EDBT 2026 Demo / reviewers in the wild / expert
Liangmin Wang 0001
dblp:53/10765-1 · also Liang-Min Wang 0001
· DBLP profile ↗
101ranked-venue papers
6as first author
60since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 38 · 2 first-author · 16 since 2021Security and privacy · 21 · 13 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 2 first-author · 10 since 2021Systems, architecture and hardware · 9 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 8 · 6 since 2021Artificial intelligence and machine learning · 7 · 6 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PidTree: A Pseudonym-Only Approach for Anonymous AKA in Vehicular NetworksabstractIn vehicular networks, pseudonyms are a fundamental mechanism for achieving anonymous communication. However, existing Authentication and Key Agreement (AKA) schemes typically require each pseudonym to be cryptographically bound to private information, such as a certificate or a secret key, to ensure authenticity. This approach leads to significant challenges, including complex certificate management and the inherent risks of secret key escrow. Furthermore, to maintain unlinkability, vehicles must store a large pool of pseudonyms and their associated private information–leading to prohibitive storage costs. The high computation and communication costs of such schemes are also ill-suited for the delay-sensitive nature of vehicular environments. To address these limitations, we propose a pseudonym-only approach for anonymous AKA in vehicular networks. The primary contribution of our scheme is its novel "pseudonym-only" approach to authentication, without the need to combine it with other private information. PidTree provides an efficient pseudonym generation method. Our scheme involves lightweight computation operations such as hash functions and Lagrange interpolation. The security analysis shows that our scheme satisfies the essential security and privacy requirements of vehicular networks. Our scheme reduces the storage cost for the trusted party fromO(MN)toO(M)and the storage cost for a vehicle by at least 86.50%. The performance analysis also shows that our scheme outperforms the representative schemes in terms of computation cost and simulation results. Jinyu Fan, Yuling Chen 0002, Xia Feng, Liangmin Wang 0001 |
IEEE Internet Things J. | 5 |
| 2026 | TolerStore: Tolerating Malicious Nodes in Decentralized Storage NetworkabstractA decentralized storage network (DSN) collects idle storage resources from Internet nodes for low-cost rental to users, and its scale has grown exponentially. In a DSN, most users rely on a centralized third-party service provider (SP) to process userside data and interact with decentralized storage nodes (SNs), making users suffer from a single point of failure. Additionally, since both SP and SNs may offer malicious services, enabling fault tolerance, data confidentiality, and availability guarantee with public verifiability is crucial in the presence of such threats. In this paper, we propose TolerStore, a completely decentralized service framework for DSNs with decentralized SPs and SNs, which can tolerate Byzantine SPs and malicious SNs. To the best of our knowledge, TolerStore is the first to develop a blockchain with multiple SPs for privacy-aware data processing in DSNs, which is formally proven to ensure Byzantine fault tolerance, data confidentiality, public verification, and data availability. Furthermore, we propose an optimized Byzantine Fault-Tolerant consensus with an adaptive leader rotation, incorporating homomorphic fingerprints to verify privacy-aware data processing with enhanced performance. We implement a TolerStore prototype over Hyperledger Fabric, and extensive experiments show that it tolerates [$\frac{N-1}{3}$] Byzantine SPs and 50% malicious SNs with up to 99.99% data availability. Wanning Bao, Liangmin Wang 0001, Haiqin Wu, Dian Shen, Boris Düdder |
IEEE Trans. Computers | 2 |
| 2026 | Dual-Verifiable Federated Learning With Vector Commitments Against Collusion AttacksabstractCollusion attacks, where the server and malicious clients collaborate to bypass gradient source confirmation or tamper with aggregation results, cause a fundamental damage to the training process in federated learning (FL). However, existing verifiable FL frameworks typically adopt a split-verification model-clients can independently validate the correctness of aggregation results, while the server is responsible for confirming the legitimacy of gradient sources. Thus, the collusion attack has emerged as a critical and intractable vulnerability, as it completely collapses this split-verification model, thereby invalidating such verification mechanisms. To tackle this fundamental issue, we propose an innovative dual-verifiable FL framework. Specifically, by leveraging vector commitments, our scheme first integrates both gradient source confirmation and aggregation result verification into a unified framework. Based on this unified design, our scheme implements two targeted strategies to defend against collusion attacks. To prevent collusion-enabled gradient source spoofing, our scheme introduces a semi-trusted verification cluster in place of unreliable server-side validation and embeds an anonymized identity-check strategy to collaboratively confirm gradient source legitimacy. To counter collusion-driven manipulation of gradient aggregation results, our scheme customizes auxiliary verification proofs with a computational one-wayness for client-uploaded gradients. This renders it infeasible for adversaries to tamper with the aggregation result through reverse engineering. Under experiments and security analyses, our scheme achieves reliable dual-verification and robust resistance to collusion attacks. Moreover, it reduces computation and communication overhead by at least 40.83% and 50.47%, respectively, compared to state-of-the-art verifiable FL schemes. Kaiping Cui, Xia Feng, Liangmin Wang 0001, Zhiquan Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | SCZ-HA: A Seamless Cross-Zone Handover Authentication Scheme for V2I Communication
Xia Feng, Ruomeng Lin, Kaiping Cui, Liangmin Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | BFCrowd: Federated Crowdsourcing With Privacy-Aware and Fine-Grained Task Matching via BlockchainabstractNowadays, crowdsourcing has evolved into a cost-efficient and scalable task execution paradigm that benefits both task requesters and workers. Task matching is a crucial crowdsourcing procedure for deciding the task execution quality, but security and privacy concerns arise as the crowdsourcing platform cannot be fully trusted. Existing privacy-aware task-matching schemes are limited to intra-platform central matching in the semi-honest model and coarse-grained keyword/location-based matching over one single attribute. Solutions supporting secure cross-platform and fine-grained task matching in the malicious model are urgently needed. In this paper, we first formally defined BFCrowd, a federated crowdsourcing system built on a consortium blockchain. BFCrowd aggregates multi-platform resources and enables decentralized and reliable cross-platform task matching using smart contracts, in the presence of malicious workers and platforms. Notably, we design a fully secure ciphertext-policy attribute-based encryption scheme with concealed access policies and user-side lightweight decryption, which thoroughly caters to the dual-side privacy demand and resource-limited workers and serves for fine-grained expressive task matching over multiple attributes. Moreover, it supports comparison over numerical attributes. Formal security analysis proves the desirable privacy guarantees in the standard model and collusion resistance. Extensive experiments implemented atop Hyperledger Fabric demonstrate both on-chain and off-chain performance. Haiqin Wu, Boris Düdder, Zihan Wu 0003, Shunrong Jiang, Liangmin Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | DIBA: Effective Transaction Topology-Based Detection of Illicit Bitcoin AddressesabstractBitcoin, as the most valuable cryptocurrency, has become a significant target for criminal activities, leading to substantial financial losses. To timely detect criminal activities and reduce losses, the accurate detection of illicit addresses is crucial. Current research typically involves extracting features from addresses to classify them as either licit or illicit. However, they neglect the transaction topology information associated with the addresses, thereby compromising the efficiency. In this article, we focus on improving the utilization of address information and propose DIBA detector, an effective framework designed for the automatic D etection of I llicit B itcoin A ddresses. DIBA first incorporates a transaction graph construction module that constructs per-address transaction graph based on UTXO model, thereby mapping to the transaction topology for each address. Subsequently, a novel hybrid spatiotemporal network is designed to learn graph representation for each per-address transaction graph, generating comprehensive graph embeddings that serve as critical inputs for the final classification model. Experimental results demonstrate that our proposed framework outperforms existing state-of-the-art methods for detecting illicit Bitcoin addresses, achieving precision and F1-score values of 92.77% and 93.58%, respectively. As a side contribution, we construct a dataset comprising over 180,000 addresses, with half labeled as licit and half as illicit. Our dataset is released at https://github.com/dlvlb123/DIBA . Chunyu Duan, Jiadong Shi, Liangmin Wang 0001 |
ACM Trans. Knowl. Discov. Data | 4 |
| 2026 | SAPE: A Scalable Aggregation With Parallel Encoder for Federated Learning in VANETsabstractFederated Learning (FL) has recently gained prominence in the context of Vehicular Ad-hoc Networks (VANETs) as a promising approach to enhancing autonomous driving capabilities. However, vehicles' high mobility, real-time communication, and dynamic network topology lead to frequent disconnections during operation, which may slow down the convergence of FL or even lead to training failure. In this study, we propose a scalable aggregation scheme (SAPE) designed to improve computation efficiency and address vehicle dropouts. SAPE employs a lossless encoding algorithm with parallel technology for efficient aggregation of large vectors. Then, we leverage TJL (ACSAC '22) to reconstruct gradients for dropout vehicles, using online vehicles to establish a$k$-regular graph. In a network with$N$vehicles, SAPE achieves a secure aggregation overhead of$O(log^{2}(N))$, as opposed to$O(N^{2})$, tolerating a vehicle dropout rate of up to 33%. Furthermore, we conduct a theoretical security analysis of SAPE to prove its security under honest-but-curious (HBC) and malicious attack models. Extensive experiments show that SAPE outperforms existing baseline aggregation schemes by up to 1.4× speedups in aggregation time. Xia Feng, Wenhao Cheng, Huijuan Zhu 0001, Zhiquan Liu 0001, Liangmin Wang 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2026 | Amoeba: Defending Against Deep Website Fingerprinting Attacks With GAN-Based Trace Generative ModelabstractDeep neural network-based website fingerprinting (WF) attacks have significantly threatened anonymous communication systems, like The Onion Router (Tor). WF defense methods based on adversarial learning techniques offer potential resistance against deep WF attacks. However, existing defenses primarily focus on packet-level perturbations, often neglecting fine-grained perturbations at the packet interval-level. In this paper, we present a novel WF defense method, called Amoeba, which is designed to generate traces that incorporate both packet-level and packet interval-level perturbations to defend against deep WF attacks while maintaining controllable overhead. Amoeba employs a two-stage framework: in the first stage, it learns the trace patterns by adversarial learning techniques with Wasserstein Generative Adversarial Networks (WGAN). The second stage introduces a dynamic cost control mechanism to pad dummy packets into normal traces to perturb trace patterns with low bandwidth overhead and time costs. Furthermore, we collect a new Tor trace dataset with Tor anonymous communication system and conduct extensive experiments on both a public dataset and our collected dataset. Experimental results demonstrate that Amoeba can reduce the classification accuracy of deep WF attacks from over 90% to below 40%, and outperform existing defenses. Moreover, Amoeba has over 4% bandwidth overhead and 13% time costs reduction than existing defenses, which shows the effectiveness and superiority of Amoeba in resisting deep WF attacks compared to existing methods. Qiang Zhou 0010, Yahan Lyu, Liangmin Wang 0001, Jiadong Shi |
IEEE Trans. Netw. | 3 |
| 2025 | CLEP: A Novel Contrastive Learning Method for Evolutionary Reentrancy Vulnerability DetectionabstractReentrancy vulnerabilities in smart contracts have been exploited to steal enormous amounts of money, thus detecting reentrancy vulnerabilities is a hotspot issue in security research. However, a new attack is emerging in which attackers continuously release new reentrancy patterns to exploit fresh vulnerabilities and obfuscate existing ones. Existing detection methods neglect the time-series evolution of vulnerabilities across different smart contract versions, leading to a gradual decline in their effectiveness over time. We investigate the time-series correlations among vulnerabilities in various versions and refer to these as Evolutionary Reentrancy Vulnerabilities (ERVs). We summarize that ERVs detection faces two key challenges: (i) capturing the evolving pattern of ERVs along a complete evolutionary chain and (ii) detecting fresh reentrancy vulnerabilities in new versions. To address these challenges, we propose CLEP, a novel Contrastive Learning with Evolving Pairs detection method. It can effectively capture the evolving patterns by discerning similarities and differences across versions. Specifically, we first modified the sample distribution by incorporating version declarations as time-series evolution information. Then, leveraging the hierarchical similarity, we design an evolving pairs scheme to form negative and positive contract pairs across versions. Finally, we build a complete evolutionary chain by proposing a version-aware contrastive sampler. Our experimental results show that CLEP not only outperforms state-of-the-art baselines in version-specific scenarios but also shows promising performance in cross-version evolution scenarios. Jie Chen 0099, Liangmin Wang 0001, Huijuan Zhu 0001, Victor S. Sheng |
AAAI | 2 |
| 2025 | Multiscale fingerprinting for robust website fingerprinting attackabstractAbstract Website fingerprinting (WF) attacks based on deep neural networks can effectively identify the target website. Recently, WF defence methods with trace adversarial examples (DTAE) can reduce classification accuracy of existing deep WF attacks from over 98% to approximately 50%. To overcome the vulnerability of deep WF attacks in classifying traces defended by adversarial examples, we propose a novel WF attack method specially designed for DTAE, called multiscale fingerprinting (MF). Specifically, MF slices each trace with different time slots to build a multi-channel matrix as the model input, and utilizes a multiscale convolutional neural network to extract the real trace patterns, which are changed and complicated by DTAE. Furthermore, we evaluate the performance of MF in closed- and open-world scenarios on the public dataset. In the closed-world scenario, MF achieves superior performance on DTAE methods, exhibiting an improvement of 12.32% over the state-of-the-art DTAE. In the open-world scenario, MF attains better performance on defended traces on Recall and Precision metrics, which demonstrates the enhanced robustness compared to existing deep WF attacks. Jiadong Shi, Qiang Zhou 0010, Liangmin Wang 0001 |
Comput. J. | 4 |
| 2025 | U'Dedup: Updatable Block-Level Deduplication Scheme Over Similar Data in Fog-Assisted Cloud StorageabstractFog-assisted cloud storage enables efficient collection and management of Internet of Things data, while large-scale data raise severe requirements for storage space. Deduplication schemes over similar data have been investigated to relieve the storage pressure. However, existing schemes are designed based on an idealized assumption that users can accept a certain degree of data loss or the stored data modification. When the uploaded data reaches the preset similarity threshold, only one copy will be stored, which causes data loss. Meanwhile, different dynamic operations on only one copy will cause the stored data modification. In this paper, we propose U’Dedup to address the above challenge, which is the first block-level deduplication scheme over similar data. The key component of U’Dedup is a self-built tree data structure that supports different update requirements to avoid data modification without duplicating the stored data. U’Dedup ensures the completeness of all unique data to avoid data loss and constructs a dual deduplication architecture to relieve the computing pressure of cloud. Finally, the security analysis proved that U’Dedup is secure in the random oracle model. Experimental results show that U’Dedup achieves 57.3% 90.6% upload computation cost saving, and at least 9.5× retrieval computation cost reduction. Liangmin Wang 0001 |
IEEE Internet Things J. | 3 |
| 2025 | FECAC: Fine-Grained and Efficient Capability-Based Access Control for Enterprize-Scale IoT SystemsabstractIn enterprize-scale Internet of Things, users need to query data by accessing the resource-constrained smart nodes. Such queries typically include data from one node (DON), and data from one catalog of multiple nodes (DOC). Traditional access control mechanisms often prove inadequate due to the lack of efficient policy management. Their authorization time for queries is linear with respect to the number of access control rules in the policy, which greatly impedes access granularity, efficiency, and scale. To address this issue, we propose FECAC, a fine-grained and efficient capability-based access control mechanism for DON and DOC access queries. Specifically, FECAC builds a policy matching tree structure by translating the rule into matching properties in the tree node, which avoids authorizing queries by traversing the entire rule collection. We then introduce an authorization scheme to match the elements of access requests in a top-down manner, and check the rules with the internal properties of the data queries sublinearly, which efficiently combines the requests of DOC and DON. Further, we give a concrete operation of FECAC from query authorization scheme to execute data querying based on capabilities. Finally, we demonstrate the improved and more stable evaluation efficiency of FECAC compared to existing schemes. Xia Feng, Liangmin Wang 0001, Haiqin Wu, Boris Düdder |
IEEE Internet Things J. | 3 |
| 2025 | CVCQ: Off-Chain Committee-Based Verifiable Cross-Chain Query Scheme for Large-Scale BIoTabstractBlockchain with the Internet of Things (BIoT) denotes that the blockchain system is used for managing node identities in centerless IoT. Large-scale BIoT (L-BIoT) means many blockchains are used for managing node identities from different IoTs. The verifiable query scheme for BIoT was widely discussed in real-time IoT system. However, the query scheme will require cross-chain operations when BIoT expands into L-BIoT. Cross-chain verifiable query schemes for BIoT exist two issues. 1) Multiround Consensus: Cross-chain query requires the relay chain and related chains to participate in consensus, and each interaction requires initiating one consensus round. 2) High-Overhead Verification: Each data item returned by various blockchains requires individual integrity verification. We propose CVCQ, an off-chain committee (OC)-based verifiable cross-chain query scheme for L-BIoT. CVCQ achieves only one-round consensus by shifting the on-chain data query and consensus to an OC. Meanwhile, the aggregation accumulator and proofs are utilized to verify data integrity, ensuring the low-overhead verification. We proved that CVCQ reduces complexity of consensus from$O(m^{\lambda +1}+m\cdot N^{\lambda })$to$O(m^{\lambda })$, and decreases the computational complexity of verification from$O(m\log n)$to$O(1)$, when cross-chain data query involving m regional IoTs with N nodes and n data. The experiment results show that CVCQ outperforms the existing schemes by achieving higher on-chain throughput and lower latency. Lu Liu 0001, Liangmin Wang 0001, Zhan Xie, Cunzheng Zhang, Pengyan Liu |
IEEE Internet Things J. | 4 |
| 2025 | GAM: A scalable and efficient multi-chain data sharing scheme
Zihan Wu 0003, Liangmin Wang 0001 |
Inf. Process. Manag. | 3 |
| 2025 | SmartGuard: Making Prediction Verifiable Through Transaction Sequences for Smart Contract Vulnerability DetectionabstractDeep learning-based detectors have been widely proposed to predict vulnerabilities in smart contracts, yet their unreliable predictions pose severe security risks to financial transactions, making it critical to verify the reliability of vulnerability predictions. However, existing methods only produce prediction results, failing to provide an evidence chain to check whether these predicted vulnerabilities genuinely exist and deliver further guidance for fixing the vulnerabilities. Thus, making these vulnerability predictions verifiable remains an unexplored problem. In this paper, we propose SmartGuard, a novel verifiable vulnerability prediction framework for deep learning-based detectors and specifically designed for smart contracts. It integrates a deep learning-based detector with a symbolic prediction validator, where the latter acts as the backend formal engine to verify vulnerability predictions. Specifically, we present a graph-sequence multi-task learning model to detect vulnerabilities while generating transaction sequences that serve as evidence chains, explicitly revealing the triggering logic behind vulnerabilities. To bridge the gap between deep learning-based detectors and symbolic validators, we symbolically execute the generated transaction sequences against the verification conditions of vulnerability predictions. Furthermore, we propose a new metric, Vulnerability Prediction Suspiciousness (VPS), to evaluate the reliability of the predicted results. We implement SmartGuard on three representative types of vulnerabilities (Reentrancy, Ether-leaking, and Suicidal) to evaluate its performance in real-world scenarios. Our experimental results show that SmartGuard can effectively verify doubtful vulnerability predictions in real-world scenarios. It also outperforms state-of-the-art baselines by consistently reducing false reports by at least 15% across various Solidity versions. Case studies on complex contracts and DApps further demonstrate SmartGuard’s effectiveness in practice. Jie Chen 0099, Liangmin Wang 0001, Huijuan Zhu 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Demo: An End-to-End Anonymous Traffic Analysis SystemabstractNetwork crimes committed through anonymous networks pose significant challenges to regulators.Identifying different types of traffic and implementing effective supervision are crucial for maintaining network security.In this demo, we present an end-to-end anonymous traffic analysis system that integrates traffic capturing, protocol parsing, feature extraction, traffic classification, and analysis result presentation, enabling comprehensive analysis of traffic on routers from end to end.Our system can be deployed on the data center network to capture network traffic routed by the routers.It automatically analyzes Tor network traffic, HTTPS encrypted traffic, and Tor network App traffic, identifies the target website or App type associated with the traffic, and displays the identification results via the visual interface. Xianglan Huang, Qiang Zhou 0010, Liangmin Wang 0001, Weiqi Yu, Shi Shen |
CCS | 3 |
| 2024 | CASAR: Cross Uc-domain Authentication Scheme with Attack Resistance for SUNetabstractSatellite-assisted Unmanned-Aerial-Vehicle Network (SUNet) is an emerging network leveraging satellite communication to boost UAV connectivity and coverage in remote or challenging environments. In SUNet, UAVs frequently require cross Uncontrollable-domain (Uc-domain) authentication, which refers to UAVs from their controlled domains authenticating with the Uc-domain entities, such as UAVs authenticating with allied forces in the Uc-domain for military applications. Unlike handover authentication and traditional cross-domain authentication, cross Uc-domain authentication confronts more complex security environments. Specifically, there is the problem with the absence of identity information and the need for enhanced attack resistance and overhead reduction. In this paper, we present CASAR, the first cross Uc-domain authentication scheme for SUNet. CASAR leverages satellites to assist in transmitting authentication messages and combines Physical Unclonable Function (PUF) and chaotic map to ensure optimal resistance to attacks and maintain lightweight overhead. We prove that CASAR can robustly defend against various attacks targeting UAV networks. The experimental results show that CASAR has less overhead than related works. Renmin Zhao, Liangmin Wang 0001 |
GLOBECOM | 2 |
| 2024 | Tor Trace in Images: A Novel Multi-Tab Website Fingerprinting Attack With Object DetectionabstractAbstract Website fingerprinting (WF) attacks on Tor enable a passive adversary to predict the encrypted web browsing activity of a victim by matching the eavesdropped traffic with pretrained classifiers. Nowadays, deep learning-based methods have led to significant achievements in the single-tab Tor WF attack. However, the practical implementation of these single-tab methods is challenging due to most real-world Tor traffic involving multiple tabs. Existing single-tab methods hardly identify multi-tab WF due to the overlapping areas of the traffic trace confusing the original features. In this paper, we propose a Trace Image-based Object Detection model named TIOD as a novel multi-tab attacking model. Specifically, we model the traffic overlap in Tor as the object overlap in object detection tasks from the computer vision field. Besides, we propose a special S-matrix scheme to convert a trace into an image: (i) Retaining the original features by keeping the direction and order of the cells and (ii) Bringing cells of the same page closer together in space. We then utilize a specially designed object detection model for trace images, WF R-CNN, to extract features and identify potential destination websites within multi-tab traces. Comparative analysis with other multi-tab attacks is conducted, and the empirical results consistently underscore the superior performance of the proposed trace image model across diverse datasets. In the two-tab setting, TIOD achieves the best accuracy with more than 85% on both the first and second tabs. Liangmin Wang 0001, Jie Chen 0099, Qiang Zhou 0010 |
Comput. J. | 2 |
| 2024 | Joint Alignment Networks For Few-Shot Website Fingerprinting AttackabstractAbstract Website fingerprinting (WF) attacks based on deep neural networks pose a significant threat to the privacy of anonymous network users. However, training a deep WF model requires many labeled traces, which can be labor-intensive and time-consuming, and models trained on the originally collected traces cannot be directly used for the classification of newly collected traces due to the concept drift caused by the time gap in the data collection. Few-shot WF attacks are proposed for using the originally and few-shot newly collected labeled traces to facilitate anonymous trace classification. However, existing few-shot WF attacks ignore the fine-grained feature alignment to eliminate the concept drift in the model training, which fails to fully use the knowledge of labeled traces. We propose a novel few-shot WF attack called Joint Alignment Networks (JAN), which conducts fine-grained feature alignment at both semantic-level and feature-level. Specifically, JAN minimizes a distribution distance between originally and newly collected traces in the feature space for feature-level alignment, and utilizes two task-specific classifiers to detect unaligned traces and force these traces mapped within decision boundaries for semantic-level alignment. Extensive experiments on public datasets show that JAN outperforms the state-of-the-art few-shot WF methods, especially in the difficult 1-shot tasks. Qiang Zhou 0010, Liangmin Wang 0001, Huijuan Zhu 0001, Heping Song |
Comput. J. | 2 |
| 2024 | Co-Sharding: A Sharding Scheme for Large-Scale Internet of Things ApplicationabstractBlockchain technology finds widespread application in the management of Internet of Things (IoT) devices. In response to the challenges posed by performance scalability and the convergence of multiple ledgers stemming from an expanding network, this study introduces the concept of Co-Sharding . Within this framework, the ledger maintained by sub-chains overseeing IoT operations in distinct geographic regions is conceptualized as a shard within the Large-scale Internet of Things (LIoT) ledger. Meanwhile, elected nodes within each region assume responsibility for maintaining a coordinating shard, facilitating cross-regional communication and data interaction. Furthermore, our work presents a multi-objective optimization algorithm grounded in the multi-shard paradigm to enact a scheduling strategy that spans various regions. We undertake a series of pertinent experiments and conduct a comparative analysis of scheduling algorithms within the context of a real-world cross-regional agricultural IoT system, utilizing actual operational data. The comparative results demonstrate that, in comparison to intra-sub-region scheduling, the Co-Sharding approach enhances machine utilization rates by approximately 30% and reduces scheduling time by around 18% when confronted with a task count of 12. In terms of performance, Co-Sharding also exhibits the capability to reduce the storage requirements of lightweight nodes within each region by approximately 39% while concurrently improving throughput by approximately 1.5 times when contrasted with a single-chain architecture. Zihan Wu 0003, Liangmin Wang 0001, Xiao Chen 0003, Lu Liu 0001 |
Distributed Ledger Technol. Res. Pract. | 4 |
| 2024 | IDPonzi: An interpretable detection model for identifying smart Ponzi schemes
Xia Feng, Qichen Shi, Xingye Li, Liangmin Wang 0001 |
Eng. Appl. Artif. Intell. | 5 |
| 2024 | Physical Layer Covert Communication in B5G Wireless Networks - its Research, Applications, and ChallengesabstractPhysical layer covert communication is a crucial secure communication technology that enables a transmitter to convey information covertly to a recipient without being detected by adversaries. Unlike typical cryptography and physical layer security systems that concentrate on protecting the sent signal content, covert communications seek to conceal the existence of legitimate transmission. Thus, with beyond fifth-generation (B5G) wireless communications, covert communications can operate in tandem or as a supplement to conventional security techniques. We provide an extensive overview of the basic theories and several strategies in physical layer covert communications in this article. In particular, we go into great detail about the basic theories of physical layer covert communications, such as channel models, codes, secret keys, and covertness metrics, as well as various covert schemes in progressively more complicated scenarios, such as covert communications in single-antenna and multiantenna three-node systems and covert communications in jammer-and relay-aided systems. In addition, we identify the challenges and future directions for research on covert communications in B5G wireless networks. Yu'e Jiang, Liangmin Wang 0001, Hsiao-Hwa Chen, Xuemin Shen |
Proc. IEEE | 2 |
| 2024 | Batch-Aggregate: Efficient Aggregation for Private Federated Learning in VANETsabstractFederated learning (FL) in Vehicular Ad-hoc Networks (VANETs) enables vehicles to collaboratively train machine learning models by aggregating local gradients without revealing the training data. To ensure no gradient is revealed during aggregation, proposals are using a secret sharing-based strategy. A major bottleneck for applying these proposals in VANETs is the overhead of model aggregation across high-mobility vehicles. Particularly, the communication overhead grows exponentially due to the dynamic of VANETs. In the paper, we propose Batch-Aggregate, an efficient aggregation scheme for FL coping with high mobility and unstable connections of VANETs. By encoding the linear encryption into a short group signature, we combine authentication into aggregation protocol. When a registered vehicle trains its local model and sends the masked gradients to the nearby Road-side Unit (RSU), the RSU can independently check the gradients for validity and aggregate the parameters in a batch way. Thus, the computation time of the aggregator will be reduced to$\mathcal {O}(n)$while the gradients can be aggregated in one communication round per training iteration. Moreover, our scheme provides privacy properties such as anonymity and unlinkability. The simulations show that the computation overhead of Batch-Aggregate grows linearly under the batch-enabled scheme, which reduces up to 50% over the existing schemes. Xia Feng, Qingqing Xie, Liangmin Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | FairECom: Towards Proof of E-Commerce Fairness Against Price DiscriminationabstractPrice discrimination has been empirically exposed where e-commercial platforms aim to gain additional profits by charging customers with different prices for the same product/service. This situation becomes even worse in nowadays’ Big Data era, giving the chance for service providers to leverage artificial intelligence technologies to have the deep analysis of personalized patterns, urgently calling for solutions to prevent such discriminated behaviors to protect customers’ rights. This article aims to defend against price discrimination by developing a secure and privacy-preserving solution, provable for e-commerce fairness. Using a newly designed cryptographic accumulator and public bulletin board, our system, called FairECom, allows an auditor (i.e., a customer or third-party auditor) to verify if customers are experiencing price discrimination. In particular, FairECom enables a customer to check if his payment to a product/service is identical to other customers through a privacy-preserving challenge-response protocol, for implementing the price transparency against discrimination. We implement a prototype using an Ethereum-based public bulletin board to conduct the system evaluation. Our evaluation indicates that FairECom can integrate with existing APIs provided by Ethereum and incur acceptable costs when deploying to the e-commercial systems. Tao Jiang 0017, Xu Yuan 0001, Qiong Cheng, Yulong Shen 0001, Liangmin Wang 0001, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | WF-Transformer: Learning Temporal Features for Accurate Anonymous Traffic Identification by Using Transformer NetworksabstractWebsite Fingerprinting (WF) is a network traffic mining technique for anonymous traffic identification, which enables a local adversary to identify the target website that an anonymous network user is browsing. WF attacks based on deep convolutional neural networks (CNN) get the state-of-the-art anonymous traffic classification performance. However, due to the locality restriction of CNN architecture for feature extraction on sequence data, these methods ignore the temporal feature extraction in the anonymous traffic analysis. In this paper, we present Website Fingerprinting Transformer (WF-Transformer), a novel anonymous network traffic analysis method that leverages Transformer networks for temporal feature extraction of traffic traces and improves the classification performance of Tor encrypted traffic. The architecture of WF-Transformer is specially designed for traffic trace processing and can classify anonymous traffic effectively. Furthermore, we evaluate the performance of WF-Transformer in both closed-world and open-world scenarios. In the closed-world scenario, WF-Transformer attains 99.1% accuracy on Tor traffic without defenses, better than state-or-the-art attacks, and archives 92.1% accuracy on the traces defended by WTF-PAD method. In the open-world scenario, WF-Transformer has better precision and recall on both defended and non-defended traces. Furthermore, WF-Transformer with a short input length (2000 cells) outperforms the DF method with a long input length (5000 cells). Qiang Zhou 0010, Liangmin Wang 0001, Huijuan Zhu 0001, Victor S. Sheng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | PBAG: A Privacy-Preserving Blockchain-Based Authentication Protocol With Global-Updated Commitment in IoVsabstractInternet of Vehicles (IoVs) is increasingly used as a medium to propagate critical information via establishing connections between entities such as vehicles and infrastructures. During message transmission, privacy-preserving authentication is considered the first line of defence against attackers and malicious information. To achieve a more secure and stable communication environment, ever-increasing numbers of blockchain-based authentication schemes are proposed. At first glance, existing approaches provide robust architectures and achieve transparent authentication. However, in these schemes, verifiers need to conduct real-time operations in the blockchain (e.g., querying certificates). To remedy this limit, we propose a privacy-preserving blockchain-based authentication protocol with global-updated commitment (PBAG). In PBAG, based on the issued certificates, a public global commitment is computed, and a unique evaluation proof is generated for each authorized vehicle. Instead of querying the blockchain in real-time, verifiers can independently authenticate vehicles using the global commitment that is pre-updated with the assistance of the blockchain. Moreover, our scheme proposes a dynamic update mechanism to ensure the freshness of the global commitment and evaluation proofs. Benefiting from the update mechanism, there will be an authentication failure for vehicles holding invalid certificates when using the latest global commitment, thus avoiding the time-consuming of checking the Certificate Revocation List (CRL). In terms of privacy protection, our scheme provides privacy properties such as anonymity and unlinkability. It allows anonymous authentication based on evaluation proofs and achieves traceability of identity in the event of a dispute. The simulation demonstrates that the average computation cost of verifying per message is 0.36ms under the batch-enabled mechanism, reducing by more than 63.7% compared with existing schemes. Xia Feng, Kaiping Cui, Liangmin Wang 0001, Zhiquan Liu 0001, Jianfeng Ma 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2024 | A Dynamic Analysis-Powered Explanation Framework for Malware DetectionabstractDeep learning has been widely adopted in Android malicious software (malware) detection. However, poor explanation in deep learning-based detection models severely undermines user trusts and poses a significant obstacle to their practical promotion in critical security domains. Some studies strive to uncover the rationale behind a model's decision. Unfortunately, these efforts are often hindered by the limitations of feature extraction methods, such as primarily relying on static analysis to derive separate and approximate behavioral descriptions of applications (apps). As a result, establishing a reliable interpretation for deep learning-based malware detection models remains an open issue. In this work, we propose a novel framework XDeepMal to interpret deep learning-based malware detection models. Specifically, in XDeepMal, we formulate a dynamic analysis tool XTracer+to capture runtime behaviors of apps and automatically generate their continuous behavior trajectories. Then, we propose a novel interpreter to pinpoint certainty behavior fragments that are crucial for deep learning models to make their decisions. This approach regards the identification of the most critical fragments as an optimization problem and leverages heuristic algorithms for implementation. We conduct extensive experiments on a real-world dataset to investigate the effectiveness and reliability of XDeepMal. These experiments cover intuitive case studies (malware family and individual app) and in-depth quantitative analysis. Additionally, we evaluate its coverage and efficiency. Our experimental results demonstrate that XDeepMal is capable of generating convincing interpretations for deep learning (e.g., Transformer) based models within feasible inference time, which greatly benefits security analysts in accurately comprehending why an app is identified as malware by deep learning-based detection models. Huijuan Zhu 0001, Xilong Chen, Liangmin Wang 0001, Victor S. Sheng |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2024 | VP$^{2}$2-Match: Verifiable Privacy-Aware and Personalized Crowdsourcing Task Matching via BlockchainabstractPrivacy-aware task allocation/matching has been an active research focus in crowdsourcing. However, existing studies focus on an honest-but-curious assumption and a single-attribute matching model. There is a lack of adequate attention paid to scheme designs against malicious behaviors and supporting user-side personalized task matching over multiple attributes. A few recent works employ blockchain and cryptographic techniques to decentralize the matching procedure with verifiable and privacy-preserving on-chain executions. However, they still bear expensive on-chain overhead. In this paper, we propose VP$^{2}$-Match, a blockchain-assisted (publicly) verifiable privacy-aware crowdsourcing task matching scheme with personalization. VP$^{2}$-Match extends symmetric hidden vector encryption for user-side expressive matching without compromising their privacy. It avoids costly on-chain matching by letting the blockchain only store evidence/proofs for public verifiability of the matching correctness and for enforcing fair interactions against misbehaviors. Specifically, we construct extended attribute sets and solve matching verification by an algorithmic reduction into subset verification with an accumulator for proof generation. Formal security proof and extensive comparison experiments on Ethereum demonstrate the provable security and better performance of VP$^{2}$-Match, respectively. Haiqin Wu, Boris Düdder, Shunrong Jiang, Liangmin Wang 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | MPC+: Secure, Compatible and Efficient Off-Blockchain Multi-Node Payment ChannelabstractPayment channels (PC) greatly improve blockchain scalability by allowing an unlimited number of off-chain transactions instead of committing every transaction to the blockchain. However, the payment channel structure is limited to only two nodes, which is inadequate in scenarios where one node frequently receives money from multiple nodes, such as Cafe. Recent proposals have extended the 2-node structure to a multi-node structure. Unfortunately, these approaches either require all participants to always be online, which is not realistic, or underestimate the efficiency problem of withdrawing funds, leading to higher fees and storage costs. What’s worse, the payment scope in these proposals is limited to their respective structures and is not mutually compatible. In this paper, we propose MPC+, a smart contract that enables multiple nodes to engage in off-chain transactions. MPC+ is designed to cater to scenarios where one node frequently receives money from multiple nodes, such as Cafe, shops, and more. The nodes in MPC+ can conduct off-chain transactions internally or with nodes in existing payment channel networks externally, and they only need to be online during off-chain transactions. Furthermore, MPC+ enhances the withdrawal logic through a binding strategy, effectively reducing the number of on-chain transactions required for fund withdrawals from O(n) to O(1), and it works over any blockchain system that supports Turing-complete smart contracts. The security is formally proven under the Universal Composability framework, and it is specifically implemented on the Ethereum platform. The experimental results clearly demonstrate that MPC+ surpasses other designs in terms of fees and storage costs. Longxia Huang, Liangmin Wang 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | DPFLA: Defending Private Federated Learning Against Poisoning AttacksabstractFederated learning (FL) is vulnerable to data poisoning attacks when an adversary attempts to upload poison gradients with the intent to corrupt the global model of FL. Various approaches have been proposed to counter these risks. However, it becomes challenging when one tries to preserve the privacy of FL participants and ensure robustness against data poisoning attacks. In this paper, we propose DPFLA, a novel scheme that can detect poisoning attacks without revealing the actual gradients of participants. DPFLA is a lossless aggregation scheme delicately designed for adopting masks to protect private data while extracting poisoned data features. Specifically, we first apply removable masks to the gradients outputted by each participant. Second, we aggregate the masked data and decompose them using Singular Value Decomposition (SVD) to extract specific features as well as achieve dimensionality reduction. Third, we leverage a clustering paradigm to detect poison gradients from the low dimension and eliminate them in the following training rounds. We conducted extensive experiments to demonstrate that DPFLA can detect poison gradients effectively. Additionally, the comparisons of case studies demonstrate that DPFLA outperforms the state-of-the-art methods. Xia Feng, Wenhao Cheng, Chunjie Cao, Liangmin Wang 0001, Victor S. Sheng |
IEEE Trans. Serv. Comput. | 4 |
| 2024 | A Novel Knowledge Search Structure for Android Malware DetectionabstractWhile the Android platform is gaining explosive popularity, the number of malicious software (malware) is also increasing sharply. Thus, numerous malware detection schemes based on deep learning have been proposed. However, they are usually suffering from the cumbersome models with complex architectures and tremendous parameters. They usually require heavy computation power support, which seriously limit their deployment on actual application environments with limited resources (e.g., mobile edge devices). To surmount this challenge, we propose a novel Knowledge Distillation (KD) structure—Knowledge Search (KS). KS exploits Neural Architecture Search (NAS) to adaptively bridge the capability gap between teacher and student networks in KD by introducing a parallelized student-wise search approach. In addition, we carefully analyze the characteristics of malware and locate three cost-effective types of features closely related to malicious attacks, namely, Application Programming Interfaces (APIs), permissions and vulnerable components, to characterize Android Applications (Apps). Therefore, based on typical samples collected in recent years, we refine features while exploiting the natural relationship between them, and construct corresponding datasets. Massive experiments are conducted to investigate the effectiveness and sustainability of KS on these datasets. Our experimental results show that the proposed method yields an accuracy of 97.89% to detect Android malware, which performs better than state-of-the-art solutions. Huijuan Zhu 0001, Mengzhen Xia, Liangmin Wang 0001, Victor S. Sheng |
IEEE Trans. Serv. Comput. | 3 |
| 2024 | A Survey on Security Analysis Methods of Smart ContractsabstractSmart contracts have gained extensive adoption across diverse industries, including finance, supply chain, and the Internet of Things. Nevertheless, the surge in security incidents of smart contracts over recent years has led to substantial economic losses. Therefore, ensuring the security of smart contracts has become a critical and complex challenge in both academic and industrial domains. Based on 539 real-world security incidents in the Ethereum platform and audit reports from 10 authoritative auditing institutions, we summarize 27 types of exploited security vulnerabilities and draw insights into their principles, typical cases, relevant research and recommended prevention strategies. Besides, we also gather 7 other potentially threatening vulnerability types as supplements. On this basis, we conduct an in-depth analysis of the root causes of vulnerabilities and further formulate eight safety practical rules. Moreover, we perform a comprehensive review of 178 recent papers on smart contract security analysis, classifying detection methods into formal verification, fuzz testing, machine learning, program analysis, and others. For each category, we seize the specific detection tools and analyze them comprehensively. Then, we conduct an extensive analysis and synthesis from various angles, presenting a comprehensive overview of the current research landscape in smart contract security detection. We also discuss current on-chain and off-chain repair methods. Finally, this review outlines major challenges and highlights potential areas for future research in this field. Huijuan Zhu 0001, Liangmin Wang 0001, Victor S. Sheng |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | GraBit: A Sequential Model-Based Framework for Smart Contract Vulnerability DetectionabstractThe security of smart contracts has garnered considerable attention given the potential for substantial financial losses and erosion of trust in blockchain platforms. Numerous methods have been proposed to detect vulnerabilities in smart contracts. Notably, as the number of smart contracts continues to proliferate, automated techniques based on deep learning (DL) are making remarkable progress. However, a significant challenge persists in acquiring an efficient embedding representation that is compatible with DL models with input length restrictions. In this paper, we propose a novel detection method named GraBit for identifying reentrancy vulnerability-one of the most critical vulnerabilities in smart contracts. GraBit leverages the pre-trained model GraphCodeBERT to embed both the source code and concise key data flow graphs extracted from the code. Additionally, we customize a sequential model based on Bi-directional Long Short-Term Memory and attention mechanism to effectively capture contextual semantic information. To evaluate the performance of GraBit, we conduct extensive experiments on a public large-scale dataset. Our experimental results reveal that GraBit achieves a remarkable F1-score of 94.44% in detecting reentrancy vulnerability, outperforming state-of-the-art methods. Huijuan Zhu 0001, Liangmin Wang 0001, Victor S. Sheng |
ISSRE | 3 |
| 2023 | Few-shot website fingerprinting attack with cluster adaptation
Qiang Zhou 0010, Liangmin Wang 0001, Huijuan Zhu 0001 |
Comput. Networks | 2 |
| 2023 | DIVRS: Data integrity verification based on ring signature in cloud storage
Yushu Zhang 0001, Youwen Zhu, Liangmin Wang 0001, Yong Xiang 0001 |
Comput. Secur. | 4 |
| 2023 | Android malware detection based on multi-head squeeze-and-excitation residual network
Huijuan Zhu 0001, Liangmin Wang 0001, Victor S. Sheng |
Expert Syst. Appl. | 3 |
| 2023 | A multi-model ensemble learning framework for imbalanced android malware detection
Huijuan Zhu 0001, Yang Li 0111, Liangmin Wang 0001, Victor S. Sheng |
Expert Syst. Appl. | 3 |
| 2023 | An effective end-to-end android malware detection method
Huijuan Zhu 0001, Huahui Wei, Liangmin Wang 0001, Victor S. Sheng |
Expert Syst. Appl. | 3 |
| 2023 | FlowMFD: Characterisation and classification of tor traffic using MFD chromatographic features and spatial-temporal modellingabstractAbstract Tor traffic tracking is valuable for combating cybercrime as it provides insights into the traffic active on the Tor network. Tor‐based application traffic classification is one of the tracking methods, which can effectively classify Tor application services. However, it is not effective in classifying specific applications due to more complicated traffic patterns in the spatial and temporal dimensions. As a solution, the authors propose FlowMFD, a novel Tor‐based application traffic classification approach using amount‐frequency‐direction (MFD) chromatographic features and spatial‐temporal modelling. Expressly, FlowMFD mines the interaction pattern between Tor applications and servers by analysing the time series features (TSFs) of different size packets. Then MFD chromatographic features (MFDCF) are designed to represent the pattern. Those features integrate multiple low‐dimensional TSFs into a single plane and retain most pattern information. In addition, FlowMFD utilises a cascaded model with a two‐dimensional convolutional neural network (2D‐CNN) and a bidirectional gated recurrent unit to capture spatial‐temporal dependencies between MFDCF. The authors evaluate FlowMFD under the public ISCXTor2016 dataset and the self‐collected dataset, where we achieve an accuracy of 92.1% (4.2%↑) and 88.3% (4.5%↑), respectively, outperforming state‐of‐the‐art comparison methods. Liukun He, Liangmin Wang 0001, Keyang Cheng |
IET Inf. Secur. | 2 |
| 2023 | A distributed message authentication scheme with reputation mechanism for Internet of VehiclesabstractReal-time and interactive traffic information sharing systems are crucial in the Internet of Vehicles (IoV) as they enable vehicles to make informed decisions, thereby improving the efficiency of intelligent transportation systems (ITS). Message authentication ensures the accuracy, integrity, and tamper-resistance of information in IoV. Existing schemes aim to achieve time-critical message authentication . However, these schemes are time-consuming and cannot meet the real-time requirements of IoV. Additionally, there are issues with latency in data synchronization and data redundancy when vehicles traverse different domains. We propose an efficient, distributed, and resistant-to-malicious-attacks authentication scheme based on the reputation mechanism. Our scheme supports batch verification, enabling fast authentication. By leveraging the decentralized and ledger-synchronized features of blockchain , our distributed scheme reduces data redundancy. We also employ a reputation mechanism to ensure reliable reports in IoVs. We experimentally confirm that our scheme outperforms EADA (59.73%), RCoM (76.35%), MLGSDT (63.36%), and TRAJ (82.08%). This approach provides a secure and reliable solution for report authentication. Xia Feng, Kaiping Cui, Qingqing Xie, Liangmin Wang 0001 |
J. Syst. Archit. | 5 |
| 2023 | Secure Similar Sequence Query over Multi-source Genomic Data on CloudabstractCloud computing has been shown promising in enabling various analyses over large-scale genomic data integrated across multiple data sources. However, outsourcing data to remote cloud servers raises data-privacy concerns, therefore demands secure computing measures over the data analyzing process on the untrusted cloud servers. Due to the scale of genomic dataset and the length of each genomic sequence, it is challenging to evaluate data-analysis functions on outsourced genomic data securely and efficiently. In this work, we study the secure similar-sequence-query (SSQ) problem over outsourced genomic data. To address the challenges of security and efficiency, we propose a set of two-party computing protocols inmixed form, which combine secure secret sharing, garbled circuit, and partial homomorphic encryptions together and use them to jointly fulfill the secure SSQ function. Moreover, our scheme supports the fusion of genomic data from multiple data owners to generate a deduplicated-joint genomic dataset, therefore reduces the redundancy in the dataset. The performance improvements of our scheme are validated through extensive experiments on a commercial cloud platform over a real-world genomic dataset. Ke Cheng 0001, Yantian Hou, Liangmin Wang 0001 |
IEEE Trans. Cloud Comput. | 3 |
| 2023 | BeDCV: Blockchain-Enabled Decentralized Consistency Verification for Cross-Chain CalculationabstractWith the increase of data stored on the blockchain, the efficiency of storage and calculation of blockchain has gradually become a bottleneck restricting the development of blockchain. By storing data on multiple chains, blockchains can request data from other chains for calculation and the storage pressure can be alleviated. But the transfer of a large amount of data between chains suffers from low transfer efficiency and poor security. A reasonable design is to perform the calculation on the data storage chain and only transfer the results across chains. However, since the calculation process is invisible, blockchains cannot judge the consistency of calculation results from other chains. In this paper, we provide a blockchain-enabled decentralized consistency verification scheme for cross-chain calculation (BeDCV). Considering the decentralized characteristic of blockchain, we adopt the blockchain calledsupervision chainfor decentralized auditing. We modify paillier homomorphic encryption to encrypt data involved in the calculation for correctness verification. Then, we aggregate the ciphertexts of data to generate the audit proof for integrity verification. Besides, we verify whether the data involved in the calculation are real-time by leveraging a counting bloom filter. The supervision chain can check the correctness, integrity, and real-time performance of cross-chain data calculation without revealing any original information about the data. The theoretical and experimental analysis demonstrates that BeDCV can verify the consistency of cross-chain data calculation result effectively, realizing secure and reliable expansion of blockchain. Yushu Zhang 0001, Xuewen Dong, Liangmin Wang 0001, Yong Xiang 0001 |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | FuzzyDedup: Secure Fuzzy Deduplication for Cloud StorageabstractData deduplication is of critical importance to reduce the storage cost for clients and to relieve the unnecessary storage pressure for cloud servers. While various techniques have been proposed for secure deduplication of identical files/blocks, the effective and secure deduplication solutions on fuzzy similar data (image, video, and others) which occupy a large portion in the real world across wide applications, remain open. In this article, we propose a novel deduplication system, named Fuzzy Deduplication (FuzzyDedup), to implement the secure deduplication of similar data (i.e., similar files, chunks, or blocks). In particular, we leverage the similarity-preserving hash, a fuzzy extractor based on error-correcting codes, and the encryption with customized design to construct a fuzzy-style deduplication encryption scheme (FuzzyMLE), achieving the ciphertext-based deduplication for similar data. Besides, to defend against data ownership cheating attack and duplicate-faking attack, a fuzzy-style proof of ownership scheme (FuzzyPoW) is designed for the cloud server to securely verify a client in possession of the similar data. To further enhance security and efficiency, we also propose both server-aided and random-tag FuzzyMLE to make FuzzyDedup robust against off-line brute-force attack and to support tag randomization, respectively. Then, we design Hamming distance reduction and tag cutting optimization algorithms to improve the tag query efficiency of FuzzyDedup. In the end, we formally prove the security of our solution and conduct experiments on real-world datasets for performance evaluation. Experimental results exhibit the efficiency of FuzzyDedup in terms of computation cost and communication overhead. Tao Jiang 0017, Xu Yuan 0001, Yuan Chen 0008, Ke Cheng 0001, Liangmin Wang 0001, Xiaofeng Chen 0001, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Covert Communications With Randomly Distributed Adversaries in Wireless Energy Harvesting Enabled D2D Underlaying Cellular NetworksabstractWireless energy harvesting (WEH) enabled Device-to-Device (D2D) communication emerges as an effective technique to improve spectral and energy efficiencies. However, D2D users are usually power-constrained devices that may be monitored or attacked by adversaries easily. To confuse randomly distributed adversaries in WEH-enabled D2D underlaying cellular networks, power beacons (PBs) can be used to send jamming signals in idle time slots. A time slot is divided into two sub-slots, i.e., WEH sub-slot and covert transmission sub-slot. The energy collected by a D2D transmitter in the first sub-slot is used to support possible covert transmission in the second sub-slot. The performance of the proposed scheme is measured by covert throughput, which is defined as D2D communication rate with several constraints, e.g., wireless energy harvesting, covertness, and cellular link communication requirements. The closed-form expressions of energy outage probability, covert probability, and desired link connection outage probabilities are derived. The minimum covert probability is used to measure covertness. Moreover, an alternating optimization algorithm is adopted to maximize covert throughput. The analytical results are compared with Monte-Carlo simulation results to verify the analytical approach. In addition, the impacts of different parameters (e.g., density of PBs and covert signal transmit power) on covert performance are evaluated. Yu'e Jiang, Liangmin Wang 0001, Hsiao-Hwa Chen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Logical Topology Inference via CPGCN Joint Optimizing With Pedestrian Re-IdabstractWith the rise of artificial intelligence, deep learning has become the main research method of pedestrian recognition re-identification (re-id). However, most of the existing researches usually just determine the retrieval order based on the geographical location of cameras, which ignore the spatio-temporal logic characteristics of pedestrian flow. Furthermore, most of these methods rely on common object detection to detect and match pedestrians directly, which will separate the logical connection between videos from different cameras. In this research, a novel pedestrian re-identification model assisted by logical topological inference is proposed, which includes: 1) a joint optimization mechanism of pedestrian re-identification and multicamera logical topology inference, which makes the multicamera logical topology provides the retrieval order and the confidence for re-identification. And meanwhile, the results of pedestrian re-identification as a feedback modify logical topological inference; 2) a dynamic spatio-temporal information driving logical topology inference method via conditional probability graph convolution network (CPGCN) with random forest-based transition activation mechanism (RF-TAM) is proposed, which focuses on the pedestrian's walking direction at different moments; and 3) a pedestrian group cluster graph convolution network (GC-GCN) is designed to measure the correlation between embedded pedestrian features. Some experimental analyses and real scene experiments on datasets CUHK-SYSU, PRW, SLP, and UJS-reID indicate that the designed model can achieve a better logical topology inference with an accuracy of 87.3% and achieve the top-1 accuracy of 77.4% and the mAP accuracy of 74.3% for pedestrian re-identification. Keyang Cheng, Qing Liu 0015, Rabia Tahir, Liangmin Wang 0001, Maozhen Li 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 4 |
| 2023 | Query Integrity Meets Blockchain: A Privacy-Preserving Verification Framework for Outsourced Encrypted DataabstractCloud outsourcing provides flexible storage and computation services for data users in a low cost, but it brings many security threats as the cloud server may not be fully trusted. Previous secure outsourcing solutions mostly assume that the server is honest-but-curious while the adversary model of a malicious server that may return incorrect results is rarely explored. Moreover, with the increasing popularity of verifiable computations, existing verification schemes are yet not efficient and cannot cater to different scenarios in practice. In this paper, we propose a blockchain-based verifiable search framework in the adversarial cloud outsourcing context. When outsourcing the encrypted data to the cloud or Interplanetary File System (IPFS), we also store the encrypted data index in a decentralized blockchain (i.e., Ethereum in this paper) which is public and cannot be modified. Once a user is authorized, he/she can flexibly obtain the query results and efficiently check the query integrity via the pre-deployed smart contract, without the need of the data owner being online. Moreover, for user's privacy protection, we construct a stealth authorization scheme to deliver the access authorization without any identity disclosure. Finally, theoretical analysis and performance evaluation validate the security and efficiency of our proposed framework. Shunrong Jiang, Jianqing Liu, Yiliang Liu, Liangmin Wang 0001, Yong Zhou 0003 |
IEEE Trans. Serv. Comput. | 5 |
| 2023 | Fair Outsourcing Paid in Fiat Money Using BlockchainabstractSeeking outsourcing from cloud service providers is common for resource-constrained users to complete complex computing. Conventional cloud computing outsourcing solutions focus on guiding users to verify the returned results, which is unfair since malicious users can refuse to pay by falsely claiming that the results are wrong. To address this problem, fair payment schemes, both blockchain-free and blockchain-based, have been proposed. However, the former is usually inefficient and the latter only supports payment through cryptocurrencies. The use of cryptocurrencies faces hurdles as it exposes cloud service providers to a significant risk of sharp currency price fluctuations, as well as vulnerability to government bans due to regulatory concerns. In contrast, fiat money payment is not only more in line with the business norm, but also naturally avoids the above troubles. Motivated by this, a blockchain-based fair outsourcing scheme to support payment in fiat money is proposed in this paper. The proposed scheme has broad compatibility and, as an example, is subsequently instantiated with a conventional outsourcing solution of eigen-decomposition. The performance of the scheme in fairness, privacy, and efficiency is verified by both theoretical and experimental evaluations. Xiangli Xiao, Yushu Zhang 0001, Xuewen Dong, Liangmin Wang 0001, Yong Xiang 0001, Xiaochun Cao |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | Load Balancing of Double Queues and Utility-Workload Tradeoff in Heterogeneous Mobile Edge ComputingabstractMobile edge computing (MEC) is a popular service paradigm by which mobile devices can offload their latency-sensitive and computation-intensive workloads to edge servers. The MEC service scheduling problem has been investigated in recent years. However, most MEC service scheduling mechanisms only consider workloads on homogeneous edge servers, causing servers’ queue backlogs to be too large when innumerable user requests arrive concurrently. In this paper, we are the first to propose a double-queue workloads scheduling model innovatively, and formulate a system (including user ends and edge server ends) utility into a scheduling optimization problem. To tackle such an NP scheduling problem, we present a Lyapunov-based decomposition strategy to convert the original problem into three equivalent subproblems. By aggregating three subproblem solving strategies, we propose the Lyapunov-based online matching algorithm for edge service scheduling, named LOMES, to obtain an optimal system utility while guaranteeing the load balancing of mobile devices and heterogeneous edge servers. Simulations further validate that LOMES realizes the load balancing of two queue lengths and a$[O(1/V); O(V)]$tradeoff between the system’s utility and workloads with a utility-workload tradeoff parameter${V}$. Xuewen Dong, Zijie Di, Liangmin Wang 0001, Qingsong Yao, Guangxia Li, Yulong Shen 0001 |
IEEE Trans. Wirel. Commun. | 3 |
| 2022 | MPC: Multi-node Payment Channel for Off-chain TransactionsabstractPayment channel (PC) greatly improves blockchain scalability by allowing an unlimited number of off-chain transactions instead of committing every transaction to the blockchain. However, one PC just confines to two nodes. Thus, for a node, like Cafe, who frequently receives money from multiple nodes, massive PCs need to be created, which leads to massively and repeatedly information addition of channels to the blockchain and costs much fees. In this paper, we introduce a multi-node payment channel (MPC) method to solve the problem above. MPC suits the scenario that one node frequently receives money from multiple nodes, such as Cafe, shop, etc. Compared to PC, MPC can contain nearly unlimited number of nodes, thus avoiding repetitive channel information addition to the blockchain and meanwhile reducing the fee. MPC supports the same transaction logic of PC and cooperates well with existing PC. The security, economy and efficiency of MPC are proved. We implement MPC’s smart contract in Ethereum and experimental results show that MPC outperforms the existing PC. Longxia Huang, Liangmin Wang 0001, Jinfu Chen 0001 |
ICC | 3 |
| 2022 | Blockchain-Based Reliable and Privacy-Aware Crowdsourcing With Truth and Fairness AssuranceabstractThe ubiquity of crowdsourcing has reshaped the static sensor-enabled data sensing paradigm with cost efficiency and flexibility. Still, most existing triangular crowdsourcing systems only work under the centralized trust assumption and suffer from various attacks mounted by malicious users. Although incorporating the emerging blockchain technology into crowdsourcing provides a possibility to mitigate some of the issues, how to concretely implement the crucial components and their functionalities in a verifiable and privacy-aware manner remains unaddressed. In this article, we present BRPC, a blockchain-based decentralized system for general crowdsourcing. BRPC integrates the confident-aware truth discovery algorithm to provide task requesters with reliable task truths while evaluating each worker’s data quality. To mitigate the biased evaluation of malicious requesters, we propose a privacy-aware verification protocol leveraging the threshold Paillier cryptosystem, with which a certain number of workers can collaboratively verify the evaluation results without knowing any sensory data. Furthermore, we define the three roles of a user and elaborate a comprehensive reputation evaluation model enforced by smart contracts for its trustworthy running. Financial and social incentives are both offered to motivate users’ honest participation. Finally, we implement a prototype of BRPC and deploy it on the Ethereum blockchain. Theoretical analyses and experiment results show its security and practicality. Haiqin Wu, Boris Düdder, Liangmin Wang 0001, Shipu Sun, Guoliang Xue |
IEEE Internet Things J. | 3 |
| 2022 | Guest Editorial: Reliability and Security for Intelligent Wireless Sensing and Control SystemsabstractNowadays billions of smart objects are connected to the internet and interact with the cloud. Remote monitoring, control systems, and data analysis becomes more intelligent with the huge amount of data been collecting and crowdsourcing. To reduce data transmission and improve executive efficiency, computing and storing functions are executed toward edge devices. However, the great convenience raises numerous issues including reliability and security of the sensors and the control systems because these issues have not always been considered the top priority. Accordingly, many new research opportunities and challenges for intelligent sensing and control have arisen. Lei Shu 0001, Gerhard P. Hancke 0002, Victor S. Sheng, Liangmin Wang 0001 |
IEEE Trans. Ind. Informatics | 4 |
| 2022 | SMA: SRv6-Based Multidomain Integrated Architecture for Industrial InternetabstractWith the increasing requirements of industrial production efficiency, the Industrial Internet has played a very important role in the fourth industrial revolution. However, the current Industrial Internet still has many drawbacks, especially in terms of network systems, such as low network expansion, inconvenient troubleshooting, and low data transmission efficiency. For this motivation, a novel SRv6-based multidomain integrated architecture (SMA) for the Industrial Internet has been proposed. Multilayer controllers are deployed in the SMA, and a software-defined network controller that generates the transmission path is replaced by SMA nodes, which realizes the high network scalability and efficient data transmission of the Industrial Internet. The faulty node in the SMA can be quickly and accurately identified through the periodic detection actively sent by the controller node in the domain and the passive feedback of the SMA nodes, and the generated SMA node trusted set (SNTS) can be used for forwarding path generation. A Bellman–Ford algorithm with a hop count constraint based on the total number of SNTS nodes is proposed, which effectively avoids long-path forwarding and improves network resource utilization. Through theoretical analysis, the safety and scalability of the SMA have been fully verified. The simulation results of the SMA on the experimental platform show that the SMA is superior to the existing Industrial Internet network structure in terms of troubleshooting efficiency of faulty nodes, network throughput, and data communication overhead. In the Industrial Internet, when the proportion of SMA nodes reaches 30%, the SMA controller can control nearly 80% of the traffic. In addition, the maximum link utilization rate will be greatly reduced, which means better adjustment of network load balance. Liangmin Wang 0001, Fan Wen, Keyang Cheng, Xia Feng, Hao Shentu |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | A Hybrid Deep Network Framework for Android Malware DetectionabstractAndroid is a growing target for malicious software (malware) because of its popularity and functionality. Malware poses a serious threat to users’ privacy, money, equipment and file integrity. A series of data-driven malware detection methods were proposed. However, there exist two key challenges for these methods: (1) how to learn effective feature representation from raw data; (2) how to reduce the dependence on the prior knowledge or human labors in feature learning. Inspired by the success of deep learning methods in the feature representation learning community, we propose a malware detection framework which starts with learning rich-features by a novel unsupervised feature learning algorithm Merged Sparse Auto-Encoder (MSAE). In order to extract more compact and discriminative feature from the rich-features to further boost the malware detection capability, a hybrid deep network learning algorithm Stacked Hybrid Learning MSAE and SDAE (SHLMD) is established by further incorporating a classical deep learning method Stacked Denoising Auto-encoders (SDAE). After that, we feed the feature learned by MSAE and SHLMD respectively to classification algorithms, e.g., Support Vector Machine (SVM) or K-NearestNeighbor (KNN), to train a malware detection model. Evaluation results on two real-world datasets demonstrate that SHLMD achieves 94.46 and 90.57 percent accuracy respectively, which outperforms the classical unsupervised feature representation learning Sparse Auto-encoder (SAE). MSAE performs similarly to SAE. SHLMD can further improve the performance of MSAE and the supervised fine-tuned method SDAE. Besides, we compare the performance of our methods with that of state-of-the-art detection approaches, including classical deep-learning-based methods. Extensive experiments show that our proposed methods are effective enough to detect Android malware. Huijuan Zhu 0001, Liangmin Wang 0001, Sheng Zhong 0002, Yang Li 0111, Victor S. Sheng |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2021 | Elastic Scheduling of Virtual Machines in Cloudlet NetworksabstractThis paper addresses the problem of elastic virtual machine scheduling in cloudlet networks, and the objective is to maximize the dominant elasticity of computing and bandwidth resources in cloudlet networks. First, a mathematical formulation of the problem is presented. Second, the bandwidth consumption incurred by intra-job communication is studied. Next, we focus on the optimal scheduling of input jobs to minimize dominant load of cloudlet networks under the constraint of minimum bandwidth consumption, which is an NP-Complete problem. In that case, we design a 2-approximation algorithm. Evaluations results validate the efficiency of our algorithm. Liangmin Wang 0001 |
IPCCC | 2 |
| 2021 | Multi-timescale and multi-centrality layered node selection for efficient traffic monitoring in SDNs
Li Feng 0003, Yiru Yao, Liangmin Wang 0001, Geyong Min |
Comput. Networks | 3 |
| 2021 | Secure $k$k-NN Query on Encrypted Cloud Data with Multiple KeysabstractThe k-nearest neighbors (k-NN) query is a fundamental primitive in spatial and multimedia databases. It has extensive applications in location-based services, classification & clustering and so on. With the promise of confidentiality and privacy, massive data are increasingly outsourced to cloud in the encrypted form for enjoying the advantages of cloud computing (e.g., reduce storage and query processing costs). Recently, many schemes have been proposed to support k-NN query on encrypted cloud data. However, prior works have all assumed that the query users (QUs) are fully-trusted and know the key of the data owner (DO), which is used to encrypt and decrypt outsourced data. The assumptions are unrealistic in many situations, since many users are neither trusted nor knowing the key. In this paper, we propose a novel scheme for secure k-NN query on encrypted cloud data with multiple keys, in which the DO and each QU all hold their own different keys, and do not share them with each other; meanwhile, the DO encrypts and decrypts outsourced data using the key of his own. Our scheme is constructed by a distributed two trapdoors public-key cryptosystem (DT-PKC) and a set of protocols of secure two-party computation, which not only preserves the data confidentiality and query privacy but also supports the offline data owner. Our extensive theoretical and experimental evaluations demonstrate the effectiveness of our scheme in terms of security and performance. Ke Cheng 0001, Liangmin Wang 0001, Yulong Shen 0001, Hua Wang 0002, Yongzhi Wang 0001, Xiaohong Jiang 0001, Hong Zhong 0001 |
IEEE Trans. Big Data | 2 |
| 2021 | P2BA: A Privacy-Preserving Protocol With Batch Authentication Against Semi-Trusted RSUs in Vehicular Ad Hoc NetworksabstractVehicular Ad-hoc Networks (VANETs) supporting the seamless operation of autonomous vehicles introduce various network-connected devices. The widespread devices are engaged in VANETs so that users can enjoy advantageous computing and reliable services. The combination brings in massive real-time message propagation and dissemination, which would be leveraged by the adversaries to perform data association, integration analysis and privacy mining. To address such challenges, existing authentication schemes use n pseudonym certificates for pre-defined k times and try to keep the vehicles anonymous. These schemes require fresh certificates for each authentication process, which cost more communication and storage resources. In this paper, we propose a novel privacy-preserving authentication protocol (P2BA) in bilinear groups, where a registered vehicle signs a traffic-related message and sends it to the nearby Road-side Unit (RSU) together with its blinded certificate. The RSU is able to independently check the message for validity based on a non-interactive zero-knowledge proof protocol. In this way, the computation time has been reduced fromO(n) toO(1) while the storage overhead fromO(nk) toO(n) compared to anonymous authentication protocols. Moreover, our scheme provides privacy properties such as anonymity and unlinkability. The simulations show that the message authentication can be processed by individual RSUs within 1 ms under the batch-enabled scheme, which outperforms the existing schemes in terms of computation overhead and latency. Xia Feng, Qichen Shi, Qingqing Xie, Liangmin Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Multilevel Identification and Classification Analysis of Tor on Mobile and PC PlatformsabstractIn digitalized and automated systems, more and more intelligent devices have become an import part of industrial Internet of Things (IIOT). However, the lack of security in IIOT makes people facing unprecedented threats from the Dark web. Traffic classification is an important means to prevent anonymous attacks. However, the growing usage of smartphones in daily life is deeply changing the nature of network traffic, which makes traffic classification more challenging. In this article, we propose a Tor traffic identification and multilevel classification framework based on network flow features, which realizes the identification of anonymous traffic (L1), traffic types (L2) of anonymous traffic, and applications (L3) on a mobile and a PC platform, respectively. We further analyze differences between the mobile and the PC platform. We conclude that the impact of time-related features is higher than that of the nontime-related features on the mobile platform, while it is opposite on the PC platform. And it is more difficult to identify and classify Tor types (L2) and specific Tor applications (L3) on the mobile platform than on the PC platform, including using different number of features and early identification and classification. Liangmin Wang 0001, Hantao Mei, Victor S. Sheng |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | ReliableBox: Secure and Verifiable Cloud Storage With Location-Aware BackupabstractWhile the prevalent cloud storage platforms are offering convenient services in support of diverse data-driven applications for clients, various security concerns raise in terms of data confidentiality, availability, and retrievability. Among them, servers' dishonesty on the location-specific data backup becomes a serious concern when the data stands out clients' control, considering the strict regulations imposed by many governments and organizations on data storage location. This article studies location-aware data backup verification for the data stored in clouds and aims to design a secure framework, named as ReliableBox, enabling the clients to verify if their data have been backed up on the remote servers with specific geolocation. In the design of ReliableBox, we leverage the prominent proof-of-storage techniques for data possession proof, and take advantage of multilateration geolocation and Intel SGX for the precise communication delay measurement and trust computing delay measurement, respectively. In ReliableBox, a client first computes integrity tags for the files and then outsources both the files and tags to the cloud storage server. In the later attestation, with the precise network delay and distance measurement from location-known verifiers, the client verifies that the outsourced files are intact and backed-up to hosts at the specific geolocation. With the customized design, ReliableBox can support the security needs in terms of both data integrity and backup location verification for clients, even when there exists potential dishonest cloud service providers who may manipulate the network delays or forge verification proofs. We provide security analysis to show the security property of ReliableBox in terms of data access, confidentiality, and verifications. In the end, we implement the system prototype and deploy it into several prevalent and commercial cloud platforms for performance evaluation. The experimental results demonstrate that ReliableBox is secure in support of data integrity checking and location-aware backup auditing, while it is robust to the data possession and location spoofing attacks. Tao Jiang 0017, Wenjuan Meng, Xu Yuan 0001, Liangmin Wang 0001, Jianhua Ge, Jianfeng Ma 0001 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2021 | Physical Layer Security Assisted Computation Offloading in Intelligently Connected Vehicle NetworksabstractIn this paper, we propose a secure computationoffloading scheme (SCOS) in intelligently connected vehicle (ICV) networks, aiming to minimize overall latency of computing via offloading part of computational tasks to nearby servers in small cell base stations (SBSs), while securing the information delivered during offloading and feedback phases via physical layer security. Existing computation offloading schemes usually neglected time-varying characteristics of channels and their corresponding secrecy rates, resulting in an inappropriate task partition ratio and a large secrecy outage probability. To address these issues, we utilize an ergodic secrecy rate to determine how many tasks are offloaded to the edge, where ergodic secrecy rate represents the average secrecy rate over all realizations in a time-varying wireless channel. Adaptive wiretap code rates are proposed with a secrecy outage constraint to match time-varying wireless channels. In addition, the proposed secure beamforming and artificial noise (AN) schemes can improve the ergodic secrecy rates of uplink and downlink channels even without eavesdropper channel state information (CSI). Numerical results demonstrate that the proposed schemes have a shorter system delay than the strategies neglecting time-varying characteristics. Yiliang Liu, Wei Wang 0100, Hsiao-Hwa Chen, Feng Lyu 0001, Liangmin Wang 0001, Weixiao Meng 0001, Xuemin Shen |
IEEE Trans. Wirel. Commun. | 5 |
| 2020 | A Lightweight Auction Framework for Spectrum Allocation with Strong Security GuaranteesabstractAuction is an effective mechanism to distribute spectrum resources. Although many privacy-preserving auction schemes for spectrum allocation have been proposed, none of them is able to perform practical spectrum auctions while ensuring enough security for bidders' private information, such as geo-locations, bid values, and data access patterns. To address this problem, we propose SLISA, a lightweight auction framework which enables an efficient spectrum allocation without revealing anything but the auction outcome, i.e., the winning bidders and their clearing prices. We present contributions on two fronts. First, as a foundation of our design, we adopt a Shuffle-then-Compute strategy to build a series of secure sub-protocols based on lightweight cryptographic primitives (e.g., additive secret sharing and basic garbled circuits). Second, we improve an advanced spectrum auction mechanism to make it data-oblivious, such that data access patterns can be hidden. Meanwhile, the modified protocols adapt to our elaborate building blocks without affecting its validity and security. We formally prove the security of all protocols under a semi-honest adversary model, and demonstrate performance improvements compared with state-of-the-art works through extensive experiments. Ke Cheng 0001, Liangmin Wang 0001, Yulong Shen 0001, Yongzhi Wang 0001, Lele Zheng |
INFOCOM | 2 |
| 2020 | SHAMC: A Secure and highly available database system in multi-cloud environment
Liangmin Wang 0001, Zhendong Yang, Xiangmei Song |
Future Gener. Comput. Syst. | 1 |
| 2020 | SEM-ACSIT: Secure and Efficient Multiauthority Access Control for IoT Cloud StorageabstractData access control in a cloud storage system is regarded as a promising technique for enhanced efficiency and security utilizing a ciphertext-policy attribute-based encryption (CP-ABE) approach. However, due to a large number of data users as well as limited resources and heterogeneity of data devices in Internet of Things (IoT), existing access control schemes for the cloud storage are not effectively applicable to IoT applications. In this article, we construct a new CP-ABE-based storage model for data storing and secure access in a cloud for IoT applications. Our new framework introduces an attribute authority management (AAM) module in the cloud storage system functioned as an agent that provides a user-friendly access control and highly reduces the storage overhead of public keys. Then, we propose a novel secure and efficient multiauthority access control scheme of the cloud storage system for IoT, namely, SEM-ACSIT, which obtains both backward security and forward security when an attribute of a user is revoked. By exploiting encryption outsourcing, simplified key structuring and the AAM module, the computational overhead of a user is immensely decreased. Moreover, a user access control list (UACL) in the cloud server is constructed newly to support authorization access for a specific user. The analysis and simulation results demonstrate that our SEM-ACSIT scheme achieves powerful security with less computational overhead and lower storage costs than the existing schemes. Shuming Xiong, Qiang Ni, Liangmin Wang 0001 |
IEEE Internet Things J. | 3 |
| 2020 | Secure and Efficient Cloud Data Deduplication with Ownership ManagementabstractData deduplication has been widely used in cloud storage to reduce storage space and communication overhead by eliminating redundant data and storing only one copy for them. In order to achieve secure data deduplication, the convergent encryption scheme and many of its variants are proposed. However, most of these schemes do not consider or cannot address the efficiently dynamic ownership changes and the secure Proof-of-Ownership (PoW), simultaneously. In this paper, we propose a secure data deduplication scheme with efficient PoW process for dynamic ownership management. Specially, our scheme supports both cross-user file-level and inside-user block-level data deduplication. During the file-level deduplication, we construct a new PoW scheme to ensure the tag consistency and achieve the mutual ownership verification. Moreover, we design a lazy update strategy to achieve efficient ownership management. For inside-user block-level deduplication, the user-aided key is used to realize convergent key management and reduce the key storage space. Finally, the security and performance analysis demonstrate that our scheme can ensure data confidentiality and tag consistency, and it is efficient in data ownership management. Shunrong Jiang, Tao Jiang 0017, Liangmin Wang 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2020 | A Truthful Online Incentive Mechanism for Nondeterministic Spectrum AllocationabstractDynamic spectrum access (DSA) is a promising platform to solve the problem of spectrum shortage for which the most challenging issue is spectrum allocation under uncertain availability information, which is referred as a nondeterministic spectrum allocation problem. The nature of such a problem is due to inaccurate spectrum sensing results, which are induced by that power or energy based sensing can be greatly impacted by thermal and environmental noise. For spectrum allocation, auction-based mechanisms have been extensively studied because of channel allocation efficiency, and its potential to achieve bidding truthfulness for secondary uses (SUs). However, most existing spectrum auction mechanisms focus on realizing the truthfulness under certain spectrum availability information. In this paper, we propose FORTUNE, the first truthful online auction mechanism for nondeterministic spectrum allocation by considering uncertain spectrum availability and dynamic spectrum requests. Specifically, we take limited information to compute expected income and losses when interference between primary users (PUs) and SUs occurs, and present a virtual request method for changing of spectrum's actual state. Thorough theoretical analysis proves the truthfulness of FORTUNE. Furthermore, given a sample set with 5%-30% noise in spectrum sensing, FORTUNE achieves not only truthfulness, but also up to 50% higher channel utilization than existing spectrum auction mechanisms. Xuewen Dong, Zhichao You, Liangmin Wang 0001, Sheng Gao 0002, Yulong Shen 0001, Jianfeng Ma 0001 |
IEEE Trans. Wirel. Commun. | 3 |
| 2019 | Flexibly and Securely Shape Your Data Disclosed to OthersabstractThis work is to enhance existing fine-grained access control to support a more expressive access policy over arithmetic operation results. We aim to enable data owners to flexibly bind a user's identity with his/her authorized access target according to a given access control policy, which indicates how a piece of data obfuscated by different noises. To this end, we design a cryptographic primitive that decouples the noisy data to two components, one associated with user identity, and the other one shared and dynamically changes, with the composite of these two components evaluated and revealed at user sides. The security of our scheme is formally proven using game based approach. We implement our system on a commercial cloud platform and use extensive experiments to validate its functionality and performance. Qing-Qing Xie, Yantian Hou, Ke Cheng 0001, Gaby G. Dagher, Liangmin Wang 0001, Shucheng Yu |
AsiaCCS | 5 |
| 2019 | Improving Division Property Based Cube Attacks by Removing Invalid Monomials
Senshan Pan, Zhuhua Li, Liangmin Wang 0001 |
Inscrypt | 3 |
| 2019 | Patients-Controlled Secure and Privacy-Preserving EHRs Sharing Scheme Based on Consortium BlockchainabstractThe large-scale deployment of eHealth systems has brought deep impact on human society. However, the centralized Electronic health records (EHRs) outsourcing system faces some critical security and privacy issues, which have raised wide concerns in both academia and industry. Moreover, the patients lose control of their health data. There is a need to construct a decentralized and secure EHRs with more flexible control by patients themselves instead of the third party. Fortunately, we observe that the characteristics of blockchain technology such as decentralization, immutability, and auditability perfectly match these aforementioned requirements. Specifically, to satisfy our application requirements, we build a consortium blockchain (PESchain) which is maintained by a set of medical institutions. The EHRs of patients are encrypted and stored in the medical institutions by local cloud while the corresponding hash values are stored on PESchain. Moreover, to enable privacy-preserving EHRs sharing, we construct a stealth authorization scheme to achieve access authorization delivery on the blockchain. Besides, we pack the transactions according to different types to guarantee efficient block deletion. The security analysis and performance evaluation show that PESchain is secure and practical for EHRs sharing. Shunrong Jiang, Haiqin Wu, Liangmin Wang 0001 |
GLOBECOM | 3 |
| 2019 | Towards Efficient Privacy-Preserving Auction Mechanism for Two-Sided Cloud MarketsabstractAuction is an efficient trading mechanism for cloud markets and adopted by many major cloud providers, such as Amazon EC2. However, most cloud auction designs only target at economic robustness without considering the bidding privacy leakage, which would dramatically hamper the practical applications of truthful cloud auctions. Existing secure cloud auction mechanisms only work on the single-sided cloud markets rather than more practical two-sided markets, and these schemes are too unwieldy to be practical due to significant computation and communication overheads. To fill these gaps, in this paper we propose a privacy-preserving double auction mechanism for two-sided cloud markets, which would not leak any bidding information beyond the auction results to anyone. Technically, we start by presenting a novel secure sorting protocol in the mixed form, which combines additive secret sharing and garbled circuits together. On this basis, our design for secure cloud auction is implemented given consideration to bidding privacy and auction efficiency. Finally, we use extensive experiments to validate its efficacy and performance. Ke Cheng 0001, Yulong Slien, Liangmin Wang 0001, Hong Zhong 0001 |
ICC | 5 |
| 2019 | Verifiable Search Meets Blockchain: A Privacy-Preserving Framework for Outsourced Encrypted DataabstractOutsourcing storage and computation to clouds is popular but also raises security concerns. Most existing solutions mainly focus on an honest-but-curious cloud server, while security designs against a malicious server have not drawn enough attention. Although there are a few works addressing the issue of verifiable designs that enable the data owner to verify the integrity of search results. Unfortunately, these verification schemes are not efficient and or applicable from one scenario to another. Motivated by this, in this paper, we propose a publicly verifiable search framework for outsourced encrypted data based on blockchain. In our framework, we store the encrypted index in a decentralized blockchain (Ethereum) while outsourcing the corresponding encrypted data to the cloud or Interplanetary File System (IPFS). Thus, once a user is authorized, he/she can get the query results and check the query integrity efficiently by the designed smart contract anytime without data owner being online. Besides, to guarantee the privacy of the data user in the Ethereum, we construct a stealth authorization scheme to achieve access authorization delivery. The security analysis and performance evaluation show that the proposed scheme is secure and practical for verification of encrypted data. Shunrong Jiang, Jianqing Liu, Liangmin Wang 0001, Seong-Moo Yoo |
ICC | 3 |
| 2019 | Privacy-Preserving and Trustworthy Mobile Sensing with Fair IncentivesabstractPervasive mobile devices and their advances in sensing and networking have led to an emerging mobile sensing paradigm. The diversity of mobile users and the openness of sensing systems raise several crucial concerns for users' privacy, data quantity, and quality. Although different aspects of these issues were addressed separately in existing researches, there is still a need to provide a holistic solution for secure and privacy-aware mobile sensing. In this paper, we propose a privacy-aware and trustworthy mobile sensing scheme with fair incentives. Leveraging group signature, (partial) blind signature, and limited number of pseudonyms technologies, our scheme enables well-behaved users to contribute their data anonymously, and prevents both greedy and malicious users from abusing the privacy protection. Moreover, we design a fair incentive scheme to stimulate users to contribute high-quality data, based on the data quality and the reputation feedback level. Security analysis demonstrates that our proposed scheme achieves the security goals. Extensive evaluation results are presented which demonstrate the effectiveness and efficiency of our scheme. Haiqin Wu, Liangmin Wang 0001, Guoliang Xue, Jian Tang 0008, Dejun Yang |
ICC | 2 |
| 2019 | Strongly Secure and Efficient Range Queries in Cloud Databases under Multiple KeysabstractCloud database provides an advantageous platform for outsourcing of database service. To protect data confidentiality from an untrusted cloud, the original database is often encrypted and then uploaded to the cloud. However, in order to support functional queries, existing secure databases require users to encrypt their data under the same public/symmetric key, which restricts the usage scenarios since users do not really trust each other in practice. Imagine a scenario where a user uploaded his/her own encrypted data to the cloud database and another user wants to execute private range queries on this data. This scenario occurs in many cases of collaborative statistical analysis where the data provider and analyst are different entities. Then either the data provider must reveal its encryption key or the analyst must reveal the private queries. In this paper, we overcome this restriction for secure range queries by enabling query executions on the multi-key encryption data. We propose a secure cloud database supporting range queries under multiple keys, in which all users could preserve the confidentiality of their own different keys, and do not have to share them with each other. At a higher level, our system is constructed on a two-cloud architecture and a novel distributed two-trapdoor public key cryptosystem. We prove that the proposed scheme achieves the goal of a secure query without leaking data privacy, query privacy, and data access patterns. Finally, we use extensive experiments over a real-world dataset on a commercial cloud platform to verify the efficacy of our proposed scheme. Ke Cheng 0001, Yulong Shen 0001, Yongzhi Wang 0001, Liangmin Wang 0001, Jianfeng Ma 0001, Xionghong Jiang, Cuicui Su |
INFOCOM | 4 |
| 2019 | Liver CT sequence segmentation based with improved U-Net and graph cut
Zhe Liu 0004, Yuqing Song 0001, Victor S. Sheng, Liangmin Wang 0001, Deqi Yuan |
Expert Syst. Appl. | 4 |
| 2019 | PAU: Privacy Assessment method with Uncertainty consideration for cloud-based vehicular networks
Xia Feng, Liangmin Wang 0001 |
Future Gener. Comput. Syst. | 2 |
| 2019 | Multi-hop interpersonal trust assessment in vehicular ad-hoc networks using three-valued subjective logicabstractFuture vehicular networks need multi‐hop trusted information among car manoeuvres as a solution to the persistent problem of road safety, and news sharing. However, malicious users in vehicular networks can also disseminate fake information among each other. Traditional public key infrastructure is not an efficient solution for recognising these malicious users, as they all have authorised entities. To cope with this problem, this study highlights novel idea, i.e. three‐valued subjective logic (3VSL) as a trust model for multi‐hop trust assessment among users in vehicular ad‐hoc network (VANET). Trust among vehicle users is represented in the form of opinion derived from 3VSL and updated frequently due to vehicles random movement on the road. To support the authors’ proposed scheme, this study contains two parts in simulation, i.e. numerical and experimental analyses. Numerical analysis shows that 3VSL gives accurate trust assessment even with a bridge or random network topology, which is ignored previously by edge splitting. In the experimental part, we extend widely accepted ad‐hoc on‐demand distance vector routing protocol by directly applying trust fields to the routing table. The simulation experiment shows that their scheme achieves better performance in term of throughput and latencies in low mobility VANET scenario. Muhammad Sohail 0001, Liangmin Wang 0001, Shunrong Jiang, Samar Zaineldeen, Rana Umair Ashraf |
IET Inf. Secur. | 2 |
| 2019 | A hierarchical mobility management scheme based on software defined networking
Xing Yin, Liangmin Wang 0001, Shunrong Jiang |
Peer-to-Peer Netw. Appl. | 2 |
| 2019 | Enabling Data Trustworthiness and User Privacy in Mobile CrowdsensingabstractUbiquitous mobile devices with rich sensors and advanced communication capabilities have given rise to mobile crowdsensing systems. The diverse reliabilities of mobile users and the openness of sensing paradigms raise concerns for data trustworthiness, user privacy, and incentive provision. Instead of considering these issues as isolated modules in most existing researches, we comprehensively capture both conflict and inner-relationship among them. In this paper, we propose a holistic solution for trustworthy and privacy-aware mobile crowdsensing with no need of a trusted third party. Specifically, leveraging cryptographic technologies, we devise a series of protocols to enable benign users to request tasks, contribute their data, and earn rewards anonymously without any data linkability. Meanwhile, an anonymous trust/reputation model is seamlessly integrated into our scheme, which acts as reference for our fair incentive design, and provides evidence to detect malicious users who degrade the data trustworthiness. Particularly, we first propose the idea of limiting the number of issued pseudonyms which serves to efficiently tackle the anonymity abuse issue. Security analysis demonstrates that our proposed scheme achieves stronger security with resilience against possible collusion attacks. Extensive simulations are presented which demonstrate the efficiency and practicality of our scheme. Haiqin Wu, Liangmin Wang 0001, Guoliang Xue, Jian Tang 0008, Dejun Yang |
IEEE/ACM Trans. Netw. | 2 |
| 2018 | Secure Similar Sequence Query on Outsourced Genomic DataabstractThe growing availability of genomic data is unlocking research potentials on genomic-data analysis. It is of great importance to outsource the genomic-analysis tasks onto clouds to leverage their powerful computational resources over the large-scale genomic sequences. However, the remote placement of the data raises personal-privacy concerns, and it is challenging to evaluate data-analysis functions on outsourced genomic data securely and efficiently. In this work, we study the secure similar-sequence-query (SSQ) problem over outsourced genomic data, which has not been fully investigated. To address the challenges of security and efficiency, we propose two protocols in the mixed form, which combine two-party secure secret sharing, garbled circuit, and partial homomorphic encryptions together and use them to jointly fulfill the secure SSQ function. In addition, our protocols support multi-user queries over a joint genomic data set collected from multiple data owners, making our solution scalable. We formally prove the security of protocols under the semi-honest adversary model, and theoretically analyze the performance. We use extensive experiments over real-world dataset on a commercial cloud platform to validate the efficacy of our proposed solution, and demonstrate the performance improvements compared with state-of-the-art works. Ke Cheng 0001, Yantian Hou, Liangmin Wang 0001 |
AsiaCCS | 3 |
| 2018 | Secure and Privacy-Preserving Report De-duplication in the Fog-Based Vehicular Crowdsensing SystemabstractNowadays, vehicles are powerful enough to carry communications, computing and storage capabilities. By interacting with each other and with local (i.e., fog) infrastructures like road-side units, a cohort of vehicles and fog devices could collaboratively provide services like crowdsensing in an unprecedentedly secure and efficient way. However, it has been widely recognized as a challenging work in the vehicular system to develop a secure and efficient sensing task allocation and data de-duplication mechanism. In this paper, we attempt to develop a scheme to address this challenge. Specifically, we use the Elliptic Curves Cryptography (ECC) algorithm to realize secure allocation of location-dependent tasks. During the report submission phase, we adopt the improved message-lock encryption to realize privacy-preserving data de-duplication and to resist the duplicate-faking attacks. Besides, we present a novel signature scheme that can efficiently record the contributions of each vehicle. The security analysis and performance evaluation demonstrate that the proposed scheme can achieve secure and privacy-preserving report de-duplication with moderate computation and communication overhead. Shunrong Jiang, Jianqing Liu, Mengjie Duan, Liangmin Wang 0001, Yuguang Fang |
GLOBECOM | 4 |
| 2018 | A Secure Data Forwarding Scheme in Vehicular Named Data NetworkingabstractIn vehicular ad hoc networks (VANETs), vehicles' mobility and urban obstacles may cause frequent communication disconnections and sudden network changes. As a result, the traditional IP-based node-to-node content delivery mechanism does not adapt well to such changes in VANETs. To solve this problem, in this paper, we study the Named Data Networking (NDN) architecture to support efficient and secure data forwarding in urban VANETs. To meet security requirements, we adopt the encryption-based name obfuscation to achieve Interest-based access control. Moreover, the revocation of illegal vehicles and the updated operation are addressed by proxy re-encryption method, which saves the main communication overhead during the process. Finally, we design an incentive scheme to guarantee the utility of NDN in VANETs. The security analysis shows that the proposed secure scheme can satisfy security requirements of the data forwarding in VANETs. The performance analysis indicates that the overhead caused by the proposed secure scheme is low and acceptable. Shunrong Jiang, Jianqing Liu, Liangmin Wang 0001, Yuguang Fang |
GLOBECOM | 3 |
| 2018 | Secure and efficient k-nearest neighbor query for location-based services in outsourced environments
Haiqin Wu, Liangmin Wang 0001, Tao Jiang 0017 |
Sci. China Inf. Sci. | 2 |
| 2018 | Secure Top-k Preference Query for Location-based Services in Crowd-outsourcing EnvironmentsabstractThis paper considers a practical crowd-outsourcing system model for location-based services which has become increasingly popular due to the rapid proliferation of location-aware mobile devices. In our system, multiple data owners (DOs) outsource their small number of points of interests (POIs) to the location-based service provider (LBSP), then LBSP manages these POIs datasets and allows users to share information and perform top-k queries according to their own preferences. One crucial problem in this system is how to deal with the untrusted LBSP, who may return fake or incorrect query results to users for certain motives. However, the traditional top-k query and verification schemes, where only an individual DO and a single query attribute are considered, cannot be efficiently applied to our system, as users have distinct query preferences and the query may involve multiple DOs. In this paper, we design a dominant authentication graph DAUG) to process the multi-attribute data on multiple datasets efficiently, and two schemes are proposed for users to verify the integrity of the query result based on DAUG. Finally, theoretical analysis and simulation results show our superiority to the previous scheme in terms of effectiveness and efficiency. Haiqin Wu, Liangmin Wang 0001, Shunrong Jiang |
Comput. J. | 2 |
| 2018 | Toward Privacy-Preserving Symptoms Matching in SDN-Based Mobile Healthcare Social NetworksabstractMobile healthcare social networks (MHSNs) have arisen as a very promising brandnew healthcare system, which will greatly improve the quality of life. Moreover, with the help of software defined networking (SDN) paradigm, it can enhance the user experience. To achieve personal health information sharing and the access control among parities, a similar symptoms matching process should be executed before that. However, the matching process requires users to exchange symptoms information, conflicting with the ever-increasing privacy concerns on protecting private symptoms from strangers. To realize privacy-preserving symptoms matching, in this paper, we design two blind signature-based symptom matching schemes in SDN-based MHSNs, which can achieve the coarse-grained symptom matching and fine-grained symptom matching, respectively. Moreover, our schemes do not relay on any trusted third party. Security analysis and detailed simulations show that our proposed schemes can realize efficient privacy-preserving symptom matching. Finally, we do comprehensive experimental evaluation on real-world smartphones to demonstrate the practicality of our proposed schemes. Shunrong Jiang, Mengjie Duan, Liangmin Wang 0001 |
IEEE Internet Things J. | 3 |
| 2018 | NOTSA: Novel OBU With Three-Level Security Architecture for Internet of VehiclesabstractInternet of Vehicles has become a massive network, which enables multinetwork fusion, including in-vehicle network, wireless local area network, dedicated short range communication, device-to-device communication, and cellular network (e.g., 5G). Proverbially, in-vehicle network is considered as a closed network and thus absolutely secure. However, multiple networks access and fusion can introduce different threats. Current on board units (OBUs) fail to protect in-vehicle network. Therefore, illegal vehicle control can be easily performed for attackers. In this paper, in consideration of vulnerabilities of current OBUs and in-vehicle controller area network, we show main attack model for actual vehicles, and assess introduced threats using the approach based on ISO 13335 guidelines for the management of IT security. Then, we design the novel OBU with three-level security architecture (NOTSA) and propose multilevel security protocols. It cannot only improve the security of external networks, but also protect the in-vehicle network by collaborating with current in-vehicle security schemes. Thereafter, we analyze security of proposed scheme, and evaluate it on hardware platform. The reliability of NOTSA and vehicular ad-hoc networks are then discussed using reliability block diagrams. In addition, we also verify the correctness of proposed protocols. Finally, the simulation results and comparison show that our scheme is feasible and more efficient than existing schemes in term of time overhead, security and reliability. Liangmin Wang 0001, Xiaolong Liu 0007 |
IEEE Internet Things J. | 1 |
| 2018 | Answering Multiattribute Top-k Queries in Fog-Supported Wireless Sensor Networks Leveraging Priority Assignment TechnologyabstractThe large-scale and distributed characteristic of multiattribute sensors requires the fog computing paradigm to support location-awareness and latency-sensitive monitoring and query in industrial applications. In these settings, supporting the preference top-k query processing in skewness distribution is a challenge. In this paper, we propose to mitigate the problem of processing a large number of continuous multiattribute (i.e., multidimensional) top-k queries, each with its specific preference, in fog-supported wireless sensor networks. Specifically, a priority-aware index tree is constructed to support the efficient filtering through querying branch nodes according to their top-k result generation probabilities. We have also considered three situations to generate the filter thresholds for the preference user queries. To further eliminate the transmission of invalid thresholds and query results, an enhanced top-k query processing mechanism based on dual transform and K-sky band is developed. Experiments using synthetic dataset and Intel Berkeley Lab dataset show that our proposed approach can have significant improvements in energy efficiency over other reactive methods. Jine Tang, Zhangbing Zhou, Liangmin Wang 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2017 | A Cloud-Based Trust Evaluation Scheme Using a Vehicular Social Network EnvironmentabstractNew generation communication technologies (e.g., 5G) enhance interactions in mobile and wireless communication networks between devices by supporting a large-scale data sharing. The vehicle is such kind of device that benefits from these technologies, so vehicles become a significant component of vehicular networks. Thus, as a classic application of Internet of Things (IoT), the vehicular network can provide more information services for its human users, which makes the vehicular network more socialized. A new concept is then formed, namely "Vehicular Social Networks (VSNs)", which bring both benefits of data sharing and challenges of security. Traditional public key infrastructures (PKI) can guarantee user identity authentication in the network; however, PKI cannot distinguish untrustworthy information from authorized users. For this reason, a trust evaluation mechanism is required to guarantee the trustworthiness of information by distinguishing malicious users from networks. Hence, this paper explores a trust evaluation algorithm for VSNs and proposes a cloud-based VSN architecture to implement the trust algorithm. Experiments are conducted to investigate the performance of trust algorithm in a vehicular network environment through building a three-layer VSN model. Simulation results reveal that the trust algorithm can be efficiently implemented by the proposed three-layer model. Biling Lin, Xiao Chen 0003, Liangmin Wang 0001 |
APSEC | 3 |
| 2017 | Secret-Sharing Approach for Detecting Compromised Mobile Sink in Unattended Wireless Sensor Networks
Xiangyi Chen, Liangmin Wang 0001 |
MSN | 2 |
| 2017 | An Efficient and Secure Authentication Scheme for In-vehicle Networks in Connected Vehicle
Mengjie Duan, Shunrong Jiang, Liangmin Wang 0001 |
MSN | 3 |
| 2017 | Trust Mechanism Based AODV Routing Protocol for Forward Node Authentication in Mobile Ad Hoc Network
Muhammad Sohail 0001, Liangmin Wang 0001, Bushra Yamin |
MSN | 2 |
| 2017 | A Fast Handover Scheme for SDN Based Vehicular Network
Xing Yin, Liangmin Wang 0001 |
MSN | 2 |
| 2017 | Personalized extended (α, k)-anonymity model for privacy-preserving data publishingabstractSummary General (α,k)‐anonymity model is a widely used method in privacy‐preserving data publishing, but it cannot provide personalized anonymity. At present, two main schemes for personalized anonymity are the individual‐oriented anonymity and the sensitive value‐oriented anonymity. Unfortunately, the existing personalized anonymity models, designed for any of the aforementioned schemes for privacy‐preserving data publishing, are not effective enough to meet the personalized privacy preservation requirement. In this paper, we propose a novel personalized extended scheme to provide the personalized services in general (α,k)‐anonymity model. The sensitive value‐oriented anonymity is combined with the individual‐oriented anonymity in the new personalized extended (α,k)‐anonymity model by the following two steps: (1) The sensitive attribute values are divided into several groups according to their sensitivities, and each group is assigned with its own frequency constraint threshold. (2) A guarding node is set for each individual to replace his/her sensitive value if necessary. We implement the personalized extended (α,k)‐anonymity model with a clustering algorithm. The performance evaluation finally shows that our model can provide stronger privacy preservation efficiently as well as achieving the personalized service. Copyright © 2016 John Wiley & Sons, Ltd. Xiangwen Liu, Qing-Qing Xie, Liangmin Wang 0001 |
Concurr. Comput. Pract. Exp. | 3 |
| 2017 | Secrecy Capacity Analysis of Artificial Noisy MIMO Channels - An Approach Based on Ordered Eigenvalues of Wishart MatricesabstractArtificial noise (AN) can be used to confuse eavesdroppers in a physical layer security system. One of the main issues concerned in AN schemes is how to improve secrecy capacities. Most existing AN schemes were proposed based on an assumption that the number of transmit antennas t is larger than that of receiver antennas r, such that they can utilize all r eigen-subchannels of a multiple-output multiple-input (MIMO) system to send messages, and use remaining t - r null spaces for transmitting AN signals. These AN signals null out legitimate receivers and degrade eavesdropper channels. However, transmitting messages in all eigen-subchannels is not always a good strategy. In particular, when the number of transmit antennas is constrained or even smaller than those of receivers, the secrecy capacities of legitimate receivers will be impaired significantly if using all eigen-subchannels for message transmission. To improve secrecy capacity, we propose an AN scheme where messages are encoded in s (which is a variable) strongest eigen-subchannels based on ordered eigenvalues of Wishart matrices, while AN signals are generated in remaining t - s spaces. We derive the average secrecy capacity of a single-user MIMO wiretap channel in the presence of an eavesdropper with multiple antennas. We show that the numerical results are in a good agreement with simulation results. The secrecy capacity of the proposed AN scheme can be improved by approximately 20% ~ 40% if compared with existing AN schemes. Yiliang Liu, Hsiao-Hwa Chen, Liangmin Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | ECDS: Efficient collaborative downloading scheme for popular content distribution in urban vehicular networksabstractThe recent development of the Vehicular Ad-hoc Networks (VANETs) has motivated an increasing interest in in-vehicle consumption, and hence, the Popular Content Distribution (PCD) has become a heated issue. Compared with PCD solutions based on the widely-used cellular networks and Dedicated Short Range Communications (DSRC), solutions based on Collaborative Downloading (CD) are more economical and efficient. Due to the limited bandwidth, the On-Board Units (OBUs) passing through a Road Side Unit (RSU) can only download a portion of the popular content. To get over that drawback and to effect a collaborative downloading, a P2P network should be constructed among the OBUs which fall out of the RSUs coverage. In this paper, we address the efficient collaborative downloading scheme (ECDS) for PCD in urban traffic scenarios. To adapt to the rapid-changing characteristics of the VANET topology, a new cell-based clustering scheme is proposed, which greatly simplifies the modeling. Besides a strategy of inter-cluster Relay Selection is proposed to construct a pear-to-pear (P2P) network of scale-free property, which will help enhancing the information spread. Furthermore, another inter-cluster strategy of generation selection is to be collaborated to accelerate the dissemination process in the P2P network. The comparison experiments to two up-to-date collaborative PCD protocols demonstrate the high performance of the proposed scheme, i.e. ECDS. Wei Huang 0007, Liangmin Wang 0001 |
Comput. Networks | 2 |
| 2016 | Power allocation design and optimization for secure transmission in cognitive relay networksabstractAbstract In this paper, physical layer security is investigated in the dual‐hop amplify‐and‐forward cognitive relay network with one secondary source, one secondary destination, multiple cognitive relays under the presence of multiple primary receivers and eavesdroppers which can be either primary receivers or secondary receivers. The power allocation method at secondary source and artificial noise at relays are utilized to secure the secondary source‐destination transmission. Two optimization problems, namely, to maximize the received signal‐to‐interference‐and‐noise ratio of secondary source in the lightly‐loaded relay cluster situation, and to minimize the relay cluster total power in the fully‐loaded relay cluster situation, are formulated. In addition, these two problems should ensure both physical‐layer security and lower interference temperature. The semi‐definite relaxation technique is used to solve the considered optimization problems. In the second problems, we further optimize the performance with the help of the bisection method. Complexity analysis shows that our proposed method is efficient and also can be solved in polynomial time. Theoretical analysis and the Monte‐Carlo simulation results validate the proposed method. Copyright © 2016 John Wiley & Sons, Ltd. Yiliang Liu, Liangmin Wang 0001 |
Secur. Commun. Networks | 4 |
| 2016 | An Efficient Anonymous Batch Authentication Scheme Based on HMAC for VANETsabstractIn vehicular ad hoc networks (VANETs), when a vehicle receives a message, the certificate revocation list (CRL) checking process will operate before certificate and signature verification. However, large communication sources, storage space, and checking time are needed for CRLs that cause the privacy disclosure issue as well. To address these issues, in this paper, we propose an efficient anonymous batch authentication scheme (ABAH) to replace the CRL checking process by calculating the hash message authentication code (HMAC). In our scheme, we first divide the precinct into several domains, in which road-side units (RSUs) manage vehicles in a localized manner. Then, we adopt pseudonyms to achieve privacy-preserving and realize batch authentication by using an identity-based signature (IBS). Finally, we use HMAC to avoid the time-consuming CRL checking and to ensure the integrity of messages that may get loss in previous batch authentication. The security and performance analysis are carried out to demonstrate that ABAH is more efficient in terms of verification delay than the conventional authentication methods employing CRLs. Meanwhile, our solution can keep conditional privacy in VANETs. Shunrong Jiang, Xiaoyan Zhu 0005, Liangmin Wang 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2015 | Lightweight and privacy-preserving agent data transmission for mobile HealthcareabstractWith the pervasiveness of smartphones and the advance of wireless body sensor networks (WBSNs), mobile healthcare (m-healthcare) has attracted considerable interest recently. In m-Healthcare, users' smartphones serve as bridges connecting their WBSNs and the healthcare center (HCC), i.e., send users' personal health information (PHI) collected by WBSNs to the HCC and receive the feedback. However, users' smartphones are not always available (e.g., left at home or out of power), resulting in an unexpected interruption of medical services sometimes, which are not considered in most existing schemes for m-healthcare. In this paper, we propose a lightweight and privacy-preserving agent data transmission scheme for m-healthcare in opportunistic social networks on condition that the smartphone is not available. By using the proposed protocol, we can provide uninterrupted healthcare while keeping the user's identity and PHI private during the agent transmitting of PHI. Security and performance analysis show that the proposed scheme can realize privacy-preservation and achieve secure end-to-end communication for m-healthcare, and is suitable for resource-limited WBSNs. Shunrong Jiang, Xiaoyan Zhu 0005, Ripei Hao, Haotian Chi, Hui Li 0006, Liangmin Wang 0001 |
ICC | 6 |
| 2013 | A conditional privacy scheme based on anonymized batch authentication in Vehicular Ad Hoc NetworksabstractAddressing security and privacy issues is a prerequisite for market-ready Vehicular Ad Hoc Networks. In this paper, an anonymous batch authentication scheme is proposed to authenticate multiple requests sent from different vehicles at the same time. The scheme achieves privacy-preserving by pseudonyms, ensures the backward privacy of the revoked vehicles by hash chain, and realize the batch authentication by using an identity-based signature (IBS). To avoid the communication overhead caused by broadcasting the Certificate Revocation List (CRL) and the privacy disclosure issue of the revocation vehicles, we revoke the illegal vehicles through calculating Hash Message Authentication Code (HMAC) by using the group key. In addition, integrity of the batch messages is ensured and efficient batch authentication is achieved. The analysis shows that our scheme has a better performance than the current batch authentication schemes on authentication delay and revocation overhead. The generated group key and pair key during the authenticated process can be used for value-added service, as the realization of HMAC doesn't require additional overhead. Shunrong Jiang, Xiaoyan Zhu 0005, Liangmin Wang 0001 |
WCNC | 3 |
| 2012 | Mechanism Design Based Nodes Selection Model for Threshold Key Management in MANETsabstractThe design of threshold based distributed Certification Authority (CA) has been proposed to provide secure and efficient key management service in mobile ad hoc networks (MANETs). However, most of previous works ignore the efficiency and effectiveness and assuming there are always honest nodes performing the service. Focusing on the development of a model which can be used to select a coalition of nodes dynamically and optimally to carry out the threshold key management service during its operation in MANETs with selfish nodes, this paper formulates the dynamic nodes selection problem as combinatorial optimization problem with the objectives of maximizing the success ratio of key management service and minimizing the nodes' cost of security and energy firstly. Then, to ensure truth-telling is the dominant strategy for any node in our scenario, we extend the payment structure of the classical Vickrey, Clarke, and Groves (VCG) mechanism design framework and divide the payment to nodes in the coalition of nodes with the consideration of the actual execution effectiveness of each one. Simulations show that proposed model enjoys an improvement of both the success ratio of key management service and lifetime of the network, and a reduction of both the cost of participating nodes and compromising probability of MANETs, compared with existing works in the presence of selfish nodes. Jianfeng Ma 0001, Chao Wang 0085, Liangmin Wang 0001 |
TrustCom | 4 |
| 2012 | Network Coding-Based Mutual Anonymity Communication Protocol for Mobile P2P NetworksabstractTo protect user privacy in mobile peer to peer (MP2P) networks, a network coding-based mutual anonymity communication protocol (NMA) is proposed. Our contributions are described as below. We first design a network coding scheme which can defend against various omniscient adversary attacks. Then a novel anonymous communication protocol is presented to meet the anonymity requirement for MP2P applications. The novel anonymous communication protocol is comprised of three steps: query issuance, reply-confirm and file delivery. They all employ the network coding scheme to split and encrypt the signaling and data information. The splitted fragments are flooded at a certain number of hops until some intermediate peers called agents, can collect enough fragments to recover the original information. Next, the agents forward the messages to their neighboring peers. For the query issuance, the neighboring peers forward the query message to the responders by random walk mechanism. For the rest steps, the data information is delivered along the reversed paths discovered by the way of onion routing plus buffer information in routing table. In the entire process, the identities and sensitive information about the initiator and responder are completely hidden. The advantages of the scheme lie in the fact that the network coding and mutli-agent can improve the load balance, the successful rate of information transmission and anonymity degree. The experimental results demonstrate that when the percentage of malicious peers is lower than 50%, the various performances of the NMA, including the response time and the success rate, outperform other mutual anonymity schemes. Zhiyuan Li 0002, Liangmin Wang 0001, Siguang Chen |
TrustCom | 2 |
| 2011 | Updatable Key Management Scheme with Intrusion Tolerance for Unattended Wireless Sensor NetworkabstractAn Unattended Wireless Sensor Network (UWSN) collects the sensing data by using mobile sinks (MSs). It differs from the traditional multi-hop wireless sensor networks in which unbalanced traffic makes the sensors close to the base station deplete their power earlier than others. An UWSN can save the battery power and prolong the network lifetime. Unfortunately, MSs would be given too much privilege when acting as the collecting base station, which will cause security concern if compromised. Besides, UWSNs are usually deployed in unreachable and hostile environments, where sensors can be easily compromised. Thus, their security issues should be carefully addressed to deal with node compromise. In this paper, we present a novel key management scheme to secure UWSNs. We employ the Blundo symmetric polynomial mechanism to guard against the newly compromised nodes in a period while utilizing the periodic key updating based on the reverse hash chain to block the compromised nodes and revoke the compromised MSs if failing the authentication. We show that our scheme is robust against node compromised attacks and carry out comparison analysis on the intrusion-tolerance ratio, communication and computing overhead. Liangmin Wang 0001, Tao Jiang 0017, Xiaoyan Zhu 0005 |
GLOBECOM | 1 |
| 2006 | Fault and intrusion tolerance of wireless sensor networksabstractThe following three questions should be answered in developing new topology with more powerful ability to tolerate node-failure in wireless sensor network. First, what is node-failure tolerance of topologies? Second, how to evaluate this tolerance ability? Third, which type of topologies is more efficient in tolerating node-failure? Without giving the answers, the existing work regards fault-tolerance topology as the multiply connected graph, and use the connectivity of the graph as the standard to evaluate tolerance ability. In this paper, we argue that fault tolerance of topologies is not equivalent to the connectivity of multiply connected graph by illustrating two concrete examples. Then the definition of node-failure tolerance is presented. According fault and intrusion, the two sources of failure nodes, we define fault tolerance and intrusion tolerance as the standards to evaluate the tolerance ability of topologies, and analyze the tolerance performance of hierarchical structure of wireless sensor network by using these standards. Finally, the function relation between hierarchical topology and its tolerance abilities of fault and intrusion is obtained, and an obvious corollary is that fault tolerance increase with the ratio of cluster head hierarchical structure, but with the intrusion tolerance decreasing. Liangmin Wang 0001, Jianfeng Ma 0001, Chao Wang 0085, Alex Chichung Kot |
IPDPS | 1 |