Shiyu Li 0002

dblp:47/1400-2 · DBLP profile ↗
← Back
12ranked-venue papers
7as first author
12since 2021 · last 2026
0000-0002-1504-5055ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 5 since 2021Computer networks · 4 · 3 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Non-Interactive Distributed Key Management With Pre-Determined Shares
Yaqing Song, Shiyu Li 0002, Zeqi Lai, Qiang Tang 0005
ICDCS3
2025 EpiOracle: Privacy-Preserving Cross-Facility Early Warning for Unknown Epidemics
abstract
Syndrome-based early epidemic warning plays a vital role in preventing and controlling unknown epidemic outbreaks. It monitors the frequency of each syndrome, issues a warning if some frequency is aberrant, identifies potential epidemic outbreaks, and alerts governments as early as possible. Existing systems adopt a cloud-assisted paradigm to achieve cross-facility statistics on the syndrome frequencies. However, in these systems, all symptom data would be directly leaked to the cloud, which causes critical security and privacy issues. In this paper, we first analyze syndrome-based early epidemic warning systems and formalize two security notions, i.e., symptom confidentiality and frequency confidentiality, according to the inherent security requirements. We propose extsf{EpiOracle}, a cross-facility early warning scheme for unknown epidemics. EpiOracle ensures that the contents and frequencies of syndromes will not be leaked to any unrelated parties; moreover, our construction uses only a symmetric-key encryption algorithm and cryptographic hash functions (e.g., [CBC]AES and SHA-3), making it highly efficient. We formally prove the security of EpiOracle in the random oracle model. We also implement an EpiOracle prototype and evaluate its performance using a set of real-world symptom lists. The evaluation results demonstrate its practical efficiency.
Shiyu Li 0002, Yuan Zhang 0006, Yaqing Song, Fan Wu 0014, Feng Lyu 0001, Kan Yang 0001, Qiang Tang 0005
Proc. Priv. Enhancing Technol.1
2024 Blockchain-Based Portable Authenticated Data Transmission for Mobile Edge Computing: A Universally Composable Secure Solution
abstract
In mobile edge computing (MEC) systems, data is frequently transmitted between MEC servers and users holding mobile devices for supporting related services. However, critical threats towards data confidentiality and authenticity are raised: adversaries always attempt to extract data content from the transmission and impersonate others to spread malicious data for profits. Furthermore, users have to store the (secret and public) keys used for data transmission locally. Consequently, only devices maintaining the keys can be utilized to access the services provided by MEC servers, and “portability” cannot be achieved. In this paper, we propose a portable authenticated data transmission scheme (dubbed Biplane) via blockchain for MEC systems. Biplane is based on two techniques. One is a blockchain-based authenticated hybrid encryption mechanism, which guarantees data authenticity and confidentiality without requiring a third party (e.g., a Certificate Authority) to assist the MEC servers in certifying users’ public keys. The other one is a blockchain-based portable key management mechanism, which enables the user to transmit data without maintaining any parameter in her/his local devices. We formally prove that Biplane achieves confidential and authenticated data transmission in the universally composable (UC) framework. We also conduct a comprehensive evaluation to demonstrate that Biplane is efficient.
Shiyu Li 0002, Yuan Zhang 0006, Yaqing Song, Nan Cheng 0001, Kan Yang 0001, Hongwei Li 0001
IEEE Trans. Computers1
2024 PrivSSO: Practical Single-Sign-On Authentication Against Subscription/Access Pattern Leakage
abstract
Single-sign-on (SSO) authentication employs an identity provider (IdP) to provide users with an efficient way to authenticate themselves with different service providers and has been widely applied in digital systems. However, existing SSO authentication schemes suffer from critical issues in terms of security and privacy. Regarding security, most SSO authentication schemes achieve a high convenience at the expense of security and are thereby susceptible to various attacks. Regarding privacy, most existing schemes fail to protect users’ subscription pattern and access pattern against adversaries who can easily extract users’ sensitive information from their authentications and launch subsequent attacks for profits. In this paper, we develop a practical SSO authentication system, dubbed PrivSSO, with the protection of users’ subscription pattern and access pattern. To balance the trade-off between security and convenience, the key technique is a secure “hybrid” key-based authentication mechanism: a long-term key stored in a well-guarded hardware token serves as the “primary” authentication factor (AF) to guarantee strong security; an ephemeral key bound with portable device(s) serves as the “daily-used” AF to achieve high convenience. To protect the subscription pattern and access pattern from leakage, we propose a redactable token generation mechanism, where the users themselves specify what IdP and the service providers can learn from their authentications. We formally define and prove the security of PrivSSO. We also implement a PrivSSO prototype and conduct a comprehensive performance evaluation to demonstrate its practicality.
Yuan Zhang 0006, Yaqing Song, Shiyu Li 0002
IEEE Trans. Inf. Forensics Secur.4
2024 Beyond Security: Achieving Fairness in Mailmen-Assisted Timed Data Delivery
abstract
Timed data delivery is a critical service for time-sensitive applications that allows a sender to deliver data to a recipient, but only be accessible at a specific future time. This service is typically accomplished by employing a set of mailmen to complete the delivery mission. While this approach is commonly used, it is vulnerable to attacks from realistic adversaries, such as a greedy sender (who accesses the delivery service without paying the service charge) and malicious mailmen (who release the data prematurely without being detected). Although some research works have been done to address these adversaries, most of them fail to achieve fairness. In this paper, we formally define the fairness requirement for mailmen-assisted timed data delivery and propose a practical scheme, dubbed DataUber, to achieve fairness. DataUber ensures that honest mailmen receive the service charge, lazy mailmen do not receive the service charge, and malicious mailmen are punished. Specifically, DataUber consists of two key techniques: 1) a new cryptographic primitive, i.e., Oblivious and Verifiable Threshold Secret Sharing (OVTSS), enabling a dealer to distribute a secret among multiple participants in a threshold and verifiable way without knowing any one of the shares; and 2) a smart-contract-based complaint mechanism, allowing anyone to become a reporter to complain about a mailman’s misbehavior to a smart contract and receive a reward. Furthermore, we formally prove the security of DataUber and demonstrate its practicality through a prototype implementation.
Shiyu Li 0002, Yuan Zhang 0006, Yaqing Song, Hongbo Liu 0002, Nan Cheng 0001, Dahai Tao, Hongwei Li 0001, Kan Yang 0001
IEEE Trans. Inf. Forensics Secur.1
2024 Hardening Password-Based Credential Databases
abstract
We propose a protection mechanism for password-based credential databases maintained by service providers against leakage, dubbed PCDL. In PCDL, each authentication credential is derived from a user’s password and a salt, where a service provider employs a set of key servers to share the salt in a threshold way. With PCDL, an external adversary cannot derive any information about the underlying passwords from a compromised credential database, even if he can compromise some of the key servers. The most prominent manifestation of PCDL is transparency: integrating PCDL with existing password-based authentication schemes does not require users to perform any additional operation (and thereby does not change users’ interaction patterns), yet enhances the security guarantee significantly. PCDL serves as an independent component only deployed on the service provider side to harden the credential database. As such, PCDL is well compatible with existing password-based authentication schemes. We analyze the security of PCDL and conduct a performance evaluation, which shows that PCDL is secure and efficient.
Yaqing Song, Chunxiang Xu, Yuan Zhang 0006, Shiyu Li 0002
IEEE Trans. Inf. Forensics Secur.4
2023 Privacy-Driven Fine-Grained Data Trading
abstract
In this paper, we investigate actual exchange-assisted data trading systems and point out that the increment of data content in a sensitive dataset always results in the increment of its privacy level, i.e., making the dataset more sensitive than before. As a consequence, data trading always follows an incremental privacy-driven paradigm, where (1) buyers with various requirements would purchase subsets of the data with different privacy levels, and (2) when a buyer purchases a subset of the entire dataset with a higher level of privacy, the subsets with all lower levels of privacy are required (in other words, there is a containment relationship between subsets with different levels of privacy). A notable example is attribute-value type datasets. Based on these observations, we propose a new concept of privacy-driven and fine-grained data trading, which enables sellers and buyers to trade in data in an efficient and flexible way. We propose a concrete instantiation, dubbed PDFG, which enables sellers and buyers to conduct fine-grained data trading with minimal costs in terms of computation and communication. We prove that PDFG is indistinguishable against the chosen plaintext attack (CPA) under the real-or-random (RoR) model. We also conduct a comprehensive performance evaluation to demonstrate the practicality and efficiency of PDFG.
Yuan Zhang 0006, Shiyu Li 0002, Yaqing Song, Hongwei Li 0001
PIMRC3
2023 Edge-Cloud-Assisted Certificate Revocation Checking: An Efficient Solution Against Irresponsible Service Providers
abstract
Certificate revocation checking (CRC) is a fundamental requirement in certificate-based public-key cryptographic systems. Most existing CRC schemes are not tailored for edge-cloud computing systems, and directly applying these schemes would cause security and efficiency problems. In this article, we first propose a two-layer edge-cloud-assisted CRC framework, dubbed ECA-CRC, where edge nodes utilizing a probabilistic checking algorithm serve as a first layer, and the cloud server utilizing a deterministic checking algorithm serves as a second layer. Both the edge nodes and the cloud server collaboratively provide verifiable CRC services for devices. The most prominent manifestations of ECA-CRC are that: 1) most CRC requests can be processed with the probabilistic checking layer, which reduces the checking delay significantly while providing an accurate CRC service and 2) devices can detect the irresponsible behavior of the service provider, including using an incorrect revoked certificate set (RCS) to compute checking results or procrastinating on updating the RCS, as soon as possible. We then propose an efficient instantiation of ECA-CRC, dubbed eECA-CRC, by utilizing a Merkle hash tree (MHT)-based homomorphic signature, Cuckoo filter, and Othello. We formally prove the security of eECA-CRC against the irresponsible service provider under the random oracle model. We implement an eECA-CRC prototype and conduct a comprehensive performance evaluation based on a public certificate database. Our results show that 95% of CRC requests are completed on the edge nodes, and only 5% of CRC requests need to be handled by the cloud server.
Yaqing Song, Yuan Zhang 0006, Chunxiang Xu, Shiyu Li 0002, Anjia Yang, Nan Cheng 0001
IEEE Internet Things J.4
2023 HealthFort: A Cloud-Based eHealth System With Conditional Forward Transparency and Secure Provenance via Blockchain
abstract
In this paper, we propose a servers-aided password-based subsequent-key-locked encryption mechanism to ensure the confidentiality of outsourced electronic health records (EHRs). The encryption mechanism achieves conditional forward transparency: a doctor can only access a patient's EHRs related to the current diagnosis with the patient's delegation. It also achieves portability: to delegate a doctor for accessing a specific part of EHRs, the patient only needs to send one key (at most 256 bits) in addition to the delegation information to the doctor; the patient does not need to maintain any secret in a local device. Then, we propose a blockchain-based secure EHR provenance mechanism, where a data structure of EHR provenance record is designed to precisely reflect the EHRs’ provenance information; a smart contract on a public blockchain is deployed to secure both EHRs and the corresponding provenance records. Finally, we develop a cloud-based eHealth system, dubbed HealthFort, based on the two mechanisms. Security analysis and comprehensive performance evaluation are conducted to demonstrate that HealthFort is secure and efficient.
Shiyu Li 0002, Yuan Zhang 0006, Chunxiang Xu, Nan Cheng 0001, Zhi Liu 0002, Yicong Du, Xuemin Shen
IEEE Trans. Mob. Comput.1
2022 Badge: Blockchain-Assisted Secure Authenticated Data Transmission in Mobile Edge Computing
abstract
In mobile edge computing (MEC) systems, data is frequently transmitted between MEC servers and mobile devices for supporting related services. However, critical threats towards data confidentiality and authenticity are raised, where adversaries always attempt to extract data content from the transmission and impersonate others to spread malicious data for profits. In this paper, we propose a blockchain-based authenticated data transmission scheme, dubbed Badge, to establish secure channels between MEC servers and mobile devices. Badge is based on a blockchain-based authenticated hybrid encryption mechanism, which frees MEC servers from maintaining devices’ certificates and allows them to encrypt/decrypt a large volume of data in a highly efficient way. We present security analysis to demonstrate that Badge achieves data confidentiality and authenticity. We conduct a comprehensive evaluation to demonstrate that Badge is efficient and practical to deploy.
Shiyu Li 0002, Yuan Zhang 0006, Nan Cheng 0001, Yaqing Song
ICC1
2021 BESURE: Blockchain-Based Cloud-Assisted eHealth System with Secure Data Provenance
abstract
In this paper, we investigate actual cloud-assisted electronic health (eHealth) systems in terms of security, efficiency, and functionality. Specifically, we propose a password-based subsequent-key-locked encryption mechanism to ensure the confidentiality of outsourced electronic health records (EHRs). We also propose a blockchain-based secure EHR provenance mechanism by designing the data structure of the EHR provenance record and deploying a public blockchain and smart contract to secure both EHRs and their provenance records. With the two mechanisms, we develop BESURE (blockchain-based cloud-assisted eHealth system with secure data provenance) to provide a secure EHR storage service with efficient provenance. Security analysis and comprehensive performance evaluation are conducted to demonstrate that BESURE is secure and efficient.
Shiyu Li 0002, Yuan Zhang 0006, Chunxiang Xu, Nan Cheng 0001, Zhi Liu 0002, Xuemin Shen
IWQoS1
2021 Cryptoanalysis of an Authenticated Data Structure Scheme With Public Privacy-Preserving Auditing
abstract
In this letter, we point out that the privacy-preserving adaptive trapdoor hash authentication tree scheme (published in IEEE TIFS, doi: 10.1109/TIFS.2020.2986879) can be invalidated by an adversarial cloud server: if the outsourced data is arbitrarily modified, the cloud server still can pass the third-party auditor's auditing.
Shiyu Li 0002, Yuan Zhang 0006, Chunxiang Xu, Kefei Chen
IEEE Trans. Inf. Forensics Secur.1