set union (PSU)), providing fundamental support for cross-domain data collaboration. This type of technology is not only applicable to multi-center medical research but also has broad value in other scenarios requiring confidential data sharing. However, existing delegated/outsourced PSO schemes face two key limitations: (1) high client-side preprocessing overhead, requiring clients to expensively mask private data before uploading; (2) performance and single-point dependency bottlenecks in client-assisted computation where one client must act as a computational leader. To address these issues, we propose a secret-shared PSO framework for lightweight clients. In our scheme, the clients can go offline while servers perform all computations, significantly reducing clients’ burden. Notably, our protocol can be extended to support multi-party settings, making it well-suited for collaborative research across multiple institutions. In addition, we prove the security of all constructions under the semi-honest model. Experiments show that when the set sizen≥ 216, our protocol has a significant advantage and is well-suited for lightweight client that holds a large set.
Ziyu Niu, Yudi Zhang 0001, Yumei Li 0003, Willy Susilo, Ye Su 0001, Hao Wang 0007
IEEE Trans. Inf. Forensics Secur.5
2026 DMPF-PSI: Enabling High-Frequency Updatable Private Set Intersection on Dynamic Data
Jiadi Zhang, Hao Wang 0007, Ye Su 0001, Zhi Li 0056, Debiao He
IEEE Trans. Inf. Forensics Secur.3
2026 SAPP: Achieving Semantic-Aware Differential Privacy for Spatiotemporal Trajectory Data Publishing
abstract
With the increasing availability of large-scale spatiotemporal data from location-based services, trajectory publishing has become essential for data-driven analysis and intelligent applications. However, insufficient protection of trajectory location data may result in the disclosure of user privacy and social relationship information. To address this issue, we propose a semantic-aware privacy-preserving trajectory data publishing scheme (SAPP). First, a sliding-window algorithm is employed to extract stay points as key semantic locations and to generate a uniformly sampled set of candidate obfuscation points. Then, a semantic-aware scoring function is designed to probabilistically select candidate points that preserve semantics while avoiding sensitive regions. Furthermore, SAPP computes the sensitivity of each location based on semantic frequency and dynamically allocates the privacy budget. Finally, random noise is added to candidate trajectories using the Laplace mechanism. Through a dual-perturbation mechanism, spatial correlations in sensitive regions are weakened. Security analysis and experimental results further demonstrate that, compared with existing approaches, SAPP reduces TPPS and SFRR by up to 18% and 14%, respectively, indicating stronger resistance against trajectory inference and semantic leakage attacks while maintaining high data utility and time efficiency.
Lei Wu 0011, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001, Zhiquan Liu 0001
IEEE Trans. Knowl. Data Eng.3
2026 EPVFL: Efficient Privacy-Preserving and Verifiable Federated Learning
Guofu Zhu, Wenting Shen, Jiewang Cai, Zhiquan Liu 0001, Ye Su 0001, Jinlu Liu
IEEE Trans. Netw. Serv. Manag.5
2026 PUDSQ: Privacy-Preserving User-Defined Skyline Query Processing With Function Secret Sharing
abstract
Skyline query is a fundamental technique in multi-criteria decision-making, aiming to extract “optimal” results that are not dominated by any other data points across all attributes. It has significant value in applications that require trade-offs among multiple criteria. However, existing skyline query methods face two critical limitations: (i) conventional approaches adopt fixed dominance relationships, making it difficult to capture personalized user preferences; and (ii) cloud-based deployment models risk exposing sensitive data and query logic, making it difficult to ensure data privacy and protect query patterns while maintaining efficiency. To address these issues, we propose Privacy-Preserving User-Defined Skyline Query (PUDSQ), a novel privacy-preserving user-defined skyline query framework, which integrates efficient cryptographic techniques–secret sharing (SS) and function secret sharing (FSS)–with a secure database shuffling mechanism to achieve efficient query processing while ensuring robust privacy guarantees. PUDSQ introduces three main innovations: (i) a privacy-preserving filtering framework based on FSS provides dual protection for both data content and user preferences, effectively concealing database content and query logic; (ii) an FSS-based secure protocol suite supporting user-defined attribute retrieval, constrained-region retrieval, and secure skyline filtering; and (iii) a high-dimensional data processing strategy that integrates dimensionality reduction with an Sort-Filter-Skyline (SFS)-based presorting approach to address the high-dimensional data processing challenge and significantly improve efficiency. Experimental results demonstrate that, under equivalent security guarantees, PUDSQ reduces query latency by 8%-90% compared with state-of-the-art solution, with particularly notable advantages in high-dimensional scenarios, achieving an effective efficiency-privacy trade-off.
Zeqian Wang, Hao Wang 0007, Ye Su 0001, Ziyu Niu, Zhi Li 0056, Jing Qin 0002, Chunpeng Ge 0001
IEEE Trans. Serv. Comput.3
2025 Machine Learning Meets Encrypted Search: The Impact and Efficiency of OMKSA in Data Security
abstract
The convergence of machine learning and searchable encryption enhances the ability to protect the privacy and security of data and enhances the processing power of confidential data. To enable users to efficiently perform machine learning tasks on encrypted data domains, we delve into oblivious keyword search with authorization (OKSA). The OKSA scheme effectively maintains the privacy of the user’s query keywords and prevents the cloud server from inferring ciphertext information through the searching process. However, limitations arise because the traditional OKSA approach does not support multi‐keyword searches. If a data file is associated with multiple keywords, each keyword and corresponding data must be encrypted one by one, resulting in inefficiency. We introduce an innovative approach aimed at enhancing the efficiency of search processes while addressing the limitation of current encryption and search systems that handle only a single keyword. This method, known as the oblivious multiple keyword search with authorization (OMKSA), is designed for more effective keyword retrieval. One of our important innovations is that it uses the arithmetic techniques of bilinear pairs to generate new tokens and new search methods to optimize communication efficiency. Moreover, we present a detailed and rigorous demonstration of the security for our proposed protocol, aligned with the predefined security model. We conducted a comparative experiment to determine which of the two schemes, OKSA and OMKSA, is more efficient when querying multiple keywords. Based on our experimental results, our OMKSA is very efficient for data searchers. As the number of query keywords increases, the computational overhead of connected keyword searches remains stable. Finally, as we move into the 5G era, the potential applications of OMKSA are huge, with clear implications for areas such as machine learning and artificial intelligence. Our findings pave the way for further exploration and deployment of these frontier areas.
Zhongkai Wei, Ye Su 0001, Xi Zhang 0005, Haining Yang, Jing Qin 0002, Jixin Ma 0001
Int. J. Intell. Syst.2
2025 Outsourced Secure Cross-Modal Retrieval Based on Secret Sharing for Lightweight Clients
abstract
Cross-modal retrieval is a technique that uses one modality to query another modality in multimedia data (e.g., retrieving images based on text, or retrieving text based on images). It can break down the barriers between different modalities and achieve seamless information connection. Secure cross-modal retrieval focuses on privacy issues in cross-modal retrieval, including private data of data owners and private query requests of users. Current work on secure cross-modal retrieval protects private information through homomorphic encryption, which makes the efficiency of the retrieval phase not ideal. Therefore, the conflict between retrieval efficiency and security has become an important issue that needs to be resolved in secure cross-modal retrieval. We propose a scheme to achieve secure cross-modal retrieval in the form of secret sharing in the IoT environment. In the scheme, the data owner (DO) can secretly divide all the original data into two parts and upload them to two non-collusive cloud servers respectively. The servers store the data and provide cross-modal retrieval for users. The security of the scheme is proved under semi-honest model, and the experiments show that our scheme is more efficient than previous work in the search phase. When the query dimension is 512 and the number of latent factors is 500, the search time is reduced by more than half compared with previous work.
Ziyu Niu, Hao Wang 0007, Zhi Li 0056, Ye Su 0001, Lijuan Xu 0001, Yudi Zhang 0001, Willy Susilo
IEEE Internet Things J.4
2025 Privacy-Preserving Machine Learning in Cloud-Edge-End Collaborative Environments
abstract
We propose a privacy-preserving machine learning scheme based on the cloud-edge–end architecture to address issues like weak computing power of Internet of Things (IoT) terminals, poor communication quality, and heavy cloud server burdens in traditional frameworks. Edge servers aggregate and forward terminal data, relieving terminals of heavy communication tasks and undertaking part of the computing tasks, which reduces the burden on cloud servers and improves system response speed. For privacy protection, we flexibly use homomorphic encryption and secret sharing techniques, and dynamically add differential privacy noise to resist member inference attacks. Task allocation is coordinated between different layers to optimize computing overhead. Shallow model training is performed on edge servers using homomorphic encryption, while deep model training is conducted on cloud servers using secret sharing. To achieve the conversion from homomorphic ciphertext to secret sharing shares, we design a distributed decryption protocol. Experimental results show our scheme reduces computation overhead by 20%–30% compared to existing privacy-preserving machine learning schemes based on the cloud-edge–end framework, while maintaining privacy protection throughout all stages.
Hao Wang 0007, Zhi Li 0056, Ziyu Niu, Lei Wu 0011, Xiaochao Wei, Ye Su 0001, Willy Susilo
IEEE Internet Things J.7
2025 Privacy-preserving and verifiable multi-task data aggregation for IoT-based healthcare
Xinzhe Zhang, Lei Wu 0011, Lijuan Xu 0001, Zhien Liu, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001
J. Inf. Secur. Appl.5
2025 MSecKNN: Maliciously Secure Outsourced KNN Classification Under Multiple Distance Metrics
Zhi Li 0056, Hao Wang 0007, Wenying Zhang 0001, Ye Su 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.4
2025 MDTL: Maliciously Secure Distributed Transfer Learning Based on Replicated Secret Sharing
abstract
As data continues to grow at an unprecedented rate and informationization accelerates, concerns over data privacy have become more prominent. In image classification tasks, the challenge of insufficient labeled data is common. Transfer learning, an effective and important machine learning method, can address this issue by leveraging knowledge from the source domain to enhance performance in the target domain. However, existing privacy-preserving transfer learning schemes continue to face challenges related to low security and multiple rounds of communication. In the following works, we design a three-party privacy-preserving transfer learning protocol based on the Joint Distributed Adaptation (JDA) algorithm, which ensures malicious security under an honest majority model. To realize this protocol, we designed a series of sub-protocols for constant-round communication, including distributed solving of eigenvalues and eigenvectors based on replicated secret sharing techniques. Compared to existing work, our protocol requires fewer rounds and satisfies malicious security. We provide formal security proofs for the designed protocol and assess its performance using real datasets. Our protocol for computing the eigenvalues of matrices in a given dimension is approximately 2.5 times faster than existing methods. The results of the experiments demonstrate both the security and effectiveness of the proposed approach.
Zhengran Tian, Hao Wang 0007, Zhi Li 0056, Ziyu Niu, Xiaochao Wei, Ye Su 0001
IEEE Trans. Netw. Serv. Manag.6
2025 DIADD: Secure Deduplication and Efficient Data Integrity Auditing With Data Dynamics for Cloud Storage
abstract
Data integrity auditing with data deduplication allows the cloud to store only one copy of the identical file while ensuring the integrity of outsourced data. To facilitate flexible updates of outsourced data, data integrity auditing schemes supporting data dynamics and deduplication have been proposed. However, existing schemes either impose significant computation and communication burden to achieve data dynamics while ensuring data integrity and deduplication, or incur substantial computation overhead during the phases of authenticator generation and auditing. To address the above problems, in this paper, we construct a secure deduplication and efficient data integrity auditing scheme with data dynamics for cloud storage (DIADD). We design a lightweight authenticator structure to produce data authenticators for data integrity auditing, which can achieve authenticator deduplication and greatly reduce the computation overhead in the authenticator generation phase. Additionally, the time-consuming operations can be eliminated in the auditing phase. To enhance the efficiency of data dynamics, we employ the multi-set hash function technology to produce the file tags. This allows data owners to compute a new file tag without needing to recover the entire original file when performing dynamic operations. Furthermore, security analysis and experimental results demonstrate that DIADD is both secure and efficient.
Xiangshuo Zheng, Wenting Shen, Ye Su 0001
IEEE Trans. Netw. Serv. Manag.3
2024 SDTA: Secure Decentralized Trading Alliance for Electronic Medical Data
abstract
Abstract Massive medical data are indispensable for training diagnostic models to provide high-quality health monitoring services. The methods for sharing data in existing works involve securely and essentially copying data but often overlook the integration and efficiency of data storage, exchange and application. In this paper, we propose a Secure Decentralized Trading Alliance (SDTA) to encompass the entire process holistically. With monetary incentives, we formulate a chain-net structure for recording data digests and authentic transactions, thereby transforming data sharing into data trading without duplicating data storage. Data privacy is promised by encryption. To manage and employ encrypted medical data, users can update and search their encrypted data using an index and keywords, subsequently retrieving data within the SDTA framework. It is realized by a novel dynamic searchable symmetric encryption (SSE) with an $l$-level access strategy, which confines users to data pertinent solely to them, thus circumventing unnecessary data leakage. We scrutinize the storage efficiency and prove the fairness and security of SDTA. Finally, we generate datasets of varying sizes, where the time required to search for a single keyword is approximately 0.04 s with 1 000 000 (keyword, identifier) pairs, showing it quite acceptable.
Xi Zhang 0005, Ye Su 0001, Jing Qin 0002, Jiameng Sun
Comput. J.2
2024 Publicly Verifiable Secure Multi-Party Computation Framework Based on Bulletin Board
abstract
Although secure multi-party computation breaks down data barriers, its utility is reduced when participants have limited computation and communication resources. To make secure multi-party computation more practical, there exists an approach to distribute users' private inputs to multiple servers in a secret sharing manner, and the servers accomplish secure computation tasks through interaction. We propose a new secure computation framework that enables the detection of malicious cloud servers by introducing homomorphic MACs. We utilize pairing-based homomorphic commitments to record MACs on a bulletin board, providing public verifiability while reducing the computation burden on the cloud servers. Additionally, our framework not only supports the underlying general computation, but also prepares for various types of nontrivial high-level operations, such as comparison and bit decomposition. We design a smart payment platform enabling fair payment with the help of smart contracts to protect the rights of both data owners and cloud service providers. Compared to previous works, our framework breaks the limitations of servers being restricted to semi-honest or even honest and provides public verifiability. Performance evaluations demonstrate satisfactory computation and communication efficiency during the online phase of our system.
Hao Wang 0007, Zhi Li 0056, Lei Wu 0011, Xiaochao Wei, Ye Su 0001, Rongxing Lu
IEEE Trans. Serv. Comput.6
2024 Keyword-Based Remote Data Integrity Auditing Supporting Full Data Dynamics
abstract
Remote data integrity auditing, as a key technology for cloud storage, allows verifier to check cloud data integrity without downloading entire file from cloud server (CS). In practice, user might only concern the integrity of the files containing the specific keyword and would like to perform data dynamic operations on data. In this paper, we construct a practical keyword-based remote data integrity auditing scheme supporting full data dynamics. In such a scheme, a novel construction called keyword tag is designed. Using the keyword tag, TPA is able to simultaneously check whether CS correctly keeps all files containing the specific keyword. TPA can detect CS's misbehaviors once CS does not keep these files correctly. Furthermore, our scheme supports full data dynamics, including file-level updates and block-level updates. The keyword tag is updated when the user performs the file-level updates. To support block-level updates, we introduce an index switcher set to maintain the relationship between the block index and the authenticator index. We can avoid the recalculation of the authenticators by using authenticator indexes to generate authenticators. After cloud data are updated, data integrity still can be guaranteed. Security analysis and experimental results show that our scheme is provably secure and efficient.
Wenting Shen, Chao Gai, Jia Yu 0003, Ye Su 0001
IEEE Trans. Serv. Comput.4
2024 Secure, Dynamic, and Efficient Keyword Search With Flexible Merging for Cloud Storage
abstract
In this paper, we propose a Mergeable Searchable Symmetric Encryption (MSSE) scheme to enable secure keyword search and updates over encrypted cloud data. Particularly, MSSE allows flexible keyword merging, where users can remotely merge file identifiers associated with keywords to create new keyword-to-file identifier relationships. The function is designed for a user to manage their outsourced data conveniently. To this end, we first introduce a new encrypted index where each keyword's relevant file identifiers are grouped, encoded, and encrypted with super-increasing sequences and homomorphic encryption. With such an index, users leverage Distributed Multi-point Functions (DMPFs) to achieve secure keyword search and merge, maintaining efficiency while ensuring high privacy. To address the issue of maintaining “merging consistency” between pre-merged entries and newly updated entries, we employ the DMPF on clusters that incorporate the updated files. The approach significantly minimizes client-side computational overhead compared to re-executing the entire keyword merging process. We formally prove that MSSE can achieve parallel privacy. Extensive performance evaluation shows that MSSE is efficient in terms of computational and communication overheads.
Xi Zhang 0005, Cheng Huang 0001, Ye Su 0001, Jing Qin 0002
IEEE Trans. Serv. Comput.3
2023 Secure Multi-party SM2 Signature Based on SPDZ Protocol
Hao Wang 0007, Jiyang Chen, Shikuan Li, Ye Su 0001
Inscrypt (1)6
2023 Efficient and Flexible Multiauthority Attribute-Based Authentication for IoT Devices
abstract
The correctness and reliability of data sources are the keys to the practicality of data collected by Internet of Things (IoT) devices. Attribute-based signature (ABS) is a cryptographic primitive for users to sign with their own attributes, which can be applied to the authentication process in IoT scenarios. The attribute authority is responsible for issuing the attribute key to the user in ABS. Multiple authorities can complete attribute management tasks to avoid the threat of a single authority. However, attribute authorities need to execute multiple interactions to collaborate to generate attribute keys for users, which brings a large transmission burden. In addition, a lot of resource-constrained terminals in the IoT mostly play the role of signer or verifier in authentication protocols. The signature generation and verification algorithms often have heavy pairing and exponentiation operations. Currently, no ABS scheme takes into account the efficiency of all participating entities simultaneously. In this article, we present an aggregated anonymous key issue (AAKI) protocol to reduce the transmission burden between multiple authorities. Meanwhile, the noninteractive zero-knowledge proof aggregate exponentiation (NI-ZKPoKAE) protocol is designed to aggregate the transmitted secret values in AAKI. To reduce the computational burden of signers and verifiers, Blakley secret sharing, where the Hadamard matrix is used more efficiently to handle the$(n, n)$-threshold, is used to construct an efficient and fine-grained multiauthority ABS (EFMA-ABS) scheme. This brings high efficiency to all three types of parties involved in IoT authentication. Our above-mentioned protocols have been proven to be feasible and effective.
Ye Su 0001, Xi Zhang 0005, Jing Qin 0002, Jixin Ma 0001
IEEE Internet Things J.1
2022 Divertible Searchable Symmetric Encryption for Secure Cloud Storage
abstract
Searchable Symmetric Encryption (SSE) is a promising method for users to store data in remote clouds securely and search them using keywords over an encrypted index. In this paper, we explore a new function named “keyword diverting” and propose a variant of SSE named Divertible Searchable Symmetric Encryption (DivSSE). Specifically, the index in DivSSE is encoded into an inverted, compressed, and encrypted format, by using the super-increasing sequence, symmetric homomorphic encryption (SHE), and a secure hash function. According to the homomorphic properties of SHE, users can construct a unique keyword diverting token, which can be utilized to update the encrypted index by obliviously merging data identifiers corresponding to different keywords without searching in advance and thus achieve keyword diverting. Moreover, based on function secret sharing, DivSSE can protect users' search patterns and reduce communication costs with the assistance of two independent clouds. Detailed security proof demonstrates that DivSSE can achieve parallel privacy, forward privacy, and backward privacy. Extensive performance evaluation also shows that DivSSE is efficient in terms of computational and communication overheads.
Xi Zhang 0005, Cheng Huang 0001, Ye Su 0001, Jing Qin 0002, Xuemin Shen
GLOBECOM3
2022 FedTor: An Anonymous Framework of Federated Learning in Internet of Things
abstract
With a large number of devices and a wealth of user data sets, the Internet of Things (IoT) has become a great host for federated learning (FL). At the same time, the massive amount of user data in IoT results in desperate demand for privacy preserving. The onion router (Tor) is a promising method to solve the privacy issue in IoT-based FL by user anonymity. However, IoT devices’ resource is too limited to execute the cryptographic operations in Tor. Moreover, network traffics in Tor can be easily controlled by malicious routers with a fake high self-reported bandwidth. In this article, taking advantage of the Tor, we will introduce an anonymous FL framework in IoT called FedTor. To decrease the cryptographic cost in conventional Tor, we propose a lightweight shared key generation scheme for resource-limited IoT devices. Furthermore, we use the difference between the self-reported bandwidth and the bandwidth observed from others to measure the reputation of onion routers. A reputation-based router selection (RBRS) scheme is then brought up to defend traffic control from malicious routers. We conducted extensive simulations to compare FedTor with related works. The results show that the RBRS scheme can decrease the malicious rate of onion routers and the lightweight shared key has a cost advantage over other schemes.
Ye Su 0001, Mingyue Zhang 0004, Haoye Chai, Yunkai Wei, Shui Yu 0001
IEEE Internet Things J.2
2022 Publicly Verifiable Shared Dynamic Electronic Health Record Databases With Functional Commitment Supporting Privacy-Preserving Integrity Auditing
abstract
Electronic health record (EHR) is a system that collects patients' digital health information and shares it with other healthcare providers in the cloud. Since EHR contains a large amount of significant and sensitive information about patients, it is required that the system ensures response correctness and storage integrity. Meanwhile, with the rise of IoT, more low-performance terminals are deployed for receiving and uploading patient data to the server, which increases the computational and communication burden of the EHR systems. The verifiable database (VDB), where a user outsources his large database to a cloud server and makes queries once he needs certain data, is proposed as an efficient updatable cloud storage model for resource-constrained users. To improve efficiency, most existing VDB schemes utilize proof reuse and proof updating technique to prove correctness of the query results. However, it ignores the “real-time” of proof generation, which results in an overhead that the user has to perform extra process (e.g., auditing schemes) to check storage integrity. In this article, we propose a publicly verifiable shared updatable EHR database scheme that supports privacy-preserving and batch integrity checking with minimum user communication cost. We modify the existing functional commitment (FC) scheme for the VDB design and construct a concrete FC under the computationall-BDHE assumption. In addition, the use of an efficient verifier-local revocation group signature scheme makes our scheme support dynamic group member operations, and gives nice features, such as traceability and non-frameability.
Ye Su 0001, Jiameng Sun, Jing Qin 0002, Jiankun Hu
IEEE Trans. Cloud Comput.1
2022 Privacy-Preserving Outsourced Inner Product Computation on Encrypted Database
abstract
We consider an outsourced computation model in the selective data sharing setting. Specifically, one of the data owners outsources the encrypted data to an untrusted cloud server, and wants to share the specific function of these data with a group of data users. A data user can perform the specific computation on the data that it is authorized to access. We propose a construction under this model for the inner product computation by using the Inner Product Functional Encryption (IPFE) as a building block. A standard IPFE used on this model has two privacy weaknesses regarding the master secret key and the encrypted vector. We propose a strengthened IPFE that revises these weaknesses. We construct a new IPFE scheme and use it to construct an efficient outsourced inner product computation scheme. In our outsourced computation scheme, the storage overhead and the computation cost for a data user are independent of the vector size. The result privacy and the outsourced data privacy are well preserved against the untrusted cloud server. The experimental results show that our schemes are efficient and practical.
Haining Yang, Ye Su 0001, Jing Qin 0002, Huaxiong Wang
IEEE Trans. Dependable Secur. Comput.2
2021 Practical wildcard searchable encryption with tree-based index
abstract
Wildcard searchable encryption is an advanced variant of searchable encryption that can simultaneously maintain the searchability and confidentiality of the encrypted data. The wildcard searchable encryption outperforms the standard one for the fact that the users can use it to search the desired data even with the inexact keywords. Considering the millisecond level response time in the era of 5G, there are higher demands on the efficiency and accuracy that may be a pair of contradictions in wildcard searchable encryption. To improve the efficiency without sacrificing the accuracy, we put forward a novel scheme, tree-based index scheme (TBIS), through filtering the search results step by step instead of enumeration in the prior works and in the instantiation of TBIS, the search time drops sharply to the millisecond level. By using more kinds of characters, the accuracy of search result is improved visibly. TBIS achieves nonadaptive security that is indistinguishable against chosen character set attacks proposed in this paper. The security criteria can capture the relationship among characters, keywords and documents. At last, we put forward a frame structure in machine learning as an application of the proposed scheme.
Xi Zhang 0005, Bo Zhao 0027, Jing Qin 0002, Ye Su 0001, Haining Yang
Int. J. Intell. Syst.5
2021 Outsourced Decentralized Multi-Authority Attribute Based Signature and Its Application in IoT
abstract
IoT (Internet of things) devices often collect data and store the data in the cloud for sharing and further processing; This collection, sharing, and processing will inevitably encounter secure access and authentication issues. Attribute based signature (ABS), which utilizes the signer’s attributes to generate private keys, plays a competent role in data authentication and identity privacy preservation. In ABS, there are multiple authorities that issue different private keys for signers based on their various attributes, and a central authority is usually established to manage all these attribute authorities. However, one security concern is that if the central authority is compromised, the whole system will be broken. In this paper, we present an outsourced decentralized multi-authority attribute based signature (ODMA-ABS) scheme. The proposed ODMA-ABS achieves attribute privacy and stronger authority-corruption resistance than existing multi-authority attribute based signature schemes can achieve. In addition, the overhead to generate a signature is further reduced by outsourcing expensive computation to a signing cloud server. We present extensive security analysis and experimental simulation of the proposed scheme. We also propose an access control scheme that is based on ODMA-ABS.
Jiameng Sun, Ye Su 0001, Jing Qin 0002, Jiankun Hu, Jixin Ma 0001
IEEE Trans. Cloud Comput.2
2020 Verifiable inner product computation on outsourced database for authenticated multi-user data sharing
Haining Yang, Ye Su 0001, Jing Qin 0002, Huaxiong Wang, Yongcheng Song
Inf. Sci.2
2020 A Dynamic Searchable Symmetric Encryption Scheme for Multiuser with Forward and Backward Security
abstract
Dynamic Searchable Symmetric Encryption for Multiuser (M-DSSE) is an advanced form of symmetric encryption. It extends the traditional symmetric encryption to support the operations of adding and deleting the encrypted data and allow an authenticated group of data users to retrieve their respective desired encrypted data in the dynamic database. However, M-DSSE would suffer from the privacy concerns regarding forward and backward security. The former allows an attacker to identify the keywords contained in the added data by lunching file-injection attacks, while the latter allows to utilize the search results and the deleted data to learn the content. To our knowledge, these privacy concerns for M-DSSE have not been fully considered in the existing literatures. Taking account of this fact, we focus on the dynamic searchable symmetric encryption for multiuser meeting the needs of forward and backward security. In order to propose a concrete scheme, the primitives of Pseudorandom Functions (PRF) and the Homomorphic Message Authenticator (HMAC) are employed to construct the inverted index and update the search token. The proposed scheme is proven secure in the random model. And the performance analysis shows that the proposed scheme achieves the enhanced security guarantees at the reasonable price of efficiency.
Xi Zhang 0005, Ye Su 0001, Jing Qin 0002
Secur. Commun. Networks2