EDBT 2026 Demo / reviewers in the wild / expert
Cong Peng 0005
dblp:35/408-5
· DBLP profile ↗
42ranked-venue papers
7as first author
40since 2021 · last 2026
0000-0002-9958-3255ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 1 first-author · 18 since 2021Computer networks · 15 · 6 first-author · 14 since 2021Systems, architecture and hardware · 7 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On the Preimage Leakage of Property-Preserving Hash
Yangzhou Cao, Min Luo 0002, Cong Peng 0005, Yi Wang 0055, Rongmao Chen, Debiao He |
PKC (4) | 3 |
| 2026 | Revisiting Subgroup Membership Testing on Pairing-Friendly Curves via the Tate Pairing
Debiao He, Dimitri Koshelev, Cong Peng 0005, Zhijian Yang |
PKC (3) | 4 |
| 2026 | Efficient and Provably Secure Heterogeneous Aggregated Signcryption Scheme for VANETs
Xiaoying Jia 0002, Cong Peng 0005 |
IEEE Internet Things J. | 3 |
| 2026 | ESVPH: Efficient Searchable and Verifiable Data Sharing Scheme With Partial Hidden Policy for IoTabstractThe Internet of Things (IoT) is a key engine of global socio-economic transformation, where data sharing stands as a central catalyst for the IoT market's growth. However, data security and privacy concerns significantly impede the advancement of IoT data sharing. Consequently, Attribute-Based Encryption (ABE), offering fine-grained access control, is increasingly favored by data users. Unfortunately, existing ABE schemes still face these drawbacks: (1) the encryption and decryption computation overhead grows linearly with attributes; (2) keyword searches within ciphertexts are intricate and inefficient; (3) the access policy is at higher risk of privacy disclosure. To address these issues, this paper presents an efficient searchable and verifiable scheme with partial hidden policy for IoT (ESVPH). This scheme not only provides flexible keyword-based search and re-encryption verification, but also achieves fixed costs for encryption, decryption, searching and verifying. Additionally, ESVPH introduces an access policy where attribute names are disclosed while their values remain concealed, thereby enhancing user privacy. In conclusion, the scheme offers outstanding performance in computation and communication, proving its feasibility for practical IoT data sharing through rigorous proofs and extensive experimentation. Yong Xie 0003, Chunpeng Ge 0001, Cong Peng 0005, Meng Shen 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Attribute-Based Credentials With Verifiable Human Binding: Toward Compactness and RevocabilityabstractDigital and physical identity authentications are often implemented concurrently to meet strict access control for online services. Although privacy-preserving digital credentials provide strong guarantees such as anonymity and minimal disclosure, these benefits are compromised if holders must simultaneously present physical identification (e.g., government issued IDs) to establish ownership. To securely bind digital credentials to their physical holders while preserving privacy, a new protocol called card-based anonymous credentials (cbAC) was proposed by Hesse et al. (USENIX Security'23). However, this approach faces two significant drawbacks: the size of the communication during credential presentation scales linearly with the number of disclosed attributes, and it lacks revocability, which is essential for internal governance, including identity management and accountability. In this paper, we bridge the above gap by first introducing a constant-size two-party proof of knowledge protocol in asymmetry settings, where there exists a disparity in storage and computational resources between the two parties. Furthermore, building upon this two-party proof of knowledge protocol and utilizing signatures with randomizable keys, we meticulously design a cbAC scheme that is both efficient and capable of supporting revocation. We formalize all notions and conduct a rigorous security proof of the proposed construction. Finally, we present benchmarks from our implementation to illustrate the better than-state-of-the-art performance and features of our solutions. Debiao He, Jianting Ning, Zijian Bao, Cong Peng 0005 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Threshold Issuance Selective Disclosure Credentials With Equivalence Class SignatureabstractAnonymous credentials offer privacy-preserving authentication and authorization by making assertions about identity in the digital realm. To overcome the reliance on a single trusted issuer, decentralized variants have emerged. A classic approach is to split the responsibility of issuing credentials among multiple issuers in a threshold manner (e.g.,t-out-of-n). Unfortunately, among existing threshold protocols, non-interactive practical constructions can only guarantee security in honest majority settings, while interactive constructions face two primary efficiency bottlenecks: either they require an excessive number of interaction rounds, or they fail to support constant-size credential showings for selective disclosure. In this work, we address these challenges by presenting a threshold issuance anonymous credential (TIAC) protocol, built upon the recent advanced signatures, i.e., Equivalence Class Signatures (EQS). Our proposed solution involves a three-round protocol that realizes a standard threshold issuing functionality, providing composable security against a malicious adversary corrupting the majority of issuers. We thereafter introduce a provably secure construction of the TIAC protocol with constant-size showings by combining the proposed threshold issuing protocol and set commitments. We rigorously prove our protocol in the universal composability (UC) framework. The practicality of our protocol is demonstrated through benchmark comparisons with the state-of-the-art EQS-based solution (ASIACRYPT ’24). The benchmarking results show that, with 64 participating issuers, our improvements go up to 6.72× for the threshold issuance phase when observed over WAN. Debiao He, Cong Peng 0005, Min Luo 0002 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | A Framework for Efficient Enhanced Privacy ID from Group Actions
Ying Chen 0030, Debiao He, Zijian Bao, Cong Peng 0005, Min Luo 0002 |
Inscrypt (3) | 4 |
| 2025 | MDKG: Module-Lattice-Based Distributed Key Generation
Debiao He, Zhichao Yang 0002, Min Luo 0002, Cong Peng 0005 |
ICICS (1) | 5 |
| 2025 | RLVP-FL: Robust and lightweight verifiable privacy-preserving federated learning scheme
Pingchao Zhou, Yong Xie 0003, Cong Peng 0005, Yazhe Kang, Debiao He, Tianhong Mu |
Comput. Networks | 3 |
| 2025 | Efficient Module-Lattice-Based Certificateless Online/Offline Signcryption Scheme for Internet of Medical ThingsabstractThe Internet of Medical Things (IoMT) has achieved remote diagnosis and real-time health monitoring through intelligent sensor devices and Internet of Things (IoT) technology, providing great convenience for analyzing medical conditions between doctors and patients. However, sensitive information such as patient medical data may face security challenges such as data leakage and abuse during transmission in the IoMT. To ensure the confidentiality and unforgeability of medical data transmission, scholars have proposed many cryptographic schemes. With the development of quantum computers, schemes based on traditional cryptographic primitives have become insecure. Existing cryptographic schemes for IoMT cannot simultaneously meet the security requirements of high communication performance, low computational overhead, and resistance to quantum attacks. Therefore, we propose an efficient module-lattice-based certificateless online/offline signcryption (MLCLOOSC) scheme resistant to quantum attacks while meeting the confidentiality and unforgeability requirements under Type I and Type II attacks. Compared with five recent CLOOSC schemes, theoretical analysis, and experimental test results show that the proposed scheme outperforms the other five schemes regarding computational and communication costs and security. Therefore, our scheme is more suitable for application in IoMT scenarios. Debiao He, Zhichao Yang 0002, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 5 |
| 2025 | Pairing-Free Blockchain-Assisted Certificateless Aggregation Signcryption Scheme for VANETsabstractSmart vehicle applications play a crucial role in intelligent transportation systems, enabling sensor-equipped vehicles to establish dynamic networks for efficient collection, sharing, and aggregation. This significantly enhances road security and efficiency by transmitting crucial information to traffic authorities. However, partial research on certificateless aggregation signcryption (CLAS) scheme reveals an intriguing phenomenon where each proposed scheme consistently exhibits numerous security vulnerabilities, particularly susceptible to public key replacement attacks. To address these challenges, this paper proposes a blockchain-assisted certificateless aggregation sign-cryption scheme (BACLAS), leveraging blockchain technology to securely store users’ public key on a distributed ledger and prevent public key replacement attacks effectively. Furthermore, it is a provably secure communication scheme for real-world Vehicle-to-Infrastructure (V2I) communication while addressing practical security concerns. The BACLAS scheme ensures security in terms of existential unforgeability against adaptive chosen message attacks (EUF-CMA) and indistinguishability against adaptive chosen ciphertext attacks (IND-CCA2) based on the hardness assumption of the elliptic curve discrete logarithm problem and computational Diffie-Hellman problem in the random oracle model. The proposed scheme effectively reduces computational costs and time consumption, resulting in a significant reduction of the computation burden ranging from 50.02% to 88.28% compared to other competitive schemes. Moreover, it successfully addresses the key-escrow problem, thereby achieving enhanced security properties. Cong Peng 0005, Xiaoying Jia 0002, Jiaming Wen 0001, Yuanyuan Zhang 0014 |
IEEE Internet Things J. | 2 |
| 2025 | An Efficient Delegatable Order-Revealing Encryption Scheme for Multi-User Range QueriesabstractTo balance data confidentiality and availability, order-revealing encryption (ORE) has emerged as a pivotal primitive facilitating range queries on encrypted data. However, challenges arise in diverse user domains where data is encrypted with different keys, giving rise to the development of delegatable order-revealing encryption (DORE) schemes. Regrettably, existing DORE schemes are susceptible to authorization token forgery attacks and rely on computationally intensive bilinear pairings. This work proposes a novel solution to address these challenges. We first introduce a delegatable equality-revealing encryption scheme, enabling the comparison of ciphertexts encrypted by distinct secret keys through authorization tokens. Building upon this, we present a delegatable order-revealing encryption that leverages bitwise encryption. DORE supports efficient multi-user ciphertext comparison while robustly resisting authorization token forgery attacks. Significantly, our approach distinguishes itself by minimizing bilinear pairings. Experimental results highlight the efficacy of DORE, showcasing a notable speedup of$2.8\times$in encryption performance and$1.33\times$in comparison performance compared to previous DORE schemes, respectively. Jingru Xu, Cong Peng 0005, Jintao Fu, Min Luo 0002 |
IEEE Trans. Cloud Comput. | 2 |
| 2025 | $k$k-TEVS: A $ k$k-Times E-Voting Scheme on Blockchain With SupervisionabstractThe e-vote is regarded as a way to express the opinion that the voters ask for. Actually, the e-vote could be applied wildly like questionnaire, survey and feedback. Moreover, the coexistences of efficiency and security as well as transparency and privacy could be considered as building blocks in the e-vote system. The blockchain could provide a public access board to reduce the storage costs for the field consisted of the vote group manager (GM) with its vote assistants (VA). Particularly the$k$-times anonymous authentication ($k$-TAA) could also be a practical approach to preserve voters’ privacy and reduce the computation costs during the vote process. However, the e-vote scheme with pure$k$-TAA strategy could damage either the supervision of voting or the efficiency and consistency of authentication process. What’s more, the impacts of dishonest voters couldn’t be stopped until the vote end. To tackle these problems, we apply the accumulator technology to add or revoke the voters at any time and extend the framework of$k$-TAA with the update process for the e-vote on blockchain for supervision ($ k$-TEVS). In our scheme, the voter updates his membership witness and proves the fact that he is still a valid member with respective VA under the latest accumulator value. What’s more, this witness update operation is not contained in the authentication process, which means that the authentication process is still constant and efficient. Moreover, our add or delete update process with signature of knowledge needs only one pairing operation. For the security, we prove that the relaxed anonymity still holds in the$ k$-TEVS framework. Finally, We implement$ k$-TEVS scheme, the Emura’s work [1] and the Huang’s work [2] for comparison. Then we make time cost and communication cost experiments, which present the feasibility and practicality of this scheme. Yang Liu 0368, Debiao He, Min Luo 0002, Lianhai Wang, Cong Peng 0005 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | EPREAR:An Efficient Attribute-Based Proxy Re-Encryption Scheme With Fast Revocation for Data Sharing in AIoTabstractThe Artificial Intelligence of Things (AIoT) is driving human society from “information” to “intelligence”, and the information technology industry is undergoing tremendous changes. However, AIoT data faces security threats such as leakage and illegal access when assisted by third parties. Therefore, some scholars use attribute-based proxy re-encryption (ABPRE) for secure sharing of data. However, the existing ABPRE schemes suffer from high computational overhead and inefficient attribution revocation, which seriously hinders practical application. To solve these problems, in this paper, we propose an efficient attribute-based proxy re-encryption scheme with fast attribute revocation (EPREAR). We design a non-interactive zero-knowledge proof protocol based on blockchain to ensure the verifiability of the key during attribute revocation. Furthermore, we devise a boundless encryption and decryption mechanism to enable the system's encryption and decryption with a fixed computation overhead, regardless of the size of the attribute set. And EPREAR possesses the ability to add infinite attributes without re-initializing the system. Finally, we perform theoretical and experimental analyses that show EPREAR has excellent computational performance. As a consequence, it has better application value in AIoT. Yong Xie 0003, Cong Peng 0005, Xiong Li 0002, Zhili Zhou 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Revisiting Pairing-Friendly Curves with Embedding Degrees 10 and 14
Debiao He, Cong Peng 0005, Zhijian Yang, Chang-an Zhao |
ASIACRYPT (2) | 3 |
| 2024 | How to Construct Public Timeline for RSA-Formed Time-Lock Cryptography
Huixuan Jin, Cong Peng 0005, Jintao Fu, Min Luo 0002 |
Inscrypt (2) | 2 |
| 2024 | CMAE-MTC: A Contextual Masked AutoEncoder Based Multi-Level Traffic ClassifierabstractTraffic classification is vital for network management, ensuring efficient resource allocation, network security, and quality of service. Due to the increasing complexity and anonymity of network traffic, traditional deep learning methods of traffic classification have exposed the following limitations on this critical task. First, traditional methods tend to consider the whole raw packet data as input of the model, ignoring the importance of a well-formed presentation. Second, direct application of the simple models without targeted improvement cannot deeply capture the feature of the traffic flow, especially those encrypted. Last but not least, supervised learning of traditional methods requires a much higher cost to learn for specific scenarios, resulting from the heavy dependence on labels. To break above limitations, we propose a classifier called CMAE-MTC, which involves a well-designed multi-level presentation matrix of traffic flows, reflecting the association between traffic flows and packets, headers and payloads. Meanwhile, our method introduces an improved masked autoencoder paradigm with a latent contextual regressor for self-supervised learning instead of supervised learning. At last, we replace the naive Vision Transformer in the fine-tuning stage with a multi-level attention module, forcing the model to capture the features from not only the small patches of headers and payloads but also the overall packets and flows. We validate the performance of our model on four real-world available encrypted traffic datasets, ISCXVPN, ISCXTor, USTC-TFC, and CICIoT. Our experimental results demonstrate that our proposed method outperforms state-of-the-art methods for traffic classification tasks. Zecheng Yuan, Min Luo 0002, Cong Peng 0005, Qin Liu 0003 |
ISPA | 3 |
| 2024 | Isogeny-Based Password-Authenticated Key Exchange Based on Shuffle Algorithm
Congrong Peng, Cong Peng 0005, Qingcai Luo, Min Luo 0002 |
ISPEC | 2 |
| 2024 | The governance technology for blockchain systems: a surveyabstractAbstract After the Ethereum DAO attack in 2016, which resulted in significant economic losses, blockchain governance has become a prominent research area. However, there is a lack of comprehensive and systematic literature review on blockchain governance. To deeply understand the process of blockchain governance and provide guidance for the future design of the blockchain governance model, we provide an in-depth review of blockchain governance. In this paper, first we introduce the consensus algorithms currently used in blockchain and relate them to governance theory. Second, we present the main content of off-chain governance and investigate two well-known off-chain governance projects. Third, we investigate four common on-chain governance voting techniques, then summarize the seven attributes that the on-chain governance voting process should meet, and finally analyze four well-known on-chain governance blockchain projects based on the previous research. We hope this survey will provide an in-depth insight into the potential development direction of blockchain governance and device future research agenda. Guocheng Zhu, Debiao He, Haoyang An, Min Luo 0002, Cong Peng 0005 |
Frontiers Comput. Sci. | 5 |
| 2024 | PEACS: A Privacy-Enhancing and Accountable Car Sharing SystemabstractCar sharing is gaining increased popularity in urban transportation which allows individuals to conveniently rent vehicles for short periods. Such systems, however, present considerable challenges to security such as unauthorized access and privacy data breaches, as service providers are able to track the precise mobility patterns of all customers. Nevertheless, efforts in solving the security and privacy concerns associated with car-sharing services are relatively few, in particular for a trade-off between privacy preservation and accountability of misbehaviors. In this work, we propose an efficient Privacy-Enhancing and Accountable Car Sharing System (PEACS), introduced to mitigate the aforementioned threats. PEACS primarily employs several key ingredients, including structure-preserving signatures on equivalence classes (J CRYPTOL’s 19), as well as two primitives designed in this paper, namely: signatures of knowledge and identity-based structure-preserving signatures with a tag on equivalence classes. Furthermore, we employ a bivariate polynomial function to establish a revocation mechanism that ensures accountability. We provide thorough security proof to demonstrate the security and privacy of PEACS. Comprehensive performance evaluation and comparison results point out that our proposed scheme is feasible in practical settings. Debiao He, Zijian Bao, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 5 |
| 2024 | Ciphertext Range Query Scheme Against Agent Transfer and Permission Extension Attacks for Cloud ComputingabstractRange query is commonly used to support ciphertext retrieval on encrypted databases in a cloud-based environment, and order-revealing encryption (ORE) plays an increasingly important role in range query for ciphertext field processing. Specifically, one can utilize ORE to facilitate comparators to determine whether the order of ciphertext(s) corresponds to the associated plaintext(s). Newer ORE designs include those that are resistant to common attacks (e.g., spectral attacks) and those that are capable of supporting both multi-client and single-client settings. However, in the scenario of cross-database range queries, existing multi-client ORE approaches generally pass the data owner’s query key to the searcher during the authorization process. Consequently, this results in agent transfer and permission extension, which can be exploited to facilitate unauthorized access to the database data. To solve these limitations, we propose om-ORE. The latter uses the oblivious pseudorandom function (OPRF) protocol to further enhance the security of token generation mechanism in ORE, and is designed to ensure that neither the data owner nor the authorized client reveals any secret key or expected query range to each other. Using the proposed om-ORE scheme as a building block, we design a secure multi-client ciphertext range query scheme that is resilient to both agent transfer and permission extension attacks. The performance evaluation shows that om-ORE inherits the advantages of state-of-the-art multi-client ORE approaches, in terms of ciphertext size and comparison efficiency, as well as having comparable performance in the token generation process. Hongyi Qiao, Cong Peng 0005, Min Luo 0002, Debiao He |
IEEE Internet Things J. | 2 |
| 2024 | High-speed batch verification for discrete-logarithm-based signatures via Multi-Scalar Multiplication Algorithm
Cong Peng 0005, Lingyan Han, Min Luo 0002 |
J. Inf. Secur. Appl. | 2 |
| 2024 | The implementation of polynomial multiplication for lattice-based cryptography: A survey
Chenkai Zeng, Debiao He, Cong Peng 0005, Min Luo 0002 |
J. Inf. Secur. Appl. | 4 |
| 2024 | Optimizing Dilithium Implementation with AVX2/-512abstractDilithium is a signature scheme that is currently being standardized to the Module-Lattice-Based Digital Signature Standard by NIST. It is believed to be secure even against attacks from large-scale quantum computers based on lattice problems. The implementation efficiency is important for promoting the migration of current cryptography algorithms to post-quantum cryptography algorithms. In this article, we optimize the implementation of Dilithium with several new approaches proposed. Firstly, we improve the efficiency of parallel NTT implementations. The overhead of shuffling operations is reduced in our implementations, and fewer loading instructions are invoked for the precomputations. Then, we optimize the sampling and bit-packing of polynomial coefficients in Dilithium. We can handle double the number of coefficients within one register using a new approach for the sampling of secret key polynomials. The approaches proposed in this article are applicable to implementations under AVX2 and AVX-512 instruction sets. Take Dilithium2 as an illustration, our AVX2 implementation demonstrates improvements of 22.7%, 16.9%, and 13.5% for KeyGen, Sign, and Verify compared with the previous implementation. Runqing Xu, Debiao He, Min Luo 0002, Cong Peng 0005, Xiangyong Zeng |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2023 | Block Ciphers Classification Based on Randomness Test Statistic Value via LightGBM
Min Luo 0002, Cong Peng 0005, Debiao He |
ICICS | 3 |
| 2023 | FleS: A Compact and Parameter-Flexible Supersingular Isogeny Based Public Key Encryption Scheme
Weihan Huang, Min Luo 0002, Cong Peng 0005, Debiao He |
ProvSec | 3 |
| 2023 | Traceable Ring Signatures from Group Actions: Logarithmic, Flexible, and Quantum Resistant
Min Luo 0002, Zijian Bao, Cong Peng 0005, Debiao He |
SAC | 4 |
| 2023 | CUFT: Cuflow-Based Approach with Multi-headed Attention Mechanism for Encrypted Traffic Classification
Xin Zong, Min Luo 0002, Cong Peng 0005, Debiao He |
SecureComm (1) | 3 |
| 2023 | A certificateless Multi-receiver Encryption scheme based on SM2 signature algorithmabstractThe Multi-receiver Encryption (MRE) scheme can meet the secure data transmission requirements in multicast and broadcast scenarios. To meet compliance, critical information infrastructure in China should be protected with Chinese national commercial cryptographic algorithms. Designing an MRE scheme based on Elliptic Curve Cryptography (ECC) is one of the current design methods with better flexibility and performance. However, the research on MRE schemes based on SM2 elliptic curve public-key cryptography is still in a blank state. This paper proposes a Certificateless SM2-based Multi-receiver Encryption (CL-SM2-MRE) scheme. We prove the security of the CL-SM2-MRE scheme under the Random Oracle Model (ROM) and analyze the performance. JingLin Zou, Debiao He, Zhe Liu 0001, Cong Peng 0005 |
High Confid. Comput. | 6 |
| 2023 | A Group Signature Scheme With Selective Linkability and Traceability for Blockchain-Based Data Sharing Systems in E-Health ServicesabstractRecently, with the rapid improvement of e-health technology, a large amount of precious medical data has been accumulated in different entities, such as hospitals, clinics, and medical institutions, promoting the development of data sharing in e-health services. However, most of them lacks fine-grained functionalities: selective linkability and traceability, which are critical in an e-health environment. Furthermore, we observe that existing schemes mostly rely on centralized storage centers, which will lead to a single point of failure and privacy disclosure. In this article, we first construct a group signature schemeSLTGSsuitable for a data sharing environment. It supports selectively linking two different message-signature pairs to the same signer. Further, it provides an algorithm to trace the signer. Then, based on theSLTGSscheme, we leverage distributed technology (i.e., interplanetary file system (IPFS) and blockchain) and attribute-based encryption to propose a distributed data sharing scheme. We claim that our scheme meets anonymity, accountability, linkability, traceability, fine-grained and efficient access control, and distributed storage. Moreover, the proposed data sharing scheme yields a practical performance making it suitable for e-health applications. Zijian Bao, Debiao He, Huaqun Wang, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 5 |
| 2023 | A Secure Certificateless Signcryption Scheme Without Pairing for Internet of Medical ThingsabstractThe Internet of Medical Things (IoMT), which integrates medical sensors with the Internet of Things, is helpful for providing remote diagnosis and real-time decision making. Massive data collected by medical and healthcare monitoring sensors in the IoMT involves sensitive patient information. It brings some security challenges to validate the legitimacy of participating entities and protect patient data privacy. A certificateless signcryption (CLSC) scheme combines encryption and signature that can offer authenticity, confidentiality, and unforgeability, providing a viable solution to the data privacy issue of the IoMT. However, existing CLSC schemes fail to meet confidentiality or unforgeability, or require expensive computation overhead to perform pairing operations. This article first presents a new CLSC scheme for secure data transmission and better smart services in IoMT, which replaces the signature part with the Schnorr signature. We then give a thorough security proof under the random oracle model. Besides, we elaborately evaluate the performance and security of some existing solutions with our solution. Finally, the experiment results indicate that our solution can achieve a better balance between security and performance than some existing schemes. Therefore, in terms of feasibility, our scheme is more suitable for the IoMT scenario. Xin Chen 0051, Debiao He, Muhammad Khurram Khan, Min Luo 0002, Cong Peng 0005 |
IEEE Internet Things J. | 5 |
| 2023 | An identity-based dynamic group signature scheme for reputation evaluation systems
Haoyang An, Debiao He, Zijian Bao, Cong Peng 0005, Qin Liu 0003 |
J. Syst. Archit. | 4 |
| 2023 | LedgerMaze: An Efficient Privacy-Preserving Noninteractive Zero-Knowledge Scheme Over Account-Model BlockchainabstractThe prosperity of blockchain has pushed various decentralized applications, e.g., cross-regional finance, due to its advantages of openness, immutability, and decentralization. The feature of openness inevitably leads to a serious privacy breach. Recently, various privacy-enhanced works (e.g., Zcash, Monero) were proposed focusing on this problem. However, most existing solutions either aim for the unspent transaction output (UTXO) model, or fail to provide full privacy protection for the account-based model with efficient performance. In this paper, we put forwardLedgerMaze, an efficient privacy-preserving non-interactive zero-knowledge (NIZK) scheme over account-model blockchain. We design a novel scheme calledchequemechanism to cut the link between the sender/receiver relationship. Namely, a sender transfers money to a receiver's cheque, then the receiver can retrieve the cheque among a set of cheques for obfuscation without revealing the original one. We construct several efficient NIZK proofs for initializing the mechanism. Moreover, we further analyze the security properties ofLedgerMaze. Experimental results show thatLedgerMazeachieves comparable performance in communication and computation costs while retaining a full privacy guarantee, compared to previous similar constructions. Zijian Bao, Debiao He, Cong Peng 0005, Xinyi Huang 0001 |
IEEE Trans. Computers | 4 |
| 2023 | High-Performance Implementation of the Identity-Based Signature Scheme in IEEE P1363 on GPUabstractIdentity-based cryptography is proposed to solve the complicated certificate management of traditional public-key cryptography. The pairing computation and high-level tower extension field arithmetic turn out to be the performance bottleneck of pairing-based signature schemes. Graphics processing units have been increasingly popular for general-purpose computing in recent years. They have shown a lot of promise in speeding up cryptographic schemes such as AES, RSA, and ECDSA. However, to our knowledge, the research on parallel implementation of pairings and identity-based cryptographic schemes on graphics processing units is somewhat outdated. Therefore, in this article, we implement the identity-based signature scheme in the IEEE P1363 Standard on a modern NVIDIA RTX 3060 card. We convert the pairing computation in signature verification into a product of pairings with fixed arguments and therefore avoid the scalar multiplication in 𝔾 2 . Then we employ the precomputation technique to improve the elliptic curve scalar multiplication, exponentiation in \(\mathbb {F}_{p^{12}}\) and the pairing computation. We also apply PTX ISA to multiple-precision arithmetic. Experiments demonstrate that our implementation can perform 43,856/46,753/39,798 pairings/sec for the Optimal Ate pairing, the pairing with a fixed argument, and two pairings with fixed arguments, respectively. Peak throughputs of signature generation and verification can achieve 322.6 and 40.6 kops/sec over the BN254 curve. Debiao He, Min Luo 0002, Cong Peng 0005, Xinyi Huang 0001 |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2023 | Faster Implementation of Ideal Lattice-Based Cryptography Using AVX512abstractWith the development of quantum computing, the existing cryptography schemes based on classical cryptographic primitives will no longer be secure. Hence, cryptographers are designing post-quantum cryptographic (PQC) schemes, and ideal lattice-based cryptography has emerged as a prime candidate. Today, as ideal lattice-based cryptography becomes more mature, its performance becomes an important optimization goal. In ideal lattice-based cryptography, polynomial arithmetic and polynomial sampling are the most time-consuming operations and therefore need to be accelerated. In this article, taking advantage of the parallelism of new 512-bit advanced vector instructions (AVX512), we present parallel implementations of polynomial arithmetic and polynomial sampling, thus comprehensively improving their performance. We conduct experiments with the Dilithium scheme(one scheme of NIST PQC Standardization Process Round-4). Our implementation gets a nice performance boost compared to its pure C language and 256-bit advanced vector instructions (AVX2) implementation. Douwei Lei, Debiao He, Cong Peng 0005, Min Luo 0002, Zhe Liu 0001, Xinyi Huang 0001 |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2022 | Multifunctional and Multidimensional Secure Data Aggregation Scheme in WSNsabstractIn wireless sensor networks (WSNs), data aggregation (DA) has become one of the most practical techniques to reduce processing delay and improve energy efficiency. To support intelligent applications, sensor nodes need to report heterogeneous and diverse data, which induce the demand for multidimensional DA and multifunctional data analysis. To solve the current security problems and functional requirements, we propose a multifunctional and multidimensional secure DA scheme to strike the balance between data availability and privacy. First, we design a Chinese remainder theorem conversion method with the counter to encode multidimensional data into large integers, which can be operated by linear homomorphic encryption schemes. Then, we introduce a multifunctional data analysis method supporting diversified aggregation functions, including linear, polynomial, and continuous functions. Moreover, we demonstrate that the proposed scheme can achieve confidentiality, integrity, authentication, and resistance against false data injection attacks. The experimental results show that the supported max dimension of one ciphertext in our scheme is at least twice that of existing schemes. Thus, in scenarios with high dimensions, our scheme is superior to the existing schemes in terms of computation and communication costs. Cong Peng 0005, Min Luo 0002, Pandi Vijayakumar, Debiao He, Omar Said, Amr Tolba |
IEEE Internet Things J. | 1 |
| 2022 | An Efficient Privacy-Preserving Aggregation Scheme for Multidimensional Data in IoTabstractInternet of Things (IoT) enables terminal devices connecting with the Internet and provides various intelligent applications by analyzing devices data. As a typical IoT technique, edge computing provides a three-tier architecture to reduce communications and improve efficiency. Specifically, edge nodes are responsible for collecting and aggregating device data, and then send processed results to the cloud for subsequent analysis. However, the data aggregation function will compromise the privacy of device data. In this article, we proposed an efficient privacy-preserving multidimensional data aggregation scheme for IoT, called PMDA. The scheme uses the Chinese remainder theorem to design a homomorphic encryption method that encryptes a multiple-dimensional small integer vector into one ciphertext and keeps linear homomorphic properties per dimension. Combining with the signature mechanism and the batch verification method, the scheme guarantees nonrepudiation of device data and enhance verification efficiency at edge nodes. Through theoretical analysis, we demonstrate that the proposed scheme can achieve correctness, privacy, authentication, and integrity. After performance evaluation, we demonstrate that our scheme is superior to other schemes in terms of computation and communication costs. In particular, as the message dimension increases, our scheme computation costs almost a tenth of others at the 80-bits security level. Cong Peng 0005, Min Luo 0002, Huaqun Wang, Muhammad Khurram Khan, Debiao He |
IEEE Internet Things J. | 1 |
| 2021 | Efficient Certificateless Online/Offline Signature Scheme for Wireless Body Area NetworksabstractWireless body area networks (WBANs) have become more commonplace, including in healthcare settings. For example, in a healthcare WBAN deployment, body sensor units (BSUs) are used to sense and collect health-related and medical-related information prior to sending relevant information to the server for analysis that can subsequently inform treatment plan. Given the sensitivity of both data-at-rest and data-in-transit, data authentication is fundamental to the success of such systems. However, BSUs are generally resource constrained and, hence, conventional cryptographic algorithms are not practical. Therefore, in this article, we propose an efficient certificateless online/offline signature scheme and design a lightweight data authentication protocol for WBANs. We then evaluate the security and performance of our proposed scheme, where the security analysis demonstrates that the proposed scheme satisfies existential unforgeability under the random oracle model. Findings from the performance evaluation also demonstrate that our scheme incurs very low computational cost during the signing operations. In comparison to several other competing approaches, our proposed scheme achieves a significant reduction in computational cost (up to 89%) for the offline signer and supports batch verification to reduce the verifier's execution time. In addition, we also show that the signature size of our proposed scheme is similar to those of the conventional signature schemes. Cong Peng 0005, Min Luo 0002, Li Li 0073, Kim-Kwang Raymond Choo, Debiao He |
IEEE Internet Things J. | 1 |
| 2021 | Efficient Distributed Decryption Scheme for IoT Gateway-based ApplicationsabstractWith the evolvement of the Internet of things (IoT), privacy and security have become the primary indicators for users to deploy IoT applications. In the gateway-based IoT architecture, gateways aggregate data collected by perception-layer devices and upload message packets to platforms, while platforms automatically push different categories of data to different applications. However, security in processes of data transmission via gateways, storage in platforms, access by applications is the major challenge for user privacy protection. To tackle this challenge, this article presents a secure IoT scheme based on a fine-grained multi-receive signcryption scheme to realize end-to-end secure transmission and data access control. To enhance the security of online application decryption keys, we design a distributed threshold decryption scheme based on secret-sharing. Moreover, from the provable security perspective, we demonstrate that the scheme can achieve the expected IND-CCA security and EUF-CMA security. After the performance analysis, evaluation results show that the computational performance is efficient and linearly subject to the number of messages and the number of receivers. Cong Peng 0005, Jianhua Chen 0002, Pandi Vijayakumar, Neeraj Kumar 0001, Debiao He |
ACM Trans. Internet Techn. | 1 |
| 2021 | EPRT: An Efficient Privacy-Preserving Medical Service Recommendation and Trust Discovery Scheme for eHealth SystemabstractAs one of the essential applications of health information technology, the eHealth system plays a significant role in enabling various internet medicine service scenes, most of which primarily rely on service recommendation or an evaluation mechanism. To avoid privacy leakage, some privacy-preserving mechanisms must be adopted to protect raters’ privacy and make evaluation trust reliable. To tackle this challenge, this article proposes an efficient service recommendation and evaluation scheme, called EPRT , which is based on a similarity calculation and trust discovery method. This scheme uses homomorphic encryption technology to encrypt the sensitive data and combines the threshold mechanism and double-trap mechanism to realize the secure computing on the encrypted data, so as to ensure that the plaintexts of the final calculation results (e.g., recommendation value and evaluation truth) are only obtained by the authorized subject. In addition, a detailed security analysis shows that the proposed EPRT scheme can achieve the expected security. In addition, performance comparison results are carried out, demonstrating its effectiveness and accuracy. Cong Peng 0005, Debiao He, Jianhua Chen 0002, Neeraj Kumar 0001, Muhammad Khurram Khan |
ACM Trans. Internet Techn. | 1 |
| 2020 | Efficient and Provably Secure Multireceiver Signcryption Scheme for Multicast Communication in Edge ComputingabstractWith the popularity of edge computing, edge nodes are connected with the Internet of Things (IoT) devices to process and analyze IoT-created data, and feedback corresponding results to users, devices, or data centers. In the edge computing environment, multicast is a typical communication pattern to support data transmitting between edges and devices. It allows the sender to send messages to multiple receivers in one broadcast message. To construct a secure multicast channel, the primary issue is to ensure the privacy and credibility of the transmitted message in the open wireless communication. Then, another essential issue for multicast channels is receiver anonymity, i.e., only the sender knows the receivers' identities. Also, efficiency and provable security are critical in scheme design. In this article, we design a certificateless multimessage and multireceiver signcryption (CLMMSC) scheme by using the elliptic curve cryptography. To facilitate lightweight deployment, we adapt the certificateless mechanism to reduce the system operation and maintenance costs. Then, through security proofs, we demonstrate that the proposed scheme can achieve the expected security properties. The performance analysis shows that the proposed scheme has lower communication costs than previous CLMMSC schemes. Cong Peng 0005, Jianhua Chen 0002, Mohammad S. Obaidat, Pandi Vijayakumar, Debiao He |
IEEE Internet Things J. | 1 |
| 2020 | CsiIBS: A post-quantum identity-based signature scheme based on isogenies
Cong Peng 0005, Jianhua Chen 0002, Lu Zhou 0002, Kim-Kwang Raymond Choo, Debiao He |
J. Inf. Secur. Appl. | 1 |