Zhaofeng Ma

dblp:48/3847 · DBLP profile ↗
← Back
25ranked-venue papers
12as first author
14since 2021 · last 2026
0000-0001-7875-4169ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 3 first-author · 7 since 2021Systems, architecture and hardware · 4 · 3 first-author · 2 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 4 · 3 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 A secure multi-party sorting protocol based on private set intersection for sealed-bid auctions
Qingan Zheng, Zhaofeng Ma, Tiezheng Wu
Comput. Networks3
2026 Blockchain-Enabled Multi-Authority Secure Data Sharing With Traceability and Attribute Revocation for IoT
abstract
To address the demand for fine-grained access control in Internet of Things (IoT) data sharing, attribute-based encryption (ABE) has emerged as a critical solution. Nevertheless, the computational overhead inherent in ABE poses a major challenge for its direct deployment on resource-constrained IoT devices. Data storage and sharing through centralized cloud may be interrupted due to cloud server failures. Additionally, if user attributes cannot be revoked, some users who should have had their data access rights canceled will still be capable of accessing the data. To solve these problems, we propose a multi-authority attribute-based data sharing scheme that combines blockchain to construct a secure and trusted data sharing environment, while supporting efficient attribute revocation. We reduce the computational burden during the online encryption phase through online/offline encryption, while introducing outsourced decryption to lessen the computational overhead of user decryption. Our scheme supports the tracing of key abusers and attribute revocation for users. Furthermore, by interplanetary file system (IPFS), we reduce on-chain storage burden, and by interplanetary name system (IPNS), we address the difficulty of logically deleting old ciphertexts when updating ciphertexts. Security analysis shows that our scheme exhibits static security, and experimental results demonstrate that our data sharing scheme exhibits excellent efficiency and practicality.
Haojie Zhou, Zhaofeng Ma, Zhiquan Liu 0001, Tiezheng Wu, Jiyuan Song, Pengfei Duan 0002
IEEE Internet Things J.2
2026 An Outsourced Attribute-Based Encryption Scheme With Verifiable Policy Update and Dynamic Attributes for Digital Twins
abstract
Digital Twins (DTs) generate vast sensitive data, demanding secure, dynamic, and fine-grained access control. While Ciphertext-Policy Attribute-Based Encryption (CP-ABE) offers such control, its inherent computational overhead, static nature, and the need to trust outsourcers for complex operations often limit its practical application in evolving DT environments. In this paper, we proposed an Outsourced Attribute-Based Encryption Scheme with Verifiable Policy Update and Dynamic Attributes (OABE-VPUDA) for Digital Twins. OABE-VPUDA empowers Data Owners (DOs) and Data Users (DUs) by enabling verifiable outsourced encryption, where a Public Verifier confirms Cloud Server (CS) computations, and verifiable outsourced de cryption, validated by DUs using an inspired tag mechanism. The scheme further incorporates dynamic attribute management via on-chain expiration tags for timely, fine-grained revocation, and allows DOs to securely and verifiably modify ciphertext access policies with CS assistance. A consortium blockchain underpins these functionalities, significantly enhancing system transparency, auditability, and overall trust in collaborative DT ecosystems. Formal security analysis rigorously demonstrates that the OABE-VPUDA scheme is secure against chosen-plaintext attacks, thereby ensuring robust data confidentiality, and its de sign ensures the verifiability of all critical outsourced operations within a provable security framework. Experimental results from a prototype implementation confirm the scheme's operational efficiency and practical applicability, highlighting its suitability for secure and agile data sharing in resource-aware digital twin applications.
Zhaofeng Ma, Jiayu Dong, Zhiquan Liu 0001, Pengfei Duan 0002
IEEE Trans. Dependable Secur. Comput.1
2026 A Regulatable Blockchain Rewriting Scheme for Identity-Aware Data Modification and User Identity Update
abstract
The immutability of blockchain technology, while fundamental to its trustworthiness, introduces significant challenges for dynamic data governance scenarios such as financial transaction corrections, privacy-preserving healthcare data updates, and GDPR compliance. Existing blockchain rewriting schemes based on chameleon hash techniques alleviate some of these issues but suffer from inherent limitations, including complex key management overhead, lack of regulatory mechanisms, and inflexible access policy enforcement. This article introduces a chameleon hash that supports the identity update, called IDCHU , which is a novel cryptographic primitive integrating identity-based proxy re-encryption and chameleon hash with ephemeral trapdoors to enable secure, traceable and identity-aware data modifications while supporting flexible user identity updates. The proposed regulable blockchain rewriting scheme built upon IDCHU algorithm ensures compliance through three core mechanisms: identity-bound modification authority, time-constrained modification and cryptographic traceability recorded on a regulatory blockchain. We provide formal security proofs for both the IDCHU algorithm and the blockchain rewriting scheme. The experimental evaluations and comparisons validate the scheme’s efficiency, showcasing its practical viability for real-world applications.
Zhaofeng Ma, Yushi Shen
ACM Trans. Web3
2025 A Searchable Encryption Scheme for Blockchain-Based Digital Twins
abstract
With the widespread adoption of digital twin (DT) technology in cross-domain data sharing scenarios, ensuring secure and efficient search over encrypted data has become a significant challenge. This article proposes a blockchain-based searchable encryption scheme tailored for DTs, supporting privacy-preserving keyword search, verifiable data access, and decentralized trust establishment. The scheme collects real-time data streams from digital sensors and devices to construct unified DT records for intelligent analytics and decision-making. The scheme integrates lightweight searchable encryption with blockchain-based trapdoor delegation and ciphertext-level indexing, enabling secure and low-complexity keyword matching. By introducing a delegated trapdoor mechanism, users can authorize repeated keyword queries via a single token, thereby minimizing communication and computational costs. Additionally, a blockchain-driven key generation protocol based on distributed voting eliminates reliance on centralized authorities and ensures transparent, auditable key management. Moreover, encrypted records are stored in IPFS, resolving the storage limitations of blockchain and preserving verifiable data availability. The trapdoor delegation records and result verification parameters are committed on-chain, enabling query correctness checking and traceable access control. Under the ciphertext indistinguishability (CI) and trapdoor indistinguishability (TI) security models, the proposed scheme is formally proven to achieve CI and trapdoor privacy, providing resistance to adaptive insider keyword guessing attacks. Compared with existing schemes, it offers stronger privacy guarantees with lower overhead, supporting scalable and secure DT data sharing.
Hongmin Gao 0002, Zhiquan Liu 0001, Zhaofeng Ma
IEEE Internet Things J.5
2025 Attribute-Based Heterogeneous Data Privacy Sharing in Blockchain-Assisted Industrial IoT
abstract
Industrial Internet of Things (IIoT) enables highly automated and intelligent cross-domain communication. Due to varying computational capabilities and security requirements, cross-domain IIoT data sharing involves the design of security protocols using different cryptosystems. Attribute-based searchable encryption enables fine-grained access control and ciphertext retrieval, but existing schemes are primarily designed on a singular cryptosystem, lacking support for searches on heterogeneous ciphertext. Moreover, related schemes still suffer from technical challenges, such as the single point bottleneck, caused by a single attribute authority, issues with attribute updates, and forward secrecy attacks. In this article, we propose an attribute-based heterogeneous data privacy sharing (AB-HDPS) scheme for blockchain-assisted IIoT. Attribute-authorized users within a public key infrastructure cryptosystem can search ciphertext from data owners in a certificateless cryptosystem. The scheme utilizes multiple authorities to generate attribute keys, employs a glass-box traceable mechanism to prevent misuse of attribute keys, and implements subset-cover trees for attribute revocation. Specifically, leveraging the immutability of blockchain, the AB-HDPS scheme supports traceability and auditing of user access. Security analysis shows that the AB-HDPS scheme can resist internal keyword guessing and chosen-plaintext attacks, and it satisfies forward security. Comparative experimental simulations demonstrate that the AB-HDPS scheme with outsourced decryption has satisfactory computational performance, and the performance of the blockchain system within the scheme is commendable.
Yushi Shen, Hongmin Gao 0002, Zhaofeng Ma, Zhetao Guo, Pengfei Duan 0002
IEEE Internet Things J.4
2025 Multi-Authority Attribute-Based Encryption Scheme With Access Delegation for Cross Blockchain Data Sharing
abstract
To achieve fine-grained access control and address the data silos challenge in data sharing, the integration of blockchain with attribute-based encryption emerges as a promising solution. Nowadays, the growing interconnectedness among diverse blockchain applications has spurred the need for efficient cross-chain data sharing. However, existing single-authority attribute-based data sharing schemes are not suitable for such cross-chain scenarios involving multiple attribute authorities. Moreover, the frequent requirement for data owners to process cross-chain data requests significantly hampers practicality. In this context, we introduce a novel multi-authority attribute-based proxy re-encryption scheme that enables ciphertext policy updating and supports secure and efficient cross-chain data sharing. By introducing a proxy, the data owner is empowered to delegate access without leaking any valid information and flexibly sells data across blockchains through cross-chain access policies. Besides, our scheme leverages the relay chain to foster a decentralized and trustworthy ecosystem. The adoption of smart contracts automates the cross-chain data sharing process and ensures equitable distribution of benefits among participants. Additionally, our scheme integrates hybrid encryption with the decentralized data hosting platform, substantially mitigating the on-chain storage burden. Security analysis affirms that our scheme is semantically secure and resistant to collusion attack. Performance analysis and simulation experiments demonstrate the excellent efficiency and practicality of our scheme when conducting cross-chain data sharing.
Pengfei Duan 0002, Zhaofeng Ma, Hongmin Gao 0002
IEEE Trans. Inf. Forensics Secur.2
2024 Secure collaborative EHR Sharing using multi-authority attribute-based proxy re-encryption in Web 3.0
Pengfei Duan 0002, Hongmin Gao 0002, Yushi Shen, Zhetao Guo, Zhaofeng Ma
Comput. Networks5
2024 Dynamic Trust-Based Redactable Blockchain Supporting Update and Traceability
abstract
Blockchain, as an emerging technology, is constantly evolving due to its remarkable advantages but is also subject to its unalterability, which leads to the misuse of blockchain storage and causes adverse effects. Hence, the redactable blockchain was proposed, which can alleviate the above issues in a controlled manner. However, a situation exists in which the modifiers specified by customized identities or attributes in the existing schemes may be malicious, which can easily lead to malicious modification events. Evaluating, filtering, and limiting malicious modifiers in advance may be a feasible solution to the situation. Hence, we propose an efficient dynamic trust-based redactable blockchain supporting update and traceability, which offers full-process security with pre-modification pre-evaluation, modification privilege restrictions, and post-modification traceability. Firstly, we consider the user’s various behaviors and multiple factors and customize a dynamic trust evaluation model for redactable blockchain to comprehensively evaluate the reliability of the user. Then, we combine the user’s trust worthiness, dynamic proactive secret sharing($\mathcal {DPSS}$), chameleon hash($\mathcal {CH}$), and digital signature ($\mathcal {DS}$) to design a dynamic trust-based chameleon hash supporting update and traceability, called$\mathcal {DTCH}$, to realize full-process security, and prove its security. Thirdly, we construct the$\mathcal {DTCH}$-based redactable blockchain supporting update and traceability, demonstrate its security and further apply it to consortium blockchain. Finally, we evaluate the performance of the constructed model and scheme, and the evaluation results illuminate that they are not only effective but also possess better performance.
Zhaofeng Ma, Shoushan Luo, Pengfei Duan 0002
IEEE Trans. Inf. Forensics Secur.2
2023 DBSDS: A dual-blockchain security data sharing model with supervision and privacy-protection
abstract
Abstract With the rapid development of big data technology and applications, sharing and supervision of massive data have become the demand of industry development. As an emerging technology, blockchain, with excellent characteristics, can promote the prosperity and development of the data‐sharing industry. However, the existing blockchain may lead to some privacy and security issues due to its transparency and lack of supervision. Hence, a secure data sharing model with supervision and privacy protection, named DBSDS, was proposed, which supports illegal content supervision and users revocation, and possesses flexible and fine‐grained access control on data sharing. Firstly, it introduces a dual‐blockchain architecture, one blockchain is used to ensure the integrity and traceability of private data and another is utilized to supervise illegal users so that they can no longer upload and share private data. Secondly, a key tracing tree was built and correspondingly different key generation strategies for different users were designed, which endows regulators with supervision capabilities. Finally, combined ABPER‐KS algorithm, both privacy protection and fine‐grained access control on private data can be accomplished. Furthermore, security analysis and performance comparison manifest that DBSDS is safe and owns better performance, and scheme implementation and experimental analysis indicate the practicality of DBSDS.
Zhaofeng Ma, Shoushan Luo, Shushuang Wang
Concurr. Comput. Pract. Exp.2
2023 An efficient confidentiality protection solution for pub/sub system
abstract
Abstract Publish/subscribe(pub/sub) systems are widely used in large-scale messaging systems due to their asynchronous and decoupled nature. With the population of pub/sub cloud services, the privacy protection problem of pub/sub systems has started to emerge, and events and subscriptions are exposed when executing event matching on untrustworthy cloud brokers. However, as the number of subscriptions increases, the effectiveness of the previous confidentiality protection approaches declines drastically. In this paper, we propose SBM (scalable blind matching), an effective confidentiality protection scheme for pub/sub systems. To the best of our knowledge, SBM is the first scheme that applies order-preserving encryption algorithm to protect the system’s confidentiality and ensure its scalability. In this scheme, SBM-I is highly effective in subscription matching but is unable to achieve ideal security IND-OCPA, whereas SBM-II is suggested to ensure system security and SGX is used to reduce interaction and boost ciphertext matching performance. The experiment demonstrates that this method has better matching performance compared to others: the average matching time of SBM-I is 3–4 orders of magnitude faster than the matching algorithm MP and SGX-based algorithm SCBR when the number of subscriptions is 500,000, and the average matching time of SBM-II is 40 times faster than MP and 24 times than SCBR.
Jinglei Pei, Qingling Feng, Ruisheng Shi, Lina Lan, Shui Yu 0001, Jinqiao Shi, Zhaofeng Ma
Cybersecur.8
2023 Fully homomorphic encryption-based privacy-preserving scheme for cross edge blockchain network
Zhaofeng Ma, Keke Gai, Shoushan Luo
J. Syst. Archit.1
2021 Blockchain-Based Decentralized Authentication Modeling Scheme in Edge and IoT Environment
abstract
Authentication is the first entrance to kinds of information systems; however, traditional centered single-side authentication is weak and fragile, which has security risk of single-side failure or breakdown caused by outside attacks or internal cheating. In the edge and Internet-of-Things (IoT) environment, blockchain can apply edge devices to better serve the IoT and provide decentralized high security service solutions. In this article, we proposed a blockchain-based decentralized authentication modeling scheme (named BlockAuth) in edge and IoT environment to provide a more secure, reliable, and strong fault tolerance novel solution, in which each edge device is regarded as a node to form a blockchain network. We designed secure registration and authentication strategy, blockchain-based decentralized authentication protocol, and developed the blockchain consensus, smart contract, and implemented a whole blockchain-based authentication platform for the feasibility, security, and performance evaluation. The analysis and evaluation show that the proposed BlockAuth scheme provides a more secure, reliable, and strong fault tolerance decentralized novel authentication with high-level security driven configuration management. The proposed BlockAuth scheme is suitable for password-based, certificate-based, biotechnology-based, and token-based authentication for high-level security requirement system in edge and IoT environment.
Zhaofeng Ma, Jialin Meng, Jihui Wang, Zhiguang Shan
IEEE Internet Things J.1
2021 BSSPD: A Blockchain-Based Security Sharing Scheme for Personal Data with Fine-Grained Access Control
abstract
Privacy protection and open sharing are the core of data governance in the AI‐driven era. A common data‐sharing management platform is indispensable in the existing data‐sharing solutions, and users upload their data to the cloud server for storage and dissemination. However, from the moment users upload the data to the server, they will lose absolute ownership of their data, and security and privacy will become a critical issue. Although data encryption and access control are considered up‐and‐coming technologies in protecting personal data security on the cloud server, they alleviate this problem to a certain extent. However, it still depends too much on a third‐party organization’s credibility, the Cloud Service Provider (CSP). In this paper, we combined blockchain, ciphertext‐policy attribute‐based encryption (CP‐ABE), and InterPlanetary File System (IPFS) to address this problem to propose a blockchain‐based security sharing scheme for personal data named BSSPD. In this user‐centric scheme, the data owner encrypts the sharing data and stores it on IPFS, which maximizes the scheme’s decentralization. The address and the decryption key of the shared data will be encrypted with CP‐ABE according to the specific access policy, and the data owner uses blockchain to publish his data‐related information and distribute keys for data users. Only the data user whose attributes meet the access policy can download and decrypt the data. The data owner has fine‐grained access control over his data, and BSSPD supports an attribute‐level revocation of a specific data user without affecting others. To further protect the data user’s privacy, the ciphertext keyword search is used when retrieving data. We analyzed the security of the BBSPD and simulated our scheme on the EOS blockchain, which proved that our scheme is feasible. Meanwhile, we provided a thorough analysis of the storage and computing overhead, which proved that BSSPD has a good performance.
Hongmin Gao 0002, Zhaofeng Ma, Shoushan Luo, Zheng Wu 0004
Wirel. Commun. Mob. Comput.2
2020 TrustedBaaS: Blockchain-Enabled Distributed and Higher-Level Trusted Platform
Zhaofeng Ma, Weizhe Zhao, Shoushan Luo
Comput. Networks1
2020 Blockchain-Enabled Decentralized Trust Management and Secure Usage Control of IoT Big Data
abstract
With the fast development of Internet-of-Things (IoT) technologies, IoT big data and its applications are getting more and more useful. However, traditional IoT data management is fragile and vulnerable. Once the gathered data are untrusted or the stored data are tampered with deliberately from the internal users or attacked by an external hacker, then the tampered data have a serious problem to be utilized. To solve the problems of trust and security of IoT big data management, in this article, we propose a permissioned blockchain-based decentralized trust management and secure usage control scheme of IoT big data (called BlockBDM), upon which all the data operations and management, such as data gathering, invoking, transfer, storage, and usage, are processed over the blockchain smart contract. To encourage the IoT client to supply high-quality content, in our scheme, we design public-blockchain-based tokens reward mechanism for the high-quality data supply contribution. All the data processing and usage procedure can be recorded in a cryptography-signed and Merkle tree-based transaction(s) and block(s) with high-level security in a global and distributed ledger with tamper resistance. For data utilization and consumption, we propose secure usage control for digital rights management and token-based data consumption approach of high-value data from being violated or spread without any limitation. We implemented the BlockBDM scheme based on public and permissioned blockchain for IoT big data management. Finally, a large amount of evaluation manifests that the proposed BlockBDM scheme is feasible, secure, and scalable for decentralized trust management of IoT big data.
Zhaofeng Ma, Zhen Wang 0011, Weizhe Zhao
IEEE Internet Things J.1
2020 Trusted forensics scheme based on digital watermark algorithm in intelligent VANET
Zhaofeng Ma, Weihua Huang
Neural Comput. Appl.1
2020 A Blockchain-Based Trusted Data Management Scheme in Edge Computing
abstract
With rapid development of computing technologies, large amount of data are gathered from edge terminals or Internet of Things (IoT) devices, however data trust and security in edge computing environment are very important issues to be considered, especially when the gathered data are fraud or dishonest, or the data are misused or spread without any authorization, which may lead to serious problems. In this article, a blockchain-based trusted data management scheme (called BlockTDM) in edge computing is proposed to solve the above problems, in which we proposed a flexible and configurable blockchain architecture that includes mutual authentication protocol, flexible consensus, smart contract, block and transaction data management, blockchain nodes management, and deployment. The BlockTDM scheme can support matrix-based multichannel data segment and isolation for sensitive or privacy data protection, and moreover, we have designed user-defined sensitive data encryption before the transaction payload stores in blockchain system, and have implemented conditional access and decryption query of the protected blockchain data and transactions through smart contract. Finally, we have evaluated the proposed BlockTDM scheme security, availability, and efficiency with large amount of experiments. Analysis and evaluations manifest that the proposed BlockTDM scheme provides a general, flexible, and configurable blockchain-based paradigm for trusted data management with tamper-resistance, which is suitable for edge computing with high-level security and creditability.
Zhaofeng Ma, Deepak Kumar Jain 0001, Haneef Khan, Hongmin Gao 0002, Zhen Wang 0011
IEEE Trans. Ind. Informatics1
2018 Blockchain for digital rights management
Zhaofeng Ma, Hongmin Gao 0002, Zhen Wang 0011
Future Gener. Comput. Syst.1
2005 SVM-Based Semantic Text Categorization for Large Scale Web Information Organization
Peng Fu 0002, Deyun Zhang, Zhaofeng Ma, Hao Dong 0002
ISNN (1)3
2005 Secure Multimedia Streaming with Trusted Digital Rights Management
abstract
Content protection is now becoming more and more important for digital rights management (DRM), which involves rights embedding, identification, rights validation digital multimedia resource is popular in the real world, how to protect multimedia content from be violated without rights control is an important thing especially to resist copy-spread kind violation. In this paper, an novel approach for multimedia rights management is proposed based on partial encryption method, which can control multimedia resource played in a rights-constraint environment, which can protect multimedia resource from being copying and spreading, and in the authorization usage environment, the protected multimedia is properly played as normal, however once the resource is beyond the authorization environment, the protected resource will not be played correctly. Experiments showed our proposed partial encryption approach was efficient with real-time quality of service, which was suitable for online multimedia streaming in content delivery network.
Jizhong Zhao, Yong Qi 0001, Zhaofeng Ma
LCN3
2005 Secure Anonymous Communication with Conditional Traceability
Zhaofeng Ma, Xibin Zhao, Zhi Guo, Ming Gu 0001, Jia-Guang Sun 0001
NPC1
2004 Support Vector Machines Learning for Web-Based Adaptive and Active Information Retrieval
Zhaofeng Ma, Boqin Feng
APWeb1
2004 Fail-Stop Authentication Protocol for Digital Rights Management in Adaptive Information Retrieval System
Zhaofeng Ma, Boqin Feng
WAIM1
2004 Adaptive Load Balancing and Fault Tolerance in Push-Based Information Delivery Middleware Service
Zhaofeng Ma, Boqin Feng
WAIM1