EDBT 2026 Demo / reviewers in the wild / expert
Jin Cao 0001
dblp:40/429-1
· DBLP profile ↗
76ranked-venue papers
17as first author
49since 2021 · last 2026
0000-0003-1372-7252ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 41 · 13 first-author · 20 since 2021Security and privacy · 16 · 4 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 7 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Systems, architecture and hardware · 3 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Ultrahigh-Speed Terminal Access and Collaborative Authentication Scheme in Satellite Networks
Yukun Zhu, Ruhui Ma, Runsheng Fu, Jin Cao 0001, Hui Li 0006, Xiaosong Zhang 0001 |
IEEE Internet Things J. | 4 |
| 2026 | Bilateral-verifiable and robust secure aggregation via TEE for asynchronous federated learning
Wei Liu 0149, Yinghui Zhang 0002, Axin Wu, Jin Cao 0001, Yunling Wang, Yangguang Tian |
J. Inf. Secur. Appl. | 4 |
| 2026 | Secure aggregation with verifiability and robustness for privacy-preserving federated learning
Yinghui Zhang 0002, Wei Liu 0149, Jin Cao 0001, Yangguang Tian |
Knowl. Based Syst. | 5 |
| 2026 | Anonymous and Byzantine-Robust Federated Learning With Secure and Efficient AggregationabstractFederated learning (FL) serves as a distributed machine learning framework that addresses the challenges of data silos while preserving data privacy. Specifically, FL enables multiple participants to collaboratively train a global model by sharing local updates without exposing their raw local data. Although FL achieves physical data isolation through local update sharing mechanisms, it still faces emerging security threats. On the one hand, adversaries may reconstruct sensitive data features or infer client attributes by analyzing local updates. On the other hand, clients might upload malicious updates to disrupt global model aggregation, causing performance degradation. To solve these issues, we propose an anonymous and Byzantine-robust FL scheme with secure and efficient aggregation. First, we propose a single-masking protocol that not only preserves data privacy but also enhances aggregation efficiency. Second, we eliminate client message metadata, such as source IP addresses and timestamps, through secure shuffling, achieving client anonymity in conjunction with the single-masking protocol. Additionally, we implement a baffle mechanism to resist the impact of malicious updates on the global model, thereby ensuring Byzantine robustness. Security analysis demonstrates that our scheme simultaneously preserves data privacy and identity anonymity. Experimental results show that our scheme can effectively resist poisoning attacks, even if 50% of the fog nodes are contaminated by malicious clients. Moreover, the aggregation efficiency of the proposed scheme is improved by over 20%. Wei Liu 0149, Yinghui Zhang 0002, Axin Wu, Jin Cao 0001, Yangguang Tian |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | SRAA: A Secure and Revocable Access Authentication Scheme in Cross-Domain Vehicular Twin NetworksabstractVehicular twin networks (VTN) create virtual agents of vehicular entities through digital twin (DT) technology, replacing physical counterparts in connecting and exchanging traffic information in cyberspace, overcoming physical range constraints and extending information sources for enhanced vehicular decision support. However, the inherent openness of VTN renders communication between DTs, vulnerable to security threats, such as tampering and impersonation, especially in scenarios where DTs are distributed across multiple cloud domains. These issues result in erroneous decisions to threaten vehicular safety because DTs may receive compromised information. To address these challenges, this article proposes a secure and revocable access authentication scheme in the cross-domain VTN. In the scheme, DTs should be authorized first to obtain identity-bound symmetric functions before joining the VTN, and then perform secure access authentication and key agreement with others based on chameleon hash functions for both intradomain and cross-domain communication. Moreover, a dynamic revocation mechanism is introduced to remove malicious DTs from VTN. Formal verification using the Tamarin tool demonstrates that the proposed scheme achieves diverse security properties. Performance evaluation further shows that the proposed scheme outperforms most related schemes in terms of computational and communication overhead. Guanjie Li, Jin Cao 0001, Jinkai Zheng, Chengzhe Lai, Tom H. Luan, Zehui Xiong |
IEEE Trans. Ind. Informatics | 2 |
| 2026 | LDST-UAVS: A Lightweight Data Secure Transmission Protocol for Unmanned Aerial Vehicle Swarms in Emergency Rescue ScenariosabstractCurrently, Unmanned Aerial Vehicles (UAV) groups can quickly build a multi-hop transmission network, which have been widely utilized in emergency communication scenarios to perform search and rescue, environmental monitoring, personnel positioning, rapid networking, etc. In such emergency rescue situations, strict demands on real-time communication, security, and minimal resource consumption become paramount. Higher requirements for security, bandwidth, and real-time performance necessitate a secure and lightweight data transmission protocol. Additionally, due to the lack of personnel supervision in these scenarios, the probability of malicious nodes increases. Therefore, it is essential to quickly and proximally block malicious nodes’ data to prevent it from affecting subsequent network propagation, and to accurately identify the malicious nodes. To address these issues, in this paper, we propose a traceable, lightweight, and secure data transmission protocol for UAV multi-hop networks in emergency rescue scenarios. The proposed protocol can verify the integrity of data transmitted by a large number of nodes in real time, detect erroneous transmissions, and trace malicious users. Experimental results show that our protocol consistently outperforms the comparison schemes in terms of computational overhead. Moreover, in scenarios involving smaller groups (m=5) and fewer hops (n=4), it exhibits significantly lower communication bandwidth overhead than the reference methods. Security analysis using BAN logic and the formal verification tool Scyther indicates that the proposed scheme meets security requirements. Additionally, comparative analysis results demonstrate that the proposed scheme is highly effective and outperforms other related schemes under the unique constraints of emergency rescue scenarios, where rapid, secure decision-making and data transmission are critical. Zhenyang Guo, Jin Cao 0001, Xiongpeng Ren, Yuchen Zhou 0001, Lifu Cheng, Peijie Yin, Hui Li 0006 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | Training Data Attribution: Was Your Model Secretly Trained On Data Created By Mine?abstractThe emergence of text-to-image models has recently sparked significant interest, but the attendant is a looming shadow of potential infringement by violating user terms. Specifically, an adversary may exploit data created by a commercial model to train their own without proper authorization. To address such risk, it is crucial to investigate the attribution of a suspicious model's training data by determining whether its training data originates, wholly or partially, from a specific source model. To trace the generated data, existing methods need to apply additional watermarks during either the training or inference phases of the source model. However, these methods are impractical for pre-trained models that have been released, especially when model owners lack security expertise. To tackle this challenge, we propose an injection-free training data attribution method for text-to-image models. It can identify whether a model's training data stems from a certain source model without adding additional watermarks on the source model. The rationale of our method lies in the inherent memorization characteristic of text-to-image models. The memorization of training data is inherited through the data generated by the source model to the model trained on that data, making the source model and the infringing model exhibit consistent behaviors on specific samples. Therefore, from instance-level, we develop detection-based and generation-based strategies to uncover these distinct samples and using them as inherent watermarks to verify if a suspicious model originates from the source model. Besides, we also propose a statistical-level attribution method, utilizing the shadow model technique to train an attribution discriminator. Experiments demonstrate that the attribution accuracy and AUC scores of our methods are over 80% even when the infringing model only uses a small proportion of generated data. Hao Wu 0067, Lingcui Zhang, Fengyuan Xu, Jin Cao 0001, Fenghua Li 0001, Ben Niu 0001 |
KDD (2) | 5 |
| 2025 | FlexiGrain: A Flexible and Fine-Grained Privacy Control Framework for Dynamic Social NetworksabstractBalancing information sharing with privacy preserving is a fundamental challenge for users in social networks, where the generation of effective privacy control strategies is a critical control mechanism. Existing efforts are typically coarse-grained (e.g., globally uniform) and static to adapt to dynamic scenarios, thus failing to achieve a precise privacy-utility trade-off. In this paper, we propose a FlexiGrain framework, jointly utilizing information diffusion prediction and multi-objective optimization to generate fine-grained privacy control strategies. In this framework, we design a DHGCNUI model, which integrates intimacy and propagation behavior features to produce a highly accurate user activation probability matrix; then we propose a privacy control strategy generation algorithm, named PDO-NSGA-II, which performs multi-objective optimization to simultaneously maximize information utility and minimize privacy risk. Extensive experiments are conducted on two public datasets, and the results demonstrate the FlexiGrain framework outperforms the state-of-the-art methods in terms of effectiveness and flexibility. Ben Niu 0001, Fanyu Gan, Jinyu Peng, Jin Cao 0001 |
TrustCom | 5 |
| 2025 | IPO-ZTA: An Intelligent Policy Orchestration Zero Trust Architecture for B5G and 6G
Yuanqi Xie, Wei Yi 0001, Bikal Poudel, Jin Cao 0001, Hui Li 0006 |
Comput. Networks | 5 |
| 2025 | NSAA: A Network Slice Access Authentication and Service Authorization Scheme for Integrated Satellite-Terrestrial NetworkabstractIntroducing slicing into integrated satellite-terrestrial networks enables the flexible deployment of network resources and being adaptable for more new applications. However, the heterogeneity of integrated satellite-terrestrial network poses challenges to network resource access control. To ensure users can securely and efficiently access service across multiple management domains, we propose a network slice access authentication and service authorization scheme based on a sharding permissioned blockchain. Slice tenants and wireless network operators with management control act as consortium blockchain nodes, which are divided into shards, and the blockchain is maintained in parallel by multiple shards. First, an efficient public ledger is constructed to establish decentralized trust and manage user identity and service authorization information. Second, utilizing the trapdoor collision resistance of the chameleon hash, users can fully self-select their secret key and generate authentication credentials to register on the blockchain without key escrow problem. When users move into a new network domain, the mutual authentication between users and the visited network can be quickly completed. The session key is negotiated based on the Diffie-Hellman ephemeral protocol with perfect forward secrecy. Then, the editable transaction blocks, storing network slice authorization information and slice templates, are linked using chameleon hashes. This allows the access permissions of slice resources to be dynamically adjusted and easily queried by the service-providing wireless network operators. Performance evaluation and security simulations demonstrate the correctness of the scheme, showing that it can achieve secure access to integrated satellite-terrestrial network slice services with low computational and communication overhead. Yurong Luo, Jin Cao 0001, Ruhui Ma, Ben Niu 0001, Yinghui Zhang 0002, Hui Li 0006 |
IEEE Internet Things J. | 2 |
| 2025 | Recipient-Aware Photo Automatic Deletion Control Policy Recommendation Scheme in Online Social NetworksabstractContent sharing, whether in Online Social Networks (OSNs) or even in the Internet of Things (IoT), serves as a pivotal link in the flow of data. To better protect the privacy of shared content, current OSNs allow sharers to manually set policies for uploaded content. However, this method of policy setting is not suitable for scenarios where IoT is deeply integrated with OSNs, as IoT devices often share content frequently and automatically. To address this issue, we propose the design, implementation, and evaluation of SmartCircles, a personalized photo-sharing and automatic deletion scheme. SmartCircles can function as a plugin within existing OSNs, supporting operations on various smart devices. It encompasses the following steps: a) Before sharing a photo, calculate the intimacy level depicted in the photo and the sharer's willingness to share. b) Before the recipient views the photo, calculate the intimacy between the sharer and the recipient, and evaluate feedback from the recipient. c) Based on the results computed above and a trade-off between profit and loss, recommend a recipient-aware automatic deletion control policy for the photo. We implement a prototype of SmartCircles, and the evaluation results demonstrate its effectiveness with an accuracy rate of policy recommendations reaching approximately 92%. Haiyang Luo, Zhe Sun 0005, Yunqing Sun, Ang Li 0005, Binghui Wang, Jin Cao 0001, Ben Niu 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | A Formal Analysis of 5G ProSe AKA Protocols for U2N Relay Communicationabstract5G Proximity-based Service (ProSe) UE-to-Network (U2N) Relay can help a remote 5G User Equipment (UE) out of coverage connect with the network. The 3GPP committee has provided the standard Authentication and Key Agreement (AKA) protocols to achieve secure access for a Remote UE and establish a secure link between a Remote UE and a U2N Relay. However, the security of these AKA protocols is a remaining issue. At first, we present two detailed 5G ProSe AKA protocols over Control Plane (CP) and User Plane (UP) for U2N Relay communication referring to multiple related standards, then transform the security requirements for 5G ProSe U2N Relay communication as formal security properties, and provide two formal faithful security models for the 5G ProSe AKA protocols. We adopt the state-of-the-art formal verification tool Tamarin to achieve automated security analysis on two models through new proof strategies, and then find some significant and unexpected flaws. Finally, we propose corresponding measures that have least impact on standards based on the analysis on the attacks. Given that the version of Release 17 (R17) of the 3GPP standard has just been frozen, our work can provide a reference for the subsequent evolution of the protocols in 5G ProSe. Xiongpeng Ren, Jin Cao 0001, Ben Niu 0001, Yinghui Zhang 0002, Lihui Xiong, Yurong Luo, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | AotmAuth: Atomic Function Module-Based 6G Authentication Protocol Combination FrameworkabstractOver the years, various mobile communication technologies have been developed and operated simultaneously, which made the mobile communication networks evolved from single-mode access to complex heterogeneous integration. The current 5 G has already accommodated diverse terminals through multiple access paths, but the upcoming 6 G ambitiously aims to achieve ubiquitous connectivity through space-air-ground-sea integrated networks. However, traditional authentication and management protocols, such as EPS-AKA and 5G-AKA, are designed for specific networks and lack the flexibility to adapt to the diverse and dynamic requirements of 6G. This limitation will inevitably result in complex management, enormous overhead, and unmanageable security risks. In this paper, we present an atomic functional module-based 6G authentication protocol combination framework (AotmAuth) to decompose the existing authentication protocols into reusable basic modules, and by combining these modules, flexible authentication protocols can be constructed to meet specific security and performance requirements. The proposed approach can significantly improve the robustness, extensibility and dependability of protocols cobmination, by simplify protocol design, enhance adaptability across diverse scenarios and facilitate quick improvements by replacing or adjusting specific modules. To validate the effectiveness of the proposed solution, we design and develop a 6G heterogeneous access security testbed. The experimental results show that the proposed framework can achieve higher authentication efficiency while ensuring security compared to traditional authentication methods. Wei Yi 0001, Jin Cao 0001, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Efficient Vehicle Secure Scheduling and Access Authentication Scheme for 5G-Integrated Emergency Rescue ScenarioabstractWith urban population density on the rise, emergency incidents are increasing in both frequency and complexity, placing growing pressure on existing rescue systems. Meanwhile, issues such as slow response times, inadequate coordination mechanisms, and inefficient information exchange further exacerbate the challenges faced by these systems. The integration of Vehicle-to-Everything (V2X) communication and 5G technology offers unprecedented capabilities, such as ultra-low latency and high data throughput, which are critical for real-time coordination and decision-making in emergency rescue scenarios. To establish secure and efficient vehicle communication in 5G and V2X-enabled emergency rescue scenarios, we propose an efficient vehicle secure scheduling and access authentication scheme based on certificateless cryptography and multireceiver signcryption. In this scheme, the command and control center can securely dispatch rescue fleets based on disaster conditions. By enabling mutual authentication and key agreement between rescue vehicles and roadside units, the scheme ensures the reliable and swift exchange of rescue information and instructions. In addition, to address unexpected situations such as traffic congestion, we design a route-switching mechanism. Furthermore, in order to mitigate potential malicious behavior, a vehicle legitimacy revocation mechanism is implemented to ensure the normal operation of the system. The security of the scheme is verified through formal analysis and informal analysis. Performance analysis demonstrates that the scheme offers significant advantages over existing ones in terms of signaling overhead, communication overhead, computational overhead, and energy efficiency. Jin Cao 0001, Yiqing Xiong, Ruhui Ma, Yinghui Zhang 0002, Ben Niu 0001, Peijie Yin, Hui Li 0006 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | A Hierarchical Encrypted Compression Scheme for Intra-Vehicle NetworkabstractThe CAN bus is the most widely used bus for intra-vehicle communication due to its high transmission stability, excellent real-time communication capability, and relatively low cost. As the number of ECUs grows, the CAN bus load increases and thus raises the possibility of data transmission delays and errors. Message compression based on the differential algorithm has been proposed to reduce the CAN bus load. However, current works do not consider the security problems of the CAN bus. Attackers can manage to acquire the original messages before compression and disturb the message statistics to decrease compression rate by injecting malicious frames. In this paper, we propose a secure compression mechanism for the intra-vehicle network, including an improved compression algorithm, a stream key distribution scheme, and a hierarchical encryption scheme. Formal verification results show that the proposed scheme can achieve mutual authentication, message confidentiality and integrity, resist replay attacks, and support secure compression. Evaluations using real vehicle data on 16 MHz boards show the average communication overhead can be reduced by 46.38% compared to the original messages. Performance analysis results show our scheme can reduce computational overhead on compression by 31.82% and 19.43% on decompression compared to related schemes. Jin Cao 0001, Zejian Li, Ben Niu 0001, Kwok-Yan Lam, Chihung Chi, Hui Li 0006 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | Secure Authentication and Trust Management Scheme for Edge AI-Enabled Cyber-Physical SystemsabstractCyber-physical systems (CPSs) connected in the form of the Industrial Internet of Things (IIoT) are susceptible to various security threats. Due to the extensive deployment of infrastructure for IIoT devices, the trustworthiness and security of data are among the major concerns in CPSs. Therefore, establishing security measures against potential threats through trust assessment and trust authentication has become a key goal. Blockchain has the characteristics of traceability, anonymity, transparency, etc., and can achieve trust authentication for trust assessment. In our work, we propose a lightweight decentralized authentication and trust management scheme for edge AI-enabled CPSs that supports access control on the basis of extended chaotic maps, which meets the privacy and security needs of data transmission in a broader sense. Moreover, we develop a trust model for checking the trustworthiness of data collected by smart devices/sensor nodes. A formal security analysis is executed by utilizing the broadly applicable real-or-random (RoR) model. Our scheme, which is different from previous methods, combines high security with relatively low communication and computational costs. Through an informal security analysis, we verify that our proposal is in compliance with the security requirements and can withstand various forms of attacks. Furthermore, the functionality and performance analysis results indicate that our method is better suited for lightweight validation in CPS networks while providing a higher level of security than other methods. Xinyin Xiang, Jin Cao 0001, Weiguo Fan |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | Ultra-High-Speed Terminal Secure Access and Intragroup Authentication Scheme in Satellite NetworksabstractUltra-High-Speed Terminals (UHSTs) can transport multiple Load Equipment (LEs) to precise locations, such as in a space station resupply mission scenario. In these scenarios, UHSTs need to access ground networks via satellite networks. However, since the connections between UHSTs and ground networks are established through insecure air interface channels, they are susceptible to attacks such as eavesdropping, impersonation, and other. Furthermore, owing to the high-speed mobility of UHSTs, they may not be able to connect successfully to the ground network through a single access point, which is possible for regular terminals. Additionally, UHST may also need to communicate with multiple LEs, which is also connected via insecure air interface channels. Therefore, this paper proposes a secure access and intra-group authentication scheme for UHSTs in satellite network scenarios. In the proposed scheme, based on pre-shared keys and trajectory prediction mechanisms, the UHST can successfully access the ground network through multiple access points and complete key establishment with the access points along its trajectory in advance. Using Shamir’s (t, n) Secret Sharing mechanism, UHST and multiple LEs can share a group key, ensuring secure intra-group data communication. Additionally, when one LE detaches from the UHST, the UHST can authorize the LE to access the ground network. Security and efficiency analysis shows that the proposed scheme achieves comprehensive security features with low overhead. Yukun Zhu, Ruhui Ma, Jin Cao 0001, Hui Li 0006, Xiaosong Zhang 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | A Message-based Lightweight Session Key Distribution Scheme for Intra-Vehicle NetworkabstractModern vehicles are equipped with ECU nodes and intra-vehicle buses. Among these, the CAN bus stands out as the most widely utilized intra-vehicle bus due to its affordability and straightforward deployment. However, the CAN bus suffers from significant security vulnerabilities, such as the absence of access control, identity authentication, message encryption, and authentication. In this paper, we propose a lightweight message-based key distribution scheme aimed at addressing these vulnerabilities. Our scheme facilitates mutual authentication during key distribution and assigns a unique key to each class of message. Formal verification using the Scyther tool demonstrates that our protocol achieves mutual authentication and effectively mitigates several protocol attacks, including replay, tampering, and manin-the-middle attacks. We evaluate our scheme using Arduino UNO boards. Performance analysis indicates that our scheme exhibits superior security capabilities compared to other related schemes and outperforms them in terms of communication and computation overheads. Jin Cao 0001, Zejian Li, Yurong Luo, Kwok-Yan Lam, Chihung Chi, Hui Li 0006 |
GLOBECOM | 1 |
| 2024 | Easy-Sharing: A Personalized Privacy Diffusion Strategy Generation Method Based on Risk-Return Trade-OffabstractIn the realm of social networks, individuals frequently engage in self-disclosure to gain social influence. However, this behavior simultaneously exposes users to significant privacy risks. Social platforms typically allow users to establish privacy diffusion control strategies, such as selecting the audience for their information. Nevertheless, the lack of privacy awareness and extensive social connections make this task time-consuming and labor-intensive for users. To address this challenge, this paper presents an automated method Easy-Sharing to assist in the effective selection of appropriate seed nodes (initial recipients), aiming to balance social influence and privacy risks according to the user’s privacy preference. This method leverages an advanced VAE-based model to predict information diffusion and proposes a privacy strategy generation method based on a risk-return trade-off. This research contributes to the development of more user-friendly and privacy-conscious social networking tools, ultimately enhancing user experience and safeguarding personal information. Ben Niu 0001, Jin Cao 0001 |
HPCC | 4 |
| 2024 | Interpreting Memorization in Deep Learning from Data DistributionabstractA deep learning model can be vulnerable to a membership inference attack (MIA) which allows an attacker to determine if a specific data record was used for its training. In this paper, we investigate the unfairness of disparate vulnerability to MIA across different subgroups in terms of their data distributions. We propose three practical methods to characterize the distribution of complex training data for deep learning models, which are validated to be effective in identifying the vulnerable data records. We then provide a theoretical definition for MIA vulnerability. Experimental results demonstrate the impact of data distribution on disparate vulnerability, where the out-of-distribution outliers are much more easily attacked than normal data records. Even if the accuracy of MIA looks no better than random guessing over the whole population, there are certain groups of "outliers" can be significantly more vulnerable than others. For example, the attack accuracy on examples with the largest 10% outlierness is 15% higher than that on in-distribution examples. Shoukun Guo, Fenghua Li 0001, Jin Cao 0001, Ben Niu 0001 |
ICASSP | 5 |
| 2024 | Signcryption based on Elliptic Curve CL-PKC for Low Earth Orbit Satellite Security NetworkingabstractLow earth orbit satellite communication has lower latency and is more suitable for real time communication than high orbit and medium orbit satellites, secure networking is crucial for providing continuous services to low earth orbit satellites. This paper proposes a method for dynamic secure networking of low earth orbit satellites, the method is based on signcryption elliptic curve algorithm in ISO/IEC 29150:2011. The biggest contribution is the combination of certificateless public key mechanism and signcryption algorithm to support secure networking of satellites. Finally, Scyther was used to conduct security analysis on the algorithm and process, it has been proven that the certificateless public key signcryption system can effectively solve the problems of authentication and secure transmission between satellites. Meiling Chen, Sixu Guo, Jin Cao 0001, Haitao Du |
TrustCom | 4 |
| 2024 | Blockchain enabled dynamic trust management method for the internet of medical things
Xinyin Xiang, Jin Cao 0001, Weiguo Fan, Shousheng Xiang, Gang Wang 0010 |
Decis. Support Syst. | 2 |
| 2024 | UAVA: Unmanned Aerial Vehicle Assisted Vehicular Authentication Scheme in Edge Computing NetworksabstractIn the pursuit of autonomous driving and intelligent traffic management, the core goal of 5G Vehicle-to-Everything (V2X) communication is to enhance the safety and efficiency of transportation systems. Modern transportation networks have evolved into 3-D structures, including bridges and tunnels from traditional 2-D ones, which poses a challenge to fixed base stations-based networks reliant on supporting continuous and seamless coverage. Against this backdrop, unmanned aerial vehicles (UAVs) play a crucial role in developing multidimensional wireless networks due to their flexibility and functionality. This article proposes a UAV-assisted vehicle authentication (UAVA) scheme. It harnesses the efficiency of edge computing and the security of zero-trust architecture, focusing on enhancing the safety and efficiency of V2X communications. The UAVA scheme employs Chebyshev chaotic mapping and elliptic curve cryptography to strengthen communication security, adapting to the dynamic interactions between vehicles and UAVs. We validate the security using BAN logic and the Scyther tool and assess performance through experiments in a real hardware environment. The results indicate that UAVA offers higher security and lower communication overhead in serverless scenarios compared to existing solutions. These comprehensive evaluations show the potential of UAVA for application in intelligent transportation systems, especially in ensuring secure communications. Zhenyang Guo, Jin Cao 0001, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006 |
IEEE Internet Things J. | 2 |
| 2024 | ADEAS: Authentication Using Doppler Effect of Acoustic Signals Caused by Hands MovingabstractPresently, the prevalent authentication approaches in smartphones are susceptible to interference from light, noise, temperature, and the risk of replay attacks. In the light of these vulnerabilities, and taking into account user behavior alongside smartphone interaction patterns, we have developed an innovative behavioral-based authentication system. This system harnesses the distinctiveness of individual keystroke dynamics for secure user authentication, offering resilience against noise and light fluctuations. In this unique approach, our smartphone’s speakers and microphones emit and capture high-frequency acoustic signals (ASs). To the best of our knowledge, this is the first instance of employing the Doppler effect generated by the high-frequency AS in response to keystroke activity as a distinctive user feature. Our definition of “keystroke behavior” encompasses the motions involved in tapping screen buttons while holding the smartphone, effectively capturing unique user attributes without necessitating any special procedures or passwords. Our initial experiments have convincingly shown that the AS Doppler effect, triggered by keystroke actions, is uniquely identifiable per user during button presses. Subsequently, we utilized a convolutional autoencoder (CAE) to distill keystroke behaviors from the reflected signals, employing an one-class support vector machine (OCSVM) for user authentication and identification processes. We then implemented a prototype of this scheme on smartphones and rigorously tested its performance across four real-world scenarios. The outcomes are promising, demonstrating that our scheme not only withstands disturbances from noise and light but also achieves an impressive average accuracy rate of 95.08%. Regarding security, it effectively thwarts replay and record attacks, further underscoring its robustness and reliability. Zhenyang Guo, Jin Cao 0001, Ben Niu 0001, Ang Li 0005, Hui Li 0006 |
IEEE Internet Things J. | 3 |
| 2024 | Lightweight privacy-preserving authentication mechanism in 5G-enabled industrial cyber physical systems
Xinyin Xiang, Jin Cao 0001, Weiguo Fan |
Inf. Sci. | 2 |
| 2024 | CEAMP: A Cross-Domain Entity Authentication and Message Protection Framework for Intra-Vehicle NetworkabstractController Area Network (CAN) is the most wide-used bus system in Intra-Vehicle Networks(IVN). However, the nature of broadcast communication and the lack of security mechanisms make the CAN bus extremely fragile against malicious attacks. Although there are works protecting IVN, most of them are not feasible when applied to real vehicles because they do not consider the IVN node capability. In this paper, we propose a security framework for the CAN bus, covering ECU entity identity management and authentication, symmetric key generation and update, intra-domain, cross-domain secure transmission, and sensitivity-based security classification methods. We formally verify our protocols using the up-to-date tool Tamarin and simulate real attacks in a simulation environment and the results show that the proposed protocol can resist these attacks. By the use of speck encryption and the Chaskey MAC algorithm in our schemes, the analysis results show that the increased time of a frame for a single ECU in our proposed intra-domain scheme is$2.09~ms$to$2.78~ms$on Arduino Mega, and$121.65 \mu s$to$152.15 \mu s$on Arduino DUE, which takes up$6.08\%$to$7.61\%$of a 10ms cyclic time frame. And in the cross-domain scheme is$2.55~ms$to$3.24~ms$on Arduino Mega, and$134.30 \mu s$to$164.80 \mu s$on Arduino DUE, which takes up$6.72\%$to$8.24\%$of a 10ms frame. To the best of our knowledge, this is the first time an IVN cross-domain secure transmission protocol has been proposed without changing the IVN network topology or the CAN protocol. Our work brings practical protection to IVN. Jin Cao 0001, Jiajia Liu 0001, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | An Anonymous and Secure Data Transmission Mechanism With Trajectory Tracking for D2D Relay Communication in 3GPP 5G NetworksabstractDevice-to-device (D2D) communication, as a traffic offloading technology in the fifth-generation (5G) network, can be widely used in several scenarios to provide 5G characteristics of higher speed, lower latency, and larger capacity. D2D data transmission over wireless channels among mobile devices is vulnerable to security threats and privacy violations from third parties and relay nodes. However, academia and industry have yet to propose relevant schemes or standards for D2D relay data transmission scenarios. We first propose a generic construction for D2D relay communication in this paper. Then, a concrete anonymous and secure D2D data transmission scheme with trajectory tracking is presented based on Chebyshev polynomials, hash-based message authentication code, and symmetric encryption. We employ a formal verification tool -Tamarin, modal logic analysis -BAN logic, and informal security analysis to demonstrate the security features of the proposed scheme. The performance evaluation shows that the proposed scheme can achieve desirable efficiency compared with other related schemes. Finally, we developed an APP‘, D2DWatchmen’, to simulate the whole protocol and test its robustness and real execution time, where the result shows good availability and effectiveness. Yunqing Sun, Jin Cao 0001, Xiongpeng Ren, Canhui Tang, Ben Niu 0001, Yinghui Zhang 0002, Hui Li 0006 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | A UAV-Assisted UE Access Authentication Scheme for 5G/6G NetworkabstractUnmanned Aircraft Vehicles (UAVs) equipped with base stations can assist ground User Equipments (UEs) in accessing the 5G/6G network. Due to the UAV’s high autonomy, easy configuration, and strong dynamic deployment capabilities, UAV-assisted ground UEs to access the 5G/6G network can effectively expand the communication network coverage. However, some vulnerabilities exist, such as eavesdropping attack, impersonation attack, etc. In addition, the 3rd Generation Partnership Project (3GPP) committee has proposed that the UAV can employ the primary authentication mechanism (i.e., 5G-AKA) to connect to the network. Nevertheless, the primary authentication mechanism 5G-AKA has some security problems. In this paper, we first improve the existing 5G-AKA, which resists quantum attack and traceability attack and consumes moderate signaling overhead and short running time. Then, based on the improved 5G-AKA protocol, we propose a UAV-assisted UE access authentication scheme for the 5G/6G network. In the proposed scheme, the UAV can perform the service access authentication process to access the 5G/6G core network and then execute the UAV-assisted UE access authentication process to assist UE in obtaining network services. Additionally, the ground UE can perform a fast and secure handover process with the target UAV to ensure continuous network services. The automation verification tool Tamarin is employed to verify the security of the proposed scheme. Additionally, we implement the improved 5G-AKA protocol and the existing 5G-AKA protocol on Field Programmable Gate Array (FPGA) to test their running time. The security and performance evaluation results show that the proposed scheme provides robust security with moderate efficiency. Ruhui Ma, Jin Cao 0001, Shiyang He, Yinghui Zhang 0002, Ben Niu 0001, Hui Li 0006 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | DP-Loc: A Differential Privacy-Based Indoor Localization Scheme with Bilateral Privacy Protection
Yinghui Zhang 0002, Hao Du 0006, Jin Cao 0001, Dong Zheng 0001 |
Inscrypt (2) | 3 |
| 2023 | A Sensitivity-aware and Block-wise Pruning Method for Privacy-preserving Federated LearningabstractFederated learning (FL) is a distributed learning framework that can reduce privacy risks by not directly sharing private data. However, recent works have shown that the adversary can launch data reconstruction attacks utilizing the gradients or model updates shared by clients. Existing defenses either fail to provide sufficient privacy guarantee or incur significant drop in model accuracy. To achieve a good privacy-utility tradeoff, we propose a novel block-wise pruning method. It mitigates the privacy leakage by locating and quantifying the privacy risk of a model at a finer-grained level. Specifically, we define the sensitivity metric to calculate the gradient sensitivity w.r.t the input to quantify privacy leakage risk of each block. Then we divide the entire model into same-sized blocks and sort them based on the sensitivity metrics. We select part of the blocks with least sensitivity values as the pruned model to be communicated during the client-server interaction. To evaluate the effectiveness and efficiency of our defense, we conduct experiments on MNIST and CIFAR10 for defending against the DLG attack and GS attack. Results demonstrate that our proposed method can significantly mitigate gradient leakage against both DLG attack and GS attack with as much as 20× mean squared errors between the reconstructed data and the raw data with only modest accuracy drop, compared with baseline defenses. Meanwhile, the communication cost between the server and clients is also reduced. Ben Niu 0001, Shoukun Guo, Jin Cao 0001, Fenghua Li 0001 |
GLOBECOM | 5 |
| 2023 | Privacy-Preserving Authentication Scheme for 5G Cloud-Fog Hybrid with Soft Biometrics
Jin Cao 0001, Hui Li 0006, Zheng Yan 0002 |
ISPEC | 4 |
| 2023 | Interpreting Disparate Privacy-Utility Tradeoff in Adversarial Learning via Attribute CorrelationabstractAdversarial learning is commonly used to extract latent data representations which are expressive to predict the target attribute but indistinguishable in the privacy attribute. However, whether they can achieve an expected privacy-utility tradeoff is of great uncertainty. In this paper, we posit it is the complex interaction between different attributes in the training set that causes disparate tradeoff results. We first formulate the measurement of utility, privacy and their tradeoff in adversarial learning. Then we propose the metrics of Statistical Reliability (SR) and Feature Reliability (FR) to quantify the relationship between attributes. Specifically, SR reflects the co-occurrence sampling bias of the joint distribution between two attributes. Beyond the explicit dependence, FR exploits the intrinsic interaction one attribute exerts on the other via exploring the representation disentanglement. We validate the metrics on CelebA and LFW dataset with a suite of target-privacy attribute pairs. Experimental results demonstrate the strong correlations between the metrics and utility, privacy and their tradeoff. We further conclude how to use SR and FR as a guide to the setting of the privacy-utility tradeoff parameter. Yahong Chen, Ang Li 0005, Binghui Wang, Yiran Chen 0001, Fenghua Li 0001, Jin Cao 0001, Ben Niu 0001 |
WACV | 7 |
| 2023 | LK-AKA: A lightweight location key-based authentication and key agreement protocol for S2S communication
Jin Cao 0001, Xiongpeng Ren, Ben Niu 0001, Yinghui Zhang 0002, Hui Li 0006 |
Comput. Commun. | 2 |
| 2023 | Secure and Efficient Smart Healthcare System Based on Federated LearningabstractThe rapid development of smart healthcare system in the Internet of Things (IoT) has made the early detection of many chronic diseases more convenient, quick, and economical. However, when healthcare organizations collect users’ health data through deployed IoT devices, there are issues of compromising users’ privacy. In view of this situation, this paper introduces federated learning technology to solve the problem of data security. In this paper, we consider the two main problems of federated learning applications in IoT smart healthcare system: (1) how to reduce the time overhead of system running and (2) how to authenticate that the user device uploading data is deployed by the system itself. To solve the above problems, we propose the first federated learning scheme based on full dynamic secret sharing. First, we use a two‐mask protocol to keep the user’s local model parameters confidential during federated learning. Then, based on homogeneous linear recursive equation, homomorphic hash function, and elliptic curve cryptosystem, the full dynamic secret sharing and user identity authentication are realized. In addition, our scheme allows users to join or quit during training. Finally, we have carried out simulation test on this scheme. The experimental results show that the efficiency of our scheme is improved by about 60% on average in the case of no user dropping and by about 30% in the case of some users dropping. Wei Liu 0149, Yinghui Zhang 0002, Jin Cao 0001, Hui Cui 0001, Dong Zheng 0001 |
Int. J. Intell. Syst. | 4 |
| 2023 | FHAP: Fast Handover Authentication Protocol for High-Speed Mobile Terminals in 5G Satellite-Terrestrial-Integrated NetworksabstractThe integration of satellite and terrestrial networks presents new opportunities and challenges for high speed rail (HSR) communications. Since the HSR runs vary fast, user terminals on the HSR have to perform handover authentication when the HSR passes through different terrestrial base stations or satellite coverage areas. To improve the security and robustness of HSR communication services, a fast handover authentication protocol (FHAP) for high-speed mobile terminals in the 5G satellite–terrestrial-integrated networks (STNs) is proposed. In the FHAP, user terminals in the same carriage form a temporary group managed by a relay node. The prehandover authentication mechanism is employed, in which the terrestrial 5G core network configures the preauthentication information to multiple access nodes based on the Chinese Remainder Theorem according to the location information of the HSR. Thus, group members and one of the access nodes can achieve fast handover authentication with the preconfigured information. Considering that HSR has a high running speed, when handover authentication fails, user terminals can perform handover authentication with other access nodes, and the probability of handover authentication failure caused by a single access node can be effectively reduced. We use the protocol verification tool Scyther and the Burrows–Abadi–Needham (BAN) logic to prove the security of the FHAP and compare it with other similar protocols in terms of signaling, bandwidth, and computational overhead. The analysis results show that the FHAP satisfies better security properties and has excellent performance. Jin Cao 0001, Ruhui Ma, Lifu Cheng, Lilan Chen, Ben Niu 0001, Hui Li 0006 |
IEEE Internet Things J. | 2 |
| 2023 | Multi-Keyword Searchable and Verifiable Attribute-Based Encryption Over Cloud DataabstractIn cloud data sharing systems, Searchable Encryption (SE) schemes ensure data confidentiality with retrieving, but it faces several issues in practice. First, most of the previous Ciphertext-Policy Attribute-Based Keyword Search (CP-ABKS) systems enable users to initiate search requests with a single keyword, which results in many inaccurate results to be returned, thereby wasting computing and bandwidth resources. Second, untrusted cloud servers may return a small portion of incomplete search results to compress communication overhead. Besides, most CP-ABKS schemes only support an unshared multi-owner setting, which incurs a large amount of computational and storage overhead. Furthermore, when the keyword space is a polynomial, most of the previous schemes suffer from offline keyword guessing attacks. To address these issues, we focus on a multi-keyword search scheme which supports the verification of search results without losing efficiency by combining Ciphertext Policy Attribute-Based Encryption (CP-ABE) technology under the shared multi-owner mechanism. We show the security of our scheme, which achieves selective security against offline keyword guessing attacks and guarantees the unforgeability of signatures. The comparison of experimental results illustrates that our scheme is effective and enjoys superior functionalities than the most relevant solutions. Yinghui Zhang 0002, Rui Guo 0005, Shengmin Xu, Hui Cui 0001, Jin Cao 0001 |
IEEE Trans. Cloud Comput. | 6 |
| 2023 | A Software-Based Remote Attestation Scheme for Internet of Things DevicesabstractWith the rapid development of intelligent applications, many Internet of Things (IoT) devices are deployed in various application scenarios, playing an extremely important role. Remote attestation is an important method to ensure the software integrity of these devices and protect them from several attacks. Due to the lack of security hardware and no support of hardware extensions for Class-1 IoT devices, it is particularly important to design a suitable remote attestation scheme for these devices. In this paper, we first propose the delayed observation mechanism to alleviate the problem that the software-based remote attestation scheme is not suitable for wireless networks. At the same time, we propose a ”filling memory at attestation-time” mechanism, which solves the problem that attackers hide malicious code through return-oriented programming. Finally, we introduce a reputation mechanism to assist our attestation, and adopt the principle of ”making higher-performance verification nodes take on more work” to greatly reduce the time-consuming attestation. We analyze the security of the scheme and implement it on a UNO-R3 development board to prove its practicability and effectiveness. Compared with traditional software-based attestation schemes, our scheme can reduce the attestation time and resist proxy attacks. Jin Cao 0001, Ruhui Ma, Zhenyang Guo, Yinghui Zhang 0002, Hui Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | A Novel Access and Handover Authentication Scheme in UAV-Aided Satellite-Terrestrial Integration Networks Enabling 5GabstractAs an outlook of the terrestrial network, the flexible Unmanned Aerial Vehicle (UAV)-aided satellite-terrestrial integration network would have numerous prospective applications such as service enhancement, maritime communication, military, and emergency communication, which is getting significant attention. However, the public and open-access network must result in various imperative risks including impersonation, sensitive data, and privacy disclosure. Due to several unique characteristics including long transmission distance, unstable communication environment, resource-limited and highly dynamic characteristics of UAVs, diversified terminals that lack the ability of accessing the satellite and may be resource-limited, there are new challenges for the access authentication process in the UAV-Aided Satellite-Terrestrial Integration Networks with 5G. In this paper, we present a novel Physically Unclonable Function (PUF)-based access authentication scheme consisting of two access authentication protocols for the UAV and the ground terminals like 5G User Equipments (UEs), respectively. Two access authentication protocols for the drone and the terminals can both achieve mutual authentication, key agreement, and privacy protection with distinct advantages of no need to store secret key and supporting physical attack resistance. Finally, we propose an efficient handover authentication protocol executed by the ground terminals when the UAV is required to switch. We employ different security analysis tools to analyze the security of all proposed protocols, as well as present informal security analysis on various security properties. The performance comparison and evaluations show our protocols have better advantages. Xiongpeng Ren, Jin Cao 0001, Ruhui Ma, Yurong Luo, Yinghui Zhang 0002, Hui Li 0006 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | A Terminal Security Authentication Protocol for Zero-Trust Satellite IoTabstractWith the help of satellites, Internet of Things (IoT) applications such as remote monitoring and ocean exploration can be realized. However, the network is vulnerable to malicious attacks due to the limited resources of satellite IoT (S-IoT) terminals and the openness of communication links. Ensuring that legitimate users can only access sensitive data remains a major concern. In this paper, a zero-trust access management model integrated with satellites, network and identity infrastructure, as well as the authentication protocol for S-IoT terminal security, was designed. The protocol adopts the Chinese cryptographic algorithms SM2, SM3, and SM4, combined with the Physical Unclonable Function (PUF) to achieve key agreement and bidirectional authentication. The security of this protocol is further analyzed, and its security, function, and performance are compared with other related protocols. Experimental results show that compared with existing similar schemes, the proposed protocol can more effectively consider the security requirements of S-IoT and reduce communication costs. Minqiu Tian, Zifu Li, Fenghua Li 0001, Jin Cao 0001, Chao Guo 0002 |
TrustCom | 4 |
| 2022 | DP-Opt: Identify High Differential Privacy Violation by Optimization
Ben Niu 0001, Zejun Zhou, Yahong Chen, Jin Cao 0001, Fenghua Li 0001 |
WASA (2) | 4 |
| 2022 | RPRIA: Reputation and PUF-Based Remote Identity Attestation Protocol for Massive IoT DevicesabstractThe smart city is a vision for urban development that combines new-generation information technologies to improve the quality of life. The Internet of Things (IoT) technology is a key technology of smart city, which provides the support for the automatic collection and transmission of massive information in smart city. However, there are some challenges for the IoT devices in a smart city in terms of security and performance, such as various security vulnerabilities and a large amount of computational overhead. With the explosive growth of the number of IoT devices and the data they generate, it is very necessary to ensure that a large number of IoT devices can establish secure and reliable communication with the central server. In this article, we design a massive IoT device remote identity attestation protocol based on the reputation mechanism and physically unclonable function (PUF). Our protocol can efficiently and securely accomplish the mutual authentication and key agreement between massive IoT devices and central server, and between IoT devices. The Burrows–Abadi–Needham (BAN) logic and a formal verification tool called Scyther are employed to prove the security of our protocol. We also evaluate the performance by comparing our protocol with other related protocols in terms of computational overhead, communication overhead, etc. The security and performance results show that our protocol has ideal security and performance. Jin Cao 0001, Ruhui Ma, Yueyu Zhang, Hui Li 0006 |
IEEE Internet Things J. | 1 |
| 2022 | A Novel PUF-Based Group Authentication and Data Transmission Scheme for NB-IoT in 3GPP 5G NetworksabstractWith the gradual commercialization of the fifth-generation (5G) network, the narrowband Internet of Things (NB-IoT) system would have potential and prospective applications in future relying on the infrastructure. Meanwhile, predictably, there are several security requirements to be satisfied, including concurrent access authentication for massive devices, identity privacy protection, physical attack resistance, application traffic security, etc. In this article, we present a novel group authentication and data transmission scheme using the physically unclonable function (PUF) for NB-IoT in which the output of PUF is viewed as shared root key to achieve the mutual authentication along with key agreement. By this scheme, a Group Leader is employed to aggregate and relay authentication information and, thus, it reduces the signaling cost and communication cost followed by activating attach request messages from a sea of devices. The network side as well can surely find fake ones through individual truncated authentication code and detect honest devices with high probability when aggregated authentication code is invalid. Furthermore, the revised security model and the formal verification tool Scyther are employed to evaluate the security of the scheme. Finally, performance analysis results show that our solution has the desired efficiency. Xiongpeng Ren, Jin Cao 0001, Maode Ma, Hui Li 0006, Yinghui Zhang 0002 |
IEEE Internet Things J. | 2 |
| 2022 | A robust authentication scheme for remote diagnosis and maintenance in 5G V2N
Ruhui Ma, Jin Cao 0001, Dengguo Feng, Hui Li 0006, Xiaowei Li 0001 |
J. Netw. Comput. Appl. | 2 |
| 2022 | Decentralized authentication and access control protocol for blockchain-based e-health systems
Xinyin Xiang, Jin Cao 0001, Weiguo Fan |
J. Netw. Comput. Appl. | 2 |
| 2022 | EAP-DDBA: Efficient Anonymity Proximity Device Discovery and Batch Authentication Mechanism for Massive D2D Communication Devices in 3GPP 5G HetNetabstractDevice-to-device (D2D) communication as direct communication technology has many application scenarios and plays a very important role in the fifth-generation (5G) era. Using D2D communication in third generation partnership project (3GPP) 5G Heterogeneous Network (HetNet) can effectively relieve the network traffic pressure and reduce the energy consumption of the base station. However, there are numerous security threats in D2D applications since the D2D communication remains in the early stage. The existing standards and solutions rarely consider device discovery, efficient authentication, mutual authentication, and key negotiation with privacy protection for D2D user equipment (UE) in heterogeneous access scenarios. In this article, we present a unified efficient anonymity proximity device discovery and batch authentication mechanism for heterogeneous D2D UEs based on a new proposed efficient pairing-free certificateless batch signature (CLBS), the identity-based prefix encryption and Chinese remainder theorem (CRT). Our proposed scheme can be applied to all the 5G heterogeneous access scenarios of D2D communication. The security analysis and performance results show that our scheme can achieve mutual authentication, key agreement, identity privacy protection, batch verification, and resist several protocol attacks with ideal efficiency. Yunqing Sun, Jin Cao 0001, Maode Ma, Yinghui Zhang 0002, Hui Li 0006, Ben Niu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | A Group-Based Multicast Service Authentication and Data Transmission Scheme for 5G-V2Xabstract5G Vehicular to everything (5G-V2X) has grown more vigorously than ever before, and services massive vehicles can obtain provided by content providers via the network in all fields are widely acknowledged, such as listening to news channels and traffic channels. In the 5G-V2X network, content providers can provide service messages to a group of vehicles belonging to a specific area in point-to-multipoint transmission mode. However, various challenges are in front of the way when vehicles obtain multicast services due to the unique features of 5G-V2X, such as massive vehicles and strong mobility. In this paper, we present a typical vehicle multicast service model in 5G-V2X and propose a group-based multicast service authentication and data transmission scheme based on this model. In the scheme, massive vehicles within the same RAN coverage are constructed into a group and connected to the content provider to gain access to a multicast service using the distributed keys securely by the 5G home network. Subsequently, the multicast service key for protecting the multicast service data is distributed to each vehicle so that the multicast service data can be securely transmitted to vehicles in point-to-multipoint mode. The security analysis results using the formal verification tool and informal security analysis show that the proposed scheme supports the multicast services authentication and authorization, multicast service data protection, key distribution protection, anonymity, unlinkability, and protocol attack resistance. The performance analysis results regarding signaling, computational and communication overheads show that the proposed scheme outperforms other related schemes. Ruhui Ma, Jin Cao 0001, Yinghui Zhang 0002, Lihui Xiong, Hui Li 0006 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2021 | AdaPDP: Adaptive Personalized Differential PrivacyabstractUsers usually have different privacy demands when they contribute individual data to a dataset that is maintained and queried by others. To tackle this problem, several personalized differential privacy (PDP) mechanisms have been proposed to render statistical information of the entire dataset without revealing individual privacy. However, existing mechanisms produce query results with low accuracy, which leads to poor data utility. This is primarily because (1) some users are over protected; (2) utility is not explicitly included in the design objective. Poor data utility impedes the adoption of PDP in the real-world applications. In this paper, we present an adaptive personalized differential privacy framework, called AdaPDP. Specifically, to maximize data utility in different cases, AdaPDP adaptively selects underlying noise generation algorithms and calculates the corresponding parameters based on the type of query functions, data distributions and privacy settings. In addition, AdaPDP performs multiple rounds of utility-aware sampling to satisfy different privacy requirements for users. Our privacy analysis shows that the proposed framework renders rigorous privacy guarantee. We conduct extensive experiments on synthetic and real-world datasets to demonstrate the much less utility losses of the proposed framework over various query functions. Ben Niu 0001, Yahong Chen, Boyang Wang 0001, Zhibo Wang 0001, Fenghua Li 0001, Jin Cao 0001 |
INFOCOM | 6 |
| 2021 | Flexible and anonymous network slicing selection for C-RAN enabled 5G service authentication
Yinghui Zhang 0002, Axin Wu, Dong Zheng 0001, Jin Cao 0001, Xiaohong Jiang 0001 |
Comput. Commun. | 5 |
| 2021 | CPPHA: Capability-Based Privacy-Protection Handover Authentication Mechanism for SDN-Based 5G HetNetsabstractUltra-dense Heterogeneous network (HetNet) technique can significantly improve wireless link quality, spectrum efficiency and system capacity, and satisfy different requirements for coverage in hotspots, which has been viewed as one of the key technologies in fifth Generation (5G) network. Due to the existence of many different types of base stations (BSs) and the complexity of the network topology in the 5G HetNets, there are a lot of new challenges in security and mobility management aspects for this multi-tier 5G architecture including insecure access points and potential frequent handovers among several different types of base stations. In this paper, we integrate user capability and Software Defined Network (SDN) technique, and propose a capability-based privacy protection handover authentication mechanism in SDN-based 5G HetNets. Our proposed scheme can achieve the mutual authentication and key agreement between User Equipments (UEs) and BSs in 5G HetNets at the same time largely reduce the authentication handover cost. We demonstrate that our proposed scheme indeed can provide robust security protection by employing several security analysis methods including the BAN logic and the formal verification tool Scyther. In addition, the performance evaluation results show that our scheme outperforms other existing schemes. Jin Cao 0001, Maode Ma, Hui Li 0006, Yinghui Zhang 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | A Framework to Preserve User Privacy for Machine Learning as a ServiceabstractSuffered from the contradiction between the limited capacity of local devices and large size of DNN models, a practical solution is transferring the heavy computational tasks from the local to the server side such as cloud. However, the untrusted server naturally requires all the user data to train neural networks and infer results, which causes the asset loss of the local and raises serious privacy concerns on user's sensitive information. To solve this problem in scenarios of machine learning as a service, we propose a general framework to balance the user privacy, model accuracy and training efficiency, simultaneously. Specifically, our representative subset selection algorithm takes the training value of data into account, selecting the most representative subset from the training data, in order to mitigate the loss of data assets, lower down the transmission overhead from the local to the server and lessen the training burden on the server at the same time. We also design a noisy representation transformation algorithm applying on the features extracted by neural networks to further perturb the data within the selected representative subset. Extensive experiments demonstrate that our framework can run locally with little sacrifice on the computation resource. It can not only protect private data before uploading, but also promote the training efficiency of servers. Ben Niu 0001, Yahong Chen, Ang Li 0005, Wei Du 0009, Jin Cao 0001, Fenghua Li 0001 |
GLOBECOM | 6 |
| 2020 | Decision-Making for Intrusion Response: Which, Where, in What Order, and How Long?abstractGenerating fine-grained response policies is a fundamental problem for Intrusion Response Systems (IRSs). Although existing schemes determine countermeasures and defense points efficiently, they ignore the deployment orders and execution durations of the selected countermeasures, which may impact response performance. To address this problem, by considering four attributes (i.e., attack damage, deployment cost, negative impact on QoS, and security benefit), we propose a decisionmaking framework for IRSs to reach fine-grained decisions to balance attack damage and response cost. We formulate decisionmaking as a single-objective optimization problem. To efficiently solve this problem, a Genetic Algorithm with Three-dimensional Encoding (GATE) is proposed to not only select countermeasures and defense points, but also determine deployment orders and execution durations. Simulation results demonstrate the efficiency of our approach. Yunchuan Guo, Zifu Li, Fenghua Li 0001, Liang Fang 0009, Lihua Yin, Jin Cao 0001 |
ICC | 7 |
| 2020 | A Secure Authentication Scheme for Remote Diagnosis and Maintenance in Internet of VehiclesabstractDue to the low latency and high speed of 5G networks, the Internet of Vehicles (IoV) under the 5G network has been rapidly developed and has broad application prospects. The Third Generation Partnership Project (3GPP) committee has taken remote diagnosis as one of the development cores of IoV. However, how to ensure the security of remote diagnosis and maintenance services is also a key point to ensure vehicle safety, which is directly related to the safety of vehicle passengers. In this paper, we propose a secure and efficient authentication scheme based on extended chebyshev chaotic maps for remote diagnosis and maintenance in IoVs. In the proposed scheme, to provide strong security, anyone, such as the vehicle owner or the employee of the Vehicle Service Centre (VSC), must enter the valid biometrics and password in order to enjoy or provide remote diagnosis and maintenance services, and the vehicle and the VSC should authenticate each other to ensure that they are legitimate. The security analysis and performance evaluation results show that the proposed scheme can provide robust security with ideal efficiency. Ruhui Ma, Jin Cao 0001, Dengguo Feng, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001, Lihua Yin |
WCNC | 2 |
| 2020 | Utility-aware Exponential Mechanism for Personalized Differential PrivacyabstractPersonalized Differential Privacy (PDP) was proposed to satisfy users' different privacy requirements. However, most of the existing PDP mechanisms may significantly destroy the utility of released statistical results. Differentially private statistical results with poor utility may mislead the data analysts, thus it may even decrease the acceptability of the technique used to protect data privacy. Therefore, in this paper, our goal is to pursue higher data utility while satisfying personalized differential privacy. To achieve this goal, we propose the Utility-aware Personalized Exponential Mechanism (UPEM) to effectively achieve PDP while pursuing better utility. UPEM distinguishes the different possible results with the same personalized score, which is used in Personalized Exponential Mechanism (PEM) [1]. PEM considers the personalized privacy budgets of changing elements to achieve PDP. Based on PEM, our UPEM further considers the quantitative changes of these changing tuples to enhance the utility. We confirm the effectiveness and efficiency of UPEM through extensive experiments. Ben Niu 0001, Yahong Chen, Boyang Wang 0001, Jin Cao 0001, Fenghua Li 0001 |
WCNC | 4 |
| 2020 | A personalized range-sensitive privacy-preserving scheme in LBSsabstractSummary Mobile social network has become a necessary part in our daily life, and location‐based services (LBSs) provide unprecedented convenience to mobile users. However, these attracting services are accompanied with privacy disclosures, including location privacy and query privacy. Mobile users have to expose their personal information to untrusted location‐based service provider (LSP) in order to obtain relevant service data. To address these privacy issues, we proposed a personalized range‐sensitive privacy‐preserving scheme, called PRPS, which considers the relationship between locations, query ranges, and query contents. Moreover, PRPS employs map storing algorithm (MSA) to facilitate the storage of two‐dimensional local map, reducing the cost of storage. Furthermore, range estimating algorithm (REA) adopts binary quad‐tree to decide the query radius of each submitted location, avoiding inference attacks by adversary. The requirements generating algorithm (RGA) selects relevant query content for each dummy location, guaranteeing mobile user's location privacy and query privacy. Finally, we illustrate the privacy analysis to proof PRPS's privacy degree; then, the performance and privacy evaluation results indicate that the proposed PRPS is effective and efficient. Weihao Li 0004, Ben Niu 0001, Jin Cao 0001, Yurong Luo, Hui Li 0006 |
Concurr. Comput. Pract. Exp. | 3 |
| 2020 | LSAA: A Lightweight and Secure Access Authentication Scheme for Both UE and mMTC Devices in 5G NetworksabstractAs a development of the next generation of mobile communication networks and systems (5G), the Third-Generation Partnership Project (3GPP) committee has standardized a new 5G authentication and key-agreement (5G-AKA) protocol to ensure the access security of a mobile equipment. However, there are still some security vulnerabilities in the 5G-AKA protocol, and there is no authentication protocol proposed for massive device concurrent connection by the 3GPP working groups. In this article, we propose a novel lightweight and secure access authentication scheme named lightweight secure access authentication (LSAA) that contains two lightweight extended Chebyshev chaotic maps-based access authentication protocols for two types of 3GPP standard mobile devices: 1) common user equipment (UE) and 2) massive machine-type communication (mMTC) devices. Our proposed protocols can achieve several security functionalities, including mutual authentication, session-key establishment, identity privacy protection, and perfect forward/backward secrecy (PFS/PBS). In addition, the proposed protocols are lightweight in nature compared with the 5G-AKA. In order to comprehensively and accurately evaluate LSAA, we carry out formal security analysis by employing two formal verification tools Proverif and Scyther, and informal security analysis on the proposed protocols. We further evaluate the performance of the proposed protocols with regard to authentication signaling cost, authentication communication cost, authentication computational cost, and authentication storage cost. The security evaluation and performance analysis results show that our proposed protocols can provide advanced security and high efficiency. Jin Cao 0001, Zheng Yan 0002, Ruhui Ma, Yinghui Zhang 0002, Hui Li 0006 |
IEEE Internet Things J. | 1 |
| 2020 | LAA: Lattice-Based Access Authentication Scheme for IoT in Space Information NetworksabstractSpace information network (SIN), which has the characteristics of large capacity, high reliability, and wide coverage, can be effectively applied to the Internet of Things (IoT) business. However, SIN is vulnerable to various attacks due to its highly exposed links, and the power and processing capacity of satellites and IoT devices (IoTDs) are usually limited. Meanwhile, massive IoTDs connecting to SIN in an instant incur a severe signaling congestion and there is no authentication protocol proposed for massive IoTDs in SIN. In this article, we first propose a novel semi-aggregated signature mechanism and session key agreement mechanism. Then, based on the above two mechanisms, we propose a novel access authentication scheme named lattice-based access authentication (LAA) which contains two types of lattice-based authentication protocols: 1) LAA for massive IoTDs and 2) LAA for a single IoTD. The security analysis by employing the formal provable security analysis, the automation verification tool named Scyther, the Burrows-Abadi-Needham-logic, and the informal security analysis demonstrate that our proposed protocols successfully achieve these security properties, including mutual authentication, conditional anonymity, unlinkability, data confidentiality, data integrity, unforgeability, undeniability, key establishment, perfect forward/backward secrecy (PFS/PBS), and resistance against protocol attacks and quantum attacks. We further evaluate the performance of our proposed protocols with regard to signaling overhead, transmission overhead, computational overhead, and authentication delay, which shows that our proposed protocols can provide high efficiency. Ruhui Ma, Jin Cao 0001, Dengguo Feng, Hui Li 0006 |
IEEE Internet Things J. | 2 |
| 2020 | An Adaptive Security Data Collection and Composition Recognition method for security measurement over LTE/LTE-A networks
Hanlu Chen, Zheng Yan 0002, Raimo Kantola, Xuyang Jing, Jin Cao 0001, Hui Li 0006 |
J. Netw. Comput. Appl. | 7 |
| 2019 | Quantum-Resistance Authentication and Data Transmission Scheme for NB-IoT in 3GPP 5G NetworksabstractThe Narrow Band Internet of Things (NB-IoT) system has become an important branch of the Internet of Everything and is an indispensable part in future fifth Generation (5G) network. However, there is currently no effective access authentication scheme for the NB-IoT system in the future 5G network. According to the current 3GPP standard, NB-IoT devices still use the traditional access authentication method to perform the mutual authentication with the network, which may bring a lot of signaling and communication overheads. This problem will be more prominent when sea of NB-IoT devices simultaneously are activated in the 5G network. In this paper, we propose a quantum-resistance access authentication and data distribution scheme for massive NB-IoT devices. This scheme can implement access authentication and data transmission for a group of NB-IoT devices at the same time based on the lattice-based homomorphic encryption technology. Our scheme can not only greatly reduce the network burden, but also can achieve the strong security including privacy protection and resisting quantum attacks. Performance analysis results show that our solution has the desired efficiency. Pu Yu, Jin Cao 0001, Maode Ma, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001 |
WCNC | 2 |
| 2019 | PPSHA: Privacy preserving secure handover authentication scheme for all application scenarios in LTE-A networks
Ruhui Ma, Jin Cao 0001, Dengguo Feng, Hui Li 0006, Yinghui Zhang 0002, Xixiang Lv |
Ad Hoc Networks | 2 |
| 2019 | Fast Authentication and Data Transfer Scheme for Massive NB-IoT Devices in 3GPP 5G NetworkabstractThe emergence of narrowband Internet of Things (NB-IoT) has brought hope for the popularization and application of mobile Internet standards. Nowadays, NB-IoT technology has been introduced into the Third Generation Partnership Project (3GPP) standards, where low-overhead, low-data-transmission IoT devices can securely access the fifth generation (5G) core network through the 3GPP access network. However, according to the current 3GPP standard, these NB-IoT devices still employ the traditional authentication process of normal user equipment to implement mutual authentication between NB-IoT devices and 5G core networks, which brings a lot of communication and storage overhead, and it will be more serious when lots of NB-IoT devices are activated simultaneously. In this paper, we propose a fast mutual authentication and data transfer scheme for massive NB-IoT devices, which integrates the access authentication and secure data transmission process and achieves the authentications and data transmissions of a group of NB-IoT devices at the same time. Our scheme can not only greatly simplify the authentication process and alleviate the load of the networks but also ensure robust security protection including user anonymity and nonrepudiation. The performance analysis results show that the proposed scheme can withstand a variety of security attacks with ideal efficiency. Jin Cao 0001, Pu Yu, Maode Ma, Weifeng Gao |
IEEE Internet Things J. | 1 |
| 2019 | Anti-Quantum Fast Authentication and Data Transmission Scheme for Massive Devices in 5G NB-IoT SystemabstractThe narrowband Internet of Things (NB-IoT) system has become an integral part of the future fifth generation (5G) network. Although the NB-IoT system has gradually been improved in the traditional LTE network currently, the NB-IoT system does not have an effective access authentication scheme in the future 5G network. According to the current 3rd Generation Partnership Project (3GPP) standard, NB-IoT devices still use the traditional access authentication method to perform mutual authentication with the network, which may bring a large amount of signaling and communication overhead. This problem will be magnified in a large-scale device environment in the future 5G network. In this article, a quantum resistance access authentication and data distribution scheme is proposed for large-scale NB-IoT devices. The scheme can simultaneously implement access authentication and data transmission of a group of NB-IoT devices based on the lattice-based homomorphic encryption technology. Our scheme not only greatly reduce the network burden but also achieve strong security, including privacy protection and anti-quantum attacks. The performance analysis results show that our scheme has the ideal efficiency. Jin Cao 0001, Pu Yu, Xinyin Xiang, Maode Ma, Hui Li 0006 |
IEEE Internet Things J. | 1 |
| 2019 | Efficient and Robust Certificateless Signature for Data Crowdsensing in Cloud-Assisted Industrial IoTabstractWith the digitalization of various industries, the combination of cloud computing and the industrial Internet of Things (IIoT) has become an attractive data processing paradigm. However, the cloud-assisted IIoT still has challenging issues, including authenticity of data, untrustworthiness of third parties, and system robustness and efficiency. Recently, a lightweight certificateless signature (CLS) scheme for the cloud-assisted IIoT, that was claimed to address both authenticity of data and untrustworthiness of third parties, has been proposed by Karati et al. (2018). In this paper, we demonstrate that the CLS scheme fails to achieve the claimed security properties by presenting four types of signature forgery attacks. We also propose a robust certificateless signature (RCLS) scheme to address the aforementioned challenges. Our RCLS only needs public channels and is proven secure against both public key replacement attacks and malicious-but-passive third parties in the standard model. Performance evaluation indicates that the RCLS scheme outperforms other CLS schemes and is suitable for the IIoT. Yinghui Zhang 0002, Robert H. Deng, Dong Zheng 0001, Jin Li 0002, Pengfei Wu 0003, Jin Cao 0001 |
IEEE Trans. Ind. Informatics | 6 |
| 2018 | Achieving Personalized k-Anonymity against Long-Term Observation in Location-Based ServicesabstractLocation privacy continues to attract significant attentions from both industry and academia in recent years. However, Location Based Service (LBS) servers or some other adversaries who can monitor a particular user's historical and current status in a long-term way may likely infer user's location privacy. To solve this problem, we propose a Longterm Observation-aware Dummy Selection (LODS) algorithm to achieve k-anonymity for users in LBSs. Different from existing approaches, the LODS takes the historical anonymity sets into account, since mobile users may query LBSs at certain places such as home or office. LODS selects candidate sets containing dummy locations with less number of occurrences firstly, in order to achieve the preferred distribution. Then, LODS further filters out candidate sets with smaller entropy. Finally, we choose the anonymity set with highest Quality of Service (QoS) as the result. Extensive experiment indicates our algorithm can protect user's location privacy effectively against long-term observation, and satisfy user's QoS requirement at the same time. Fenghua Li 0001, Yahong Chen, Ben Niu 0001, Yuanyuan He 0002, Kui Geng, Jin Cao 0001 |
GLOBECOM | 6 |
| 2018 | EGHR: Efficient group-based handover authentication protocols for mMTC in 5G wireless networks
Jin Cao 0001, Maode Ma, Hui Li 0006, Xuefeng Liu 0002 |
J. Netw. Comput. Appl. | 1 |
| 2018 | UPPGHA: Uniform Privacy Preservation Group Handover Authentication Mechanism for mMTC in LTE-A NetworksabstractMachine Type Communication (MTC), as one of the most important wireless communication technologies in the future wireless communication, has become the new business growth point of mobile communication network. It is a key point to achieve seamless handovers within Evolved-Universal Terrestrial Radio Access Network (E-UTRAN) for massive MTC (mMTC) devices in order to support mobility in the Long Term Evolution-Advanced (LTE-A) networks. When mMTC devices simultaneously roam from a base station to a new base station, the current handover mechanisms suggested by the Third-Generation Partnership Project (3GPP) require several handover signaling interactions, which could cause the signaling load over the access network and the core network. Besides, several distinct handover procedures are proposed for different mobility scenarios, which will increase the system complexity. In this paper, we propose a simple and secure uniform group-based handover authentication scheme for mMTC devices based on the multisignature and aggregate message authentication code (AMAC) techniques, which is to fit in with all of the mobility scenarios in the LTE-A networks. Compared with the current 3GPP standards, our scheme can achieve a simple authentication process with robust security protection including privacy preservation and thus avoid signaling congestion. The correctness of the proposed group handover authentication protocol is formally proved in the Canetti-Krawczyk (CK) model and verified based on the AVISPA and SPAN. Jin Cao 0001, Hui Li 0006, Maode Ma, Fenghua Li 0001 |
Secur. Commun. Networks | 1 |
| 2017 | Trajectory prediction-based handover authentication mechanism for mobile relays in LTE-A high-speed rail networksabstractThe handover mechanism with the assist of mobile relay mounted in high-speed trains has been researched to support continuous communication services for Long-Term Evolution Advanced (LTE-A) high-speed rail networks. According to the third Generation Partnership Project (3GPP) standard, the handover process for Mobile Relay Nodes (MRNs) from a donor eNB (DeNB) to another is the same as that for the common User Equipment (UE), which requires several rounds of message exchange with a complex key management mechanism. In addition, it cannot achieve the mutual authentication in handover procedures. In this paper, we propose a handover authentication mechanism based on trajectory prediction for mobile relays. In our scheme, the mutual authentication and key agreement between a MRN and the target DeNB is accomplished with ideal efficiency. Compared with the current 3GPP standards and other related schemes, our scheme effectively reduces the handover delays and at the same time provides strong security protection. Security analysis by using the formal verification tool AVISPA and SPAN and performance evaluation results show the security and efficiency of our scheme. Jin Cao 0001, Maode Ma, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001 |
ICC | 1 |
| 2017 | A secure SDN based multi-RANs architecture for future 5G networks
Zheng Yan 0002, Hui Li 0006, Xiaolong Xin 0001, Jin Cao 0001 |
Comput. Secur. | 5 |
| 2015 | GAHAP: A group-based anonymity handover authentication protocol for MTC in LTE-A networksabstractMachine Type Communication (MTC) has quickly become the driving force of the mobile operators for a large number of real-time network applications. The design of the MTC security mechanisms in the mobile environments of the Long Term Evaluation-Advanced (LTE-A) networks is the major point of the future research for the LTE-A security. When a good deal of MTC devices simultaneously move to a new eNodeB (eNB), the current third Generation Partnership Project (3GPP) handover mechanisms require several handover signaling interactions, which could not only cause the signaling load over the access network and the core network, but also increase the energy consumption of MTC devices. In this paper, we enhance the current handover mechanisms and propose an efficient group-based anonymity handover authentication protocol for a lot of MTC devices with mobility, which is to fit in with all of the mobility scenarios in the LTE-A networks. Compared with the current 3GPP standards, our scheme can not only largely reduce the signaling costs in both the access network and the core network, but also achieve the privacy preservation. Jin Cao 0001, Hui Li 0006, Maode Ma |
ICC | 1 |
| 2015 | UGHA: Uniform group-based handover authentication for MTC within E-UTRAN in LTE-A networksabstractMachine Type Communication (MTC) as one of the most important wireless communication technologies in the future wireless communication, has become the new business growth point of mobile communication network. It is a key point to achieve seamless handovers within Evolved Universal Terrestrial Radio Access Network (E-UTRAN) for a large number of MTC devices in order to support mobility in the Long Term Evolution Advanced (LTE-A) networks. When a good deal of MTC devices simultaneously roam from a base station to another, the current handover mechanisms suggested by the third Generation Partnership Project (3GPP) require several handover signaling interactions, which could cause the signaling load over the network nodes. Besides, several distinct handover procedures are proposed for different mobility scenarios, which will increase the system complexity. In this paper, we propose a simple and secure uniform group-based handover authentication scheme for a lot of MTC devices based on the multi-signature and aggregate message authentication codes (AMAC) techniques, which is to fit in with all of the mobility scenarios in the LTE-A networks. Compared with the current 3GPP standards, our scheme can achieve a simple authentication process with robust security protection, and thus avoid signaling congestion. Jin Cao 0001, Hui Li 0006, Maode Ma, Fenghua Li 0001 |
ICC | 1 |
| 2015 | GBAAM: group-based access authentication for MTC in LTE networksabstractMachine Type Communication (MTC), as one of the most important communication approaches in the future mobile communication, has drawn more and more attention. To meet the requirements of low power consumption of devices and mass device transmission is the key issue to achieve MTC applications security in the Long Term Evolution (LTE) networks. When a large number of MTC devices simultaneously connect to the network, each MTC device needs to implement an independent access authentication procedure in the current third Generation Partnership Project (3GPP) standard, which will cause a severe signaling congestion in the LTE network. In this paper, we propose a group-based access authentication scheme, by which a good deal of MTC devices can be simultaneously authenticated by the network and establish an independent session key with the network respectively. Our scheme cannot only greatly reduce the signal transmission for mass of devices to the network and thus avoid the signaling overload over the LTE network, but also achieve robust security including Key Forward/Backward Secrecy (KFS/KBS) and non-repudiation verification. The experimental results and formal verification by using the TLA+ and TLC show that the proposed scheme is secure against various malicious attacks. Jin Cao 0001, Maode Ma, Hui Li 0006 |
Secur. Commun. Networks | 1 |
| 2012 | A group-based authentication and key agreement for MTC in LTE networksabstractMachine Type Communication (MTC), as one of the most important communication approaches in the future mobile communication, has drawn more and more attention. To meet the requirements of low power consumption of devices and mass device transmission is the key issue to achieve MTC applications security in the Long Term Evolution (LTE) networks. When a large number of MTC devices simultaneously connect to the network, each MTC device needs to implement an independent access authentication process according to the current third Generation Partnership Project (3GPP) standard, which will cause a severe signaling congestion in the LTE network. In this paper, we propose a group-based access authentication scheme, by which a good deal of MTC devices can be simultaneously authenticated by the network and establish an independent session key with the network respectively. The experimental results show that the proposed scheme can achieve robust security with desirable efficiency and avoid the signaling overload over the LTE networks. Jin Cao 0001, Maode Ma, Hui Li 0006 |
GLOBECOM | 1 |
| 2012 | Unified handover authentication between heterogeneous access systems in LTE networksabstractTo achieve seamless handovers between the Evolved Universal Terrestrial Radio Access Network (E-UTRAN) and other access networks is a challenging task as it requires comprehensive real-time interconnectivity in the LTE networks. The third Generation Partnership Project (3GPP) has suggested support the mobility between the E-UTRAN and non-3GPP access networks, which requires full access authentication procedures and distinct procedures for different mobility scenarios, which will bring a lot of message exchanges and increase the system complexity. Besides, the existing handover schemes for other wireless networks are not suitable for the mobility scenarios in the LTE networks due to their inherent vulnerabilities. In this paper, we propose a fast and secure handover authentication scheme to fit in with all of the mobility scenarios in the LTE networks. Compared with other handover schemes, our scheme cannot only provide strong security guarantees including Perfect Forward Secrecy (PFS) and Master Key Forward Secrecy (MKFS) and user anonymity, but also achieve a simple authentication process with robust efficiency in terms of communication cost, storage cost and computational cost. The analysis results show that the proposed scheme is efficient and secure against various malicious attacks. Jin Cao 0001, Maode Ma, Hui Li 0006 |
GLOBECOM | 1 |
| 2012 | A lightweight roaming authentication protocol for anonymous wireless communicationabstractIn wireless network, a secure roaming authentication protocol enables a mobile user to get services from a foreign server when he/she is outside of the home server. However, the conventional approach requires the home server's participation during the authentication between the mobile user and the foreign server. So the larger number of the roaming requests are performed the heavier burden will be on the home server. Meanwhile, in wireless communication the privacy protection is also of great concern for the mobile user. In this paper we propose a lightweight roaming authentication protocol for anonymous wireless communication without the home server's participation. The new roaming authentication protocol takes advantage of the ID-based cryptography and provides user anonymity. It has good performance compared with the roaming authentication protocols whose authentication do not need the home server's participation in terms of security and computation costs. Moreover, it can be applied to various kinds of wireless networks such as Cellular Networks and Wireless Mesh Networks. Xiaowei Li 0001, Yuqing Zhang 0001, Xuefeng Liu 0002, Jin Cao 0001 |
GLOBECOM | 4 |
| 2012 | A simple and robust handover authentication between HeNB and eNB in LTE networks
Jin Cao 0001, Hui Li 0006, Maode Ma, Yueyu Zhang, Chengzhe Lai |
Comput. Networks | 1 |
| 2012 | An efficient MAC scheme for secure network coding with probabilistic detection
Boyang Wang 0001, Hui Li 0006, Jin Cao 0001 |
Frontiers Comput. Sci. | 3 |
| 2012 | An Uniform Handover Authentication between E-UTRAN and Non-3GPP Access NetworksabstractTo achieve seamless handovers between the Evolved Universal Terrestrial Radio Access Network (E-UTRAN) and other access networks is a challenging task as it requires comprehensive real-time interconnectivity in the LTE networks. The third Generation Partnership Project (3GPP) has suggested support the mobility between the E-UTRAN and non-3GPP access networks, which requires full access authentication procedures and distinct procedures for different mobility scenarios, which will bring a lot of message exchanges and increase the system complexity. Besides, the existing handover schemes for other wireless networks are not suitable for the mobility scenarios in the LTE networks due to their inherent vulnerabilities. In this paper, we propose a fast and secure handover authentication scheme to fit in with all of the mobility scenarios in the LTE networks. Compared with other handover schemes, our scheme cannot only provide strong security guarantees including Perfect Forward Secrecy (PFS) and Master Key Forward Secrecy (MKFS) and user anonymity, but also achieve a simple authentication process with robust efficiency in terms of communication cost, storage cost and computational cost. The experimental results and formal verification by using the TLA+ and TLC show that the proposed scheme is secure against various malicious attacks. Jin Cao 0001, Maode Ma, Hui Li 0006 |
IEEE Trans. Wirel. Commun. | 1 |