Bo Yang 0003

dblp:46/999-3 · DBLP profile ↗
← Back
133ranked-venue papers
7as first author
58since 2021 · last 2026
0000-0002-0419-1209ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 49 · 3 first-author · 16 since 2021Applied, interdisciplinary, general and emerging computing · 28 · 2 first-author · 7 since 2021Computer networks · 22 · 1 first-author · 20 since 2021Databases, data management, data science and information retrieval · 13 · 1 first-author · 2 since 2021Theory of computation · 12 · 4 since 2021Systems, architecture and hardware · 10 · 1 first-author · 7 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Artificial intelligence and machine learning · 2
YearPublicationVenuePosition
2026 RCBPS: Revocable certificate-based proxy signature scheme in the standard model for secure cloudIoT communications
Guangjin Zhang, Yanwei Zhou, Xianxiang Liu, Bo Yang 0003, Mingwu Zhang
Comput. Networks4
2026 IB-BPSE: A Blockchain-Assisted Privacy-Preserving Data Sharing Scheme Using Searchable Encryption
abstract
In a typical Internet of Medical Things (IoMT) system, it is common for users’ physiological data, collected by medical sensors, to be processed and shared in a third-party environment, such as a cloud server. Medical data sharing in a third-party environment must guarantee data integrity and source authentication, and robust privacy-preserving measures must be taken to enhance reliability. Searchable encryption (SE) has been leveraged in the IoMT to address the issue of exposing private data during storage and transmission. However, existing works suffer from shortcomings, such as vulnerability to data tampering. In this paper, we propose a novel privacy-preserving data sharing scheme with identity authentication based on SE that addresses the heavyweight public key management problem within a Public Key Infrastructure (PKI) framework. In IB-BPSE, a redactable signature (RS) assisted by blockchain and Merkle tree structure ensures authentication and integrity. Searchable proxy re-encryption encrypts private data, enabling efficient ciphertext search and multi-user data sharing. In addition, the scheme is provably secure in the random oracle model, and the performance analysis demonstrates that the system achieves ideal comprehensive performance. Finally, we propose an application scenario in IoMT based on IB-BPSE.
Bo Yang 0003, Xinyan Wu, Peize Liu, Naixin Zhang, Fagen Li
IEEE Internet Things J.1
2026 Leakage-resilient attribute-based encryption scheme with CCA security
Yanwei Zhou, Ran Xu 0012, Zirui Qiao, Bo Yang 0003
Theor. Comput. Sci.4
2026 Leakage-Resilient Data Transmission Protocol With Multi-Receiver for Internet of Things
abstract
The Internet of Things (IoT) is transforming lives, making daily tasks more convenient and efficient than ever before. However, the true potential of IoT can only be realized if its nodes interact with robust security, ensuring that sensitive data and personal information remain protected. While many data transmission protocols have been proposed in recent years, most fail to deliver on their security promises in real-world scenarios. Adversaries can exploit vulnerabilities through sophisticated leakage attacks such as side channel attacks or cold boot attacks to compromise encryption keys and undermine system integrity. Without advanced, resilient protocols, the promise of IoT is put at serious risk. In addition, the corresponding protocols deployed in IoT should enjoy high computational efficiency, because the mobile terminals have weak computing power. Also, from the viewpoint of actual application, the proposed data transmission protocol should have wider universality and can be used in multiple scenarios of IoT. Therefore, to further address the above problems, we propose a general construction of a leakage-resilient data transmission protocol with multi-receiver from an identity-based hash proof system (IB-HPS) and identity-based signature (IBS) scheme. For our proposal, the unforgeability, anonymity, and confidentiality can be proved based on the security of the underlying cryptography tools. Compared with the existing protocols, our proposal has better performance, such as dynamic anonymity, leakage resilience, traceability, etc. Furthermore, to guarantee the highest levels of security and efficiency, we have developed a novel IB-HPS construction that offers continuous leakage resilience and perfect key updates. Alongside this, our new leakage-resilient IBS scheme delivers the computational efficiency essential for practical deployment in IoT networks, ensuring that security enhancements do not come at the expense of performance. Both performance analysis and security analysis show that our data transmission protocol is secure, efficient, and highly practical.
Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Zhe Xia, Mingwu Zhang
IEEE Trans. Dependable Secur. Comput.3
2026 CLR-IA: An Efficient Identity Authentication Protocol With Continuous Leakage Resilience for Mobile Edge Computing
Yanwei Zhou, Yasi Zhu, Zirui Qiao, Xianxiang Liu, Guangjin Zhang, Bo Yang 0003, Tianqing Zhu, Mingwu Zhang
IEEE Trans. Dependable Secur. Comput.6
2025 Online participant selection incorporating coverage quality and participant ability for edge-aided vehicular crowdsensing
abstract
Recently, the edge-aided vehicular crowdsensing (EAVC) system has become a promising data collection mode, which utilizes vehicles to collect sensing data under the guidance of edge servers. Participant selection is a fundamental problem in vehicular crowdsensing. The available relevant schemes are unsuitable for newly arrived participants, ignore the differentiated sensing requirements of different areas, and underestimate heterogeneity among participants, which seriously damages the service quality. To handle these problems, this paper proposes an improved reinforcement learning-based online participant selection scheme incorporating coverage quality and participant ability (PSCQA) in EAVC. Coverage quality considering different spatiotemporal partitions is formulated based on the entropy theory to measure coverage uniformity of all areas and the coverage degree of the hotspot areas . Participant ability is designed by combining data quality , movement predictability, and priorities of passing areas to comprehensively measure performance differences among participants. In PSCQA, the coverage quality and ability of the selected participants are optimized through two separate value functions . In particular, participants are dynamically grouped into vehicle clusters based on the similarity of their trajectories to solve the state explosion problem that plagues traditional Q-learning. Simulation results on a real-world dataset demonstrate that the proposed PSCQA outperforms other reinforcement learning-based online participant selection schemes and traditional offline participant selection schemes.
Mengge Li, Miao Ma, Liang Wang 0014, Bo Yang 0003
Comput. Networks4
2025 An Efficient Pairing-Free Certificateless Signcryption Scheme Under the Standard Model for VANET
abstract
With the rapid advancement of the Internet of Things (IoT), its applications are becoming increasingly essential in actual application. Specifically, the recent surge in electric vehicles has spurred significant advancements in vehicle ad hoc networks (VANET). Therefore, efficient data transmission is a critical challenge in IoT, especially VANET. The certificateless signcryption (CLS) scheme has high authentication efficiency, which has become increasingly important in IoT. However, most existing schemes rely on bilinear pairing, resulting in high calculation costs or failure to achieve their claimed security. Furthermore, the security of some CLS schemes is proved in the random oracle, which limits the usefulness of the CLS scheme. To further address these issues, we propose an efficient and secure CLS scheme in the standard model for VANET, which enhances its practical applicability in VANET. Our construction employs formal security proofs and cost simulations to ensure the scheme’s security and low calculation costs, making it suitable for VANET. Finally, the security and efficiency analyses prove that our scheme offers enhanced security features and superior performance compared to existing schemes.
Xianxiang Liu, Yanwei Zhou, Bo Yang 0003, Tianqing Zhu, Mingwu Zhang
IEEE Internet Things J.3
2025 A Provably Secure Certificateless Signature Scheme With Anonymity for Healthcare IIoT
abstract
The Industrial Internet of Things (IIoT) is changing our way of life and work. As the number of mobile devices connected to IIoT increases, users will face many security challenges, such as insecure communication environments. The certificateless signature (CLS) scheme can ensure the integrity and validity of data and provide secure identity authentication for the IIoT, and several pairing-free CLS schemes have been proposed in recent years. However, we find they are vulnerable to the signature forgery attack of malicious key generation centers by safety analysis, which does not realize the security they have claimed. To solve this problem, we show an improved CLS scheme that achieves anonymity and formally proves its security under the hardness of the discrete logarithm problem in the random oracle. Comprehensive performance analysis and comparison show that our scheme has less communication and computation costs with higher security, and our construction is suitable for scenarios with limited resources. Finally, we apply this scheme to construct a mutual identity authentication protocol in the healthcare IIoT environment.
Zirui Qiao, Ran Xu 0012, Yanwei Zhou, Bo Yang 0003, Tianqing Zhu, Mingwu Zhang
IEEE Internet Things J.4
2025 Decentralized Electronic Cash Payment Scheme Using SM2-Based Blind Signcryption
abstract
Electronic cash (e-cash) payment is facing the privacy leakage, money laundering and tax evasion. To address these issues, we use SM2-based blind signcryption to construct a decentralized e-cash payment scheme (DECPS). SM2-based blind signcryption allows a signcrypter to generate a ciphertext with unknown message content. Double spending is prevented because the blockchain uploads the e-cash to public chain for transparency. DECPS has low calculation overhead for scalar multiplication and there is no key escrow. In addition, the pseudo-random number generator (RNG) is used to trace illegal transactions.
Huifang Yu 0001, Bo Yang 0003
IEEE Internet Things J.3
2025 CR²-ABE: A Blockchain-Assisted Coercion-Resistant and Revocable Attribute-Based Encryption for IoMT
abstract
The Internet of Medical Things (IoMT) has rapidly developed due to its ability to enhance the efficiency of medical data collection and utilization. Encryption technology is vital for ensuring IoMT data security and privacy. However, existing solutions often fail when secret keys or random numbers are exposed under coercion, undermining their effectiveness and security. Additionally, medical data stored on cloud platforms is vulnerable to risks, such as tampering or loss. To address these challenges, we propose CR2-ABE, a novel encryption scheme specifically designed for the IoMT environment. CR2-ABE combines chameleon hash functions and deniable encryption techniques, enabling medical data owners and recipients to present deceptive messages under coercion, thereby enhancing the coercion resistance of sensitive medical data. Moreover, CR2-ABE employs ciphertext-policy attribute-based encryption (CP-ABE) to facilitate fine-grained access control for medical data, while also leveraging blockchain technology to ensure data integrity and tamper resistance within cloud services. In terms of user management, CR2-ABE implements a policy revocation mechanism that operates directly on ciphertexts using software Guard extensions (SGX). We rigorously prove the correctness and semantic security of CR2-ABE, demonstrating its resilience against coercion attacks. Comprehensive evaluation results show that CR2-ABE exhibits significant performance improvements in key generation, encryption, decryption, and policy revocation compared to other solutions. Therefore, CR2-ABE possesses strong security and scalability.
Yuan Zhai, Haochen Yang 0001, Jingyu Yao, Tao Wang 0039, Yanwei Zhou, Bo Yang 0003
IEEE Internet Things J.7
2025 Revocable-Hierarchical-Identity-Based Inner Product Function Encryption in Smart Healthcare
abstract
With the development of cloud computing and the digital transformation of the medical industry, the application scenarios and effects of smart healthcare are constantly expanding and improving. Smart healthcare plays an important role in improving service quality and medical efficiency and reducing medical costs. However, in the process of data collection, storage, and transmission, the risk of patients’ privacy being illegally accessed or leaked has become increasingly prominent. These medical data contain sensitive information about patients, and once leaked, it will violate the privacy of patients, cause medical accidents, and seriously damage the legitimate rights and interests of patients. An efficient and reliable privacy protection mechanism is the foundation and key to establishing a harmonious doctor-patient relationship and improving medical quality. Although traditional encryption methods can provide certain information security protection, they cannot balance data protection and data analysis and processing and are not suitable for intelligent medical environments that require more precise medical decisions. Therefore, we propose a hierarchical identity-based inner product functional encryption scheme with a malicious user revocation mechanism aimed at addressing the privacy and security issues of patients in smart healthcare. This solution allows specific access and analysis of data while ensuring that patients’ sensitive information is protected from infringement, enabling doctors to diagnose and treat more accurately and optimize the allocation of medical resources to the greatest extent possible. Furthermore, we have formally demonstrated the security of the scheme and conducted a security analysis and performance comparison. The results show that our solution has better performance while ensuring security and is suitable for the efficient and secure data processing requirements of smart healthcare.
Yasi Zhu, Yanwei Zhou, Bo Yang 0003, Mingwu Zhang
IEEE Internet Things J.4
2025 DRAC: A dynamic fine-grained access control scheme for cloud storage with censorship-coerced resistance
Yuan Zhai, Haochen Yang 0001, Jingyu Yao, Tao Wang 0039, Yanwei Zhou, Bo Yang 0003
J. Inf. Secur. Appl.7
2025 AUKA: Asynchronous updatable key agreement for edge-based mobile crowd sensing
Ru Meng, Tao Wang 0039, Yanwei Zhou, Bo Yang 0003
J. Inf. Secur. Appl.5
2025 A continuous leakage-resilient CCA secure identity-based key encapsulation mechanism in the standard model
Zirui Qiao, Yasi Zhu, Yanwei Zhou, Bo Yang 0003
J. Syst. Archit.4
2025 Secure task-worker matching and privacy-preserving scheme for blockchain-based federated crowdsourcing
Pei Ren, Bo Yang 0003, Tao Wang 0039, Yanwei Zhou
J. Syst. Archit.2
2025 Bidirectional Identity-Based Inner-Product Functional Re-Encryption in Vaccine Data Sharing
abstract
With the development of cloud computing, more and more data is stored in cloud servers, which leads to an increasing degree of privacy of data stored in cloud servers. For example, in the critical domain of medical vaccine trials, where public health outcomes hinge on the analysis of sensitive patient data, the imperative to safeguard privacy has never been more pronounced. Traditional encryption methods, though effective at protecting data, often expose vulnerabilities during decryption and lack the ability to support granular data access and computation. One-way re-encryption schemes further impede the agility of data sharing, which is indispensable for the collaborative efforts of research institutions. To address these limitations, we propose a novel bidirectional re-encryption scheme for inner-product functional encryption (IPFE). Our scheme secures data while allowing computation and sharing in an encrypted state, preserving patient privacy without hindering research. By harnessing inner-product functional encryption, our approach allows authorized researchers to extract valuable insights from encrypted data, significantly enhancing privacy protections. Our scheme’s security is predicated on the$l$-ABDHE (augmented bilinear Diffie-Hellman exponent) assumption, ensuring robustness against chosen plaintext attacks within the standard model. This foundation not only secures the data but also yields compact ciphertext length, minimizing storage demands. We introduce a protocol specifically designed for medical vaccine trials, which leverages our bidirectional IB-IPFRE (Identity-Based Inner-Product Functional Re-Encryption) scheme. This protocol enhances data security, supports collaborative research, and maintains patient privacy. Its application in vaccine trials demonstrates the scheme’s effectiveness in protecting sensitive information while enabling critical research insights.
Yanwei Zhou, Yasi Zhu, Zhiquan Liu 0001, Bo Yang 0003, Mingwu Zhang
IEEE Trans. Cloud Comput.5
2025 Towards Authorization and Batch Validation for NFTs: A Cryptographic Generic Framework
abstract
The rapid growth in the NFT (Non-fungible token) market has offered a wide variety of opportunities for scammers, fraudsters, wash tradings, and so on. One of the most urgent security issues is how to efficiently authorize and validate the ownership to make the NFT ecosystem avoid infringement and counterfeiting. By exploiting linear homomorphic tagging and robust digital watermarking technologies, this article proposes a generic framework for ownership authorization and batch validation of NFTs. Within this framework, the digital artwork creators can authorize the ownership to a buyer before the NFT is minted in the public blockchain. Anytime in the future who questions the ownership of a claimant can initiate a validation procedure to get an auditing report by running a Challenge-Response protocol that supports efficient batch verification. The completeness and soundness of the proposed framework have been proven by assuming a secure homomorphic tag scheme and a robust watermarking scheme. We also present instantiations of the generic construction, especially with$\Pi _{Pub}$, one can outsource the validation procedure to the public blockchain to release local computation burden. A series of elaborated experiments have shown our proposed framework is practical and efficient.
Tao Wang 0039, Keyong Hong, Bo Yang 0003, Qiliang Yang, Wenzheng Zhang 0001
IEEE Trans. Dependable Secur. Comput.3
2025 DADD: Direct Authentication With Vehicles From Different Domains
abstract
As Vehicular Ad hoc Networks (VANETs) become integrated into daily life, drivers can conveniently transmit messages to other vehicles. However, since most messages are sent over public channels, they are vulnerable to leakage and tampering, posing risks to user privacy and security. A secure authentication scheme is essential to ensure message authenticity and integrity. Vehicles frequently cross multiple domains while driving, but existing schemes mainly support authentication within a single domain, making it difficult for vehicles from different domains to establish trusted connections. Moreover, many current approaches rely heavily on bilinear pairings, reducing efficiency and increasing communication overhead. To address these issues, we propose an efficient cross-domain authentication scheme for VANETs. Our scheme uses pseudonyms to protect vehicle privacy and allows vehicles to directly authenticate with entities from other domains without relying on a trusted authority, enabling the establishment of a secure session key. We verified the security of our protocol using ProVerif and evaluated its performance with JPBC, a Java-based cryptographic library. Results show that our approach outperforms existing methods and is well-suited for high-traffic, densely populated, and resource-constrained VANET environments.
Zirui Qiao, Yasi Zhu, Yanwei Zhou, Xianxiang Liu, Bo Yang 0003
IEEE Trans. Intell. Transp. Syst.6
2025 SRACS: Sanitizable and Revocable Access Control Scheme for Crowdsourcing Healthcare Against Malicious Requesters
Ying Zhang 0127, Bo Yang 0003, Tao Wang 0039, Yanwei Zhou
IEEE Trans. Serv. Comput.2
2024 A New Construction of Leakage-Resilient Identity-Based Encryption Scheme
Zirui Qiao, Ran Xu 0012, Yonghui Lu, Yanwei Zhou, Bo Yang 0003
ISPEC5
2024 A Secure Incentive Mechanism in Blockchain-Based Mobile Crowdsensing
Mingwu Zhang, Bo Yang 0003
ISPEC3
2024 An Efficient and Secure Lightweight Certificateless Hybrid Signcryption Scheme
abstract
With the limited resources of the Internet of Things (IoT), security and efficiency have become a challenge. The hybrid signcryption scheme is a proper method to ensure data security and integrity. Recently, through continuous and in-depth research, the signcryption scheme has made many achievements, but there are still some problems. Most proposals use bilinear mapping, which reduces computational efficiency. It brings a heavy burden to the resource-constrained IoT. And many constructions cannot meet the claimed security, causing the leakage of private messages. Therefore, we propose a lightweight certificateless hybrid signcryption (CLHS) scheme with better performance and higher security to solve the above problems. First, we have reduced storage pressure and improved computational efficiency by using certificateless public-key cryptography and elliptic curves instead of bilinear maps to construct a signcryption scheme, and the construction is lightweight. At the same time, to securely transmit messages of different lengths, we employ a hybrid signcryption scheme. Through formal security proof, efficiency, and performance analysis, our proposal has the security requirements of confidentiality and unforgeability and has better computational efficiency and security performance. Finally, we propose a secure data transmission protocol based on our CLHS scheme in Smart Grid, which inherits the advantages of high computational efficiency and better security of the underlying CLHS scheme.
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang
IEEE Internet Things J.3
2024 An Anonymous and Efficient Certificate-Based Identity Authentication Protocol for VANET
abstract
In recent years, the development of Internet of Things technology has led to a surge in interest in the vehicular ad hoc network (VANET), which has greatly improved travel efficiency and facilitated vehicle data sharing. To ensure the privacy and security of both vehicles and personnel, researchers have proposed various measures for securing VANET systems. Recently, certificate-based aggregate signature (CBAS) schemes have been proposed to design an identity authentication protocol for the VANET to prevent tampering and corruption of private vehicle data. In this study, we conduct a security analysis of the previous CBAS scheme by presenting a security attack. Afterward, we propose a novel and concrete construction of the CBAS scheme that offers improved performance for VANET, which can enhance protection in the VANET scenario. We also demonstrate its security based on standard cryptographic assumptions. Comparative results from theoretical analysis and experimental evaluation illustrate the practicality of our proposed scheme. Similarly, the identity authentication protocol created based on the above CBAS scheme has the properties of dynamic anonymity, mutual identity authentication, unforgeability.
Zirui Qiao, Yanwei Zhou, Qiliang Yang, Zhe Xia, Bo Yang 0003, Mingwu Zhang
IEEE Internet Things J.6
2024 A Lightweight and Robust Multidimensional Data Aggregation Scheme for IoT
abstract
Data aggregation technology plays a very important role in improving the efficiency of data collection of the Internet of Things (IoT). Most data collected by sensor nodes (SNs) in IoT is multi-dimensional. However, there are a few existing multi-dimensional data aggregation schemes, which are almost based on homomorphic encryption and not suitable for resource-constrained IoT smart devices. In addition, when SNs cannot upload in time for some reason, such as device error or network interruption, control center cannot get the correct aggregation result, i.e., robustness is not considered in most schemes. Therefore, we propose a lightweight and robust multi-dimensional data aggregation scheme for IoT. First, multi-dimensional data is packaged into one-dimensional data based on the Chinese Remainder Theorem, which greatly reduces communication and storage overhead. Second, the encryption in our scheme only uses addition operations without the costly additive homomorphic encryption. At the same time, our proposed scheme supports batch verification, which reduces the computation complexity of bilinear pairs by nearly half. Third, our scheme also supports dynamic SNs management and fault tolerance, enabling scalability and robustness. Finally, performance evaluation shows that our scheme has lower communication overhead and is more suitable for resource-constrained IoT scenarios.
Yanping Li 0001, Yong Ding 0005, Bo Yang 0003
IEEE Internet Things J.4
2024 A Lightweight Cross-Domain Direct Identity Authentication Protocol for VANETs
abstract
With the rapid development of Internet of Things (IoT) technology and the growth of traffic demand, vehicular ad hoc networks (VANETs) will become a major component of intelligent transportation systems. However, identity authentication in VANETs has emerged as a crucial challenge in maintaining communication security. The existing identity authentication methods have complex certificate management and key escrow problems, and many authentication schemes can not resist common attacks and are inefficient. Also, the above proposals cannot meet the lightweight needs of the IoT. At the same time, vehicles in the VANETs may move between different network domains, which will lead to an increase in cross-domain identity authentication requirements. Therefore, this article proposes an efficient and lightweight cross-domain direct identity authentication protocol. We apply the unpaired certificateless signature scheme to the cross-domain authentication and generate cross-domain communication credentials for the vehicles in advance in the local domain, which will greatly improve the efficiency of cross-domain authentication between the vehicles. In addition, we demonstrate the security of our protocol and further validate the security of the protocol through the simulation experiments. Finally, experiments show that our protocol is more efficient than the existing authentication protocols.
Yasi Zhu, Yanwei Zhou, Bo Yang 0003, Mingwu Zhang
IEEE Internet Things J.4
2024 An efficient and secure certificateless aggregate signature scheme
Ran Xu 0012, Yanwei Zhou, Qiliang Yang, Kunwei Yang, Bo Yang 0003, Zhe Xia
J. Syst. Archit.6
2024 Quality-Improved and Delay-Aware Incentive Mechanism for Mobile Crowdsensing With Social Concerns: A Stackelberg Game Approach
abstract
With the explosive popularity of mobile devices, mobile crowdsensing (MCS) has emerged as a promising large-scale data collection paradigm. Suitable incentive mechanisms are essential for encouraging user participation. Current MCS work more or less ignores three factors. First, mobile users are assumed to be independent of each other, ignoring social effects. Second, due to the heterogeneity of users, if you just blindly attract users without distinguishing them, the data quality can decrease. Finally, the limited communication resource allocation problem during uploading sensing results is ignored. Therefore, we model the quality-improved and delay-aware incentive mechanism with social concerns as a two-stage Stackelberg game, in which the rational use of social effects not only motivates user participation but also avoids a serious decline in information value due to repetition, and reasonable allocation of communication resources ensures the timeliness of delay-sensitive tasks. Furthermore, data screening, similarity analysis, voting, and reputation are used simultaneously to improve data quality. The Hessian matrix in a multiuser, multitask hyperspace setting is utilized to verify the existence and uniqueness of the game equilibrium. The closed-form expressions of the optimal requester pricing and the optimal user data load strategies are derived, respectively. The proposed mechanism is compared with gather–scatter, incentive-G, Blockchain-based secure, interactive, and fair MCS (BSIF), and Socially-aware incentive mechanism (SAIM) algorithms. Extensive simulation results on a real trajectory dataset show that compared with these state-of-the-art algorithms, the proposed incentive mechanism can motivate users to provide more data loads with few rewards, greatly improve the requester utility, and suppress the data upload of malicious users.
Mengge Li, Miao Ma, Liang Wang 0014, Bo Yang 0003
IEEE Trans. Comput. Soc. Syst.4
2024 Lightweight and Decentralized Cross-Cloud Auditing With Data Recovery
abstract
Cloud storage has benefited millions of users with its remarkable advantages of economy and flexibility. Since a single cloud service provider is not always reliable and prone to a single point of failure, multi-cloud storage is proposed to enhance data availability. However, cross multiple clouds (cross-cloud) auditing to provide users with the integrity verification of outsourced data also faces many challenges, such as the fact that a large quantity of existing schemes rely heavily on the trusted third-party. Therefore, we propose a decentralized data storage and integrity auditing scheme for multi-cloud scenarios to eliminate the dependence on the third-party, namely BDDR, and an improved version iBDDR with stronger security. First, both BDDR and iBDDR adopt multi-cloud data storage and support batch auditing to greatly save computation costs. Second, our schemes not only get rid of a third-party, but also do not require a dispute arbitration since the outsourced data can be verified by cloud server providers via the homomorphic verifiable tags published on the blockchain. Third, locating the corrupted cloud server providers and accurately recovering the corrupted data at a lower communication and computation costs are supported. Finally, security and performance analyses demonstrate the security and effectiveness of our schemes.
Liping Qiao, Yanping Li 0001, Yong Ding 0005, Bo Yang 0003
IEEE Trans. Serv. Comput.4
2023 A Certificateless Aggregate Signature Scheme with Better Security
Ran Xu 0012, Yanwei Zhou, Bo Yang 0003
ProvSec4
2023 A Novel Construction Of Certificateless Aggregate Signature Scheme For Healthcare Wireless Medical Sensor Networks
abstract
Abstract To ensure privacy and security of healthcare wireless medical sensor networks (HWMSNs), several concrete constructions of efficient certificateless aggregate signature (CLAS) scheme without bilinear pairing were proposed in the last few years. However, many previous constructions of CLAS scheme were found to be impractical, which either fail to meet the claimed security or contain design flaws. For example, in some of the previous proposals, any adversary can forge a valid signature on any new message. In this paper, we first demonstrate some security issues and design flaws in the previous proposals of CLAS scheme. As follows, to further address the above deficiencies, a new construction of CLAS scheme with improved security is presented, and the formal security proof is given using Forking Lemma in the random oracle model, assuming that the discrete logarithm problem is hard. Compared with the previous CLAS schemes, our construction has similar computational costs, and it provides better security guarantees. Therefore, compared with the existing solutions, our proposal with strong security and high computational efficiency is more suitable for use in HWMSNs.
Zirui Qiao, Qiliang Yang, Yanwei Zhou, Bo Yang 0003, Mingwu Zhang
Comput. J.4
2023 Identity-Based Encryption With Continuous Leakage-Resilient CCA Security From Static Complexity Assumption
abstract
Abstract Although a large number of provably secure cryptographic primitives have been proposed in the literature, many of these schemes might be broken in practice because of various leakage attacks. Therefore, the leakage resilience should be considered in designing these primitives. However, in identity-based cryptography, most of the existing leakage-resilient identity-based encryption (IBE) schemes suffer some limitations: they either resist the leakage attacks in the selective identity security model or achieve the chosen-ciphertext attack (CCA) security based on a non-static assumption. In this paper, an IBE scheme with adaptive leakage-resilient CCA security is proposed, and its security is rigorously proved in the random oracle model under a classic static complexity assumption, e.g. decisional bilinear Diffie–Hellman assumption. In our construction, all elements of ciphertext are randomly distributed in the adversary’s view. Hence, the adversary cannot obtain any useful information of the user’s private key from the given ciphertexts. Moreover, a unique property of our construction is that the leakage parameter is independent of the plaintext space, which contributes a better leakage rate.
Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Yi Mu 0001, Mingwu Zhang
Comput. J.5
2023 Leakage-resilient identity-based cryptography from minimal assumptions
Yanwei Zhou, Bo Yang 0003, Zirui Qiao, Zhe Xia, Mingwu Zhang, Yi Mu 0001
Des. Codes Cryptogr.2
2023 An Anonymous and Revocable Authentication Protocol for Vehicle-to-Vehicle Communications
abstract
In the vehicular ad hoc network (VANET), the communication between the vehicle and other nodes is performed in an open channel, which puts forward the requirements for its privacy security and message integrity. Most previous protocols either frequently verify identities before accepting traffic information or do not involve identity revocation mechanisms, and they may assume that third parties are fully trusted. To further solve the above problem, a certificateless-based anonymous and revocable authentication protocol for vehicle-to-vehicle communications is proposed in this article. Our construction separates the identity authentication process from the traffic message verification, which not only avoids the disadvantage of a frequent identity revocation list (IRL) checking but also reduces the overhead in communication and message authentication. These features can make “identity authentication once, broadcast efficiency” really happen. In addition, since our authentication process is based on certificateless signature, it can resist malicious key generation centers (KGCs) and road-side units (RSUs), which is very necessary for privacy-sensitive application scenarios. Finally, the performance analyses show that our proposal is superior to the existing schemes in terms of authentication speed and communication overhead.
Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Yuan Xu 0032, Mingwu Zhang
IEEE Internet Things J.4
2023 An Efficient Identity Authentication Scheme With Dynamic Anonymity for VANETs
abstract
Nowadays, as an essential technique for intelligent transportation, vehicular ad hoc networks (VANETs) has significantly improved people’s travel experience, providing richer, and smarter services for vehicles while ensuring driver safety. However, considering that VANETs are complex, some security challenges still remain, including but not restricted to privacy preserving of vehicles, authentication of messages, limited resources in computational power, and network bandwidth. To address these issues, many privacy-preserving identity authentication schemes for VANETs have been proposed recently. However, these schemes still suffer some limitations. First, their computational overheads are heavy due to the complex calculations. Second, some schemes are vulnerable to various security weaknesses, unable to resist normal attacks. Third, in some schemes, the same pseudonym keeps unchanged and it is linked to the corresponding private key of user. The consequence is that if the user wants to change its pseudonym, the corresponding private key must be changed. In order to further solve the above problems, we propose a novel privacy-preserving identity authentication protocol based on the certificateless aggregate signature scheme, allowing the user to generate a fuzzy identity to hide her real identity, and the private key can be kept unchanged even if the corresponding pseudonym is updated. Furthermore, to achieve efficiency in computation, bilinear mapping is avoided in our proposed scheme. We prove that our protocol satisfies unforgeability in the random oracle based on a classic complexity assumption. Finally, the security and efficiency analyses demonstrate that our construction enjoys more security features and better performance compared with the existing schemes.
Yanwei Zhou, Zirui Qiao, Zhe Xia, Bo Yang 0003, Mingwu Zhang, Wenzheng Zhang 0001
IEEE Internet Things J.5
2023 An Efficient and Provably Secure Identity Authentication Scheme for VANET
abstract
In recent years, many researchers have applied aggregated signature techniques to resource-constrained vehicular ad hoc networks (VANETs) authentication scenarios. We reviewed two recent VANET authentication schemes based on certificateless aggregated signatures (CLASs) while demonstrating that neither of them is resistant to public key replacement attacks under their security models. An eavesdropper can successfully forge a legitimate signature to perform malicious operation. To further address the above security flaws, we propose an improved CLAS scheme for VANET. Considering that some researchers have briefly or even incorrectly used forking lemmas in their security proofs to prove an insecure CLAS scheme, we further improve and refine the security model and security proof method for CLAS, which make the proof process transparent by using general forking lemma. Based on these improvements, our scheme can resist attacks from two types of adversaries in the CLAS security model. In the final performance analysis, the improved CLAS scheme outperforms the secure-related scheme of recent years in terms of both computational and communication efficiency. Therefore, our proposal is more suitable for resource-constrained VANET environments.
Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Mingwu Zhang
IEEE Internet Things J.4
2023 An Anonymous and Efficient Multimessage and Multireceiver Certificateless Signcryption Scheme for VANET
abstract
In future intelligent transportation systems, vehicular ad hoc network (VANET) is a popular application. They provide early warning of dangers through wireless communication to improve road safety. Therefore, we should protect messages from leakage and changes during transmission. To ensure the security issues in the communication process, we propose a secure and effective certificateless signcryption scheme with multiple messages and multiple receivers and prove its confidentiality and unforgeability based on the hardness of the discrete logarithm problem and the computational Diffie Hellman problem. Our scheme implements the signature and encryption of multiple messages for different receivers and achieves anonymity for the receiver. Based on our signcryption scheme, we design an identity authentication and key agreement protocol applying the construction in VANET. In addition, we also point out that through comprehensive performance analysis, our proposal has higher security and efficiency of computation and communication compared to other signcryption constructions.
Yanwei Zhou, Ran Xu 0012, Zirui Qiao, Bo Yang 0003, Zhe Xia, Mingwu Zhang
IEEE Internet Things J.4
2023 Public-key encryption scheme with optimal continuous leakage resilience
Yanwei Zhou, Ran Xu 0012, Wenzheng Zhang 0001, Zhe Xia, Bo Yang 0003, Meijuan Huang
Inf. Process. Lett.5
2023 A redesigned secure and efficient data transaction protocol for mobile payment system
Zirui Qiao, Qiliang Yang, Yanwei Zhou, Bo Yang 0003, Mingwu Zhang
J. Syst. Archit.4
2023 Algebraic Signature-Based Public Data Integrity Batch Verification for Cloud-IoT
abstract
With the rapid development of Internet of Things, the related data are growing explosively. However, IoT devices have limited storage and computing capabilities so that they cannot deal with massive data storage and computing locally. The integration of IoT and cloud is regarded as an effective solution to the above issue, i.e., IoT devices outsource collected data to cloud to enjoy powerful storage and computing resources. Because the data stored in cloud are out of the control of IoT users, some security risks need to be addressed in advance. In this paper, we propose a public data integrity verification scheme, called AIVCI, to check the data integrity for Cloud-IoT scenarios. Firstly, based on algebraic signature and homomorphic hash function, AIVCI can efficiently complete data auditing. Secondly, AIVCI adopts blind technology to prevent the privacy leakage of IoT data and further protect the privacy of IoT users. Thirdly, batch auditing is implemented to improve auditing efficiency and meet realistic demands for Cloud-IoT scenarios. And a new data structure named Improved Divide and Conquer Table (ID&CT) is designed to realize efficient data dynamics. Finally, the security and performance analysis demonstrates that AIVCI is more secure and efficient.
Yanping Li 0001, Bo Yang 0003, Yong Ding 0005
IEEE Trans. Cloud Comput.3
2023 Multitask-Oriented Collaborative Crowdsensing Based on Reinforcement Learning and Blockchain for Intelligent Transportation System
abstract
With the rapid development of smart cities, vehicles equipped with various sensors can effectively sense traffic, thus forming a crowdsensing paradigm for the intelligent transportation system (ITS). Although mobile crowdsensing in ITS has broad application advantages, it still faces many challenges, such as single point of failure, inefficient independent task allocation, and the inability to deal with safety emergency tasks in time. To handle the abovementioned issues, we establish a decentralized ITS architecture based on blockchain and propose the concurrent tasks assignment problem proved to be NP-hard and safety emergency tasks assignment problem. Then, we propose reinforcement learning-based concurrent tasks and the safety emergency tasks assignment method, which can maximize the utility of concurrent tasks based on satisfying the requirements of safety emergency tasks. Simulation results demonstrate the effectiveness of the proposed methods.
Mengge Li, Miao Ma, Liang Wang 0014, Bo Yang 0003, Tao Wang 0039, Jinqiu Sun
IEEE Trans. Ind. Informatics4
2023 ABCrowdMed: A Fine-Grained Worker Selection Scheme for Crowdsourcing Healthcare With Privacy-Preserving
abstract
Crowdsourcing for healthcare, which is an application of crowd intelligence, has become a novel and important auxiliary way for traditional healthcare, showing a huge application perspective. In a crowdsourcing platform for healthcare, patients can act as requesters who recruit workers, such as doctors, to provide professional advice by posting a task. However, privacy concerns pose a significant obstacle for patients willing to participate in crowdsourcing, as task data often contain sensitive personal information. To address this issue, we propose a novel attribute-based, lightweight, and dynamic fine-grained worker selection scheme, called ABCrowdMed, with privacy-preserving features. With this scheme, requesters can select workers in a non-interactive way by using a novel CP-ABE scheme that incorporates online/offline encryption, verifiable outsourcing decryption, revocation, and hidden policy properties. Additionally, requesters can revoke and update their tasks by withdrawing some workers’ decryption privileges. Participants can also release the computation burden with the aid of a third-party server. The proposed scheme’s security has been proven to be selectively secure under the decisional$ (q-1)$assumption and satisfies forward/backward security. The performance of ABCrowdMed has been evaluated and compared with state-of-art schemes, with the results demonstrating that our scheme achieves the lowest computation and is suitable for resource-constrained settings.
Tao Wang 0039, Bo Yang 0003, Qiliang Yang, Wenzheng Zhang 0001, Keyong Hong
IEEE Trans. Serv. Comput.3
2022 Bilateral Privacy-Preserving Task Assignment with Personalized Participant Selection for Mobile Crowdsensing
Shijin Chen, Mingwu Zhang, Bo Yang 0003
ISC3
2022 Lightweight integrity auditing of edge data for distributed edge computing scenarios
Liping Qiao, Yanping Li 0001, Bo Yang 0003
Ad Hoc Networks4
2022 Continual Leakage-Resilient Hedged Public-Key Encryption
abstract
Abstract Hedged public-key encryption (HPKE), introduced by Bellare et al. (ASIACRYPT 2009), provides useful security when the per-message randomness fails to be uniform due to faulty implementations or adversarial actions. The HPKE scheme achieves IND-CPA (chosen plaintext attack) security when the randomness they used is of high quality, but, when the randomness is poor quality, rather than breaking completely, it achieves a weaker but a useful notion of security called IND-CDA (chosen distribution attack) as long as the message and randomness together have sufficient min-entropy. However, little research on HPKE in the presence of key leakage was done. In this paper, we study HPKE featuring key leakage-resilience and formulate appropriate security notion for key leakage-resilient HPKE. We work in the continual key leakage model where the secret key is refreshed periodically and an adversary can learn arbitrary but bounded leakage on the secret key between the updates. We present two generic constructions of continual leakage-resilient HPKE in the standard model by using a continual leakage-resilient all-but-one lossy trapdoor function. Finally, we give an instantiation of leakage-resilient HPKE under the linear assumption in bilinear groups.
Meijuan Huang, Bo Yang 0003, Yanwei Zhou, Xuewei Hu
Comput. J.2
2022 Continuous Leakage-Amplified Public-Key Encryption With CCA Security
abstract
Abstract Secret key leakage has become a security threat in computer systems, and it is crucial that cryptographic schemes should resist various leakage attacks, including the continuous leakage attacks. In the literature, some research progresses have been made in designing leakage resistant cryptographic primitives, but there are still some remaining issues unsolved, e.g. the upper bound of the permitted leakage is fixed. In actual applications, the leakage requirements may vary; thus, the leakage parameter with fixed size is not sufficient against various leakage attacks. In this paper, we introduce some novel idea of designing a continuous leakage-amplified public-key encryption scheme with security against chosen-ciphertext attacks. In our construction, the leakage parameter can have an arbitrary length, i.e. the length of the permitted leakage can be flexibly adjusted according to the specific leakage requirements. The security of our proposed scheme is formally proved based on the classic decisional Diffie–Hellman assumption.
Wenzheng Zhang 0001, Zirui Qiao, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang
Comput. J.3
2022 Modular-based secret image sharing in Internet of Things: A global progressive-enabled approach
abstract
Summary Due to the continuous development and progress of information technology, the Internet has also entered the era of big data based on the Internet of Things (IoT). How to protect the security of data stored and transmitted in the IoT is one of the urgent problems to be solved. This article focuses on the security issues of storage and transmission of image data in the IoT. Secret image sharing (SIS) is a kind of image protection mechanism by dividing an image into n shares, and different shares are given to different participants separately for preservation. Only when the number of shares reaches the threshold can the original image be recovered. From the perspective of image reconstruction mode, there are two types of SIS schemes: one is the traditional (k, n) threshold scheme, which provides an all‐or‐nothing reconstruction mode, the other is the progressive scheme, which can gradually restore the original image. In this article, a novel (k, k2) progressive secret image sharing based on modular operations is proposed, this method can divide the important images stored in the IoT into many parts and then transmit them to people in different places. It takes the whole as a unit in terms of the progressive recovery form. When the share reaches the threshold, certain blocks of the original image can be seen. As the share increases, the image will be clearer. When all shares participate in the reconstruction together, the original image can be restored without loss. Compared with other schemes, our scheme has the same smoothness, shadow size and satisfies the security, and is fine‐grained progressive.
Lina Zhang 0003, Xiangqin Zheng, Keping Yu, Wenjuan Li 0001, Tao Wang 0039, Xuan Dang, Bo Yang 0003
Concurr. Comput. Pract. Exp.7
2022 Constructing totally disjoint spectra plateaued functions and searching five-value spectrum functions in odd variables
Xuewei Hu, Bo Yang 0003, Meijuan Huang
Discret. Appl. Math.2
2022 Practical algorithm substitution attack on extractable signatures
Yi Zhao 0011, Kaitai Liang, Yanqi Zhao, Bo Yang 0003, Yang Ming 0001, Emmanouil A. Panaousis
Des. Codes Cryptogr.4
2022 An Efficient Verifiable Searchable Encryption Scheme With Aggregating Authorization for Blockchain-Enabled IoT
abstract
Blockchain-enabled Internet of Things (IoT) provides a secure sharing of data and resources to the various miners of the IoT network, removes centralized control, and can overcome part of the existing challenges in traditional IoT. However, the IoT ecosystem faces some great challenges in terms of security, such as privacy leaking, eavesdropping, and so on, which seriously impede the deployment of the IoT ecosystem. Verifiable searchable encryption (SE) can make data owners (DOs) in the IoT dispel concerns about privacy and make data users (DUs) believe they get correct search results. For the blockchain-enabled IoT, this article proposes an efficient verification SE scheme with aggregation authorization and trusted revocation. With this scheme, DOs are willing to share their data to DUs for reward in a secure, efficient, and trusted way. For the DU, the DO can generate an aggregating key of a subset of encrypted documents, and then the DU has the privilege to search these documents and to verify the search results. By utilizing the trusted execution environment, the DO can revoke the search privilege of the DU. We present the analysis to show our proposed scheme achieves confidentiality, soundness, and fair payment at the same time. With the performance evaluations, we prove our proposal practical for blockchain-enabled IoT in terms of computational and smart contracts overhead.
Tao Wang 0039, Qiliang Yang, Bo Yang 0003, Zirui Qiao
IEEE Internet Things J.4
2022 Constructions of non-basic totally disjoint spectra plateaued functions for cryptographic applications
Xuewei Hu, Bo Yang 0003, Meijuan Huang
J. Inf. Secur. Appl.2
2022 Decentralized Self-Auditing Scheme With Errors Localization for Multi-Cloud Storage
abstract
With the popularity of cloud storage, increasing users begin to outsource data to the cloud. In order to resist possible data analysis for centralized outsourced data and improve the fault tolerance, users prefer to distribute data to cloud servers of different cloud service providers. However, once the data have been outsourced, it will be out of user’s control and many security issues may occur, such as outsourced data being illegally tamper with, or rarely accessed data being secretly deleted. In this article, we propose a decentralized self-auditing scheme for multi-cloud storage, called DSAS. First, based on the symmetric balanced incomplete block design, DSAS achieves integrity verification for outsourced data via the interactions of cloud servers and the auditing costs are shared by the participating CSs. Second, DSAS can locate misbehavior cloud server with low computation costs, and resist denial of service attack initiated by malicious cloud servers which attempts to destroy the audit. Third, DSAS can recover the corrupted data without fetching data, and support the revocation of cloud servers and batch auditing. Finally, security proof and function evaluation show that DSAS has comprehensive security and functionality, and performance simulations and experiment results show that DSAS is efficient.
Yuan Su, Yanping Li 0001, Bo Yang 0003, Yong Ding 0005
IEEE Trans. Dependable Secur. Comput.3
2021 Robust and auditable distributed data storage with scalability in edge computing
Yanping Li 0001, Bo Yang 0003
Ad Hoc Networks4
2021 Novel generic construction of leakage-resilient PKE scheme with CCA security
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang, Yi Mu 0001
Des. Codes Cryptogr.2
2021 A privacy-preserving public integrity check scheme for outsourced EHRs
Yuan Su, Yanping Li 0001, Kai Zhang 0044, Bo Yang 0003
Inf. Sci.4
2021 Blockchain-based searchable encryption with efficient result verification and fair payment
Tao Wang 0039, Zirui Qiao, Bo Yang 0003, Yueyang Gong, Guoyong Qiu
J. Inf. Secur. Appl.4
2021 Continuous leakage-resilient certificate-based signcryption scheme and application in cloud computing
Yanwei Zhou, Yuan Xu 0032, Zirui Qiao, Bo Yang 0003, Mingwu Zhang
Theor. Comput. Sci.4
2021 Direct Anonymous Attestation With Optimal TPM Signing Efficiency
abstract
Direct Anonymous Attestation (DAA) is an anonymous signature scheme, which allows the Trusted Platform Module (TPM), a small chip embedded in a host computer, to attest to the state of the host system, while preserving the privacy of the user. DAA provides two signature modes: fully anonymous signatures and pseudonymous signatures. One main goal of designing DAA schemes is to reduce the TPM signing workload as much as possible, as the TPM has only limited resources. In an optimal DAA scheme, the signing workload on the TPM will be no more than that required for a normal signature like ECSchnorr. To date, no scheme has achieved the optimal signing efficiency for both signature modes. In this paper, we propose the first DAA scheme which achieves the optimal TPM signing efficiency for both signature modes. In this scheme, the TPM takes only a single exponentiation to generate a signature, and this single exponentiation can be pre-computed. Our scheme can be implemented using the existing TPM 2.0 commands, and thus is compatible with the TPM 2.0 specification. We benchmarked the TPM 2.0 commands needed for three DAA use cases on an Infineon TPM 2.0 chip, and also implemented the host signing and verification algorithm for our DAA scheme on a laptop with 1.80GHz Intel Core i7-8550U CPU. Our experimental results show that our DAA scheme obtains a total signing time of about 144 ms for either signature mode, while with pre-computation we can obtain a signing time of about 65 ms. Based on our benchmark results for the pseudonymous signature mode, our scheme is roughly$2\times $(resp.,$5\times $) faster than the existing DAA schemes supported by TPM 2.0 in terms of total (resp., online) signing efficiency.
Kang Yang 0002, Liqun Chen 0002, Zhenfeng Zhang, Christopher J. P. Newton, Bo Yang 0003, Li Xi
IEEE Trans. Inf. Forensics Secur.5
2021 PrivCrowd: A Secure Blockchain-Based Crowdsourcing Framework with Fine-Grained Worker Selection
abstract
Blockchain‐based crowdsourcing systems can mitigate some known limitations of the centralized crowdsourcing platform, such as single point of failure and Sybil attacks. However, blockchain‐based crowdsourcing systems still endure the issues of privacy and security. Participants’ sensitive information (e.g., identity, address, and expertise) have the risk of privacy disclosure. Sensitive crowdsourcing tasks such as location‐based data collection and labeling images including faces also need privacy‐preserving. Moreover, current work fails to balance the anonymity and public auditing of workers. In this paper, we present a secure blockchain‐based crowdsourcing framework with fine‐grained worker selection, named PrivCrowd which exploits a functional encryption scheme to protect the data privacy of tasks and to select workers by matching the attributes. In PrivCrowd, requesters and workers can achieve both exchange and evaluation fairness by calling smart contracts. Solutions collection also can be done in a secure, sound, and noninteractive way. Experiment results show the feasibility, usability, and efficiency of PrivCrowd.
Qiliang Yang, Tao Wang 0039, Bo Yang 0003, Yong Yu 0002, Zirui Qiao
Wirel. Commun. Mob. Comput.4
2020 Improvement of Attribute-Based Encryption Using Blakley Secret Sharing
Zhe Xia, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang, Yi Mu 0001
ACISP2
2020 Updatable Lossy Trapdoor Functions Under Consecutive Leakage
abstract
Abstract Lossy trapdoor functions (LTFs), introduced by Peikert and Waters (STOC’08), have already been found to be a very useful tool in constructing complex cryptographic primitives in a black-box manner, such as one-way trapdoor functions, deterministic public-key encryption, CCA-secure public-key encryption, etc. Due to the existence of the side-channel attack, the leakage of trapdoor information in lossy trapdoor function systems can lead to the impossibility of provable security. Recently, Zhang et al. introduced a model of consecutive and continual leakage-resilient and updatable lossy trapdoor functions (ULTFs) and provided a concrete construction to achieve the security. Meanwhile, they proposed a consecutive and continual leakage-resilient public-key encryption scheme. However, in this paper, we demonstrate that the correctness of injective function can not be satisfied. Furthermore, the attacker can easily distinguish the evaluation key of ULTFs generated by the challenger according to the security model. Finally, we show two new constructions based on the continual leakage-resilient public-key encryption scheme of Brakerski et al. (FOCS 2010) and demonstrate the security of our scheme in the consecutive and continual leakage model.
Meijuan Huang, Bo Yang 0003, Mingwu Zhang, Lina Zhang 0003, Hong-xia Hou
Comput. J.2
2020 Continuous Leakage-Resilient Certificate-Based Encryption Scheme Without Bilinear Pairings
abstract
Abstract Recently, much attention has been focused on designing provably secure cryptographic primitives in the presence of key leakage, even the continuous leakage attacks. However, several constructions on the (continuous) leakage-resilient certificate-based encryption (CBE) scheme were proposed based on the bilinear pairings, and the corresponding computational efficiency is lower. Also, the leakage on the master secret key is omitted in the previous constructions. In this paper, to further achieve the better performance, a new construction method of continuous leakage-resilient CBE scheme without bilinear pairings is proposed, and the chosen-ciphertext attacks security of designed scheme is proved based on the hardness of the classic decisional Diffie–Hellman assumption. The performance analysis shows that our method not only can obtain higher computational efficiency but also enjoys better security performances, such as the leakage parameter of secret key of user has the constant size, and an adversary cannot obtain any leakage on the secret key of user from the corresponding given ciphertext etc. The advantage is that our proposal allows leakage attacks of multiple keys, i.e. continuous leakage resilience of the secret key of user and bounded leakage resilience of the master secret key. Additionally, to provide the leakage resilience for the cloud computing, a novel data access control scheme for cloud storage service is proposed from our continuous leakage-resilient CBE scheme, which can keep its claimed security in the leakage seting.
Yanwei Zhou, Bo Yang 0003, Tao Wang 0039, Zhe Xia, Hong-xia Hou
Comput. J.2
2020 Privacy preserving search services against online attack
Yi Zhao 0011, Jianting Ning, Kaitai Liang, Yanqi Zhao, Liqun Chen 0002, Bo Yang 0003
Comput. Secur.6
2020 A construction of highly nonlinear Boolean functions with optimal algebraic immunity and low hardware implementation cost
Xuewei Hu, Bo Yang 0003, Meijuan Huang
Discret. Appl. Math.2
2020 Practical continuous leakage-resilient CCA secure identity-based encryption
Yanwei Zhou, Bo Yang 0003
Frontiers Comput. Sci.2
2020 A generic construction of CCA-secure deterministic encryption
Meijuan Huang, Bo Yang 0003, Yi Zhao 0011, Xin Wang 0058, Yanwei Zhou, Zhe Xia
Inf. Process. Lett.2
2020 Fully secure wicked identity-based encryption resilient to continual auxiliary- inputs leakage
Hong-xia Hou, Bo Yang 0003, Yanwei Zhou, Meijuan Huang
J. Inf. Secur. Appl.2
2020 Novel updatable identity-based hash proof system and its applications
Yanwei Zhou, Bo Yang 0003, Tao Wang 0039, Yi Mu 0001
Theor. Comput. Sci.2
2020 Identity-based encryption with leakage-amplified chosen-ciphertext attacks security
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang, Yi Mu 0001
Theor. Comput. Sci.2
2019 Provably Secure Group Authentication in the Asynchronous Communication Model
Zhe Xia, Lein Harn, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001, Willy Susilo, Weizhi Meng 0001
ICICS3
2019 Provably Secure Proactive Secret Sharing Without the Adjacent Assumption
Zhe Xia, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang, Hua Shen 0002, Yi Mu 0001
ProvSec2
2019 Leakage Resilient CCA Security in Stronger Model: Branch Hidden ABO-LTFs and Their Applications
abstract
Lossy trapdoor functions (LTFs) have already found various applications in cryptography with many priorities. But constructing leakage resilient (LR) CCA secure PKE schemes through this way received less attention. Existing works could only be proven secure in a weakened model due to the power of leakage attack. To address this problem, we introduce a new variant of ABO-LTF which is called branch hidden ABO-LTF (BHABO-LTF) in this paper. This primitive provides protection for the information of evaluated branches rather than lossy branches, which means even an adversary knows the information of the set of lossy branches, it can still not determine whether the output is evaluated on an injective or a lossy branch as long as the inversion key is kept secret. We observe that if this primitive has Chameleon property, we could present a generic construction of CCA secure PKE schemes. Due to the transparency of lossy branches of the primitive, we find that our construction can naturally be extended to accommodate leakage resilience. We give a generic construction with a realization of LR-BHABO-LTFs under the decisional composite residuosity assumption. This construction can be proved secure in a well-accepted security model rather than existing LTF-based ones in weak key-leakage model. Besides, without the need to hide the information of lossy branches, a Chameleon BHABO-LTF can be constructed by additively homomorphic CPA secure PKE alone. So our work can also be viewed as an interesting progress to give a construction of CCA secure PKE from additively homomorphic CPA secure PKE with certain properties as well as their LR counterparts, which has been a longstanding problem.
Yi Zhao 0011, Yong Yu 0002, Bo Yang 0003
Comput. J.3
2019 Continuous Leakage-Resilient Identity-Based Encryption with Tight Security
abstract
Abstract In the actual applications, an adversary can break the security of cryptography scheme through various leakage attacks (e.g. side-channel attacks, cold-boot attacks, etc.), even the continuous leakage attacks. That is, a practical cryptography scheme must maintain its claimed security in the continuous leakage setting. However, the previous constructions on the leakage-resilient identity-based encryption (IBE) scheme could tolerate a leakage that is bounded, and cannot resist the continuous leakage attacks. In order to further achieve the better security, a novel method to build the continuous leakage-resilient IBE scheme with tight security is presented in this paper, and the scheme’s security is proved, in the standard model, based on a stronger security assumption that depends on the number of queries made by the adversary. In addition, our proposal has several advantages over previous such constructions, e.g. shorter public parameters, higher communication efficiency, tight security, etc.
Yanwei Zhou, Bo Yang 0003, Hong-xia Hou, Lina Zhang 0003, Tao Wang 0039, Mingxiao Hu
Comput. J.2
2019 Continuous leakage-resilient identity-based encryption with leakage amplification
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001
Des. Codes Cryptogr.2
2019 Identity-based encryption resilient to continuous key leakage
abstract
Leakage of private information has become a threat to the security of computing systems. It has become a common security requirement that a cryptography scheme should withstand various leakage attacks, even the continuous leakage attacks. However, in the current constructions on the (continuous) leakage‐resilient identity‐based encryption (CLR‐IBE) scheme, the leakage parameter is a fixed value. Aiming to solve these problems, in this study, the authors show how to construct the CLR‐IBE scheme, and the adaptive chosen‐ciphertext attacks security of proposed construction can be proved in the standard model. To further improve the practicability of CLR‐IBE scheme, they design an improved IBE scheme with continuous leakage amplified property, and the leakage parameter has an arbitrary length.
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001, Tao Wang 0039, Xin Wang 0058
IET Inf. Secur.2
2019 Efficient attribute-based encryption with attribute revocation for assured data deletion
Yong Yu 0002, Yannan Li 0001, Man Ho Au, Xiaojiang Du, Bo Yang 0003
Inf. Sci.6
2019 A secure data sharing scheme with cheating detection based on Chaum-Pedersen protocol for cloud storage
abstract
With the development of cloud computing technology, data can be outsourced to the cloud and conveniently shared among users. However, in many circumstances, users may have concerns about the reliability and integrity of their data. It is crucial to provide data sharing services that satisfy these security requirements. We introduce a reliable and secure data sharing scheme, using the threshold secret sharing technique and the Chaum-Pedersen zero-knowledge proof. The proposed scheme is not only effective and flexible, but also able to achieve the semantic security property. Moreover, our scheme is capable of ensuring accountability of users’ decryption keys as well as cheater identification if some users behave dishonestly. The efficiency analysis shows that the proposed scheme has a better performance in terms of computational cost, compared with the related work. It is particularly suitable for application to protect users’ medical insurance data over the cloud.
Xin Wang 0058, Bo Yang 0003, Zhe Xia, Hong-xia Hou
Frontiers Inf. Technol. Electron. Eng.2
2019 An Approach Enabling Various Queries on Encrypted Industrial Data Stream
abstract
Massive data are generated and collected by devices in the industrial Internet of Things. Data sources would encrypt the data and send them to the data center through the gateway. For some supervision purpose, the gateway needs to observe the encrypted data stream and label the suspicious data. Instead of decrypting ciphertext at the gateway, which is not efficient, this paper presents a Φ -searchable functional encryption scheme that supports inner product evaluations on encrypted data. Based on this scheme, an approach enabling various queries on the encrypted industrial data stream is proposed. The adaptive security of our proposed underlying functional encryption scheme can be proven under general subgroup decision assumptions, and our scheme has the smaller public key, the smaller secret key, and the smaller ciphertext size compared to the related schemes. In addition, the experimental results show that our proposed scheme is efficient. Especially for the gateway, querying on the encrypted data only needs less than 20ms, which is practical for industrial data stream auditing scenario.
Tao Wang 0039, Bo Yang 0003, Guoyong Qiu, Lina Zhang 0003, Yong Yu 0002, Yanwei Zhou, Juncai Guo 0001
Secur. Commun. Networks2
2019 CCA Secure Public Key Encryption against After-the-Fact Leakage without NIZK Proofs
abstract
In leakage resilient cryptography, there is a seemingly inherent restraint on the ability of the adversary that it cannot get access to the leakage oracle after the challenge. Recently, a series of works made a breakthrough to consider a postchallenge leakage. They presented achievable public key encryption (PKE) schemes which are semantically secure against after-the-fact leakage in the split-state model. This model puts a more acceptable constraint on adversary’s ability that the adversary cannot query the leakage of secret states as a whole but the functions of several parts separately instead of prechallenge query only. To obtain security against chosen ciphertext attack (CCA) for PKE schemes against after-the-fact leakage attack (AFL), existing works followed the paradigm of “double encryption” which needs noninteractive zero knowledge (NIZK) proofs in the encryption algorithm. We present an alternative way to achieve AFL-CCA security via lossy trapdoor functions (LTFs) without NIZK proofs. First, we formalize the definition of LTFs secure against AFL (AFLR-LTFs) and all-but-one variants (ABO). Then, we show how to realize this primitive in the split-state model. This primitive can be used to construct AFLR-CCA secure PKE scheme in the same way as the method of “CCA from LTFs” in traditional sense.
Yi Zhao 0011, Kaitai Liang, Bo Yang 0003, Liqun Chen 0002
Secur. Commun. Networks3
2019 An alternative approach to public cloud data auditing supporting data dynamics
Tao Wang 0039, Bo Yang 0003, Yong Yu 0002, Guoyong Qiu, Zhe Xia
Soft Comput.2
2019 The generic construction of continuous leakage-resilient identity-based cryptosystems
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001
Theor. Comput. Sci.2
2018 Anonymous Identity-Based Hash Proof System from Lattices in the Standard Model
Qiqi Lai, Bo Yang 0003, Yong Yu 0002, Yuan Chen 0008, Liju Dong
ACISP2
2018 Verifiable Secret Sharing Based on Hyperplane Geometry with Its Applications to Optimal Resilient Proactive Cryptosystems
Zhe Xia, Liuying Sun, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang
ACISP3
2018 An Efficient and Provably Secure Private Polynomial Evaluation Scheme
Zhe Xia, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001
ISPEC2
2018 Continuous leakage-resilient access control for wireless sensor networks
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001, Zhe Xia
Ad Hoc Networks2
2018 Novel Smooth Hash Proof Systems Based on Lattices
abstract
As a basic and important primitive, hash proof system can be used to construct many cryptographic schemes and protocols. Therefore, it is significant to instantiate more efficient hash proof systems from various assumptions. Although there are many hash proof systems based on various classical assumptions, only a handful of efficient hash proof systems are known based on post-quantum assumptions. In this paper, we present several new hash proof systems based on the standard learning with errors (LWE) problem, which is at least as hard as standard worst-case lattice problems. Comparing with other existing constructions based on lattices, our main advantages are 2-fold: much simpler and more efficient. And our constructions can be easily extended to be identity-based ones and updatable ones. Throughout the paper, our main idea is to base hash proof systems on a new subset indistinguishability problem related to LWE, and employ the property of smooth parameter of q-ary orthogonal lattices to ensure smoothness.
Qiqi Lai, Bo Yang 0003, Yong Yu 0002, Yuan Chen 0008
Comput. J.2
2018 Structural Key Recovery of Simple Matrix Encryption Scheme Family
abstract
Advances in quantum computers threaten the security of public-key cryptosystems whose security is based on the hardness of factoring or on the discrete logarithm problem. Multivariate encryption schemes are promising alternatives to traditional cryptosystems. Tao et al. proposed a new Multivariate Public-Key Cryptosystem for encryption called simple matrix encryption scheme (ABC for short). Further, they proposed an improved simple matrix encryption schemes and a cubic simple matrix encryption scheme. In this paper, we show that the three schemes are vulnerable to a structural key recovery attack by tensor and vectorization notation and associated algebraic re-writing rules. We derive a set of linear equations from the public key whose solution yields an equivalent key pair that hide the central map. The proposed cryptanalysis approaches require polynomial computational complexity to achieve some equivalent keys from associated public keys. In addition, we provide an example to illustrate feasibility of proposed analysis method.
Yong Yu 0002, Bo Yang 0003, Jianwei Jia
Comput. J.3
2018 Continuous Leakage-Resilient Identity-Based Encryption without Random Oracles
abstract
Provably secure identity-based encryption (IBE) schemes in the presence of key-leakage have attracted a lot of attention recently. However, most of them were designed in the bounded-leakage model, and might not be able to meet the claimed security under the continuous-leakage attacks. The main issue is that the most of previous leakage-resilient IBE schemes could not ensure the randomness of all elements in the ciphertext, because some elements can be written as a function on the private key of user; therefore, the adversary can obtain the leakage on the private key of user from the corresponding given ciphertext. In this paper, a new construction of CCA-secure IBE scheme tolerating continuous-leakage attacks in the standard model is proposed, and its security is proved in the selective-ID security model based on the hardness of decisional bilinear Diffie–Hellman assumption, which is a classical static assumption. In our construction, the adversary cannot obtain any leakage on the private key from the corresponding ciphertext, since all elements in the ciphertext are random in the adversary’s view. The striking advantage of our constructions is the key leakage ratio, which is the best one among the previous leakage-resilient IBE constructions.
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001
Comput. J.2
2018 Privacy preserving cloud data auditing with efficient key update
Yannan Li 0001, Yong Yu 0002, Bo Yang 0003, Geyong Min, Huai Wu
Future Gener. Comput. Syst.3
2018 Leakage-resilient CCA2-secure certificateless public-key encryption scheme without bilinear pairing
Yanwei Zhou, Bo Yang 0003
Inf. Process. Lett.2
2018 Secure rational numbers equivalence test based on threshold cryptosystem with rational numbers
Linming Gong, Bo Yang 0003, Jinguang Chen, Wei Wang 0227
Inf. Sci.2
2018 Witness-based searchable encryption
Sha Ma, Yi Mu 0001, Willy Susilo, Bo Yang 0003
Inf. Sci.4
2018 Updatable Identity-Based Hash Proof System Based on Lattices and Its Application to Leakage-Resilient Public-Key Encryption Schemes
Qiqi Lai, Bo Yang 0003, Yong Yu 0002, Zhe Xia, Yanwei Zhou, Yuan Chen 0008
J. Comput. Sci. Technol.2
2018 Aleakage-resilient certificateless public key encryption scheme with CCA2 security
abstract
In recent years, much attention has been focused on designing provably secure cryptographic primitives in the presence of key leakage. Many constructions of leakage-resilient cryptographic primitives have been proposed. However, for any polynomial time adversary, most existing leakage-resilient cryptographic primitives cannot ensure that their outputs are random, and any polynomial time adversary can obtain a certain amount of leakage on the secret key from the corresponding output of a cryptographic primitive. In this study, to achieve better performance, a new construction of a chosen ciphertext attack 2 (CCA2) secure, leakage-resilient, and certificateless public-key encryption scheme is proposed, whose security is proved based on the hardness of the classic decisional Diffie-Hellman assumption. According to our analysis, our method can tolerate leakage attacks on the private key. This method also achieves better performance because polynomial time adversaries cannot achieve leakage on the private key from the corresponding ciphertext, and a key leakage ratio of 1/2 can be achieved. Because of these good features, our method may be significant in practical applications.
Yanwei Zhou, Bo Yang 0003
Frontiers Inf. Technol. Electron. Eng.2
2018 A Cheating Detectable Privacy-Preserving Data Sharing Scheme for Cloud Computing
abstract
Cloud computing provides a new, attractive paradigm for the effective sharing of storage and computing resources among global consumers. More and more enterprises have begun to enter the field of cloud computing and storing data in the cloud to facilitate the sharing data among users. However, in many cases, users may be concerned about data privacy, trust, and integrity. It is challenging to provide data sharing services without sacrificing these security requirements. In this paper, a data sharing scheme of reliable, secure, and privacy protection based on general access structure is introduced. The proposed scheme is not only effective and flexible, but also is capable of protecting privacy for the cloud owner, supporting data sharing under supervision, enabling accountability of users’ decryption keys, and identifying cheaters if some users behave dishonestly. Security analysis and efficiency analysis demonstrate that our proposed scheme has better performance in computational costs compared with most related works. The scheme is versatile to be used in various environments. For example, it is particularly suitable to be employed to protect personal health data and medical diagnostic data in information medical environment.
Xin Wang 0058, Bo Yang 0003, Zhe Xia, Yanqi Zhao, Huifang Yu 0001
Secur. Commun. Networks2
2018 Assured Data Deletion With Fine-Grained Access Control for Fog-Based Industrial Applications
abstract
The advances of cloud computing, fog computing, and Internet of things (IoT) make industries more prosperous than ever. A wide range of industrial systems such as transportation and manufacturing systems have been developed by integrating cloud computing, fog computing, and IoT infrastructure successfully. However, in this sophisticated system, security and privacy issues are major concerns that hinder the widespread adoptions of these novel techniques. In this paper, we focus on assured data deletion, an issue that is important but received less attention in academia and industry. We first propose a framework to integrate the cloud, the fog, and the things together to manage stored data from industries or individuals. We then focus on secure data deletion in this framework by proposing an assured data deletion scheme that fulfills verifiable data deletion as well as flexible access control over sensitive data. Only data owners and fog devices are involved when deleting cloud data and validating the deletion of these data, which makes the protocol practical due to the features of low latency as well as real-time interaction with fog. The proposed protocol takes advantage of the attribute-based encryption, whose security can be proved under the standard model. The theoretical analysis shows good performance and functionality requirements while the implementation results demonstrate the feasibility of our proposal.
Yong Yu 0002, Yannan Li 0001, Xiaojiang Du, Mohsen Guizani, Bo Yang 0003
IEEE Trans. Ind. Informatics6
2017 Direct constructions and proofs for CCA secure (LR)IBE with dual system encryption
Yi Zhao 0011, Bo Yang 0003
Sci. China Inf. Sci.2
2017 Pairing-Free and Secure Certificateless Signcryption Scheme
abstract
Certificateless signcryption (CLSC) can simultaneously fulfill certificateless encryption and certificateless signature; however, most CLSC schemes need costly computational overhead due to the usage of pairing operations. How to improve its computational efficiency is a very significant research problem. In this paper, we propose a pairing-free and secure CLSC scheme. In the random oracle model, the proposed scheme is indistinguishability against adaptive chosen-ciphertext attacks secure in confidentiality and unforgeability against adaptive chosen-message attacks secure in unforgeability. In the new scheme, only a designated receiver can recover the message, and a third party can verify the validity of a signcrypted text without knowing the receiver's secret value. In addition, this cryptographic algorithm is very appropriate to applications in online auction, email system and private contractual signature.
Huifang Yu 0001, Bo Yang 0003
Comput. J.2
2017 Continuous Leakage-Resilient Public-Key Encryption Scheme with CCA Security
abstract
In recent years, much attention has been focused on designing provably secure public-key encryption (PKE) scheme in the presence of key-leakage. However, most of them are researched in the bounded-leakage model, and cannot keep their claimed security in the continuous leakage setting. What's more, most of traditional leakage-resilient PKE schemes cannot ensure that all of elements in ciphertext are random from the adversary's view, and any polynomial time adversary can get leakage on the secret key from the corresponding ciphertext. But, in the real world, an adversary can trivially break the security of PKE scheme under the continuous leakage attacks. To get an efficient PKE scheme which can keep its original security in the continuous-leakage model, we propose a new construction of chosen-ciphertext attacks secure PKE scheme, and whose security is based on the hardness of the classical decisional Diffie–Hellman assumption and the target collision resistance of the hash function. Our method not only can tolerate continuous leakage attacks on the secret key through key update operation, but also enjoys better performances, such as the round leakage parameter λC≤logq−ω(logk) (k is the security parameter, q is a big prime order of the underlying group.) is independent of the plaintext space, and has the constant size, also, any polynomial time adversary unable to obtain leakage on the secret key from the corresponding ciphertext, etc. Because of these good performance features, our proposal may have some significant value in the practical applications.
Yanwei Zhou, Bo Yang 0003
Comput. J.2
2017 Low-computation certificateless hybrid signcryption scheme
abstract
Hybrid signcryption is an important technique signcrypting bulk data using symmetric encryption. In this paper, we apply the technique of certificateless hybrid signcryption to an elliptic-curve cryptosystem, and construct a low-computation certificateless hybrid signcryption scheme. In the random oracle model, this scheme is proven to have indistinguishability against adaptive chosen-ciphertext attacks (IND-CCA2) under the elliptic-curve computation Diffie-Hellman assumption. Also, it has a strong existential unforgeability against adaptive chosen-message attacks (sUF-CMA) under the elliptic-curve discrete logarithm assumption. Analysis shows that the cryptographic algorithm does not rely on pairing operations and is much more efficient than other algorithms. In addition, it suits well to applications in environments where resources are constrained, such as wireless sensor networks and ad hoc networks.
Huifang Yu 0001, Bo Yang 0003
Frontiers Inf. Technol. Electron. Eng.2
2017 Continuous leakage-resilient certificateless public key encryption with CCA security
Yanwei Zhou, Bo Yang 0003
Knowl. Based Syst.2
2016 AEP-M: Practical Anonymous E-Payment for Mobile Devices Using ARM TrustZone and Divisible E-Cash
Bo Yang 0003, Kang Yang 0002, Zhenfeng Zhang, Dengguo Feng
ISC1
2016 An error-tolerant keyword search scheme based on public-key encryption in secure cloud computing
abstract
Summary An error‐tolerant keyword search scheme permits to make searches on encrypted data with only an approximation of some keyword. The scheme is suitable to the case where users' searching input might not exactly match those pre‐set keywords. An error‐tolerant keyword search scheme can be generated based on a public‐key encryption scheme, in which anyone with access to a user's public key can generate the trapdoors and indexes to keywords, and only the user holding the decryption key can obtain the records it retrieves. In this paper, we first present a general framework for searching on error‐tolerant keywords based on a public‐key encryption scheme. Then, we propose a concrete scheme based on the Cramer–Shoup cryptosystem. The scheme is adaptive chosen‐ciphertext attack secure and suitable for all similarity metrics including Hamming distance metric, edit distance metric, and set difference metric. It does not require the user to construct and store anything in advance, other than the cryptosystem used to calculate the trapdoor of keywords and to encrypt data documents. Thus, our scheme tremendously eases the users' burden. What is more, our scheme is able to transform the servers' searching for error‐tolerant keywords on ciphertexts to searching for exact keywords on plaintexts. The server can use any existing approaches of exact keywords search to search plaintexts on an index table. Copyright © 2015 John Wiley & Sons, Ltd.
Bo Yang 0003, Mingwu Zhang, Jun-Qiang Du
Concurr. Comput. Pract. Exp.1
2016 Provably secure and efficient leakage-resilient certificateless signcryption scheme without bilinear pairing
Yanwei Zhou, Bo Yang 0003, Wenzheng Zhang 0001
Discret. Appl. Math.2
2016 Continual key leakage tolerant encryption from extensible set delegation
abstract
Abstract Many attention has been attracted by a new security primitive called leakage‐resilient cryptography, which guarantees that the cryptographic system is semantic secure even if the key has been partially leaked, which is due to the side‐channel attacks that the part of secret key can be recovered. In this work, we present a leakage‐resilient functional encryption that supports unbounded extensible subset delegation, which remains provably secure even if the attacker learns some arbitrary partial information about the secret keys. The proposed scheme provides the tolerance of continual leakage in which both memory leakage and continual leakage are captured, which has many appealing applications because there are multiple secret keys per subset string by periodically refreshing the key. The security relies on the static complex assumptions that are based on the static (bilinear) subgroup decisional problems. Finally, we give the performance evaluation such as the size of public parameters, keys, ciphertexts, leakage bound, and leakage ratio under 80‐bit security standard. Copyright © 2013 John Wiley & Sons, Ltd.
Mingwu Zhang, Bo Yang 0003
Secur. Commun. Networks2
2016 CCA2 secure public-key encryption scheme tolerating continual leakage attacks
abstract
Abstract For a public‐key encryption scheme to be applied in practical applications, it should withstand various leakage attacks (e.g., side‐channel attacks and cold‐boot attacks). To this end, we present a way of construct the more practical CCA2 secure public‐key encryption scheme tolerating leakage attacks, and the scheme's security is based on the hardness of classical decisional Diffie–Hellman assumption and the target collision resistant of one‐way hash function. Additionally, our proposal enjoys better performance, for example, all of elements of ciphertext will be random from the adversary's view, and any probabilistic polynomial‐time adversary cannot obtain leakage on the secret key from the ciphertext, and so on. In the bounded‐leakage setting, for any leakage parameter λ⩽logq − ω(logk)(q is the prime order of the underlying group, and k denotes the security parameter.), our proposal is secure against leakage‐resilient chosen‐ciphertext attacks, where λ is independent of the plaintext space, and has the constant size. However, in the real world, an adversary can continuously learn information on the secret key through a variety of leakage attacks and can trivially break the security of public‐key encryption scheme under the continual leakage attacks. Thus, we will improve our method to resist the continual leakage attacks. Similarly, for any round leakage parameter λC⩽logq − ω(logk), we can prove the security of the improvement scheme based on the hardness of decisional Diffie–Hellman assuming and the target collision resistant of one‐way hash function. With this important performance, our proposal may have some significant value in the practical applications, such as our proposal can provide the leakage‐resilient security for outsourcing data in the cloud computing environment. Copyright © 2016 John Wiley & Sons, Ltd.
Yanwei Zhou, Bo Yang 0003, Wenzheng Zhang 0001, Yi Mu 0001
Secur. Commun. Networks2
2015 Public Key Encryption with Delegated Equality Test in a Multi-User Setting
abstract
Probabilistic public key encryption with equality test (PKEET), introduced by Yang et al. in CT-RSA 2010, is able to check whether two ciphertexts are encryptions of the same message under different public keys without leaking anything else about the message encrypted under either public key. PKEET schemes have many applications, for example, in constructing searchable encryption and partitioning encrypted data. Previous PKEET schemes lack a delegation mechanism for users to specify who can perform the equality test between their ciphertexts. In this paper, we propose the notion of public key encryption with delegated equality test (PKE-DET), which requires only the delegated party to deal with the work in a practical multi-user setting, and present a concrete construction in Type 2 pairing, which is provably secure under the newly introduced security notions.
Sha Ma, Mingwu Zhang, Qiong Huang 0001, Bo Yang 0003
Comput. J.4
2015 On security against the server in designated tester public key encryption with keyword search
Zhi-Yi Shao, Bo Yang 0003
Inf. Process. Lett.2
2015 Private set intersection via public key encryption with keywords search
abstract
Abstract We introduce the public key encryption with keywords search into the problem of secure two‐party computation and obtain a novel approach to accomplish private set intersection (PSI), which uses the public key encryption with keywords search as the basic tool. The public key encryption with keywords search scheme we adopt does not need the expensive MapToPoint operation, thus the computation complexity can be reduced significantly compared with other PSI schemes, which also obtain linear computation complexity. We aim to achieve PSI in computationally asymmetric settings, which can be instantiated by cloud computing. Our protocol satisfies the privacy with respect to semi‐honest behavior, and the client only needs to compute m multiplications, m hashes, and one modular exponentiation to obtain the intersection, where m denotes the cardinality of the client's input set. Copyright © 2014 John Wiley & Sons, Ltd.
Zhi-Yi Shao, Bo Yang 0003
Secur. Commun. Networks2
2015 Efficient Public Key Encryption With Equality Test Supporting Flexible Authorization
abstract
We reformalize and recast the notion of public key encryption with equality test (PKEET), which was proposed in CT-RSA 2010 and supports to check whether two ciphertexts encrypted under different public keys contain the same message. PKEET has many interesting applications, for example, in constructing searchable encryption and partitioning encrypted data. However, the original PKEET scheme lacks an authorization mechanism for a user to control the comparison of its ciphertexts with others’. In this paper, we study the authorization mechanism for PKEET, and propose four types of authorization policies to enhance the privacy of users’ data. We give the definitions of the policies, propose a PKEET scheme supporting these four types of authorization at the same time, and prove its security based on the computational Diffie–Hellman assumption in the random oracle model. To the best of our knowledge, it is the only PKEET scheme supporting flexible authorization.
Sha Ma, Qiong Huang 0001, Mingwu Zhang, Bo Yang 0003
IEEE Trans. Inf. Forensics Secur.4
2014 Anonymous encryption with partial-order subset delegation and its application in privacy email systems
abstract
In privacy‐carrying email systems, the authors should guarantee that the email content is confidential and sometimes the sender/receiver identities are hidden. Also, they require that the key generation is flexible and manageable. In this study, first, they propose an anonymous encryption scheme that supports a partial‐order subset delegatable ability. The proposed scheme achieves the security properties of confidentiality against adaptive chosen‐plaintext attacks, anonymity against adaptive chosen‐subset attacks and computational delegation indistinguishability. Secondly, they provide a deployment application of their anonymous encryption in an interdisciplinary group email management system with flexible and fine‐grained key delegation. The deployment can achieve the privacy of message confidentiality, receiver anonymity and delegation obliviousness, which has fine‐grained security in secure email systems. Finally, they provide an extension for the chosen‐ciphertext secure scheme, and discuss the efficiency for decryption and the security level.
Mingwu Zhang, Takashi Nishide, Bo Yang 0003, Tsuyoshi Takagi
IET Inf. Secur.3
2014 Anonymous spatial encryption under affine space delegation functionality with full security
Mingwu Zhang, Bo Yang 0003, Tsuyoshi Takagi
Inf. Sci.2
2014 Effective Error-Tolerant Keyword Search for Secure Cloud Computing
Bo Yang 0003, Xiaoqiong Pang, Jun-Qiang Du
J. Comput. Sci. Technol.1
2014 PPGJ: A privacy-preserving general join for outsourced encrypted database
abstract
ABSTRACT In outsourced database, it is desirable to store sensitive data in an encrypted form to reduce security and privacy risks because the server may not be fully trusted. Several approaches have been proposed in recent literatures to efficiently support queries on encrypted databases. Most researches focus on keywords search and range query while few works study on join query because of a lack of related cryptography primitives. We propose a solution of a privacy‐preserving general join supporting both equality tests and simple non‐equality tests on ciphertexts by using the revised Boneh–Goh–Nissim encryption algorithm and a Bloom filter. Finally, we analyze its advantages and disadvantages by the comparison with existing method on the performance and the newly introduced security notions. Copyright © 2013 John Wiley & Sons, Ltd.
Sha Ma, Bo Yang 0003, Mingwu Zhang
Secur. Commun. Networks2
2014 Unbounded anonymous hierarchical IBE with continual-key-leakage tolerance
abstract
ABSTRACT Modern cryptographic schemes are constructed under the fundamental assumption that secret keys are perfectly hidden from all possible attackers. In practice, however, keys and internal states may partially be leaked. Recently, cryptographic construction with key‐leakage resilience has been a crucial research topic. In this work, we proposed an anonymous hierarchical identity‐based encryption that can tolerate partial leakage of secret keys. Our results were as follows. First, we provided a tolerance for continual key leakage that can capture both memory leakage and continual leakage. We extended a dual‐system encryption mechanism in orthogonal subgroups to achieve key‐leakage resilience and implicitly employed an update algorithm to guard against continual leakage. Second, the delegation depth is unbounded, which means that no predetermined depth was imposed in the setup algorithm, thus making the scheme very flexible in practice. We employed a secret‐sharing approach to split the master key into multiple shares in key components corresponding to the elements. Third, we analyzed and discussed the performance of allowable leakage‐tolerance bounds and the leakage rate of the proposed scheme and gave an evaluation that attains about 40–70% leakage rate under the Advanced Encryption Standard 112 security level. Copyright © 2013 John Wiley & Sons, Ltd.
Mingwu Zhang, Bo Yang 0003, Tsuyoshi Takagi
Secur. Commun. Networks2
2013 Bounded Leakage-Resilient Functional Encryption with Hidden Vector Predicate
abstract
Recent research shows that many public-key or identity-based encryption schemes are vulnerable to side-channel attacks on the keys by the interaction of an adversary with a physical device. To tolerate the possible key leakage, leakage-resilient cryptography models a class of leakage output by allowing the adversary to be able to specify a computable leakage function and obtaining the partial keys or other possibly internal states from the output of function. In this article, we propose a leakage-resilient hidden-vector encryption (HVE) scheme that supports the predicate operators such as conjunction, disjunction, comparison, range query and subset query, etc. The proposed scheme is leakage-resilient attribute-hiding secure in the sense that the adversary cannot only obtain the tokens of non-match vectors but also learn amount of key information of the vector that matches the challenge vector. To the best of our knowledge, this is the first HVE that supports token-leakage resilience. We prove the security with a series of computationally indistinguishable games that uses the dual system encryption mechanism. We also analyze and discuss the performance of leakage bound parameters and leakage fraction in the practical security level. Finally, we also give an extensive scheme to achieve the security of both attribute-hiding and payload-hiding, and analyze the performance in larger alphabets.
Mingwu Zhang, Bo Yang 0003, Tsuyoshi Takagi
Comput. J.2
2013 A Secure Scalar Product Protocol Against Malicious Adversaries
Bo Yang 0003, Yong Yu 0002, Chung-Huang Yang
J. Comput. Sci. Technol.1
2013 Efficient and adaptively secure broadcast encryption systems
abstract
ABSTRACT Broadcast encryption is an effective way to broadcast a message securely such that more than one privileged receiver can decrypt it. The well‐known constructions of identity‐based broadcast encryption only support bounded broadcast users that had to deploy the maximum user number in advance. This is somewhat inefficient and impractical if the broadcast user number is predetermined. In this paper, we propose an adaptively secure identity‐based broadcast encryption in the standard model that supports arbitrary number of users in broadcast set, which eliminates the size of public parameters with a constant number of group elements and obtain short ciphertexts, secret keys, and public parameters. We use the techniques of semi‐functional ciphertexts and semi‐functional keys in orthogonal subgroups to implement the boundless broadcast set and adaptive security by means of dual‐system encryption mechanism in a composite‐order group, and we prove the scheme to be fully secure without the random oracles in the static assumptions. The proposed scheme captures the properties of confidentiality, adaptive security, constant key, and short ciphertext. We also evaluate the computational costs and communication overheads and give the deployment in secure set‐top box broadcast systems. Copyright © 2012 John Wiley & Sons, Ltd.
Mingwu Zhang, Bo Yang 0003, Zhenhua Chen 0001, Tsuyoshi Takagi
Secur. Commun. Networks2
2013 Efficient Multicast Key Distribution Using HOWP-Based Dynamic Group Access Structures
abstract
When assigning personal keys, stateful multicast key distribution (MKD) protocols usually rely on some type of dynamic group access structure which helps achieve a better tradeoff among storage, communication, and computation overheads. However, there exist some stateful MKD protocols whose personal key assignments are based on two static group access structures called Dual Hash Chain (DHC) and Binary Hash Tree (BHT). We introduce two new types of group access structures called Dual Homomorphic One-way Function Chain (D-HOFC) and Top-Down Homomorphic One-way Function Tree (TD-HOFT). Both can be regarded as dynamic counterparts of DHC and BHT, respectively. Our research motivation is to investigate what benefits these two new dynamic structures will bring for MKD protocols compared with their static counterparts. Using D-HOFC, we propose a time-based MKD protocol that counters the rejoining member attack on a DHC-based protocol, and a stateful user-based MKD protocol that has a lower computational overhead for Group Controller (GC) than the DHC-based protocol. Using TD-HOFT, we design a stateful user-based MKD protocol that outperforms the original EKT protocol. Performance comparisons and experiment results show that our protocols based on dynamic structures have their own advantages compared with those based on the corresponding static counterparts.
Qiong Huang 0001, Bo Yang 0003
IEEE Trans. Computers3
2012 Privacy-Preserving Noisy Keyword Search in Cloud Computing
Xiaoqiong Pang, Bo Yang 0003, Qiong Huang 0001
ICICS2
2012 LR-UESDE: A Continual-Leakage Resilient Encryption with Unbounded Extensible Set Delegation
Bo Yang 0003, Mingwu Zhang
ProvSec1
2012 Improved certificateless signature scheme provably secure in the standard model
abstract
Certificateless cryptography shares many features of identity-based cryptography and partially solves the problem of key escrow. Three certificateless signature schemes without random oracles were found in the literature. However, all the schemes suffer from some common drawbacks. First, by obtaining a signature on a message and replacing the public key of a signer, an adversary can forge valid signatures on the same message under the replaced public key. Secondly, all the schemes require a relatively large size of public parameters. The authors propose a new certificateless signature scheme, which exhibits an improvement on the existing schemes. Compared with the previous schemes, the proposed scheme offers stronger security, shorter system parameters and higher computational efficiency.
Yong Yu 0002, Yi Mu 0001, Guilin Wang, Qi Xia 0001, Bo Yang 0003
IET Inf. Secur.5
2012 Reconciling and improving of multi-receiver signcryption protocols with threshold decryption
abstract
ABSTRACT Signcryption is a cryptographic primitive that offers both confidentiality and authentication simultaneously, which combines the functionalities of signature and encryption in a provably secure manner. Indistinguishability against adaptive chosen‐ciphertext attacks (ind‐cca2) and unforgeability against adaptive chosen‐message attacks (euf‐cma2) are two important security requirements of a signcryption protocol. In a multi‐receiver signcryption with a threshold decryption scheme, the ciphertext can be decrypted and verified when arbitrary t or more receivers among the n candidate decrypters work together. Recently, Qin et al. [Security and Communication Networks, 2011] proposed an identity‐based multi‐receiver signcryption scheme with threshold decryption, and they declared that the scheme achieves ind‐cca2 and euf‐cma2 security. In this paper, we first indicate that Qin et al.'s scheme is not secure, that is, Qin et al.'s scheme is neither semantically secure against ind‐cca2 nor unforgeable against euf‐cma2. After that, we present an improved scheme to capture the security requirements. Furthermore, we construct an anonymous version that can preserve the identity privacy of the sender and receiver, and we give the performance evaluation to indicate that our scheme has lower communication overhead although it provides the identity privacy preservation. Copyright © 2012 John Wiley & Sons, Ltd.
Mingwu Zhang, Bo Yang 0003, Tsuyoshi Takagi
Secur. Commun. Networks2
2011 An Efficient Construction of Time-Selective Convertible Undeniable Signatures
Qiong Huang 0001, Duncan S. Wong, Willy Susilo, Bo Yang 0003
ISC4
2011 Anonymous Encryption with Partial-Order Subset Delegation Functionality
Mingwu Zhang, Takashi Nishide, Bo Yang 0003, Tsuyoshi Takagi
ProvSec3
2011 Improvement of a proxy multi-signature scheme without random oracles
Chunxiang Xu, Yong Yu 0002, Bo Yang 0003
Comput. Commun.4
2011 Group-oriented setting's multisigncryption scheme with threshold designcryption
Mingwu Zhang, Bo Yang 0003, Tsuyoshi Takagi
Inf. Sci.2
2009 Fuzzy Identity Based Encryption Scheme with Some Assigned Attributes
abstract
In this paper the concept of fuzzy IBE schemes with some fixed attributes (SAA-FIBE) is proposed and one construction of it is presented. SAA-FIBE scheme can be viewed as a variant of SW scheme described in which demanding no fixed positive or negative attributes. In our scheme, a user with identity omega can decrypt the message that is encrypted with a set of attributes, omega', if and only if |omega' capomega| ges d and omega must have or must have not some attributes described in encryption policy. The scheme are both error-tolerant and secure against collusion attacks in the SPID-FIBE attack model.
Ximing Li 0001, Bo Yang 0003, Yubin Guo
IAS2
2009 Analysis and Improvement of an ID-Based Anonymous Signcryption Model
Mingwu Zhang, Yusheng Zhong, Bo Yang 0003, Wenzheng Zhang 0001
ICIC (1)3
2008 Assertions Signcryption Scheme in Decentralized Autonomous Trust Environments
Mingwu Zhang, Bo Yang 0003, Shenglin Zhu, Wenzheng Zhang 0001
ATC2
2008 Generalized ElGamal Public Key Cryptosystem Based on a New Diffie-Hellman Problem
Huawei Huang, Bo Yang 0003, Shenglin Zhu, Guozhen Xiao
ProvSec2
2007 Provably Secure Identity-Based Threshold Unsigncryption Scheme
Bo Yang 0003, Yong Yu 0002, Fagen Li
ATC1
2007 Efficient Identity-Based Signcryption Scheme for Multiple Receivers
Yong Yu 0002, Bo Yang 0003, Xinyi Huang 0001, Mingwu Zhang
ATC2
2003 Anonymous and dynamic conference-key distribution system
abstract
In order to hold secure electronic conference in communication networks via insecure channels, a conference key distribution system should be constructed. The conference key distribution system (CKDS) is used for distributing a conference key shared among the participants of the conference and hence secure communications are achieved. In this paper, by using the secret sharing scheme based on the MDS code and the Diffie-Hellman key exchange scheme as the basic component, we propose an efficient and anonymous conference-key distribution scheme that supports conference membership changes dynamically. We also show that, based on the Diffie-Hellman (DH) and the one-way assumption, the proposed CKDS is secure against impersonation and conspiracy attacks, and the unattended ones reveal no useful knowledge about the conference key. In addition, the proposed CKDS allows for user anonymity.
Jane Mao, Bo Yang 0003
PIMRC2