Guiyi Wei

dblp:39/3529 · DBLP profile ↗
← Back
63ranked-venue papers
12as first author
30since 2021 · last 2026
0000-0002-0635-2053ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 27 · 6 first-author · 15 since 2021Security and privacy · 15 · 8 since 2021Systems, architecture and hardware · 8 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 4 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 GTPAN: A GRU-TPA-KAN Integrated Temporal-Pattern-Aware Neural Network for Shared Bicycle Deployment Forecasting and Dynamic Pricing Optimization
abstract
This paper develops GTPAN, an IoT-enabled temporal-pattern-aware neural framework for real-time shared mobility forecasting and dynamic pricing optimization. Within the Internet of Things (IoT) ecosystem of smart urban transportation, massive spatiotemporal data streams are continuously generated from bicycles, docking stations, and user mobile sensors. Traditional pricing and deployment schemes are often static and fail to adapt to this rapidly evolving IoT environment, leading to over-deployment and revenue loss. The proposed GTPAN framework integrates a Gated Recurrent Unit (GRU) for temporal encoding, a Temporal Pattern Attention (TPA) mechanism for adaptive feature weighting, and a Kolmogorov–Arnold Network (KAN) for nonlinear mapping, jointly enabling accurate demand prediction under complex IoT data dependencies. Furthermore, an improved domain-constrained simulated annealing algorithm is incorporated to achieve real-time dynamic pricing with low computational latency, making the model suitable for edge-intelligent deployment. Experimental results on real-world IoT-based shared bicycle datasets demonstrate that GTPAN improves mean prediction accuracy by 5.74% and revenue by 45% compared with state-of-the-art methods. The proposed framework provides an interpretable and scalable solution for IoT-driven smart mobility management, contributing to sustainable and efficient urban transportation systems.
Guiyi Wei, Qinyi Long, Youlin Fu, Xiaojun Cheng, Yuman Zhou, Huangcheng Zhang
IEEE Internet Things J.1
2026 Public Key Encryption With Case-Insensitive Fuzzy Equality Test
abstract
Public key encryption with equality test (PKEET) has been widely adopted in applications such as private health record management, secure outsourced data processing, and email filtering, owing to its ability to test equality on ciphertexts encrypted under different public keys. However, existing PKEET schemes often fall short in specialized settings, such as case-insensitive matching. Moreover, their security guarantees remain inadequate. In particular, many existing schemes are vulnerable to offline message recovery attacks (OMRA), which present a significant security challenge to PKEET. Furthermore, the existing IND-CCA security model is incomplete, as it fails to model all potential attacks that an adversary could exploit to execute the OMRA. To address these challenges, we propose a new variant of PKEET, termed public key encryption with case-insensitive fuzzy equality test (PKE-CIFET). To analyze security, we propose a unified security model that more closely aligns with IND-CCA security than previous works. This model includes more comprehensive oracles and considers adversaries launching the OMRA through multi-hop testing. Based on this model, we provide a comprehensive and rigorous security proof. Furthermore, experimental results demonstrate that the proposed PKE-CIFET scheme is efficient in terms of computational cost.
Chengyu Jin, Jun Shao 0001, Donghai Zhu, Cong Zuo 0001, Guiyi Wei
IEEE Trans. Inf. Forensics Secur.8
2025 Fuzzy Neural Network Enhanced Information Fusion for Multimodel Action Recognition
abstract
With the development of hardware and communication technology, human action recognition (HAR) in the Internet of Things (IoT) environment is gradually becoming the solution to problems such as long-term healthcare, security surveillance, etc. However, HAR in IoT faces challenges due to heterogeneous, uncertain, and resource-constrained sensing conditions. To address this, we propose FIFIAR, a lightweight adaptive fuzzy neural network (FNN)-based decision fusion framework designed for image-based HAR in IoT systems. FIFIAR learns fuzzy relationships across multiple modalities (RGB, depth, IR, skeleton) to reduce decision uncertainty and support efficient, real-time inference on edge devices. Experiments on MSR Daily Activity and NTU RGB+D 120 datasets show that FIFIAR achieves 99.8% and 96.36% accuracy, respectively, outperforming conventional fusion methods and demonstrating strong potential for real-world IoT deployments.
Guiyi Wei, Zhengguo Sheng
IEEE Internet Things J.2
2025 Spatial-Sampling-Based Spectrum Aliasing Analysis and Antenna Array Structure Optimization for Massive MIMO Systems
abstract
Massive multiple-input multiple-output (MIMO) arrays have emerged as pivotal technology for 5G wireless communication systems, finding widespread implementation and deployment. However, despite their significant potential, the performance gains achieved in practical environments do not consistently scale with the accompanying rise in hardware costs. To address this issue, we delve into the design of rectangular array structures for massive MIMO with varying parameters. The core idea is to optimize the array structure to suit diverse propagation characteristics. Our approach treats the massive MIMO array as a spatial sampling system. A 2-D Fourier transform concerning the elevation and azimuth steering factors is employed to derive the angular spectrum of incoming signals at the base station. Building on spatial spectrum analysis, we unveil the relationship between antenna array parameters, such as the number of antennas and the vertical/horizontal antenna spacings, and the spatial resolution and spectral aliasing inherent to the massive MIMO system. Furthermore, we investigate how array structure parameters impact channel capacity in multiuser scenarios and propose effective strategies for enhancing capacity while mitigating aliasing through parameter adjustments. Finally, we present numerical results that validate the effectiveness of our proposed approaches. The outcomes of this study establish a solid foundation for optimizing the design, deployment, and spatial resource allocation of practical massive MIMO systems.
Anding Wang, Rui Yin 0001, Guiyi Wei
IEEE Internet Things J.3
2025 Hyperparameter Optimization for Wireless Network Traffic Prediction Models With a Novel Meta-Learning Framework
abstract
This paper proposes a novel meta-learning based hyper-parameter optimization framework for wireless network traffic prediction (NTP) models. The primary objective is to accumulate and leverage the acquired hyper-parameter optimization experience, enabling the rapid determination of optimal hyper-parameters for new tasks. In this paper, an attention-based deep neural network (ADNN) is employed as the base-learner to address specific NTP tasks. The meta-learner is an innovative framework that integrates meta-learning with the k-nearest neighbor algorithm (KNN), genetic algorithm (GA), and gated residual network (GRN). Specifically, KNN is utilized to identify a set of candidate hyper-parameter selection strategies for a new task, which then serves as the initial population for GA, while a GRN-based chromosome screening module accelerates the validation of offspring chromosomes, ultimately determining the optimal hyper-parameters. Experimental results demonstrate that, compared to traditional methods such as Bayesian optimization (BO), GA, and particle swarm optimization (PSO), the proposed framework determines optimal hyper-parameters more rapidly, significantly reduces optimization time, and enhances the performance of the base-learner. It achieves an optimal balance between optimization efficiency and prediction accuracy.
Liangzhi Wang, Jie Zhang 0003, Yuan Gao 0013, Jiliang Zhang 0001, Guiyi Wei, Bin Zhuge, Zitian Zhang
IEEE Internet Things J.5
2024 Keep the Key Part: Exploring Drone-Captured Digital Elevation Model Data Augmentation for Deep Learning-based Crop Height Estimation
abstract
In precision farming, accurate crop height estimation is crucial. Deep neural networks (DNNs) have been shown to effectively estimate crop height from drone-captured images, offering more precise and automated measurements. However, the reliability of RGB and multispectral images is compromised by lighting conditions, shadows, and seasonal variations. Digital Elevation Models (DEMs) derived from drone images provide a stable terrain elevation representation, which is less susceptible to environmental fluctuations. Moreover, training DNN models demands a large amount of data, necessitating extensive datasets for each crop height measurement setting. Data augmentation is a common strategy to enhance data diversity. It works well on RGB images by mimicking real-world variations to help the models adapt to a range of environments. However, applying similar augmentation methods to DEM can alter its geometry, potentially misrepresenting the terrain elevation and introducing errors and noise. This study investigates the performance of augmentation methods on DEM and introduces the KeepKey DEM augmentation, which is designed to preserve crucial DEM features while increasing data diversity, thus improving DNN training efficiency without additional data collection and keeping data variation within a controllable level. Our evaluation, conducted on a public cotton dataset from a sloped area, demonstrates that the KeepKey DEM augmentation improves DNN performance, reducing Root Mean Square Error by up to 19.36% compared to non-augmented models, by 39.1% compared to AutoAugment, by 14.29% compared to models with conventional augmentation method, by 23.5% compared to DEM-specific augmentation– Terrain amplification, by 40.7% compared to manual ground-canopy differentiation.
Nobuyuki Oishi, Renhui Ying, Guiyi Wei, Philip Birch, Bao Kha Nguyen
VCIP4
2024 Dynamic spectrum access for Internet-of-Things with joint GNN and DQN
Feng Li 0008, Kwok-Yan Lam, Bowen Shen, Guiyi Wei
Ad Hoc Networks5
2024 A novel verifiable chinese multi-keyword fuzzy rank searchable encryption scheme in cloud environments
abstract
As an important cryptographic primitive, searchable encryption (SE) plays a crucial role in performing keyword searching on encrypted texts. However, in order to realize fuzzy keyword search, most fuzzy search encryption schemes utilize wildcards and gram technology to construct fuzzy sets, which consumes a lot of storage and computational resources. Therefore, in this paper, we propose a new verifiable Chinese multi-keyword fuzzy rank searchable encryption (VCMKFRSE) scheme. Firstly, we take advantage of the Yongzi Ba method to convert Chinese keywords into stroke strings, and employ chinese keywords vector generation algorithm to convert the stroke string into a keyword vector. Secondly, we utilize inverted index tables to establish the relationship between keywords and documents. In particular, the relevance score between keywords and documents is calculated by using the three-factor algorithm. Also, we adopt the MinHash function to construct a fuzzy index table for each keyword vector. Thirdly, in order to realize the authentication of search results and avoid receiving useless search results, we build an authentication tag table by using an authentication tag generation function. Afterwards, we apply probabilistic trapdoors to resist distinguishability attacks. At last, our scheme achieves IND-CCA secure and is more efficient comparing with the state of the art. Overall, our proposal achieves fuzzy multi-keyword search and more accurate search result ranking, while ensuring data security and higher efficiency.
Mande Xie, Xuekang Yang, Haibo Hong, Guiyi Wei
Future Gener. Comput. Syst.4
2024 Efficient and Privacy-Preserving Aggregate Query Over Public Property Graphs
abstract
Graph data structures’ ability of representing vertex relationships has made them increasingly popular in recent years. Amid this trend, many property graph datasets have been collected and made public to facilitate a variant of queries such as the aggregate queries that will be extensively exploited in this paper. While cloud deployment of both the datasets and query services is intriguing, it could raise privacy concerns related to user queries and results. In past years, many works on graph privacy have been put forth, however they either do not consider query privacy or cannot be adapted for aggregate queries. Some others consider queries over encrypted graphs but cannot protect access pattern privacy. In particular, when deploying them to handle queries over public graph datasets, the cloud server can infer additional information related to user queries. Aiming at this challenge, we propose a privacy-preserving property graph aggregate query scheme in this paper. Specifically, we first design new privacy-preserving vertex matching and matching update techniques, which securely initialize and update the mapping between vertices in the dataset and the user-specified patterns, respectively. Based on them, we construct our proposed scheme to achieve aggregate queries over public property graphs. Rigid security analysis shows that our proposed scheme can protect the privacy of user queries and results as well as achieve access pattern privacy. In addition, extensive experiments also demonstrate the efficiency of our scheme in terms of computational overheads.
Yunguo Guan, Rongxing Lu, Songnian Zhang, Yandong Zheng, Jun Shao 0001, Guiyi Wei
IEEE Trans. Big Data6
2024 $k$kTCQ: Achieving Privacy-Preserving $k$k-Truss Community Queries Over Outsourced Data
abstract
Community search over graphs, which is believed as a powerful tool for locating subgraphs of closely related vertices, has received considerable attention in recent years, and$k$-truss is such a popular community search metric to obtain subgraphs in which every edge forms$(k-2)$triangles. In this paper, we particularly consider$k$-truss community query services, which will return all$k$-truss communities containing a given query vertex. As is known, when the size of graph grows, for achieving better performance, it is natural for a service provider to outsource the services to a powerful cloud. However, this stresses the need for privacy-preserving$k$-truss community query services, as the cloud server is not fully trustable. Over the past years, many schemes focusing on privacy-preserving graph computation have been put forth, but none of them can well support privacy-preserving$k$-truss community queries. Aiming at this challenge, we first propose a privacy-preserving$k$-truss community query scheme ($k$TCQ) by constructing boolean circuits with homomorphic encryption technique and a table-based index. After that, we also design an efficiency-enhanced version ($k$TCQ+) based on a stream cipher scheme to reduce the encrypted index's size and improve the query efficiency. Detailed security analysis shows that both$k$TCQ and$k$TCQ+ can well preserve data privacy and access pattern privacy, and extensive experimental results also demonstrate that$k$TCQ+ can observably reduce the size of encrypted index and the query time by$12\times$and$5.9\times$, respectively.
Yunguo Guan, Rongxing Lu, Songnian Zhang, Yandong Zheng, Jun Shao 0001, Guiyi Wei
IEEE Trans. Dependable Secur. Comput.6
2024 The Potential Harm of Email Delivery: Investigating the HTTPS Configurations of Webmail Services
abstract
Webmail, protected by the HTTPS protocol, only works correctly if both the server and client implement HTTPS-related features without vulnerability. Nevertheless, the deployment situation of these features in the webmail world is still unclear. To this end, we perform the first end-to-end and large-scale measurement of webmail service. For the server side, we first build an email address set with a size of 2.2 billion. Then we construct two webmail domain datasets: one contains 21 k domains filtered from the email address set; the other only includes 34 domains but supports more than 75% of the 2.2 billion email addresses. After performing a comprehensive measurement on these two webmail domain datasets, we find that some features are poorly deployed. Furthermore, we also rank servers by analyzing the properties of HTTPS-related features. For the client side, we investigate implement of HTTPS-related features in 50 different combinations of web browsers and operating systems (OSes). We find that even the latest browsers have poor support for some features. For example, Firefox in all OSes does not support CT. Our findings highlight that the full deployment of the security features for the HTTPS ecosystem is still a challenge, even in the webmail service.
Ruixuan Li 0008, Zhenyong Zhang, Jun Shao 0001, Rongxing Lu, Xiaoqi Jia, Guiyi Wei
IEEE Trans. Dependable Secur. Comput.6
2024 Anonymous Multi-Hop Payment for Payment Channel Networks
abstract
Payment Channel Networks (PCNs) have flourished as one of the most promising solutions to the blockchain scalability problem. Unfortunately, the existing PCN solutions either fail to provide path privacy guarantees or require the not-always-true All-Anonymous-Connected assumption (i.e., an anonymous communication channel always exists for any two participants). To alleviate these problems, we first present a new cryptographic primitive named anonymous multi-hop payment (AMHP), which is an improvement of anonymous multi-hop lock (AMHL). Using AMHP and payment channels, we can have a new PCN solution with path privacy but removing the All-Anonymous-Connected assumption. After that, we present the first AMHP scheme, called AMHL+, by adapting the generic construction of AMHL, but at the cost of high communication overhead. To reduce the communication cost, we further present a new AMHP scheme (named EAMHL+) using bilinear pairing. The communication cost of the EAMHL+ is reduced by 92.3% compared to the AMHL+. The rigorous security analysis demonstrates that the EAMHL+ holds consistency, balance security, and path privacy. Finally, we implement the proposed AMHP schemes using Java. The extensive experimental results show that, though the EAMHL+ requires more computational cost than the AMHL+, it is more efficient than the latter in terms of communication overhead.
Yi Zhang 0104, Bianjing Pan, Jun Shao 0001, Liming Fang 0001, Rongxing Lu, Guiyi Wei
IEEE Trans. Dependable Secur. Comput.7
2024 Covert Communication in Large-Scale Multi-Tier LEO Satellite Networks
abstract
We leverage covert communication to enhance the security of a large-scale multi-tier Low Earth Orbit (LEO) satellite network against vigilant adversarial terrestrial Base Stations (BSs) aiming at detecting satellite transmissions. This approach involves deploying massive LEO satellites at different altitudes around Earth to form a multi-tier network serving as a backhaul for near-ground Unmanned Aerial Vehicles (UAVs) that provide network services to terrestrial mobile users. Meanwhile, terrestrial BSs attempt to detect satellite transmissions based on their own received signal powers. To evade detection, the LEO satellite network performs power control to obscure the satellite transmission within the co-channel interference among the LEO satellites. We formulate a two-stage Stackelberg game to model the conflict dynamics between the terrestrial BSs and the LEO satellite network. In this game, the terrestrial BSs act as non-cooperative followers at the lower stage aiming to minimize their detection errors. On the other hand, the LEO satellite network acts as the leader at the upper stage aiming to maximize its utility while ensuring communication covertness. In contrast to existing works that focus on a small set of network nodes, our study considers a large-scale multi-tier LEO satellite network and employs stochastic geometry to model the spatial distribution of network nodes. To achieve the Stackelberg equilibrium, we develop a bi-level algorithm based on Successive Convex Approximation (SCA) and golden-section search. Our numerical results provide practical insights, revealing a trade-off in leveraging co-channel interference (i.e., while it improves the communication covertness of satellite transmission, it simultaneously degrades the link reliability).
Shaohan Feng, Xiao Lu 0001, Sumei Sun, Ekram Hossain 0001, Guiyi Wei, Zhengwei Ni
IEEE Trans. Mob. Comput.5
2024 Equilibrium-Equation-Based Fast Recursive Principal Component Tracking With an Adaptive Forgetting Factor for Joint Spatial Division and Multiplexing Systems
abstract
In massivemultiple-input multiple-output(MIMO) systems, block diagonalization-based precoding methods are employed to mitigate interference among users by relying on channel state information. However, as the number of antennas increases, the task of eigenvalue decomposition or matrix inversion for the channel covariance matrix becomes progressively challenging. In this paper, we propose an equilibrium-equation-based recursive channel principal component tracking algorithm specifically designed for linear precoding inJoint Spatial Division and Multiplexing(JSDM) systems. Unlike many existing algorithms that depend on gradient formulations and the choice of step size, our proposed recursive tracking algorithm operates without the need for a step size, significantly enhancing convergence speed and learning performance. We also derive the adaptive forgetting factor, which improves the convergence capability. Additionally, we provide a mathematical analysis of the algorithm’s convergence performance, mean deviation, and learning curve. Finally, we implement various precoding strategies to a downlink channel in a massive MIMO JSDM system, leveraging the channel’s principal components. Our simulations conclusively demonstrate that the proposed algorithm outperforms traditional tracking algorithms, while principal component-based precoding effectively enhances spectral efficiency.
Anding Wang, Guiyi Wei
IEEE Trans. Wirel. Commun.2
2023 Federated Learning based Vehicular Threat Sharing: A Multi-Dimensional Contract Incentive Approach
abstract
Connected and Autonomous Vehicles (CAVs) provide significant societal benefits but pose serious security risks due to their high connectivity and openness. Traditional security measures like cryptography and intrusion detection systems (IDSs) are reactive and passive, posing significant challenges to securing CAVs. We propose a proactive and collaborative threat-sharing framework to tackle the above challenges and enhance CAV security through vehicular honeypots. The proposed framework leverages federated learning, which allows CAVs to share threat information decentralized while preserving their privacy. Additionally, we design an optimal incentive mechanism that considers three private information of CAVs, including deployment, training, and communication costs. Specifically, we leverage the self-disclosure property of the contract theory, which can effectively address information asymmetry and incentive mismatches between CAVs and the IDS server, motivating CAVs to participate in threat sharing. Finally, through a series of simu- lation experiments, we validate the feasibility of the contract and evaluate the effectiveness of our proposed incentive mechanism.
Tom H. Luan, Nan Cheng 0001, Guiyi Wei, Zhou Su 0001, Yiliang Liu
VTC Fall4
2023 A domain name management system based on account-based consortium blockchain
Genhua Lu, Yi Zhang 0104, Jun Shao 0001, Guiyi Wei
Peer Peer Netw. Appl.5
2023 Achieving Efficient and Privacy-Preserving ($\alpha,\beta$α,β)-Core Query Over Bipartite Graphs in Cloud
abstract
Bipartite graphs have been widely adopted in applications such as e-healthcare thanks to their ability to model various real-world relationships. Meanwhile, (,)-core query services over bipartite graphs are recognized as a promising approach for finding communities, i.e., closely related sets of vertices in a bipartite graph. As the bipartite graph grows, service providers tend to outsource the services to the cloud. However, there are privacy concerns related to the dataset, queries, and results. Although many schemes have been proposed for privacy-preserving graph analysis, they cannot be directly adopted to handle accurate (,)-core queries. Aiming at the challenges, under the two-server setting, this paper constructs two privacy-preserving schemes with different security levels to handle (,)-core queries. In the proposed schemes, a graph is represented as an index containing two tables and further encrypted by a symmetric homomorphic encryption scheme, and then the servers securely traverse the index. Detailed security analysis shows that both schemes can achieve access pattern privacy, while the security-enhanced one can further protect the structure of the query requests and results. In addition, extensive performance evaluations are conducted to indicate the efficiency of our proposed schemes.
Yunguo Guan, Rongxing Lu, Yandong Zheng, Songnian Zhang, Jun Shao 0001, Guiyi Wei
IEEE Trans. Dependable Secur. Comput.6
2023 Achieving Privacy-Preserving Discrete Fréchet Distance Range Queries
abstract
The advances in Internet of Things, Big Data, and machine learning technologies have greatly transformed our daily lives into much more intelligent ones by offering various promising services. Among those services, the discrete Fréchet distance (DFD) range query, which aims to obtain a set of trajectories whose distances to a given query trajectory do not exceed a given threshold, has been widely applied to support applications such as vehicle trajectory clustering and other data processing tasks. Meanwhile, due to the huge data volume issue in the Big Data era, there is a trend towards outsourcing various query services to the cloud for achieving a better performance. However, since the cloud is not fully trustable, designing privacy-preserving query services becomes a research focus. Over the past years, many schemes focusing on privacy-preserving trajectory analysis have been proposed, but none of them can well support privacy-preserving DFD range queries. Aiming at addressing this challenge, this paper proposes a novel privacy-preserving DFD range query scheme, in which queries are conducted in a filtration-and-verification manner and the privacy of the dataset and queries can be preserved. Specifically, by indexing the dataset with two R-trees, a query can be conducted by i) querying the two R-trees to obtain a candidate set and ii) verifying each trajectory in the set, which involve two basic operations, namely, rectangle intersection detection and proximity detection. To preserve the privacy of the dataset and queries, we build the two basic operations upon a novel Inner-Product Preserving Encryption (IPPE) scheme, which is proved to be selectively secure with trivial leakages. Besides, extensive experiments are conducted, and the results demonstrate that our proposed scheme can significantly reduce the computational cost by effectively reducing the candidate set’s size.
Yunguo Guan, Rongxing Lu, Yandong Zheng, Songnian Zhang, Jun Shao 0001, Guiyi Wei
IEEE Trans. Dependable Secur. Comput.6
2023 Cross-Chain Virtual Payment Channels
abstract
With the emergence of countless independent blockchain systems in recent years, cross-chain transactions have attracted considerable attention, and lots of solutions have been put forth by both industry and academia. However, most of the existing solutions suffer from either centralization or scalability issues. To mitigate these issues, in this paper, we propose the concept of cross-chain virtual payment channels, which allows two users in different blockchain systems to conduct limitless off-chain transactions with the help of an intermediate node, hence solving the centralization and scalability issues. Furthermore, as the intermediate node is only involved in the channel open and close operations, it further improves the efficiency of cross-chain transactions, and to a certain extent, it even enhances the privacy of the cross-chain transaction. Meanwhile, we also present the first concrete cross-chain virtual payment channel scheme, which only requires one of the blockchain systems supporting the Turing-complete scripting language. The corresponding detailed security analysis in the Universal Composability framework demonstrates that our proposal holds the Consensus on Open, Update, and Close. Finally, we implement and deploy our cross-chain virtual payment channel scheme on the Ethereum and Bitcoin test networks. The extensive experimental results show that our proposal dramatically improves the efficiency of cross-chain transactions, and the advantage becomes more pronounced as the number of transactions increases.
Jun Shao 0001, Rongxing Lu, Guiyi Wei, Zhenguang Liu
IEEE Trans. Inf. Forensics Secur.5
2023 A Longitudinal and Comprehensive Measurement of DNS Strict Privacy
abstract
The DNS privacy protection mechanisms, DNS over TLS (DoT) and DNS over HTTPS (DoH), only work correctly if both the server and client support the Strict Privacy profile and no vulnerability exists in the implemented TLS/HTTPS. A natural question then arises: what is the landscape of DNS Strict Privacy? To this end, we provide the first longitudinal and comprehensive measurement of DoT/DoH deployments in recursive resolvers, authoritative servers, and browsers. With the collected data, we find the number of DoT/DoH servers increased substantially during our ten-month-long scan. However, around 60% of DoT and 44% of DoH recursive resolver certificates are invalid. Worryingly, our measurements confirm the centralization problem of DoT/DoH. Furthermore, we classify DNS Strict Privacy servers into four levels according to daily scanning results on TLS/HTTPS-related security features. Unfortunately, around 25% of DoH Strict Privacy recursive resolvers fail to meet the minimum level requirements. To help the Internet community better perceive the landscape of DNS Strict Privacy, we implement a DoT/DoH server search engine and recommender system. Additionally, we investigate five popular browsers across four operating systems and find some inconsistent behavior with their DNS privacy implementations. For example, Firefox in Windows, Linux, and Android allows DoH communication with the server without the SAN certificate. At last, we advocate that all participants head together for a bright DNS Strict Privacy landscape by discussing current hindrances and controversies in DNS privacy.
Ruixuan Li 0008, Zhenyong Zhang, Jun Shao 0001, Rongxing Lu, Jingqiang Lin 0001, Xiaoqi Jia, Guiyi Wei
IEEE/ACM Trans. Netw.8
2023 Multi-Agent Deep Reinforcement Learning Based Downlink Beamforming in Heterogeneous Networks
abstract
We consider a heterogeneous network (HetNet), where multiple access points (APs) of potentially different transmission capacities serve users simultaneously via beamforming in the same spectrum band. We propose a beamforming framework that exploits multi-agent deep reinforcement learning (DRL) for the HetNet to maximize the system downlink sum-rate. In our framework, each AP acts as an agent, which is equipped with an online policy deep neural network (DNN) and an online Q-function DNN. The former generates an AP’s beamforming vector based only on local observations in a time slot, while the latter evaluates the appropriateness of this beamforming vector. We present a distributed-updating-centralized-rewarding scheme to train the policy DNNs and Q-function DNNs of all the APs in an online trial-and-error way. Under this scheme, all the APs take the system downlink sum-rate in a recent time slot (informed by a central controller) as their identical one-step reward. Trained by the experience items with centralized rewards in every time slot, the weight vectors of each AP’s local DNNs will be updated in the direction to the global optimum. Simulation results demonstrate that the proposed framework converges fast and outperforms the benchmark beamforming methods in terms of the system downlink sum-rate performance.
Zitian Zhang, Jinbo Hou, Xiaoli Chu, Guiyi Wei, Jie Zhang 0003
IEEE Trans. Wirel. Commun.5
2022 A CCA secure public key encryption scheme based on finite groups of Lie type
Haibo Hong, Jun Shao 0001, Licheng Wang 0004, Mande Xie, Guiyi Wei, Yixian Yang, Song Han 0006, Jianhong Lin
Sci. China Inf. Sci.5
2022 EPGQ: Efficient and Private Feature-Based Group Nearest Neighbor Query Over Road Networks
abstract
The rapidly growing location-based services enable service providers to accumulate plentiful descriptions on points of interest (POIs), which can be used to support expressive POI queries. In this article, we study a type of POI query, named feature-based group$k$nearest neighbor query over road networks, in which a user has a feature set and several locations and wishes to find$k$closest POIs that have similar sets of features to the query. As the POI data sets grow, service providers tend to outsource their data sets to a powerful yet not-fully trusted cloud, which calls for privacy preservation on data sets and user queries. Although many schemes have been proposed for privacy-preserving POI queries, none of them can simultaneously support privacy-preserving set similarity and road network distance comparison. To address this challenge, we propose an efficient and private feature-based group nearest neighbor query scheme. In our scheme, we achieve privacy-preserving distance comparison by employing the road network hypercube embedding technique, and design an encrypted index based on B+-tree for privacy-preserving set similarity range queries. Security analysis shows our proposed scheme can preserve the privacy of the data set and queries, and performance evaluation also demonstrates it is computationally efficient.
Yunguo Guan, Rongxing Lu, Yandong Zheng, Songnian Zhang, Jun Shao 0001, Guiyi Wei
IEEE Internet Things J.6
2022 Fair Outsourcing Polynomial Computation Based on the Blockchain
abstract
Due to the big data blowout from the Internet of Things and the rapid development of cloud computing, outsourcing computation has received considerable attention in recent years. Particularly, many outsourcing computation schemes have been proposed to dedicate the outsourcing polynomial computation due to its use in numerous fields, such as data analysis and machine learning. However, none of those schemes are practical enough, as they either require some time-consuming cryptographic operations to achieve fairness between the user and the worker, or cannot allow the user to outsource arbitrary polynomial to the worker, or need two non-collusive workers. To tackle these challenges, in this article, we propose a new outsourcing polynomial computation scheme by employing a variant of Horner’s method and the blockchain technology. Specifically, the former makes the computational cost on the worker side as low as possible, and the latter guarantees the fairness between the user and the worker if the result from the worker can be publicly verified. To achieve the public verifiability property, we apply the sampling technique, which is effective in our proposal according to a game-theoretic analysis. Furthermore, we also implement a prototype of our proposal and run it on an Ethereum test net. The extensive experimental results demonstrate that our proposal is efficient in terms of computational cost.
Yunguo Guan, Jun Shao 0001, Rongxing Lu, Guiyi Wei
IEEE Trans. Serv. Comput.5
2022 Achieve Efficient and Verifiable Conjunctive and Fuzzy Queries over Encrypted Data in Cloud
abstract
Due to the high demands of searchability over encrypted data, searchable encryption (SE) has recently received considerable attention and been widely suggested in encrypted cloud storage. Typically, the cloud server is assumed to be honest-but-curious in most SE-based cloud storage systems, i.e., the cloud server should follow the protocol to return valid and complete search results to users. However, this trust assumption is not always true due to some unanticipated situations, such as misconfigurations and malfunctions. Therefore, the function of verifiability of search results becomes crucial for the success of SE-based cloud storage systems. For this reason, many verifiable SE schemes have been proposed; however, they either fail to support query operators “OR”, “AND”, “$\ast$” and “?” simultaneously, or require many time-consuming operations. Aiming at addressing this problem, in this paper, we propose a new verifiable SE scheme for encrypted cloud storage. The proposed scheme is characterized by integrating various techniques, i.e., bitmap index, radix tree, format preserving encryption, keyed-hash message authentication code and symmetric key encryption, for achieving efficient and verifiable conjunctive and fuzzy queries over encrypted data in the cloud. Detailed security analysis shows that our proposed scheme holds the confidentiality of data and verifiability of search results at the same time. In addition, extensive experiments are conducted, and the results demonstrate our proposed scheme is efficient and suitable for users to retrieve their data from the cloud to their mobile devices.
Jun Shao 0001, Rongxing Lu, Yunguo Guan, Guiyi Wei
IEEE Trans. Serv. Comput.4
2022 Principal Component Tracking for Massive MIMO Channels in High Mobility Scenarios With Diagonal Step Size Matrix
abstract
The present article proposes a novel adaptive algorithm with an optimal diagonal step size matrix for multi-dimensional channel principal component tracking in two dimensional massive multiple-input and multiple-output (M-MIMO) systems. First, we prove that the weighted subspace algorithm globally converges to the stationary stochastic process’ major eigenvectors. Then, using the maximum likelihood criterion, we optimize the weight coefficient matrix and derive the convergent condition for the step size range in order to maintain the algorithm stability. To accelerate the convergence, we initially suggest the diagonal step size matrix for multi-dimensional eigenvector tracking. Simultaneously, an optimal diagonal step size matrix is derived, which not only accelerates the convergence speed distinctively but also improves the tracking of multi-dimensional eigenvectors. Moreover, the transient behavior during the adaptation process is investigated in a straight-forward way and the relationship between the convergence time constant and the eigenvalues of the received signals is uncovered. Finally, simulations reveal that the proposed approach outperforms established algorithms such as Oja$^{\prime}\text{s}$, Delmas and gradient descent algorithms. This approach establishes a sound foundation for tracking channel state information in M-MIMO systems with great mobility.
Anding Wang, Guiyi Wei
IEEE Trans. Wirel. Commun.2
2021 Achieve space-efficient key management in lightning network
Guiyi Wei, Xiaohang Mao, Rongxing Lu, Jun Shao 0001, Yunguo Guan, Genhua Lu
Comput. Networks1
2021 Toward Oblivious Location-Based k-Nearest Neighbor Query in Smart Cities
abstract
Enabled by the flourishing Internet-of-Things technology, smart cities can offer a variety of smart services to our daily lives and have received considerable attention in recent years. As a pivotal component of smart cities, location-based services (LBSs) have been deeply exploited by both academia and industry. Meanwhile, since cloud computing can provide reliable and flexible IT resources, many LBS services have been outsourced to the cloud for offering better services. Nevertheless, as the cloud is not fully trusted, privacy preservation becomes an essential requirement for these services. Over the past years, many privacy-preserving location-based k-nearest neighbor ( kNN) query schemes over the cloud have been proposed. However, most of them are subjected to an inevitable design defect, i.e., whenever a user queries twice at the same location, the cloud can identify and return the same query result to the query user, and such information together with third-party data breaches could be exploited by the cloud for some location disclosures. Although some existing schemes can cope with the issue, they are not quite practical, as they will bring heavy overheads on the query user side. In this article, aiming to address the above challenge, we propose a novel oblivious location-based kNN query scheme, in which the cloud cannot link two queries even if they are initiated by query users at the same location. Specifically, based on the modified Paillier cryptosystem, we first present three privacy-preserving protocols, namely, oblivious absolute value calculation, sorting, and top- k extraction. Then, by integrating these three protocols, we propose our novel oblivious location-based kNN query scheme. The detailed security analysis shows that our proposed scheme really enhances the privacy preservation in LBS queries. In addition, extensive performance analysis and experiments are conducted, and the results indicate that our proposed scheme is also efficient for the query user.
Yunguo Guan, Rongxing Lu, Yandong Zheng, Jun Shao 0001, Guiyi Wei
IEEE Internet Things J.5
2021 Toward Privacy-Preserving Cybertwin-Based Spatiotemporal Keyword Query for ITS in 6G Era
abstract
The sixth-generation (6G) communication technology has been attracting great interests from both industry and academia, as it is regarded as a promising approach to achieve more stable and low-latency communication. These promising features of 6G make it an enabler for cybertwin, a technique to create digital representations for physical objects to implement various functionalities. In this article, we consider a cybertwin-based spatiotemporal keyword query service over a dynamic message data set in intelligent transportation system (ITS) scenarios. Particularly, in the considered service, publishers upload messages to the cloud, and each cybertwin predictively launches queries to retrieve messages on behalf of the corresponding vehicle, such that each vehicle can timely receive messages that are of its interest whenever it arrives at a location. Nevertheless, as the cloud is not fully trustable, there exist privacy concerns related to the messages and queries. Up to now, although many schemes have been proposed to handle privacy-preserving spatial, temporal, or keyword queries, none of them can simultaneously support queries containing both spatial, temporal, and keyword criteria on dynamic data sets. Aiming at the issue, we design a layered index based on segment trees to dynamically organize messages containing both spatial, temporal, and keyword information. Moreover, based on a symmetric homomorphic encryption scheme, we encrypt the messages and queries and present a two-server privacy-preserving spatiotemporal keyword query scheme. We analyze the security of the proposed scheme and also conduct extensive experiments to evaluate its performance. The results show that our proposed scheme is indeed privacy preserving and computationally efficient.
Yunguo Guan, Rongxing Lu, Yandong Zheng, Songnian Zhang, Jun Shao 0001, Guiyi Wei
IEEE Internet Things J.6
2021 Secure Fine-Grained Encrypted Keyword Search for E-Healthcare Cloud
abstract
E-Healthcare systems are increasingly popular due to the introduction of wearable healthcare devices and sensors. Personal health records (PHRs) are collected by these devices and stored in a remote cloud. Due to privacy concern, these records should not be accessible by any unauthorized party, and the cloud providers should not be able to learn any information from the stored records. To address the above issues, one promising solution is to employ attribute based encryption (ABE) for fine-grained access control and searchable encryption for keyword search on encrypted data. However, most of existing ABE schemes leak the privacy of access policy which may also contain sensitive information. On the other hand, for users' devices with limited computing power and bandwidth, the mechanism should enable them to be able to search the PHRs efficiently. Unfortunately, most existing works on ABE do not support efficient keyword search on encrypted data. In this work, we propose an efficient hidden policy ABE scheme with keyword search. Our scheme enables efficient keyword search with constant computational overhead and constant storage overhead. Moreover, we enhance the recipient's privacy which hides the access policy. As of independent interest, we present a trapdoor malleability attack and demonstrate that some of previous schemes may suffer from such attack.
Haijiang Wang 0003, Jianting Ning, Xinyi Huang 0001, Guiyi Wei, Geong Sen Poh, Ximeng Liu
IEEE Trans. Dependable Secur. Comput.4
2020 Achieving Privacy-Preserving Vehicle Selection for Effective Content Dissemination in Smart Cities
abstract
By integrating various connected devices, it is possible for smart cities to optimize the efficiency of various aspects of city operations. In particular, connected vehicles in smart cities, which are coordinated by Intelligent Transportation Systems (ITS), can not only enjoy enhanced safety and efficiency, but also offer content dissemination services through smart cities. In order to achieve effective content dissemination, a vehicle selection approach usually needs to be involved to select a limited number of vehicles while disseminating content to a city as wide as possible. However, such an approach inevitably requires the trajectories of vehicles, which are private to the vehicles. In this paper, to preserve the trajectory privacy of the vehicles during the vehicle selection, we propose a privacy-preserving vehicle selection scheme for effective content dissemination. Specifically, in the proposed scheme, given encrypted trajectories of n vehicles, a cloud with two non-collusive servers can select k vehicles that jointly cover an approximately optimal area of the city. Detailed security analysis and performance evaluation show that our proposed scheme can not only preserve the privacy of vehicles' trajectories, but also achieve efficient vehicle selection with an approximately optimal coverage.
Yunguo Guan, Rongxing Lu, Yandong Zheng, Jun Shao 0001, Guiyi Wei
GLOBECOM5
2020 Achieving Efficient and Privacy-Preserving Max Aggregation Query for Time-Series Data
abstract
The vision of future intelligent information society will be globally data driven, enabled by Internet of Things (IoT) techniques. In any IoT-enabled applications, huge volumes of time-series data are continuously generated by IoT devices, which will be fed for high-level functions. Among these functions, the max aggregation query over a specific time interval is one of the frequently used operations. However, due to the limited resources in IoT devices, a common way to deal with the max aggregation query is to involve powerful cloud servers. Nevertheless, as the sensed data from IoT devices and its pattern (e.g., local ranking sequences) are usually private and the cloud servers are not fully trusted, the data should be encrypted before being outsourced to cloud servers. Obviously, the data encryption will incur some efficiency issues. In this paper, to mitigate the privacy and efficiency issues, we propose an efficient and privacy-preserving max aggregation query scheme for time-series data in IoT scenarios. Specifically, we first employ a segment tree based data structure to represent the data collected by IoT devices. Then, to protect the privacy, we leverage two encryption techniques to encrypt the data structure. With the encrypted data structure, our proposed scheme can handle a ranged max aggregation query with O(log L) time complexity, where L is the range length of the query. Detailed security analysis and performance evaluation show that our scheme can not only preserve the privacy of data and its local ranking sequences, but also achieve efficient ranged max aggregation query.
Yunguo Guan, Rongxing Lu, Yandong Zheng, Jun Shao 0001, Guiyi Wei
ICC5
2020 Attribute-based encryption with outsourced decryption in blockchain
Jun Shao 0001, Guiyi Wei
Peer-to-Peer Netw. Appl.3
2019 Attribute-Based Encryption with Publicly Verifiable Outsourced Decryption
Jun Shao 0001, Guiyi Wei, Bianjing Pan, Xiaohang Mao
NSS3
2019 New Game-Theoretic Analysis of DDoS Attacks Against Bitcoin Mining Pools with Defence Cost
Rongxin Zheng, Cuiwen Ying, Jun Shao 0001, Guiyi Wei, Hongyang Yan, Jianmin Kong, Yekun Ren, Weiguang Hou
NSS4
2019 A Miniature CCA Public Key Encryption Scheme Based on Non-abelian Factorization Problem in Finite Groups of Lie Type
abstract
Abstract With the development of Lie theory, Lie groups have attained profound significance in several branches of Mathematics and Physics. In Lie theory, the matrix exponential plays a crucial role between Lie groups and Lie algebras. Meanwhile, as the finite analogue of Lie groups, finite groups of Lie type have potential applications in cryptography due to their unique mathematical structures. In this paper, we first put forward a novel idea of designing cryptosystems based on Lie theory. First of all, combing with discrete logarithm problem and group factorization problem, we proposed several new intractable assumptions based on the matrix exponential in finite groups of Lie type. Subsequently, in analog with Boyen’s scheme (Asiacrypt 2007), we designed a public-key encryption scheme based on the non-abelian factorization problem in finite groups of Lie type. Finally, our proposal was proved to be indistinguishable against adaptively chosen-ciphertext attack in the random oracle model. It is encouraging that our scheme also has the potential to resist against Shor’s quantum algorithm attack.
Haibo Hong, Licheng Wang 0004, Jun Shao 0001, Haseeb Ahmad, Guiyi Wei, Mande Xie, Yixian Yang
Comput. J.6
2018 CCA-secure ABE with outsourced decryption for fog computing
Cong Zuo 0001, Jun Shao 0001, Guiyi Wei, Mande Xie, Min Ji 0001
Future Gener. Comput. Syst.3
2018 Indoor Floor Plan Construction Through Sensing Data Collected From Smartphones
abstract
With the development of sensing technology, smartphones can provide various kinds of data, including inertial sensing data, WiFi data, depth data, and images. These data make it possible to construct accurate indoor floor plans that are the critical foundations of flourishing indoor location-based services for smartphone. However, even with the popular crowdsourcing approach, the wide construction of indoor floor plans has not yet to be realized due to the intensive time consumption. In this paper, we utilize deep learning techniques to build PlanSketcher, a system that enables one user to construct fine-grained and facility-labeled indoor floor plans accurately. First, the proposed system extracts novel integrated features to recognize diverse landmarks. Second, traverse-independent hallway topologies are constructed based on the sensing data, depth data, and images through the proposed hallway construction algorithms. Finally, PlanSketcher constructs the room shape and labels recognized facilities in their corresponding positions to generate a complete indoor floor plan. Because PlanSketcher exploits different kinds of data collected from smartphones with new feature extraction method, it can obtain accurate indoor floor plan topology and facility labels. We implement PlanSketcher and conduct extensive experiments in three large indoor settings. The evaluation results show that the 90th percentile accuracy of positions and orientations of facilities are 1 m–2.5 m and 4°–6°, while 85%–95% facilities are recognized and labeled precisely.
Zhe Peng, Shang Gao 0006, Bin Xiao 0001, Guiyi Wei, Songtao Guo, Yuanyuan Yang 0001
IEEE Internet Things J.4
2018 Fine-Grained Two-Factor Protection Mechanism for Data Sharing in Cloud Storage
abstract
Data sharing in cloud storage is receiving substantial attention in information communications technology because it can provide users with efficient and effective storage services. To protect the confidentiality of the shared sensitive data, cryptographic techniques are usually applied. However, the data protection is still posing significant challenges in cloud storage for data sharing. Among them, how to protect and revoke the cryptographic key is the fundamental challenge. To tackle this, we propose a new data protection mechanism for cloud storage, which holds the following properties. First, the cryptographic key is protected by the two factors. Only if one of the two factors works, the secrecy of the cryptographic key is held. Second, the cryptographic key can be revoked efficiently by integrating the proxy re-encryption and key separation techniques. Finally, the data is protected in a fine-grained way by adopting the attribute-based encryption technique. Furthermore, the security analysis and performance evaluation show that our proposal is secure and efficient, respectively.
Cong Zuo 0001, Jun Shao 0001, Joseph K. Liu, Guiyi Wei
IEEE Trans. Inf. Forensics Secur.4
2017 LDSCD: A loss and DoS resistant secure code dissemination algorithm supporting multiple authorized tenants
Mande Xie, Urmila Bhanja, Jun Shao 0001, Guiyi Wei
Inf. Sci.5
2016 Chosen Ciphertext Secure Attribute-Based Encryption with Outsourced Decryption
Cong Zuo 0001, Jun Shao 0001, Guiyi Wei, Mande Xie, Min Ji 0001
ACISP (1)3
2016 A game-based incentive model for service cooperation in VANETs
abstract
Summary Because of the highly dynamic topology and the unstable service status of nodes, services in vehicular ad hoc networks (VANETs) are not always reliable enough for users. Nodes in such a VANET incline to be selfish, which will even enhance this situation. In this work, we present an incentive model for VANETs to support more reliable services in network. We model the situation of service request and response in VANETs by using game theory. We consider the competitive and cooperative relationship between the nodes to formulate the game for VANETs. A contribution measurement is given in order to encourage cooperation during the game. Nodes are encouraged to provide more services to their neighbors in order to acquire more services from other nodes in our model. We also conduct a simulation for the proposed model and give detailed analysis in this work. From the results of the simulation, we argue that we could enable a VANET to support more reliable service by configuring suitable parameters for it. Copyright © 2014 John Wiley & Sons, Ltd.
Yuxin Mao, Ping Zhu 0007, Guiyi Wei, Mohammad Mehedi Hassan, M. Anwar Hossain 0001
Concurr. Comput. Pract. Exp.3
2015 Social role-based secure large data objects dissemination in mobile sensing environment
Mande Xie, Urmila Bhanja, Guiyi Wei
Comput. Commun.4
2015 Availability, resilience, and fault tolerance of internet and distributed computing systems
abstract
Availability, resilience, and fault tolerance of internet and distributed computing systemsThe emergence of Web as a ubiquitous platform for innovations has laid the foundation for the rapid growth of the Internet.Side-by-side, the use of mobile and wireless devices such as PDAs, laptops, and cell phones for accessing the Internet has paved the ways for related technologies to flourish through recent developments.However, development of these technologies and systems adds complexity due to the performance, fault tolerance, and availability requirements.These issues are required to be explored for the effective design and implementation of high-performance modern computing systems.In this special issue, we are delighted to present ten technical papers on resilient, highly available, and fault-tolerant Internet and distributed systems, with a particular focus on the practical experiences with the design and implementation of related technologies as well as their theoretical perspectives.These papers were selected out of 80 submissions from 17 countries in the 6th International Conference on Internet and Distributed Computing Systems (IDCS 2013).The selection has been very rigorous, and only the best papers in the conference were selected.Performance and dependability evaluation plays a key role in the design of a broad range of systems, especially when strict requirements need to be met.In the first paper, 'Variable Operating Conditions in Distributed Systems: Modeling and Evaluation' [1], Longo et al. present an analytical method that allows the study of a class of systems where different operating conditions alternate changing the stochastic behavior of the system components but still preserving the continuity of the performance and dependability quantities to investigate.In the second paper, 'Supporting Personal Security Using Participatory Sensing' [2], Carreno et al. propose a mobile collaborative application, named Personal Guardian, which used by civilians while walking in urban areas.The application is focused on crime prevention, and it implements participatory sensing to help people be aware of the risks that appear to exist in a certain place.This is an interesting application on information feeding process and the unattended delivery of awareness information about personal security.In the third paper, 'Self-healing Wireless Sensor Networks' [3], A. Miyaji and K. Omote propose three self-healing schemes to provide availability in wireless sensor networks.This is very important for long-term use of wireless sensor networks.These self-healing schemes are effective and efficient according to the evaluations done by the authors.Smooth data streaming in wireless sensor networks is a challenging problem.In the fourth paper, 'A Slot Demand based Path Reservation Approach for the Timely and Reliable Delivery of Bursty Traffic in WSNs' [4], P. V. Vinh and H. Oh propose an efficient approach to deliver bursty data reliably by reserving time slots to transmit the required packets on all the paths from the selected multimedia nodes to the server.The nodes that are not on the selected paths are put into sleep mode to conserve energy during the transmission.In the fifth paper, 'SCRRM: A Stability-Aware Cooperative Routing Scheme for Reliable High-Speed Data Transmission in Multi-Rate Mobile Ad-hoc Wireless Networks' [5], L. T. Dung and B. An present a stability-aware cooperative routing scheme for reliable high-speed data transmission in multi-rate mobile ad-hoc wireless networks, called SCRRM, to provide high data transmission with stable and reliable routes.The performance evaluation shows that this scheme can adaptively select optimal data rate and outperforms single rate routing protocol in terms of packet delivery ratio, network throughput, and average end-to-end delay in all settings of node density and node mobility.
Yang Xiang 0001, Mukaddim Pathan, Guiyi Wei, Giancarlo Fortino
Concurr. Comput. Pract. Exp.3
2015 SecNRCC: a loss-tolerant secure network reprogramming with confidentiality consideration for wireless sensor networks
abstract
Summary Network reprogramming faces lots of threats from both external attackers and potentially compromised nodes. Security thus becomes a critical requirement for network reprogramming protocols. This paper describes a secure network reprogramming system called SecNRCC for dynamically reprogramable wireless sensor network. In SecNRCC, a light weight authentication method is firstly introduced for the reboot control command. Secondly, a program image preprocess method with security and loss‐tolerance consideration is proposed. Furthermore, a novel immediate packet authentication algorithm with confidentiality consideration is also presented to resist the denial of service attacks exploiting the authentication delay, and finally, a weak authentication operation is performed before the digital signature verification to mitigate denial of service attacks against signature packets. The experimental results show that SecNRCC can securely disseminate the program image to all of node in the wireless sensor networks with acceptable latency and message cost. Copyright © 2014 John Wiley & Sons, Ltd.
Mande Xie, Urmila Bhanja, Guiyi Wei, Mohammad Mehedi Hassan, Atif Alamri
Concurr. Comput. Pract. Exp.3
2015 Efficient multiple sources network coding signature in the standard model
abstract
Summary Network coding is a new routing technique that can improve a network's throughput. The key idea is to allow network routers to code the received packets before transmission. However, network coding is vulnerable to pollution attacks where malicious node(s) can flood the network with invalid packets and prevent the receiver from the right decoding. Network coding signature offers a good solution to this problem. Nevertheless, existing network coding signature schemes cannot either be proven secure in the standard model, support multiple sources, or in‐time signing. In this paper, we propose a new network coding signature scheme to solve the aforementioned problems. Copyright © 2014 John Wiley & Sons, Ltd.
Jinlin Zhang, Jun Shao 0001, Min Ji 0001, Guiyi Wei, Bishan Ying
Concurr. Comput. Pract. Exp.5
2015 Obtain confidentiality or/and authenticity in Big Data by ID-based generalized signcryption
Guiyi Wei, Jun Shao 0001, Yang Xiang 0001, Pingping Zhu, Rongxing Lu
Inf. Sci.1
2015 Detecting stepping stones by abnormal causality probability
abstract
Abstract Locating the real source of the Internet attacks has long been an important but difficult problem to be addressed. In the real world, attackers can easily hide their identities and evade punishment by relaying their attacks through a series of compromised systems or devices called stepping stones. Currently, researchers mainly use similar features from the network traffic, such as packet timestamps and frequencies, to detect stepping stones. However, these features can be easily destroyed by attackers using evasive techniques. In addition, it is also difficult to implement an appropriate threshold of similarity that can help justify the stepping stones. In order to counter these problems, in this paper, we introduce the consistent causality probability to detect the stepping stones. We formulate the ranges of abnormal causality probabilities according to the different network conditions, and on the basis of it, we further implement to self‐adaptive methods to capture stepping stones. To evaluate our proposed detection methods, we adopt theoretic analysis and empirical studies, which demonstrate accuracy of the abnormal causality probability. Moreover, we compare our proposed methods with previous works. The result shows that our methods in this paper significantly outperform previous works in the accuracy of detection malicious stepping stones, even when evasive techniques are adopted by attackers. Copyright © 2014 John Wiley & Sons, Ltd.
Sheng Wen, Di Wu 0050, Ping Li 0019, Yang Xiang 0001, Wanlei Zhou 0001, Guiyi Wei
Secur. Commun. Networks6
2014 An analytical model for optimal spectrum leasing under constraints of quality of service in CRNs
Guiyi Wei, Yang Xiang 0001, Min Ji 0001, Ping Zhu 0007
Comput. Networks1
2014 EFADS: Efficient, flexible and anonymous data sharing protocol for cloud computing with proxy re-encryption
Guiyi Wei, Rongxing Lu, Jun Shao 0001
J. Comput. Syst. Sci.1
2014 Internet Traffic Classification Using Constrained Clustering
abstract
Statistics-based Internet traffic classification using machine learning techniques has attracted extensive research interest lately, because of the increasing ineffectiveness of traditional port-based and payload-based approaches. In particular, unsupervised learning, that is, traffic clustering, is very important in real-life applications, where labeled training data are difficult to obtain and new patterns keep emerging. Although previous studies have applied some classic clustering algorithms such as K-Means and EM for the task, the quality of resultant traffic clusters was far from satisfactory. In order to improve the accuracy of traffic clustering, we propose a constrained clustering scheme that makes decisions with consideration of some background information in addition to the observed traffic statistics. Specifically, we make use of equivalence set constraints indicating that particular sets of flows are using the same application layer protocols, which can be efficiently inferred from packet headers according to the background knowledge of TCP/IP networking. We model the observed data and constraints using Gaussian mixture density and adapt an approximate algorithm for the maximum likelihood estimation of model parameters. Moreover, we study the effects of unsupervised feature discretization on traffic clustering by using a fundamental binning method. A number of real-world Internet traffic traces have been used in our evaluation, and the results show that the proposed approach not only improves the quality of traffic clusters in terms of overall accuracy and per-class metrics, but also speeds up the convergence.
Yu Wang 0017, Yang Xiang 0001, Jun Zhang 0010, Wanlei Zhou 0001, Guiyi Wei, Laurence T. Yang
IEEE Trans. Parallel Distributed Syst.5
2013 Optimal Spectrum Leasing with the Constraints of User Admission Rate and Quality of Service
abstract
This paper study the optimal spectrum leasing problem with constrains of secondary user admission rate and quality of service from the view of secondary network operators. We model a secondary network as a dynamical data package transportation system, in which data transmission arrives according to a Poisson distribution. An analytical approach is proposed to deduce the upper and lower bounds of the optimal amount of spectrum. With the bounds, the approximate optimum is computed.
Guiyi Wei, Min Ji 0001, Ping Zhu 0007
MASS1
2013 Cooperation Dynamics on Collaborative Social Networks of Heterogeneous Population
abstract
In collaborative social networks (CSNs), autonomous individuals cooperate for their common reciprocity interests. The intrinsic heterogeneity of individuals' capability and willingness makes significant impact on the promotion of cooperation rate. In this paper, we propose a two-phase Heterogeneous Public Goods Game (HPGG) model to study the cooperation dynamics in CSNs. We introduce two factors to represent the heterogeneity of individual behaviors and the benefit-to-cost enhancement of population, respectively. Based on HPGG CSN model, we quantitatively investigate the relationship between cooperation rate and individuals' heterogeneous behaviors from an evolutionary game perspective. Simulations on the population structure of scale-free networks show the evolution of cooperation in CSNs has no-trivial dependence on the individuals' heterogeneous behaviors. Compared with standard PGG and single-phase heterogeneous PGG, HPGG provides a more precise mechanism to promote cooperation rate of CSNs. Finally, data traces collected from real experiments also demonstrate the preciseness of HPGG in formulating the cooperation dynamics on CSNs.
Guiyi Wei, Ping Zhu 0007, Athanasios V. Vasilakos, Yuxin Mao, Jun Luo 0001
IEEE J. Sel. Areas Commun.1
2013 Unreconciled Collisions Uncover Cloning Attacks in Anonymous RFID Systems
abstract
Cloning attacks threaten radio-frequency identification (RFID) applications but are hard to prevent. Existing cloning attack detection methods are enslaved to the knowledge of tag identifiers (IDs). Tag IDs, however, should be protected to enable and secure privacy-sensitive applications in anonymous RFID systems. In a first step, this paper tackles cloning attack detection in anonymous RFID systems without requiring tag IDs as a priori. To this end, we leverage unreconciled collisions to uncover cloning attacks. An unreconciled collision is probably due to responses from multiple tags with the same ID, exactly the evidence of cloning attacks. This insight inspires GREAT, our pioneer protocol for cloning attack detection in anonymous RFID systems. We evaluate the performance of GREAT through theoretical analysis and extensive simulations. The results show that GREAT can detect cloning attacks in anonymous RFID systems fairly fast with required accuracy. For example, when only six out of 50,000 tags are cloned, GREAT can detect the cloning attack in 75.5 s with a probability of at least 0.99.
Kai Bu, Xuan Liu 0001, Jiaqing Luo, Bin Xiao 0001, Guiyi Wei
IEEE Trans. Inf. Forensics Secur.5
2012 Anonymous proxy re-encryption
abstract
ABSTRACT Proxy re‐encryption (PRE) is a public key encryption that allows a semi‐trusted proxy with some information (a.k.a., re‐encryption key) to transform a ciphertext under one public key into another ciphertext under another public key. Because of this special property, PRE has many applications, such as the distributed file system. Some of these applications demand that the underlying PRE scheme is anonymous under chosen‐ciphertext attacks (CCAs); that is, the adversary cannot identify the recipient of the original/transformed ciphertext, even if it knows the PRE key and can launch the CCA. However, to the best of our knowledge, none of the existing PRE schemes satisfy this requirement. In this work, we propose the first anonymous PRE with CCA security and collusion resistance. Our proposal is proved in the random oracle model based on the DDH assumption. Copyright © 2011 John Wiley & Sons, Ltd.
Jun Shao 0001, Peng Liu 0005, Guiyi Wei
Secur. Commun. Networks3
2011 Multi-Use Unidirectional Proxy Re-Encryption
abstract
This paper presents the first multi-use unidirectional proxy re-encryption scheme proven-secure against chosenciphertext attacks and collusion attacks in the standard model. Although our proposal features a linear ciphertext size and decryption time in the number of translations, we emphasize that it is the first multi-use and unidirectional realization of the primitive satisfying the chosen-ciphertext security and collusion resistance. The proposal gives an answer to the problem proposed by Canetti and Hohenberger at ACM CCS 2007.
Jun Shao 0001, Peng Liu 0005, Zhenfu Cao, Guiyi Wei
ICC4
2011 Identity-Based Conditional Proxy Re-Encryption
abstract
This paper proposes a new cryptographic primitive, named identity-based conditional proxy re-encryption (IBCPRE). In this primitive, a proxy with some information (a.k.a. re-encryption key) is allowed to transform a subset of ciphertexts under an identity to other ciphertexts under another identity. Due to the specific transformation, IBCPRE is very useful in encrypted email forwarding. Furthermore, we propose a concrete IBCPRE scheme based on Boneh-Franklin identity-based encryption. The proposed IBCPRE scheme is secure against the chosen ciphertext and identity attack in the random oracle.
Jun Shao 0001, Guiyi Wei, Mande Xie
ICC2
2011 Unidirectional Identity-Based Proxy Re-Signature
abstract
To construct a suitable and secure proxy re-signature scheme is not an easy job, up to now, there exist only a few schemes. None of these schemes is unidirectional identity-based proxy re-signature, where a semi-trusted proxy can transform a signature under an identity to another signature under another identity on the same message, while the proxy cannot generate any signature on behalf of any of these two identities. In this paper, based on Schnorr's signature and Libert-Vergnaud proxy re-signature, we propose the first unidirectional identity-based proxy re-signature, which is existentially unforgeable in the random oracle model based on the extended computational Diffie-Hellman assumption.
Jun Shao 0001, Guiyi Wei, Mande Xie
ICC2
2011 Prediction-based data aggregation in wireless sensor networks: Combining grey model and Kalman Filter
Guiyi Wei, Binfeng Guo, Bin Xiao 0001, Athanasios V. Vasilakos
Comput. Commun.1
2010 PIVOT: An adaptive information discovery framework for computational grids
Guiyi Wei, Athanasios V. Vasilakos, Bin Xiao 0001, Yao Zheng 0003
Inf. Sci.1
2010 A game-theoretic method of fair resource allocation for cloud computing services
Guiyi Wei, Athanasios V. Vasilakos, Yao Zheng 0003, Naixue Xiong
J. Supercomput.1
2009 LD-BSCA: A local-density based spatial clustering algorithm
abstract
Density-based clustering algorithms are very powerful to discover arbitrary-shaped clusters in large spatial databases. However, in many cases, varied local-density clusters exist in different regions of data space. In this paper, a new algorithm LD-BSCA is proposed with introducing the concept of local MinPts (a minimum number of points) and the new cluster expanding condition: ExpandConClId (Expanding Condition of ClId-th Cluster). We minimize the algorithm input down to only one parameter and let the local MinPts diversified as clusters change from one to another simultaneously. Experiments show LD-BSCA algorithm is powerful to discover all clusters in gradient distributing databases. In addition, we introduce an efficient searching method to reduce the runtime of our algorithm. Using several databases, we demonstrate the high quality of the proposed algorithm in clustering the implicit knowledge in asymmetric distribution databases.
Guiyi Wei, Haiping Liu
CIDM1
2006 Design and Implementation of an Ontology Algorithm for Web Documents Classification
Guiyi Wei
ICCSA (4)1