EDBT 2026 Demo / reviewers in the wild / expert
Yanwei Zhou
dblp:50/7035
· DBLP profile ↗
62ranked-venue papers
27as first author
38since 2021 · last 2026
0000-0002-7254-3579ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 7 first-author · 8 since 2021Computer networks · 14 · 4 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 7 first-author · 7 since 2021Theory of computation · 9 · 8 first-author · 3 since 2021Systems, architecture and hardware · 5 · 5 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RCBPS: Revocable certificate-based proxy signature scheme in the standard model for secure cloudIoT communications
Guangjin Zhang, Yanwei Zhou, Xianxiang Liu, Bo Yang 0003, Mingwu Zhang |
Comput. Networks | 2 |
| 2026 | Leakage-resilient attribute-based encryption scheme with CCA security
Yanwei Zhou, Ran Xu 0012, Zirui Qiao, Bo Yang 0003 |
Theor. Comput. Sci. | 1 |
| 2026 | Leakage-Resilient Data Transmission Protocol With Multi-Receiver for Internet of ThingsabstractThe Internet of Things (IoT) is transforming lives, making daily tasks more convenient and efficient than ever before. However, the true potential of IoT can only be realized if its nodes interact with robust security, ensuring that sensitive data and personal information remain protected. While many data transmission protocols have been proposed in recent years, most fail to deliver on their security promises in real-world scenarios. Adversaries can exploit vulnerabilities through sophisticated leakage attacks such as side channel attacks or cold boot attacks to compromise encryption keys and undermine system integrity. Without advanced, resilient protocols, the promise of IoT is put at serious risk. In addition, the corresponding protocols deployed in IoT should enjoy high computational efficiency, because the mobile terminals have weak computing power. Also, from the viewpoint of actual application, the proposed data transmission protocol should have wider universality and can be used in multiple scenarios of IoT. Therefore, to further address the above problems, we propose a general construction of a leakage-resilient data transmission protocol with multi-receiver from an identity-based hash proof system (IB-HPS) and identity-based signature (IBS) scheme. For our proposal, the unforgeability, anonymity, and confidentiality can be proved based on the security of the underlying cryptography tools. Compared with the existing protocols, our proposal has better performance, such as dynamic anonymity, leakage resilience, traceability, etc. Furthermore, to guarantee the highest levels of security and efficiency, we have developed a novel IB-HPS construction that offers continuous leakage resilience and perfect key updates. Alongside this, our new leakage-resilient IBS scheme delivers the computational efficiency essential for practical deployment in IoT networks, ensuring that security enhancements do not come at the expense of performance. Both performance analysis and security analysis show that our data transmission protocol is secure, efficient, and highly practical. Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Zhe Xia, Mingwu Zhang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | CLR-IA: An Efficient Identity Authentication Protocol With Continuous Leakage Resilience for Mobile Edge Computing
Yanwei Zhou, Yasi Zhu, Zirui Qiao, Xianxiang Liu, Guangjin Zhang, Bo Yang 0003, Tianqing Zhu, Mingwu Zhang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | A novel construction of certificateless aggregate signcryption scheme for smart healthcare
Xianxiang Liu, Yanwei Zhou, Yasi Zhu, Zhe Xia |
Expert Syst. Appl. | 2 |
| 2025 | An Efficient Pairing-Free Certificateless Signcryption Scheme Under the Standard Model for VANETabstractWith the rapid advancement of the Internet of Things (IoT), its applications are becoming increasingly essential in actual application. Specifically, the recent surge in electric vehicles has spurred significant advancements in vehicle ad hoc networks (VANET). Therefore, efficient data transmission is a critical challenge in IoT, especially VANET. The certificateless signcryption (CLS) scheme has high authentication efficiency, which has become increasingly important in IoT. However, most existing schemes rely on bilinear pairing, resulting in high calculation costs or failure to achieve their claimed security. Furthermore, the security of some CLS schemes is proved in the random oracle, which limits the usefulness of the CLS scheme. To further address these issues, we propose an efficient and secure CLS scheme in the standard model for VANET, which enhances its practical applicability in VANET. Our construction employs formal security proofs and cost simulations to ensure the scheme’s security and low calculation costs, making it suitable for VANET. Finally, the security and efficiency analyses prove that our scheme offers enhanced security features and superior performance compared to existing schemes. Xianxiang Liu, Yanwei Zhou, Bo Yang 0003, Tianqing Zhu, Mingwu Zhang |
IEEE Internet Things J. | 2 |
| 2025 | MRDT: An Enhanced Multireceiver Secure Data Transmission Protocol for WBANsabstractWireless Body Area Networks (WBANs) have gained significant attention due to their numerous advantages in healthcare monitoring and applications. However, WBANs also face challenges related to data transmission security and privacy protection. Many researchers have proposed solutions to address these issues, but most of them are based on one-to-one communication models, which suffer from security vulnerabilities. Hence, we first review the previous protocol and show potential attack scenarios. Building upon their work, we propose an enhanced certificateless multi-receiver secure data transmission protocol for WBANs. Our proposal addresses security concerns and improves the efficiency and practicality of data transmission in WBANs. The security analysis and performance evaluation demonstrate that the proposed protocol achieves higher security levels, increases efficiency, and enhances practicality compared to existing approaches. Furthermore, our protocol provides a reliable framework for secure data transmission in WBANs, ensuring the privacy of users and maintaining the integrity and confidentiality of sensitive medical information. Zirui Qiao, Yanwei Zhou, Yong Yu 0002, Dong Zheng 0001 |
IEEE Internet Things J. | 3 |
| 2025 | A Provably Secure Certificateless Signature Scheme With Anonymity for Healthcare IIoTabstractThe Industrial Internet of Things (IIoT) is changing our way of life and work. As the number of mobile devices connected to IIoT increases, users will face many security challenges, such as insecure communication environments. The certificateless signature (CLS) scheme can ensure the integrity and validity of data and provide secure identity authentication for the IIoT, and several pairing-free CLS schemes have been proposed in recent years. However, we find they are vulnerable to the signature forgery attack of malicious key generation centers by safety analysis, which does not realize the security they have claimed. To solve this problem, we show an improved CLS scheme that achieves anonymity and formally proves its security under the hardness of the discrete logarithm problem in the random oracle. Comprehensive performance analysis and comparison show that our scheme has less communication and computation costs with higher security, and our construction is suitable for scenarios with limited resources. Finally, we apply this scheme to construct a mutual identity authentication protocol in the healthcare IIoT environment. Zirui Qiao, Ran Xu 0012, Yanwei Zhou, Bo Yang 0003, Tianqing Zhu, Mingwu Zhang |
IEEE Internet Things J. | 3 |
| 2025 | CR²-ABE: A Blockchain-Assisted Coercion-Resistant and Revocable Attribute-Based Encryption for IoMTabstractThe Internet of Medical Things (IoMT) has rapidly developed due to its ability to enhance the efficiency of medical data collection and utilization. Encryption technology is vital for ensuring IoMT data security and privacy. However, existing solutions often fail when secret keys or random numbers are exposed under coercion, undermining their effectiveness and security. Additionally, medical data stored on cloud platforms is vulnerable to risks, such as tampering or loss. To address these challenges, we propose CR2-ABE, a novel encryption scheme specifically designed for the IoMT environment. CR2-ABE combines chameleon hash functions and deniable encryption techniques, enabling medical data owners and recipients to present deceptive messages under coercion, thereby enhancing the coercion resistance of sensitive medical data. Moreover, CR2-ABE employs ciphertext-policy attribute-based encryption (CP-ABE) to facilitate fine-grained access control for medical data, while also leveraging blockchain technology to ensure data integrity and tamper resistance within cloud services. In terms of user management, CR2-ABE implements a policy revocation mechanism that operates directly on ciphertexts using software Guard extensions (SGX). We rigorously prove the correctness and semantic security of CR2-ABE, demonstrating its resilience against coercion attacks. Comprehensive evaluation results show that CR2-ABE exhibits significant performance improvements in key generation, encryption, decryption, and policy revocation compared to other solutions. Therefore, CR2-ABE possesses strong security and scalability. Yuan Zhai, Haochen Yang 0001, Jingyu Yao, Tao Wang 0039, Yanwei Zhou, Bo Yang 0003 |
IEEE Internet Things J. | 5 |
| 2025 | Revocable-Hierarchical-Identity-Based Inner Product Function Encryption in Smart HealthcareabstractWith the development of cloud computing and the digital transformation of the medical industry, the application scenarios and effects of smart healthcare are constantly expanding and improving. Smart healthcare plays an important role in improving service quality and medical efficiency and reducing medical costs. However, in the process of data collection, storage, and transmission, the risk of patients’ privacy being illegally accessed or leaked has become increasingly prominent. These medical data contain sensitive information about patients, and once leaked, it will violate the privacy of patients, cause medical accidents, and seriously damage the legitimate rights and interests of patients. An efficient and reliable privacy protection mechanism is the foundation and key to establishing a harmonious doctor-patient relationship and improving medical quality. Although traditional encryption methods can provide certain information security protection, they cannot balance data protection and data analysis and processing and are not suitable for intelligent medical environments that require more precise medical decisions. Therefore, we propose a hierarchical identity-based inner product functional encryption scheme with a malicious user revocation mechanism aimed at addressing the privacy and security issues of patients in smart healthcare. This solution allows specific access and analysis of data while ensuring that patients’ sensitive information is protected from infringement, enabling doctors to diagnose and treat more accurately and optimize the allocation of medical resources to the greatest extent possible. Furthermore, we have formally demonstrated the security of the scheme and conducted a security analysis and performance comparison. The results show that our solution has better performance while ensuring security and is suitable for the efficient and secure data processing requirements of smart healthcare. Yasi Zhu, Yanwei Zhou, Bo Yang 0003, Mingwu Zhang |
IEEE Internet Things J. | 2 |
| 2025 | DRAC: A dynamic fine-grained access control scheme for cloud storage with censorship-coerced resistance
Yuan Zhai, Haochen Yang 0001, Jingyu Yao, Tao Wang 0039, Yanwei Zhou, Bo Yang 0003 |
J. Inf. Secur. Appl. | 5 |
| 2025 | AUKA: Asynchronous updatable key agreement for edge-based mobile crowd sensing
Ru Meng, Tao Wang 0039, Yanwei Zhou, Bo Yang 0003 |
J. Inf. Secur. Appl. | 4 |
| 2025 | A continuous leakage-resilient CCA secure identity-based key encapsulation mechanism in the standard model
Zirui Qiao, Yasi Zhu, Yanwei Zhou, Bo Yang 0003 |
J. Syst. Archit. | 3 |
| 2025 | Secure task-worker matching and privacy-preserving scheme for blockchain-based federated crowdsourcing
Pei Ren, Bo Yang 0003, Tao Wang 0039, Yanwei Zhou |
J. Syst. Archit. | 4 |
| 2025 | Bidirectional Identity-Based Inner-Product Functional Re-Encryption in Vaccine Data SharingabstractWith the development of cloud computing, more and more data is stored in cloud servers, which leads to an increasing degree of privacy of data stored in cloud servers. For example, in the critical domain of medical vaccine trials, where public health outcomes hinge on the analysis of sensitive patient data, the imperative to safeguard privacy has never been more pronounced. Traditional encryption methods, though effective at protecting data, often expose vulnerabilities during decryption and lack the ability to support granular data access and computation. One-way re-encryption schemes further impede the agility of data sharing, which is indispensable for the collaborative efforts of research institutions. To address these limitations, we propose a novel bidirectional re-encryption scheme for inner-product functional encryption (IPFE). Our scheme secures data while allowing computation and sharing in an encrypted state, preserving patient privacy without hindering research. By harnessing inner-product functional encryption, our approach allows authorized researchers to extract valuable insights from encrypted data, significantly enhancing privacy protections. Our scheme’s security is predicated on the$l$-ABDHE (augmented bilinear Diffie-Hellman exponent) assumption, ensuring robustness against chosen plaintext attacks within the standard model. This foundation not only secures the data but also yields compact ciphertext length, minimizing storage demands. We introduce a protocol specifically designed for medical vaccine trials, which leverages our bidirectional IB-IPFRE (Identity-Based Inner-Product Functional Re-Encryption) scheme. This protocol enhances data security, supports collaborative research, and maintains patient privacy. Its application in vaccine trials demonstrates the scheme’s effectiveness in protecting sensitive information while enabling critical research insights. Yanwei Zhou, Yasi Zhu, Zhiquan Liu 0001, Bo Yang 0003, Mingwu Zhang |
IEEE Trans. Cloud Comput. | 2 |
| 2025 | DADD: Direct Authentication With Vehicles From Different DomainsabstractAs Vehicular Ad hoc Networks (VANETs) become integrated into daily life, drivers can conveniently transmit messages to other vehicles. However, since most messages are sent over public channels, they are vulnerable to leakage and tampering, posing risks to user privacy and security. A secure authentication scheme is essential to ensure message authenticity and integrity. Vehicles frequently cross multiple domains while driving, but existing schemes mainly support authentication within a single domain, making it difficult for vehicles from different domains to establish trusted connections. Moreover, many current approaches rely heavily on bilinear pairings, reducing efficiency and increasing communication overhead. To address these issues, we propose an efficient cross-domain authentication scheme for VANETs. Our scheme uses pseudonyms to protect vehicle privacy and allows vehicles to directly authenticate with entities from other domains without relying on a trusted authority, enabling the establishment of a secure session key. We verified the security of our protocol using ProVerif and evaluated its performance with JPBC, a Java-based cryptographic library. Results show that our approach outperforms existing methods and is well-suited for high-traffic, densely populated, and resource-constrained VANET environments. Zirui Qiao, Yasi Zhu, Yanwei Zhou, Xianxiang Liu, Bo Yang 0003 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2025 | Broadcast Authentication: An Efficient Identity Authentication Protocol With Provable Security for VANETsabstractWith the advancement of the Internet of Things (IOT), Vehicular Ad Hoc networks (VANETs) are integrated into intelligent transportation systems to facilitate vehicle communication. However, as the number of vehicles and application diversity increase, significant security concerns have emerged, including message authentication and vehicle privacy protection. Consequently, researchers have devised several identity authentication protocols to ensure legitimate communication between parties. Nevertheless, existing schemes fail to address real-time response identity authentication due to high-speed vehicle movement and the need for traversing multiple domains. This limitation poses challenges in traffic management and even threatens human life. To overcome these issues, we propose a novel identity authentication method called broadcast authentication and design a new protocol incorporating this approach. The confidentiality and unforgeability of our proposal are proven based on classic hardness assumptions. Our protocol enables vehicles to authenticate with multiple roadside units through a single request communication process, thereby avoiding delays in authentication while saving costs associated with communication and computation. Compared with existing schemes, our protocol demonstrates superior computing efficiency and performance. Yanwei Zhou, Yasi Zhu, Zirui Qiao, Chuanyuan Zhao |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | SRACS: Sanitizable and Revocable Access Control Scheme for Crowdsourcing Healthcare Against Malicious Requesters
Ying Zhang 0127, Bo Yang 0003, Tao Wang 0039, Yanwei Zhou |
IEEE Trans. Serv. Comput. | 4 |
| 2024 | A New Construction of Leakage-Resilient Identity-Based Encryption Scheme
Zirui Qiao, Ran Xu 0012, Yonghui Lu, Yanwei Zhou, Bo Yang 0003 |
ISPEC | 4 |
| 2024 | An Efficient and Secure Lightweight Certificateless Hybrid Signcryption SchemeabstractWith the limited resources of the Internet of Things (IoT), security and efficiency have become a challenge. The hybrid signcryption scheme is a proper method to ensure data security and integrity. Recently, through continuous and in-depth research, the signcryption scheme has made many achievements, but there are still some problems. Most proposals use bilinear mapping, which reduces computational efficiency. It brings a heavy burden to the resource-constrained IoT. And many constructions cannot meet the claimed security, causing the leakage of private messages. Therefore, we propose a lightweight certificateless hybrid signcryption (CLHS) scheme with better performance and higher security to solve the above problems. First, we have reduced storage pressure and improved computational efficiency by using certificateless public-key cryptography and elliptic curves instead of bilinear maps to construct a signcryption scheme, and the construction is lightweight. At the same time, to securely transmit messages of different lengths, we employ a hybrid signcryption scheme. Through formal security proof, efficiency, and performance analysis, our proposal has the security requirements of confidentiality and unforgeability and has better computational efficiency and security performance. Finally, we propose a secure data transmission protocol based on our CLHS scheme in Smart Grid, which inherits the advantages of high computational efficiency and better security of the underlying CLHS scheme. Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang |
IEEE Internet Things J. | 2 |
| 2024 | An Anonymous and Efficient Certificate-Based Identity Authentication Protocol for VANETabstractIn recent years, the development of Internet of Things technology has led to a surge in interest in the vehicular ad hoc network (VANET), which has greatly improved travel efficiency and facilitated vehicle data sharing. To ensure the privacy and security of both vehicles and personnel, researchers have proposed various measures for securing VANET systems. Recently, certificate-based aggregate signature (CBAS) schemes have been proposed to design an identity authentication protocol for the VANET to prevent tampering and corruption of private vehicle data. In this study, we conduct a security analysis of the previous CBAS scheme by presenting a security attack. Afterward, we propose a novel and concrete construction of the CBAS scheme that offers improved performance for VANET, which can enhance protection in the VANET scenario. We also demonstrate its security based on standard cryptographic assumptions. Comparative results from theoretical analysis and experimental evaluation illustrate the practicality of our proposed scheme. Similarly, the identity authentication protocol created based on the above CBAS scheme has the properties of dynamic anonymity, mutual identity authentication, unforgeability. Zirui Qiao, Yanwei Zhou, Qiliang Yang, Zhe Xia, Bo Yang 0003, Mingwu Zhang |
IEEE Internet Things J. | 3 |
| 2024 | A Lightweight Cross-Domain Direct Identity Authentication Protocol for VANETsabstractWith the rapid development of Internet of Things (IoT) technology and the growth of traffic demand, vehicular ad hoc networks (VANETs) will become a major component of intelligent transportation systems. However, identity authentication in VANETs has emerged as a crucial challenge in maintaining communication security. The existing identity authentication methods have complex certificate management and key escrow problems, and many authentication schemes can not resist common attacks and are inefficient. Also, the above proposals cannot meet the lightweight needs of the IoT. At the same time, vehicles in the VANETs may move between different network domains, which will lead to an increase in cross-domain identity authentication requirements. Therefore, this article proposes an efficient and lightweight cross-domain direct identity authentication protocol. We apply the unpaired certificateless signature scheme to the cross-domain authentication and generate cross-domain communication credentials for the vehicles in advance in the local domain, which will greatly improve the efficiency of cross-domain authentication between the vehicles. In addition, we demonstrate the security of our protocol and further validate the security of the protocol through the simulation experiments. Finally, experiments show that our protocol is more efficient than the existing authentication protocols. Yasi Zhu, Yanwei Zhou, Bo Yang 0003, Mingwu Zhang |
IEEE Internet Things J. | 2 |
| 2024 | An efficient and secure certificateless aggregate signature scheme
Ran Xu 0012, Yanwei Zhou, Qiliang Yang, Kunwei Yang, Bo Yang 0003, Zhe Xia |
J. Syst. Archit. | 2 |
| 2023 | A Certificateless Aggregate Signature Scheme with Better Security
Ran Xu 0012, Yanwei Zhou, Bo Yang 0003 |
ProvSec | 2 |
| 2023 | A Novel Construction Of Certificateless Aggregate Signature Scheme For Healthcare Wireless Medical Sensor NetworksabstractAbstract To ensure privacy and security of healthcare wireless medical sensor networks (HWMSNs), several concrete constructions of efficient certificateless aggregate signature (CLAS) scheme without bilinear pairing were proposed in the last few years. However, many previous constructions of CLAS scheme were found to be impractical, which either fail to meet the claimed security or contain design flaws. For example, in some of the previous proposals, any adversary can forge a valid signature on any new message. In this paper, we first demonstrate some security issues and design flaws in the previous proposals of CLAS scheme. As follows, to further address the above deficiencies, a new construction of CLAS scheme with improved security is presented, and the formal security proof is given using Forking Lemma in the random oracle model, assuming that the discrete logarithm problem is hard. Compared with the previous CLAS schemes, our construction has similar computational costs, and it provides better security guarantees. Therefore, compared with the existing solutions, our proposal with strong security and high computational efficiency is more suitable for use in HWMSNs. Zirui Qiao, Qiliang Yang, Yanwei Zhou, Bo Yang 0003, Mingwu Zhang |
Comput. J. | 3 |
| 2023 | Identity-Based Encryption With Continuous Leakage-Resilient CCA Security From Static Complexity AssumptionabstractAbstract Although a large number of provably secure cryptographic primitives have been proposed in the literature, many of these schemes might be broken in practice because of various leakage attacks. Therefore, the leakage resilience should be considered in designing these primitives. However, in identity-based cryptography, most of the existing leakage-resilient identity-based encryption (IBE) schemes suffer some limitations: they either resist the leakage attacks in the selective identity security model or achieve the chosen-ciphertext attack (CCA) security based on a non-static assumption. In this paper, an IBE scheme with adaptive leakage-resilient CCA security is proposed, and its security is rigorously proved in the random oracle model under a classic static complexity assumption, e.g. decisional bilinear Diffie–Hellman assumption. In our construction, all elements of ciphertext are randomly distributed in the adversary’s view. Hence, the adversary cannot obtain any useful information of the user’s private key from the given ciphertexts. Moreover, a unique property of our construction is that the leakage parameter is independent of the plaintext space, which contributes a better leakage rate. Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Yi Mu 0001, Mingwu Zhang |
Comput. J. | 1 |
| 2023 | Leakage-resilient identity-based cryptography from minimal assumptions
Yanwei Zhou, Bo Yang 0003, Zirui Qiao, Zhe Xia, Mingwu Zhang, Yi Mu 0001 |
Des. Codes Cryptogr. | 1 |
| 2023 | An Anonymous and Revocable Authentication Protocol for Vehicle-to-Vehicle CommunicationsabstractIn the vehicular ad hoc network (VANET), the communication between the vehicle and other nodes is performed in an open channel, which puts forward the requirements for its privacy security and message integrity. Most previous protocols either frequently verify identities before accepting traffic information or do not involve identity revocation mechanisms, and they may assume that third parties are fully trusted. To further solve the above problem, a certificateless-based anonymous and revocable authentication protocol for vehicle-to-vehicle communications is proposed in this article. Our construction separates the identity authentication process from the traffic message verification, which not only avoids the disadvantage of a frequent identity revocation list (IRL) checking but also reduces the overhead in communication and message authentication. These features can make “identity authentication once, broadcast efficiency” really happen. In addition, since our authentication process is based on certificateless signature, it can resist malicious key generation centers (KGCs) and road-side units (RSUs), which is very necessary for privacy-sensitive application scenarios. Finally, the performance analyses show that our proposal is superior to the existing schemes in terms of authentication speed and communication overhead. Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Yuan Xu 0032, Mingwu Zhang |
IEEE Internet Things J. | 2 |
| 2023 | An Efficient Identity Authentication Scheme With Dynamic Anonymity for VANETsabstractNowadays, as an essential technique for intelligent transportation, vehicular ad hoc networks (VANETs) has significantly improved people’s travel experience, providing richer, and smarter services for vehicles while ensuring driver safety. However, considering that VANETs are complex, some security challenges still remain, including but not restricted to privacy preserving of vehicles, authentication of messages, limited resources in computational power, and network bandwidth. To address these issues, many privacy-preserving identity authentication schemes for VANETs have been proposed recently. However, these schemes still suffer some limitations. First, their computational overheads are heavy due to the complex calculations. Second, some schemes are vulnerable to various security weaknesses, unable to resist normal attacks. Third, in some schemes, the same pseudonym keeps unchanged and it is linked to the corresponding private key of user. The consequence is that if the user wants to change its pseudonym, the corresponding private key must be changed. In order to further solve the above problems, we propose a novel privacy-preserving identity authentication protocol based on the certificateless aggregate signature scheme, allowing the user to generate a fuzzy identity to hide her real identity, and the private key can be kept unchanged even if the corresponding pseudonym is updated. Furthermore, to achieve efficiency in computation, bilinear mapping is avoided in our proposed scheme. We prove that our protocol satisfies unforgeability in the random oracle based on a classic complexity assumption. Finally, the security and efficiency analyses demonstrate that our construction enjoys more security features and better performance compared with the existing schemes. Yanwei Zhou, Zirui Qiao, Zhe Xia, Bo Yang 0003, Mingwu Zhang, Wenzheng Zhang 0001 |
IEEE Internet Things J. | 1 |
| 2023 | An Efficient and Provably Secure Identity Authentication Scheme for VANETabstractIn recent years, many researchers have applied aggregated signature techniques to resource-constrained vehicular ad hoc networks (VANETs) authentication scenarios. We reviewed two recent VANET authentication schemes based on certificateless aggregated signatures (CLASs) while demonstrating that neither of them is resistant to public key replacement attacks under their security models. An eavesdropper can successfully forge a legitimate signature to perform malicious operation. To further address the above security flaws, we propose an improved CLAS scheme for VANET. Considering that some researchers have briefly or even incorrectly used forking lemmas in their security proofs to prove an insecure CLAS scheme, we further improve and refine the security model and security proof method for CLAS, which make the proof process transparent by using general forking lemma. Based on these improvements, our scheme can resist attacks from two types of adversaries in the CLAS security model. In the final performance analysis, the improved CLAS scheme outperforms the secure-related scheme of recent years in terms of both computational and communication efficiency. Therefore, our proposal is more suitable for resource-constrained VANET environments. Yanwei Zhou, Zirui Qiao, Bo Yang 0003, Mingwu Zhang |
IEEE Internet Things J. | 1 |
| 2023 | An Anonymous and Efficient Multimessage and Multireceiver Certificateless Signcryption Scheme for VANETabstractIn future intelligent transportation systems, vehicular ad hoc network (VANET) is a popular application. They provide early warning of dangers through wireless communication to improve road safety. Therefore, we should protect messages from leakage and changes during transmission. To ensure the security issues in the communication process, we propose a secure and effective certificateless signcryption scheme with multiple messages and multiple receivers and prove its confidentiality and unforgeability based on the hardness of the discrete logarithm problem and the computational Diffie Hellman problem. Our scheme implements the signature and encryption of multiple messages for different receivers and achieves anonymity for the receiver. Based on our signcryption scheme, we design an identity authentication and key agreement protocol applying the construction in VANET. In addition, we also point out that through comprehensive performance analysis, our proposal has higher security and efficiency of computation and communication compared to other signcryption constructions. Yanwei Zhou, Ran Xu 0012, Zirui Qiao, Bo Yang 0003, Zhe Xia, Mingwu Zhang |
IEEE Internet Things J. | 1 |
| 2023 | Public-key encryption scheme with optimal continuous leakage resilience
Yanwei Zhou, Ran Xu 0012, Wenzheng Zhang 0001, Zhe Xia, Bo Yang 0003, Meijuan Huang |
Inf. Process. Lett. | 1 |
| 2023 | A redesigned secure and efficient data transaction protocol for mobile payment system
Zirui Qiao, Qiliang Yang, Yanwei Zhou, Bo Yang 0003, Mingwu Zhang |
J. Syst. Archit. | 3 |
| 2022 | Continual Leakage-Resilient Hedged Public-Key EncryptionabstractAbstract Hedged public-key encryption (HPKE), introduced by Bellare et al. (ASIACRYPT 2009), provides useful security when the per-message randomness fails to be uniform due to faulty implementations or adversarial actions. The HPKE scheme achieves IND-CPA (chosen plaintext attack) security when the randomness they used is of high quality, but, when the randomness is poor quality, rather than breaking completely, it achieves a weaker but a useful notion of security called IND-CDA (chosen distribution attack) as long as the message and randomness together have sufficient min-entropy. However, little research on HPKE in the presence of key leakage was done. In this paper, we study HPKE featuring key leakage-resilience and formulate appropriate security notion for key leakage-resilient HPKE. We work in the continual key leakage model where the secret key is refreshed periodically and an adversary can learn arbitrary but bounded leakage on the secret key between the updates. We present two generic constructions of continual leakage-resilient HPKE in the standard model by using a continual leakage-resilient all-but-one lossy trapdoor function. Finally, we give an instantiation of leakage-resilient HPKE under the linear assumption in bilinear groups. Meijuan Huang, Bo Yang 0003, Yanwei Zhou, Xuewei Hu |
Comput. J. | 3 |
| 2022 | Continuous Leakage-Amplified Public-Key Encryption With CCA SecurityabstractAbstract Secret key leakage has become a security threat in computer systems, and it is crucial that cryptographic schemes should resist various leakage attacks, including the continuous leakage attacks. In the literature, some research progresses have been made in designing leakage resistant cryptographic primitives, but there are still some remaining issues unsolved, e.g. the upper bound of the permitted leakage is fixed. In actual applications, the leakage requirements may vary; thus, the leakage parameter with fixed size is not sufficient against various leakage attacks. In this paper, we introduce some novel idea of designing a continuous leakage-amplified public-key encryption scheme with security against chosen-ciphertext attacks. In our construction, the leakage parameter can have an arbitrary length, i.e. the length of the permitted leakage can be flexibly adjusted according to the specific leakage requirements. The security of our proposed scheme is formally proved based on the classic decisional Diffie–Hellman assumption. Wenzheng Zhang 0001, Zirui Qiao, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang |
Comput. J. | 4 |
| 2021 | Novel Public-Key Encryption with Continuous Leakage AmplificationabstractAbstract Leakage of private information, such as the secret keys, has become a threat to the security of computing systems. It has become a common requirement that cryptographic schemes should withstand various leakage attacks, including the continuous leakage attacks. Although some research progresses have been made toward this area, there are still some unsolved issues. In the literature, the public-key encryption (PKE) constructions with (continuous) leakage resilience normally require the upper bound of leakage to be fixed. However, in many real-world applications, this requirement cannot provide sufficient protection against leakage attacks. In order to mitigate these problems, this paper demonstrates how to design a leakage amplified PKE scheme with continuous leakage resilience and chosen-plaintext attacks security. In our proposed PKE scheme, the leakage parameter can have an arbitrary length. Moreover, the length of permitted leakage in our scheme can be flexibly adjusted according to the leakage requirements of application environment. Its security is formally proved under the classic static assumption. Zirui Qiao, Qiliang Yang, Yanwei Zhou, Zhe Xia, Mingwu Zhang |
Comput. J. | 3 |
| 2021 | Novel generic construction of leakage-resilient PKE scheme with CCA security
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang, Yi Mu 0001 |
Des. Codes Cryptogr. | 1 |
| 2021 | Continuous leakage-resilient certificate-based signcryption scheme and application in cloud computing
Yanwei Zhou, Yuan Xu 0032, Zirui Qiao, Bo Yang 0003, Mingwu Zhang |
Theor. Comput. Sci. | 1 |
| 2020 | Improvement of Attribute-Based Encryption Using Blakley Secret Sharing
Zhe Xia, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang, Yi Mu 0001 |
ACISP | 3 |
| 2020 | Continuous Leakage-Resilient Certificate-Based Encryption Scheme Without Bilinear PairingsabstractAbstract Recently, much attention has been focused on designing provably secure cryptographic primitives in the presence of key leakage, even the continuous leakage attacks. However, several constructions on the (continuous) leakage-resilient certificate-based encryption (CBE) scheme were proposed based on the bilinear pairings, and the corresponding computational efficiency is lower. Also, the leakage on the master secret key is omitted in the previous constructions. In this paper, to further achieve the better performance, a new construction method of continuous leakage-resilient CBE scheme without bilinear pairings is proposed, and the chosen-ciphertext attacks security of designed scheme is proved based on the hardness of the classic decisional Diffie–Hellman assumption. The performance analysis shows that our method not only can obtain higher computational efficiency but also enjoys better security performances, such as the leakage parameter of secret key of user has the constant size, and an adversary cannot obtain any leakage on the secret key of user from the corresponding given ciphertext etc. The advantage is that our proposal allows leakage attacks of multiple keys, i.e. continuous leakage resilience of the secret key of user and bounded leakage resilience of the master secret key. Additionally, to provide the leakage resilience for the cloud computing, a novel data access control scheme for cloud storage service is proposed from our continuous leakage-resilient CBE scheme, which can keep its claimed security in the leakage seting. Yanwei Zhou, Bo Yang 0003, Tao Wang 0039, Zhe Xia, Hong-xia Hou |
Comput. J. | 1 |
| 2020 | Practical continuous leakage-resilient CCA secure identity-based encryption
Yanwei Zhou, Bo Yang 0003 |
Frontiers Comput. Sci. | 1 |
| 2020 | A generic construction of CCA-secure deterministic encryption
Meijuan Huang, Bo Yang 0003, Yi Zhao 0011, Xin Wang 0058, Yanwei Zhou, Zhe Xia |
Inf. Process. Lett. | 5 |
| 2020 | Fully secure wicked identity-based encryption resilient to continual auxiliary- inputs leakage
Hong-xia Hou, Bo Yang 0003, Yanwei Zhou, Meijuan Huang |
J. Inf. Secur. Appl. | 4 |
| 2020 | Novel updatable identity-based hash proof system and its applications
Yanwei Zhou, Bo Yang 0003, Tao Wang 0039, Yi Mu 0001 |
Theor. Comput. Sci. | 1 |
| 2020 | Identity-based encryption with leakage-amplified chosen-ciphertext attacks security
Yanwei Zhou, Bo Yang 0003, Zhe Xia, Mingwu Zhang, Yi Mu 0001 |
Theor. Comput. Sci. | 1 |
| 2019 | Provably Secure Proactive Secret Sharing Without the Adjacent Assumption
Zhe Xia, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang, Hua Shen 0002, Yi Mu 0001 |
ProvSec | 3 |
| 2019 | Continuous Leakage-Resilient Identity-Based Encryption with Tight SecurityabstractAbstract In the actual applications, an adversary can break the security of cryptography scheme through various leakage attacks (e.g. side-channel attacks, cold-boot attacks, etc.), even the continuous leakage attacks. That is, a practical cryptography scheme must maintain its claimed security in the continuous leakage setting. However, the previous constructions on the leakage-resilient identity-based encryption (IBE) scheme could tolerate a leakage that is bounded, and cannot resist the continuous leakage attacks. In order to further achieve the better security, a novel method to build the continuous leakage-resilient IBE scheme with tight security is presented in this paper, and the scheme’s security is proved, in the standard model, based on a stronger security assumption that depends on the number of queries made by the adversary. In addition, our proposal has several advantages over previous such constructions, e.g. shorter public parameters, higher communication efficiency, tight security, etc. Yanwei Zhou, Bo Yang 0003, Hong-xia Hou, Lina Zhang 0003, Tao Wang 0039, Mingxiao Hu |
Comput. J. | 1 |
| 2019 | Continuous leakage-resilient identity-based encryption with leakage amplification
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001 |
Des. Codes Cryptogr. | 1 |
| 2019 | Identity-based encryption resilient to continuous key leakageabstractLeakage of private information has become a threat to the security of computing systems. It has become a common security requirement that a cryptography scheme should withstand various leakage attacks, even the continuous leakage attacks. However, in the current constructions on the (continuous) leakage‐resilient identity‐based encryption (CLR‐IBE) scheme, the leakage parameter is a fixed value. Aiming to solve these problems, in this study, the authors show how to construct the CLR‐IBE scheme, and the adaptive chosen‐ciphertext attacks security of proposed construction can be proved in the standard model. To further improve the practicability of CLR‐IBE scheme, they design an improved IBE scheme with continuous leakage amplified property, and the leakage parameter has an arbitrary length. Yanwei Zhou, Bo Yang 0003, Yi Mu 0001, Tao Wang 0039, Xin Wang 0058 |
IET Inf. Secur. | 1 |
| 2019 | An Approach Enabling Various Queries on Encrypted Industrial Data StreamabstractMassive data are generated and collected by devices in the industrial Internet of Things. Data sources would encrypt the data and send them to the data center through the gateway. For some supervision purpose, the gateway needs to observe the encrypted data stream and label the suspicious data. Instead of decrypting ciphertext at the gateway, which is not efficient, this paper presents a Φ -searchable functional encryption scheme that supports inner product evaluations on encrypted data. Based on this scheme, an approach enabling various queries on the encrypted industrial data stream is proposed. The adaptive security of our proposed underlying functional encryption scheme can be proven under general subgroup decision assumptions, and our scheme has the smaller public key, the smaller secret key, and the smaller ciphertext size compared to the related schemes. In addition, the experimental results show that our proposed scheme is efficient. Especially for the gateway, querying on the encrypted data only needs less than 20ms, which is practical for industrial data stream auditing scenario. Tao Wang 0039, Bo Yang 0003, Guoyong Qiu, Lina Zhang 0003, Yong Yu 0002, Yanwei Zhou, Juncai Guo 0001 |
Secur. Commun. Networks | 6 |
| 2019 | The generic construction of continuous leakage-resilient identity-based cryptosystems
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001 |
Theor. Comput. Sci. | 1 |
| 2018 | Verifiable Secret Sharing Based on Hyperplane Geometry with Its Applications to Optimal Resilient Proactive Cryptosystems
Zhe Xia, Liuying Sun, Bo Yang 0003, Yanwei Zhou, Mingwu Zhang |
ACISP | 4 |
| 2018 | Continuous leakage-resilient access control for wireless sensor networks
Yanwei Zhou, Bo Yang 0003, Yi Mu 0001, Zhe Xia |
Ad Hoc Networks | 1 |
| 2018 | Continuous Leakage-Resilient Identity-Based Encryption without Random OraclesabstractProvably secure identity-based encryption (IBE) schemes in the presence of key-leakage have attracted a lot of attention recently. However, most of them were designed in the bounded-leakage model, and might not be able to meet the claimed security under the continuous-leakage attacks. The main issue is that the most of previous leakage-resilient IBE schemes could not ensure the randomness of all elements in the ciphertext, because some elements can be written as a function on the private key of user; therefore, the adversary can obtain the leakage on the private key of user from the corresponding given ciphertext. In this paper, a new construction of CCA-secure IBE scheme tolerating continuous-leakage attacks in the standard model is proposed, and its security is proved in the selective-ID security model based on the hardness of decisional bilinear Diffie–Hellman assumption, which is a classical static assumption. In our construction, the adversary cannot obtain any leakage on the private key from the corresponding ciphertext, since all elements in the ciphertext are random in the adversary’s view. The striking advantage of our constructions is the key leakage ratio, which is the best one among the previous leakage-resilient IBE constructions. Yanwei Zhou, Bo Yang 0003, Yi Mu 0001 |
Comput. J. | 1 |
| 2018 | Leakage-resilient CCA2-secure certificateless public-key encryption scheme without bilinear pairing
Yanwei Zhou, Bo Yang 0003 |
Inf. Process. Lett. | 1 |
| 2018 | Updatable Identity-Based Hash Proof System Based on Lattices and Its Application to Leakage-Resilient Public-Key Encryption Schemes
Qiqi Lai, Bo Yang 0003, Yong Yu 0002, Zhe Xia, Yanwei Zhou, Yuan Chen 0008 |
J. Comput. Sci. Technol. | 5 |
| 2018 | Aleakage-resilient certificateless public key encryption scheme with CCA2 securityabstractIn recent years, much attention has been focused on designing provably secure cryptographic primitives in the presence of key leakage. Many constructions of leakage-resilient cryptographic primitives have been proposed. However, for any polynomial time adversary, most existing leakage-resilient cryptographic primitives cannot ensure that their outputs are random, and any polynomial time adversary can obtain a certain amount of leakage on the secret key from the corresponding output of a cryptographic primitive. In this study, to achieve better performance, a new construction of a chosen ciphertext attack 2 (CCA2) secure, leakage-resilient, and certificateless public-key encryption scheme is proposed, whose security is proved based on the hardness of the classic decisional Diffie-Hellman assumption. According to our analysis, our method can tolerate leakage attacks on the private key. This method also achieves better performance because polynomial time adversaries cannot achieve leakage on the private key from the corresponding ciphertext, and a key leakage ratio of 1/2 can be achieved. Because of these good features, our method may be significant in practical applications. Yanwei Zhou, Bo Yang 0003 |
Frontiers Inf. Technol. Electron. Eng. | 1 |
| 2017 | An Efficient Key-Policy Attribute-Based Searchable Encryption in Prime-Order Groups
Ru Meng, Yanwei Zhou, Jianting Ning, Kaitai Liang, Jinguang Han, Willy Susilo |
ProvSec | 2 |
| 2017 | Continuous Leakage-Resilient Public-Key Encryption Scheme with CCA SecurityabstractIn recent years, much attention has been focused on designing provably secure public-key encryption (PKE) scheme in the presence of key-leakage. However, most of them are researched in the bounded-leakage model, and cannot keep their claimed security in the continuous leakage setting. What's more, most of traditional leakage-resilient PKE schemes cannot ensure that all of elements in ciphertext are random from the adversary's view, and any polynomial time adversary can get leakage on the secret key from the corresponding ciphertext. But, in the real world, an adversary can trivially break the security of PKE scheme under the continuous leakage attacks. To get an efficient PKE scheme which can keep its original security in the continuous-leakage model, we propose a new construction of chosen-ciphertext attacks secure PKE scheme, and whose security is based on the hardness of the classical decisional Diffie–Hellman assumption and the target collision resistance of the hash function. Our method not only can tolerate continuous leakage attacks on the secret key through key update operation, but also enjoys better performances, such as the round leakage parameter λC≤logq−ω(logk) (k is the security parameter, q is a big prime order of the underlying group.) is independent of the plaintext space, and has the constant size, also, any polynomial time adversary unable to obtain leakage on the secret key from the corresponding ciphertext, etc. Because of these good performance features, our proposal may have some significant value in the practical applications. Yanwei Zhou, Bo Yang 0003 |
Comput. J. | 1 |
| 2017 | Continuous leakage-resilient certificateless public key encryption with CCA security
Yanwei Zhou, Bo Yang 0003 |
Knowl. Based Syst. | 1 |
| 2016 | Provably secure and efficient leakage-resilient certificateless signcryption scheme without bilinear pairing
Yanwei Zhou, Bo Yang 0003, Wenzheng Zhang 0001 |
Discret. Appl. Math. | 1 |
| 2016 | CCA2 secure public-key encryption scheme tolerating continual leakage attacksabstractAbstract For a public‐key encryption scheme to be applied in practical applications, it should withstand various leakage attacks (e.g., side‐channel attacks and cold‐boot attacks). To this end, we present a way of construct the more practical CCA2 secure public‐key encryption scheme tolerating leakage attacks, and the scheme's security is based on the hardness of classical decisional Diffie–Hellman assumption and the target collision resistant of one‐way hash function. Additionally, our proposal enjoys better performance, for example, all of elements of ciphertext will be random from the adversary's view, and any probabilistic polynomial‐time adversary cannot obtain leakage on the secret key from the ciphertext, and so on. In the bounded‐leakage setting, for any leakage parameter λ⩽logq − ω(logk)(q is the prime order of the underlying group, and k denotes the security parameter.), our proposal is secure against leakage‐resilient chosen‐ciphertext attacks, where λ is independent of the plaintext space, and has the constant size. However, in the real world, an adversary can continuously learn information on the secret key through a variety of leakage attacks and can trivially break the security of public‐key encryption scheme under the continual leakage attacks. Thus, we will improve our method to resist the continual leakage attacks. Similarly, for any round leakage parameter λC⩽logq − ω(logk), we can prove the security of the improvement scheme based on the hardness of decisional Diffie–Hellman assuming and the target collision resistant of one‐way hash function. With this important performance, our proposal may have some significant value in the practical applications, such as our proposal can provide the leakage‐resilient security for outsourcing data in the cloud computing environment. Copyright © 2016 John Wiley & Sons, Ltd. Yanwei Zhou, Bo Yang 0003, Wenzheng Zhang 0001, Yi Mu 0001 |
Secur. Commun. Networks | 1 |