EDBT 2026 Demo / reviewers in the wild / expert
Jian Ren 0001
dblp:59/2180-1
· DBLP profile ↗
101ranked-venue papers
16as first author
16since 2021 · last 2025
0000-0001-7796-8501ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 66 · 11 first-author · 7 since 2021Security and privacy · 14 · 4 first-author · 2 since 2021Systems, architecture and hardware · 6 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Theory of computation · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Lightweight and Effective Characterization, Screening, and Identification Process for Anomalous Road Traffic AttacksabstractSmart mapping applications- Google Maps, Apple Maps, Waze- have become ubiquitous in the modern smart city. While the use of these apps undoubtedly eases a number of daily frustrations, their rapid acceptance and integration into every facet of transportation, public safety, and disaster response raises security concerns. Among these concerns is the possibility of an easily-implemented client-side attack; the traffic state shown on a smart map indicates the number of users- not cars- and this disconnect between the ground truth and virtual environment could be exploited by an adversary simply operating a disingenuous number of client devices. In this paper we examine the vulnerabilities exposed by such an adversary and propose a model which combines machine learning traffic prediction and real-time statistical analysis to screen for anomalous traffic attacks. Extensive simulations suggest that our model greatly increases the resources (number of client devices) required to noticeably influence traffic patterns. We show that our model correctly identifies 54.17 % of attacks immediately and reduces the duration of initially undetected attacks by 60.4 % compared to a typical polling system under ideal circumstances, where an adversary has access to an average of 76.0 % more client devices. Jaxon Hancock, Tongtong Li, Jian Ren 0001 |
ICC | 3 |
| 2025 | From Bi-Level to One-Level: A Framework for Structural Attacks to Graph Anomaly DetectionabstractThe success of graph neural networks stimulates the prosperity of graph mining and the corresponding downstream tasks including graph anomaly detection (GAD). However, it has been explored that those graph mining methods are vulnerable to structural manipulations on relational data. That is, the attacker can maliciously perturb the graph structures to assist the target nodes in evading anomaly detection. In this article, we explore the structural vulnerability of two typical GAD systems: unsupervised FeXtra-based GAD and supervised graph convolutional network (GCN)-based GAD. Specifically, structural poisoning attacks against GAD are formulated as complex bi-level optimization problems. Our first major contribution is then to transform the bi-level problem into one-level leveraging different regression methods. Furthermore, we propose a new way of utilizing gradient information to optimize the one-level optimization problem in the discrete domain. Comprehensive experiments demonstrate the effectiveness of our proposed attack algorithm $\textsf {BinarizedAttack}$ . Yulin Zhu 0001, Yuni Lai, Kaifa Zhao, Xiapu Luo, Mingquan Yuan, Jun Wu 0001, Jian Ren 0001, Kai Zhou 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 7 |
| 2024 | Accurate Traffic State Prediction with Deep Learning - Analyzing Statistical Aides for Identifying Anomalous Traffic TrendsabstractTraffic is an expected part of many people’s lives. To be able to accurately estimate the traffic state and determine the optimal route is of crucial importance to maintain coherence in both a smart-city system and in long-distance travel scenarios. Applications such as Google Maps, Apple Maps and Waze are critical tools in the hands of everyday commuters and emergency service providers alike-but also a potential vulnerability for those seeking to influence or disrupt regular traffic patterns. In this paper, we consider the most basic scenario-where the majority of end-users of mapping software are benign and truthful. We go on to propose a lightweight and adaptable model for estimating traffic states and demonstrate its effectiveness. We also analyze the feasibility of the proposed model for identifying anomalous traffic attacks in comparison with similar models. We create a theoretical framework based on minimization of error rate and conduct simulations which support efficacy in identifying these attacks using a statistically-augmented lightweight LSTM network with up to 84% fewer parameters than existing models, promoting use in low-resource applications. Moreover, the proposed model relies only on data which would be readily available to a smart mapping application. In 4-hour estimation scenarios with real-world data, the proposed model performed 11.8% better than a comparably complex LSTM model without statistical augmentation. Jaxon Hancock, Jian Ren 0001 |
ICPADS | 2 |
| 2024 | Graph isomorphism - Characterization and efficient algorithmsabstractThe Graph isomorphism problem involves determining whether two graphs are isomorphic and the computational complexity required for this determination. In general, the problem is not known to be solvable in polynomial time, nor to be NP-complete. In this paper, by analyzing the algebraic properties of the adjacency matrices of the undirected graph, we first established the connection between graph isomorphism and matrix row and column interchanging operations. Then, we prove that for undirected graphs, the complexity in determining whether two graphs are isomorphic is at most O(n3). Jian Ren 0001, Tongtong Li |
High Confid. Comput. | 1 |
| 2024 | Automated Adaptive Cinematography for User Interaction in Open WorldabstractAdvancements in wearable technology and their capacity to interpret user movements, transforming them into interactive actions in virtual environments, have sparked an increased demand for user flexibility within these spaces. A direct outcome of this growing trend is the imperative need for automated cinematography in expansive, open-world scenarios. Nevertheless, the task of interpreting these interactive sequences through automated cinematography in unconstrained environments involves significant computational challenges. In response to this, we introduce the Automated Adaptive Cinematography for Open-world Generative Adversarial Network (AACOGAN) -an innovative solution that addresses these issues. Contrary to traditional models, which require comprehensive prior knowledge about scenes, characters, and objects, AACOGAN identifies and models the relationships among user interactions, object positions, and camera movements during the process of user engagement. This novel approach allows the model to function effectively even in open-world scenarios riddled with numerous uncertain factors. In the experimental phase, we developed and employed theMineStory Dataset, designed specifically for automatic cinematography in open-world scenarios. We devised and implemented novel metrics that are more congruent with the distinctive features of open-world scenarios. These innovative metrics provide a more nuanced understanding of the performance and effectiveness of our proposed method. Experimental findings substantiate that AACOGAN significantly enhances automatic cinematography performance within open-world contexts, including an average augmentation of 73% in the correlation between user interactions and camera trajectories, and an increase of up to 32.9% in the quality of multi-focus scenes. Therefore, AACOGAN emerges as an efficient, and innovative solution for creating appropriate camera shots in a myriad of interactive motions in open-world scenarios. An exemplary video footage can be found athttps://youtu.be/pbSHF-uxomw. Zixiao Yu, Xinyi Wu 0001, Haohong Wang, Aggelos K. Katsaggelos, Jian Ren 0001 |
IEEE Trans. Multim. | 5 |
| 2023 | A Mathematical Model for Neuronal Activity and Brain Information Processing CapacityabstractNeurophysiological measurements suggest that human information processing is evinced by neuronal activity. However, the quantitative relationship between the activity of a brain region and its information processing capacity remains unclear. In this paper, we introduce an information conservation law for regional brain activation, and establish a mathematical model to quantify the relationship between the information processing capacity, input storage capacity, the arrival rate of exogenous information, and the neuronal activity of a brain region—referred to as the brain information processing capacity (IPC) model. We apply the IPC model to event related fMRI data from a flanker test, designed to determine age-related differences in brain activation. Our analysis demonstrates the predictive validity of the model in terms of providing accurate account of fMRI responses, and shows that for a given cognitive task, higher information processing capacity leads to lower neuronal activity level and faster response. Relying solely on the information conservation law, the IPC model provides a framework for modeling distributed neuronal processing—and can be applied to different data types and scales: i.e., single neurons, brain regions, and networks. David C. Zhu, Jian Ren 0001, Taosheng Liu, Karl J. Friston, Tongtong Li |
ICASSP | 3 |
| 2023 | d-EMR: Secure and distributed Electronic Medical Record managementabstractAs more and more data is produced, finding a secure and efficient data access structure has become a major research issue. The centralized systems used by medical institutions for the management and transfer of Electronic Medical Records (EMRs) can be vulnerable to security and privacy threats, often lack interoperability, and give patients limited or no access to their own EMRs. In this paper, we first propose a privilege-based data access structure and incorporates it into an attribute-based encryption mechanism to handle the management and sharing of big data sets. Our proposed privilege-based data access structure makes managing healthcare records using mobile healthcare devices efficient and feasible for large numbers of users. We then propose a novel distributed multilevel EMR (d-EMR) management scheme, which uses blockchain to address security concerns and enables selective sharing of medical records among staff members that belong to different levels of a hierarchical institution. We deploy smart contracts on Ethereum blockchain and utilize a distributed storage system to alleviate the dependence on the record-generating institutions to manage and share patient records. To preserve privacy of patient records, our smart contract is designed to allow patients to verify attributes prior to granting access rights. We provide extensive security, privacy, and evaluation analyses to show that our proposed scheme is both efficient and practical. Ehab Zaghloul, Tongtong Li, Jian Ren 0001 |
High Confid. Comput. | 3 |
| 2023 | Security and Energy Efficiency: Breaking the Barriers of High Peak-to-Average Power Ratio and Disguised Jamming in NextG IoT System DesignabstractAs a popular modulation technique in wireless communications, orthogonal frequency-division multiplexing (OFDM) has two major disadvantages—one is its high peak-to-average power ratio (PAPR), which causes nonlinear distortion, lower power efficiency, and performance losses; the other is its fragility under hostile jamming attacks, where the authorized user asciitext’s signal is deliberately interfered by the adversary, leading to communication failures. In this article, first, we reintroduce the IFFT-relocated OFDM (IR-OFDM), which is essentially a single-carrier system with frequency-domain equalization. By relocating the inverse fast Fourier transform (IFFT) block in OFDM from the transmitter to receiver, IR-OFDM can completely liberate OFDM from the barriers of high PAPR while achieving the same spectral efficiency. Second, to combat hostile jamming, especially disguised jamming, where the jamming is highly correlated with the authorized signal, we propose a securely precoded IR-OFDM (SP-IR-OFDM). By integrating the advanced encryption standard (AES) into IR-OFDM transceiver design, we obtain a random (or dynamic) constellation. The shared secure randomness introduced by AES breaks the symmetry between the authorized signal and the jamming interference and, hence, ensures reliable performance of the system under disguised jamming. The efficiency and robustness of IR-OFDM and SP-IR-OFDM are demonstrated through simulation examples. It is shown that IR-OFDM can deliver comparable or better performances than OFDM under multipath propagation, and SP-IR-OFDM can achieve strong resistance under disguised jamming while enjoying low PAPR and relatively high spectral efficiency. Our result indicates that, potentially, SP-IR-OFDM can serve as a promising modulation candidate for next-generation secure and energy-efficient high-speed communications, especially for the resource-constrained Internet of Things (IoT) networks. Tongtong Li, Jinxian Deng, Jian Ren 0001 |
IEEE Internet Things J. | 3 |
| 2023 | Guest Editorial Special Issue on When Blockchain Meets 5G/6G - Enabling Endogenously Secure IoTabstractThe standardization of the fifth-generation (5G) communications has been completed, and the visioning and planning of the sixth-generation (6G) communications have begun, with an objective of casting the high technical standard of new spectrum, high time and phase synchronization accuracy, and 100% geographical coverage to flexibly and efficiently connect upper trillion-level devices in the future. The transition from 5G to 6G is expected to integrate all operational networks, especially the Internet of Things (IoT), which involves massive heterogeneous devices to interact with our physical world. Dongxiao Yu, Jian Ren 0001, Sasu Tarkoma, Madhuri Siddula, Falko Dressler |
IEEE Internet Things J. | 2 |
| 2023 | A Novel Automatic Content Generation and Optimization FrameworkabstractWith the rapid growth of IoT multimedia devices, more and more content is being delivered in multimedia forms which generally requires more effort and resources from users to create and could be challenging to streamline. In this article, we propose Text2Animation (T2A), a framework that helps to generate complex multimedia content, and animation, from the simple textual script input. By leveraging recent advances in computational cinematography and video understanding, the purposed workflow further reduces associated knowledge requirements dramatically for cinematography. By jointly incorporating the fidelity and aesthetic models, T2A jointly considers the comprehensiveness of the visual presentation of the input script and the compliance of generated video with given cinematography specifications. The virtual camera placement in a 3-D environment is mapped into an optimization problem that can be resolved by using dynamic programming to achieve the lowest computational complexity. Experimental results show that T2A can reduce the manual animation production process by around 74%, and the new optimization framework can improve the perceptual quality of the output video by up to 35%. More video footage can be found athttps://www.youtube.com/watch?v=MMTJbmWL3gs. Zixiao Yu, Haohong Wang, Aggelos K. Katsaggelos, Jian Ren 0001 |
IEEE Internet Things J. | 4 |
| 2022 | BinarizedAttack: Structural Poisoning Attacks to Graph-based Anomaly DetectionabstractGraph-based Anomaly Detection (GAD) is becoming prevalent due to the powerful representation abilities of graphs as well as recent advances in graph mining techniques. These GAD tools, however, expose a new attacking surface, ironically due to their unique advantage of being able to exploit the relations among data. That is, attackers now can manipulate those relations (i.e., the structure of the graph) to allow some target nodes to evade detection. In this paper, we exploit this vulnerability by designing a new type of targeted structural poisoning attacks to a representative regression-based GAD system termed OddBall. Specifically, we formulate the attack against OddBall as a bi-level optimization problem, where the key technical challenge is to efficiently solve the problem in a discrete domain. We propose a novel attack method termed BinarizedAttack based on gradient descent. Comparing to prior arts, BinarizedAttack can better use the gradient information, making it particularly suitable for solving combinatorial optimization problems. Furthermore, we investigate the attack transferability of BinarizedAttack by employing it to attack other representation-learning-based GAD systems. Our comprehensive experiments demonstrate that BinarizedAttack is very effective in enabling target nodes to evade graph-based anomaly detection tools with limited attacker's budget, and in the black-box transfer attack setting, BinarizedAttack is also tested effective and in particular, can significantly change the node embeddings learned by the GAD systems. Our research thus opens the door to studying a new type of attack against security analytic tools that rely on graph data. Yulin Zhu 0001, Yuni Lai, Kaifa Zhao, Xiapu Luo, Mingquan Yuan, Jian Ren 0001, Kai Zhou 0001 |
ICDE | 6 |
| 2022 | Feasible Region of Secure and Distributed Data Storage in Adversarial NetworksabstractLarge volumes of data are being generated daily from IoT networks, healthcare, and many other applications, which makes secure, reliable, and cost-effective data storage a critical infrastructure of the computing system. Existing data storage largely depends on centralized clouds, which is not only costly but also vulnerable to single points of failure and other types of security attacks. Moreover, cloud providers will have full access to user data and revision history beyond user control. To provide data security, data encryption has to be used, which requires extensive computing power and cumbersome key management. Distributed storage system (DSS) is being widely viewed as a natural solution to future online data storage due to improved access time and lower storage cost. However, the existing DSS also has the limitations of low storage efficiency and weak data security. In this article, we investigate multi-layer code-based distributed data storage systems that can achieve inherit content confidentiality and optimal storage efficiency. Our comprehensive performance analysis shows that the optimal code can improve the feasible region in reliable data storage by 50% under various adversarial attack scenarios. Jian Ren 0001, Jian Li 0007, Tongtong Li, Matt W. Mutka |
IEEE Internet Things J. | 1 |
| 2022 | RealPRNet: A Real-Time Phoneme-Recognized Network for "Believable" Speech AnimationabstractWith the technology development, more and more Internet of Things (IoT) devices with displays are making “face-to-face” interaction through visualization a reality. To protect the privacy of users, communications can be represented through avatars and use audio-driven real-time speech animation. However, if audio is the only available input, the quality of the outcome relies heavily on real-time phoneme recognition, such as recognition accuracy and latency. This article introduces a novel deep-learning-based real-time phoneme recognition network (RealPRNet) scheme to leverage spatial and temporal patterns in the input audio data. With featured long short-term memory stack block and long short-term features, RealPRNet can achieve super performance in phoneme recognition. Our comprehensive empirical results show that compared to the state-of-the-art algorithms, RealPRNet can achieve 20% phoneme error rate (PER) improvement and 4% block error distance (BDE) improvement in the best case. Zixiao Yu, Haohong Wang, Jian Ren 0001 |
IEEE Internet Things J. | 3 |
| 2022 | $d$d-MABE: Distributed Multilevel Attribute-Based EMR Management and ApplicationsabstractCurrent systems used by medical institutions for the management and transfer of Electronic Medical Records (EMRs) can be vulnerable to security and privacy threats. In addition, these systems are centralized, often lack interoperability, and give patients limited or no access to their own EMRs. In this article, we propose a novel distributed data sharing scheme that applies the security benefits of blockchain to address these concerns. We deploy smart contracts on Ethereum blockchain and utilize a distributed storage system to alleviate the dependence on the record-generating institutions to manage and share patient records. To preserve privacy of patient records, we implement our smart contracts as a method to allow patients to verify attributes prior to granting access rights. Our proposed scheme also facilitates selective sharing of medical records among staff members that belong to different levels of a hierarchical institution. We provide extensive security, privacy, and evaluation analyses to show that our proposed scheme is both efficient and practical. Ehab Zaghloul, Tongtong Li, Matt W. Mutka, Jian Ren 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | d-BAME: Distributed Blockchain-Based Anonymous Mobile Electronic VotingabstractElectronic voting (e-voting) presents a convenient and cost-effective alternative to current paper ballot-based voting. It provides many benefits such as increased voter turnout and accuracy in the decision-making process. While presenting many improvements, e-voting still faces serious security challenges that hinder its adoption, especially when designed to be run over mobile devices. In this article, we propose a novel remote e-voting model for large-scale elections by proposing the participation of two conflicting parties to ensure election integrity and accountability. Our scheme can be implemented in IoT devices such as smartphones, which we believe can significantly increase voter turnout of the election process. Our proposed work is secure and preserves voter privacy through secure multiparty computations performed by parties of differing allegiances. It also leverages a blockchain running smart contracts as a publicly accessible and tamper-resistant bulletin board to permanently store votes and prevent double voting. In our security and privacy analysis, we show that our proposed scheme is secure against potential security threats and provides voter anonymity. We show orthogonality between universal verifiability and coercion resistance in our proposed scheme, allowing an election to favor one over the other. Our performance analysis and smartphone simulation results show that the proposed scheme is practical for large-scale elections. Ehab Zaghloul, Tongtong Li, Jian Ren 0001 |
IEEE Internet Things J. | 3 |
| 2021 | CASO: Cost-Aware Secure Outsourcing of General Computational ProblemsabstractComputation outsourcing is an integral part of cloud computing. It enables end-users to outsource their computational tasks to the cloud and utilize the shared cloud resources in a pay-per-use manner. However, once the tasks are outsourced, the end-users will lose control of their data, which may result in severe security issues especially when the data is sensitive. To address this problem, secure outsourcing mechanisms have been proposed to ensure security of the end-users' outsourced data. In this paper, we investigate outsourcing of general computational problems which constitute the mathematical basics for problems emerged from various fields such as engineering and finance. To be specific, we propose affine mapping based schemes for the problem transformation and outsourcing so that the cloud is unable to learn any key information from the transformed problem. Meanwhile, the overhead for the transformation is limited to an acceptable level compared to the computational savings introduced by the outsourcing itself. Furthermore, we develop cost-aware schemes to balance the trade-offs between end-users' various security demands and computational overhead. We also propose a verification scheme to ensure that the end-users will always receive a valid solution from the cloud. Our extensive complexity and security analysis show that our proposed Cost-Aware Secure Outsourcing (CASO) scheme is both practical and effective. Kai Zhou 0001, Jian Ren 0001 |
IEEE Trans. Serv. Comput. | 2 |
| 2020 | Bitcoin and Blockchain: Security and PrivacyabstractBlockchain is a technology that was proposed to enable the decentralized digital currency, Bitcoin. Since its inception, blockchain has been widely used in many other areas, including tracing sensor data and mitigating its duplication in IoT applications, the healthcare industry, and e-voting. In this article, we provide a comprehensive review and analysis of the major security and privacy issues of Bitcoin and blockchain, the major challenges, and opportunities in utilizing the technology. First, we present a comprehensive background of Bitcoin and the preliminary on security. Second, the major security threats and countermeasures of Bitcoin are investigated. We analyze the risk of double-spending attacks, evaluate the probability of success in performing the attacks, and derive the profitability for the attacker to perform such attacks. Third, we analyze the underlying Bitcoin peer-to-peer network security risks and Bitcoin storage security. We compare three types of Bitcoin wallets in terms of security, types of services, and their tradeoffs. Finally, we discuss the security and privacy features of alternative cryptocurrencies and present an overview of emerging technologies today. Our results can help Bitcoin users to determine a tradeoff between the risk of double-spending attempts and the transaction time delay or confidence before accepting transactions. These results can also assist miners to develop suitable strategies to get involved in the mining process and maximize their profits. Ehab Zaghloul, Tongtong Li, Matt W. Mutka, Jian Ren 0001 |
IEEE Internet Things J. | 4 |
| 2020 | P-MOD: Secure Privilege-Based Multilevel Organizational Data-Sharing in Cloud ComputingabstractCloud computing has changed the way enterprises store, access and share data. Big data sets are constantly being uploaded to the cloud and shared within a hierarchy of many different individuals with different access privileges. With more data storage needs turning over to the cloud, finding a secure and efficient data access structure has become a major research issue. In this paper, a Privilege-based Multilevel Organizational Data-sharing scheme (P-MOD) is proposed that incorporates a privilege-based access structure into an attribute-based encryption mechanism to handle the management and sharing of big data sets. Our proposed privilege-based access structure helps reduce the complexity of defining hierarchies as the number of users grows, which makes managing healthcare records using mobile healthcare devices feasible. It can also facilitate organizations in applying big data analytics to understand populations in a holistic way. Security analysis shows that P-MOD is secure against adaptively chosen plaintext attack assuming the DBDH assumption holds. The comprehensive performance and simulation analyses using the real U.S. Census Income data set demonstrate that P-MOD is more efficient in computational complexity and storage space than the existing schemes. Ehab Zaghloul, Kai Zhou 0001, Jian Ren 0001 |
IEEE Trans. Big Data | 3 |
| 2020 | Secure OFDM System Design and Capacity Analysis Under Disguised JammingabstractIn this paper, we propose a securely precoded OFDM (SP-OFDM) system for efficient and reliable transmission under disguised jamming, where the jammer intentionally misleads the receiver by mimicking the characteristics of the authorized signal and causes complete communication failure. More specifically, we bring off a dynamic constellation by introducing secure randomness shared between the legitimate transmitter and receiver, and hence, break the symmetricity between the authorized signal and the disguised jamming. We analyze the channel capacities of both the traditional OFDM and SP-OFDM under hostile jamming using the arbitrarily varying channel (AVC) model. It is shown that the deterministic coding capacity of the traditional OFDM is zero under the worst disguised jamming. On the other hand, due to the secure randomness shared between the authorized transmitter and receiver, SP-OFDM can achieve a positive capacity under disguised jamming since the AVC channel corresponding to SP-OFDM is not symmetrizable. A remarkable feature of the proposed SP-OFDM scheme is that while achieving strong jamming resistance, it has roughly the same high spectral efficiency as the traditional OFDM system. The robustness of the proposed SP-OFDM scheme under disguised jamming is demonstrated through both theoretic and numerical analyses. Yuan Liang 0002, Jian Ren 0001, Tongtong Li |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | Beyond the MDS Bound in Distributed Cloud StorageabstractRegenerating code is a class of distributed storage codes that can optimally trade the bandwidth with the amount of data stored per node to repair a failed node. There are two extreme points in the optimal regenerating trade-off curve, which correspond to minimum-storage regenerating (MSR) and minimum-bandwidth regenerating (MBR). Recently, Reed-Solomon (RS) code based regenerating codes (RS-RC) were constructed under the product-matrix framework. It can also achieve the maximum distance separable (MDS) property in code regeneration and reconstruction. However, in case that the network is hostile and the storage nodes could be compromised or packets be modified, the storage capacity and the bandwidth required to regenerate or reconstruct the original file can be significantly affected. In this paper, we propose Hermitian code based regenerating codes (H-RC) by developing constructions under the product-matrix framework for minimum storage regenerating (H-MSR) and the minimum bandwidth regenerating (H-MBR). We also propose data regeneration and reconstruction algorithms for both H-MSR and H-MBR codes under both error-free and hostile networks. We demonstrate that the proposed algorithms can also successfully determine the erroneous decodings in hostile networks. Theoretical evaluation shows that our proposed H-RC can detect and correct more errors in hostile networks well beyond the RS-RC with the same code rate. Our analysis shows that the proposed H-RC have lower computational complexity than the RS-RC for both code regeneration and code reconstruction. Jian Li 0007, Tongtong Li, Jian Ren 0001 |
IEEE Trans. Inf. Theory | 3 |
| 2019 | Malicious Link Detection in Multi-Hop Wireless Sensor NetworksabstractThis paper considers malicious link detection in multi-hop wireless sensor networks (WSNs). Existing work on malicious link detection generally requires that the detection process being performed at the intermediate nodes, leading to considerable overhead in system design, as well as unstable detection accuracy due to limited resources and the uncertainty in the loyalty of the intermediate nodes themselves. In this paper, we propose an efficient and robust malicious link detection scheme by exploiting the statistics of packet delivery rates only at the base station. More specifically, first, we present a secure packet transmission protocol to ensure that except the base station, any intermediate nodes on the route cannot access the contents and routing paths of the packets. Second, we design a malicious link detection algorithm that can effectively detect the irregular dropout at every hop (or link) along the routing path. We prove that the proposed algorithm has guaranteed false alarm rate and low miss detection rate. Simulation results are provided to validate the proposed approaches. Yuan Liang 0002, Yunhao Liu 0001, Jian Ren 0001, Tongtong Li |
GLOBECOM | 3 |
| 2018 | UBNB-PPDP: Utility-Boosting Negotiation-Based Privacy Preserving Data PublishingabstractIn the era of big data and artificial intelligence, almost every aspect of research is driven by collecting data. However, privacy concerns substantially limit the usability of such data. This prevents a vast amount of possible advances in all branches of science. While privacy rules are inevitable, data owners will always seek data publishing models and techniques that can maximize data utility within the frame of the imposed privacy rules. In this paper we propose a negotiation-based data publishing model to jointly address the utility requirements of the Data User (DU) and the privacy and possibly the monetary requirements of the Data Owner (DO). We also re-define the data utility based on the DU's rather than the DO's perspective. Based on the proposed model, we present two data publishing scenarios that satisfy a given privacy constraint while achieving the DU's required data utility. The variation in a DO's flat or variable monetary rate objective motivates the data publishing scenarios. Our protocol fills the gap between the existing theoretical work and the ultimate goal of practicality. M. H. Afifi, Ehab Zaghloul, Tongtong Li, Jian Ren 0001 |
GLOBECOM | 4 |
| 2018 | The Worst Jamming Distribution for Securely Precoded OFDMabstractIn this paper, we address the problem of finding the worst jamming distribution in terms of channel capacity for the securely precoded OFDM (SP-OFDM) system, so as to evaluate the performance of SP-OFDM under destructive hostile jamming. We consider a practical communication scenario, where the transmitting symbols are uniformly distributed over a discrete and finite alphabet, and the jamming interference is subject to both average and peak power constraints. Using tools in functional analysis and complex analysis, first, we show the existence and uniqueness of the worst jamming distribution; then we further prove that the worst jamming distribution is discrete in amplitude with a finite number of mass points. Numerical examples are provided under different scenarios to demonstrate our theoretical results. Yuan Liang 0002, Jian Ren 0001, Tongtong Li |
GLOBECOM | 2 |
| 2018 | Decoding Behavioral Accuracy in an Attention Task Using Brain fMRI DataabstractIn this paper, we investigate whether we can distinguish that a subject is making a correct or incorrect behavioral response by analyzing the fMRI data of localized brain regions, obtained from a feature-based attention experiment. For each subject, we first construct the feature vectors for each region of interest (including V1, MT or IPS1) from the fMRI signals. Second, we project the feature vectors onto a lower dimensional subspace using Linear Discriminant Analysis (LDA), where the difference between two classes (correct vs. incorrect response) is maximized. Finally, we apply the Bayesian classifier to the projected data, and find that the classification accuracies corresponding to V1, MT and IPS1 are 87.2%, 90.8% and 81.7%, respectively, when all the trials are considered. Our analysis indicates that: when people make correct or incorrect responses, significant difference exists in the fMRI signals, especially in V1 and MT regions, and the difference can be effectively captured by the LDA-Bayesian classifier. We also prove that: when the original data are normally distributed, LDA, which aims to maximize the difference between different classes, is equivalent to the optimal Maximum Likelihood (ML) based classification method. Zhe Wang 0016, Michael Jigo, Taosheng Liu, Jian Ren 0001, Zhi Tian, Tongtong Li |
GLOBECOM | 5 |
| 2018 | An Attribute-Based Distributed Data Sharing SchemeabstractPatients rely on their public health records shared among medical institutions to receive the appropriate treatment they require. They must completely trust that these institutions will secure their records, protect their privacy, and efficiently share them when requested by other institutions. Unfortunately, medical institutions cannot fully be trusted for several reasons. First, patient records are stored on the servers of the medical institutions which could result in security issues and also a single point of failure. Second, centralized storage may also result in privacy concerns if records are incorrectly shared or leaked. Third, institutions may purposely delay sharing patient records for competitive reasons. To address these issues, we propose an attribute-based distributed data sharing scheme for patients to control how their records are shared. The distributed file sharing can effectively prevent the single point of failure and ensure data availability upon its request. Moreover, patients are also given the capability of selectively sharing their records for privacy protection. Our analysis shows that while ensuring attribute-based sharing of medical records, the proposed scheme can also work with the peer-to-peer distributed network storage such as InterPlanetary File System (IPFS) to improve efficient data retrieval. Ehab Zaghloul, Tongtong Li, Jian Ren 0001 |
GLOBECOM | 3 |
| 2018 | Security and Privacy Enhancement for Outsourced Biometric IdentificationabstractA lot of research has been focused on secure outsourcing of biometric identification in the context of cloud computing. In such schemes, both the encrypted biometric database and the identification process are outsourced to the cloud. The ultimate goal is to protect the security and privacy of the biometric database and the query templates. Security analysis shows that previous schemes suffer from the enrolment attack and unnecessarily expose more information than needed. In this paper, we propose a new secure outsourcing scheme aims at enhancing the security from these two aspects. First, besides all the attacks discussed in previous schemes, our proposed scheme is also secure against the enrolment attack. Second, we model the identification process as a fixed radius similarity query problem instead of the kNN search problem. Such a modelling is able to reduce the exposed information thus enhancing the privacy of the biometric database. Our comprehensive security and complexity analysis show that our scheme is able to enhance the security and privacy of the biometric database and query templates while maintaining the same computational savings from outsourcing. Kai Zhou 0001, Jian Ren 0001, Tongtong Li |
GLOBECOM | 2 |
| 2018 | HPMAP: A Hash-Based Privacy-Preserving Mutual Authentication Protocol for Passive IoT Devices Using Self-Powered TimersabstractThe proliferation of passive Internet-of-Things (IoT) into the consumer and the enterprise market has necessitated enhanced security requirements. Many security protocols have been proposed in literature to address these requirements, however, they are either prone to certain types of attacks or are computationally expensive for resource- constrained passive IoT devices. In this paper we propose two variants of a novel mutual authentication protocol that utilizes the synchronization property of Fowler Nordheim (FN) tunneling based self-powered timers. The first protocol provides mutual authentication using the dynamic timer values. The protocol is both lightweight and provably immune to most of the well-known security attacks. Moreover, it offers an efficient and secure capability for easy revocation of tags and readers from the IoT system. The second protocol, an enhanced version of the first, provides disguised identities for applications that require privacy preserving. This protocol can thus serve as a perfect candidate for high-security passive IoT applications such as e- passports. M. H. Afifi, Liang Zhou 0004, Shantanu Chakrabartty, Jian Ren 0001 |
ICC | 4 |
| 2018 | Updatable Block-Level Deduplication with Dynamic Ownership Management on Encrypted DataabstractDeduplication is becoming increasingly important in that it can effectively reduce the storage space in the cloud server. Unfortunately the static file- level deduplication only supports limited data updatability and low deduplication ratio. In this paper, we show that by using updatable block-level deduplication (UBLDe) on encrypted data, all these issues can be addressed. In addition, this approach can also protect the user data privacy. However, updatable block-level dedeplication also faces several challenges. First, block-level deduplication should be achieved across different encrypted files. Second, an updatable authenticated data structure has to be designed for proof of file ownership. Finally, file ownership revocation has to be dealt with for forward secrecy. While the first challenge can be addressed by message-locked encryption, the last two challenges have not been solved yet. To address these two issues, we present a new UBLDe protocol on encrypted data with dynamic ownership management. Specifically, we design a new authenticated data structure for Proof of Ownership, named DBSL, to support update operations with low computation cost. We also propose a dynamic file ownership management scheme based on a novel lightweight MIX algorithm to protect forward secrecy. The security analysis and experimental results show that the proposed UBLDe protocol is secure and efficient. Maozhen Liu 0001, Chao Yang 0016, Qi Jiang 0001, Xiaofeng Chen 0001, Jianfeng Ma 0001, Jian Ren 0001 |
ICC | 6 |
| 2018 | Dynamic Authentication Protocol Using Self-Powered Timers for Passive Internet of ThingsabstractPassive Internet of Things (IoT) like radio frequency identification (RFID) tags can be used to offer a wide range of services, such as object tracking or classification, marking ownership, noting boundaries, and indicating identities. While the communication link between a reader of the tag and the authentication server is generally assumed to be secure, the communication link between the reader and participating tags is mostly vulnerable to malicious acts. Many authentication protocols have been proposed in literature, however, they either are vulnerable to certain types of attacks or require prohibitively a large amount of computational resources to be implemented on a passive tag. In this paper, we present variants of a novel authentication protocol that can overcome the security flaws of previous protocols while being well suited to the computational capability of the tags. At the core of the proposed approach is our recently demonstrated self-powered timing devices that can be used for robust time-keeping and synchronization without the need for any external powering. The outputs of the timers are processed using a single hash function on the tag to produce tokens that continuously change with time, while being synchronized to tokens generated by the authentication server. The proposed protocol also incorporates margins of tolerance that make the authentication process robust to any deviations in the timer responses due to fabrication artifacts. M. H. Afifi, Liang Zhou 0004, Shantanu Chakrabartty, Jian Ren 0001 |
IEEE Internet Things J. | 4 |
| 2018 | PassBio: Privacy-Preserving User-Centric Biometric AuthenticationabstractThe proliferation of online biometric authentication has necessitated security requirements of biometric templates. The existing secure biometric authentication schemes feature aserver-centricmodel, where a service provider maintains a biometric database and is fully responsible for the security of the templates. The end-users have to fully trust the server in storing, processing, and managing their private templates. As a result, the end-users’ templates could be compromised by outside attackers or even the service provider itself. In this paper, we propose auser-centricbiometric authentication scheme (PassBio) that enables end-users to encrypt their own templates with our proposed light-weighted encryption scheme. During authentication, all the templates remain encrypted such that the server will never see them directly. However, the server is able to determine whether the distance of two encrypted templates is within a pre-defined threshold. Our security analysis shows that no critical information of the templates can be revealed under both passive and active attacks. PassBio follows a “compute-then-compare” computational model over encrypted data. More specifically, our proposed threshold predicate encryption (TPE) scheme can encrypt two vectors x and y in such a manner that the inner product of x and y can be evaluated and compared to a pre-defined threshold. TPE guarantees that only the comparison result is revealed and no key information about x and y can be learned. Furthermore, we show that TPE can be utilized as a flexible building block to evaluate different distance metrics, such as Hamming distance and Euclidean distance over encrypted data. Such a compute-then-compare computational model, enabled by TPE, can be widely applied in many interesting applications, such as searching over encrypted data while ensuring data security and privacy. Kai Zhou 0001, Jian Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | Privacy Characterization and Quantification in Data PublishingabstractThe increasing interest in collecting and publishing large amounts of individuals' data as public for purposes such as medical research, market analysis, and economical measures has created major privacy concerns about individual's sensitive information. To deal with these concerns, many Privacy-Preserving Data Publishing (PPDP) techniques have been proposed in literature. However, they lack a proper privacy characterization and measurement. In this paper, we first present a novel multi-variable privacy characterization and quantification model. Based on this model, we are able to analyze the prior and posterior adversarial belief about attribute values of individuals. We can also analyze the sensitivity of any identifier in privacy characterization. Then, we show that privacy should not be measured based on one metric. We demonstrate how this could result in privacy misjudgment. We propose two different metrics for quantification of privacy leakage, distribution leakage, and entropy leakage. Using these metrics, we analyzed some of the most well-known PPDP techniques such as k-anonymity, l-diversity, and t-closeness. Based on our framework and the proposed metrics, we can determine that all the existing PPDP schemes have limitations in privacy characterization. Our proposed privacy characterization and measurement framework contributes to better understanding and evaluation of these techniques. Thus, this paper provides a foundation for design and analysis of PPDP schemes. M. H. Afifi, Kai Zhou 0001, Jian Ren 0001 |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2018 | Enjoy the Benefit of Network Coding: Combat Pollution Attacks in 5G Multihop NetworksabstractIn the upcoming 5G era, many new types of networks will greatly expand the connectivity of the world such as vehicular ad hoc networks (VANETs), Internet of Things (IoT), and device‐to‐device communications (D2D). Network coding is a promising technology that can significantly improve the throughput and robustness of these emerging 5G multihop networks. However, network coding is generally very fragile to malicious attacks such as message content corruption and node compromise attacks. To take advantage of network coding in performance gain while refraining malicious network attacks is an interesting and challenging research issue. In this paper, we propose a new error‐detection and error‐correction (EDEC) scheme that can jointly detect and remove the malicious attacks based on the underlying error‐control scheme for general multihop networks that can model the 5G multihop networks. The proposed scheme can increase the throughput for network with pollution attacks compared to existing error‐detection based schemes. Then we propose a low‐density parity check (LDPC) decoding based EDEC (LEDEC) scheme. Our theoretical analysis demonstrates that the LEDEC scheme can further increase the throughput for heavily polluted network environments. We also provide extensive performance evaluation and simulation results to validate the proposed schemes. This research ensures the expected performance gain for the application of network coding in the 5G network under malicious pollution attacks. Jian Li 0007, Tongtong Li, Jian Ren 0001, Han-Chieh Chao |
Wirel. Commun. Mob. Comput. | 3 |
| 2017 | A client-based secure deduplication of multimedia dataabstractThe replication and dissemination of multimedia data become increasingly convenient and efficient, so a lot of redundant multimedia data, especially image files, have been generated and stored on the Internet. Therefore, it is necessary to perform deduplication of images. However, the existing deduplication methods of regular files are hash-based, which cannot be applied to the deduplication of images. The deduplication of images faces following three challenges: it needs to check duplicates fuzzily; it needs to verify the ownership of similar images; it needs perceptual image quality assessment. Aiming at these challenges, we propose a scheme named the Client-based Security Provable Deduplication of Multimedia Data (CSPD). The proposed CSPD scheme is capable of responding to the above challenges. Furthermore, it meets provable security requirements. Our extensive simulation and performance analysis show that the CSPD can check duplicates accurately and assess the perceptual quality of distorted images. Moreover, the proposed CSPD is more efficient than the existing schemes in communication bandwidth and storage spaces. Danping Li, Chao Yang 0016, Chengzhou Li, Qi Jiang 0001, Xiaofeng Chen 0001, Jianfeng Ma 0001, Jian Ren 0001 |
ICC | 7 |
| 2017 | Zero knowledge based client side deduplication for encrypted files of secure cloud storage in smart cities
Chao Yang 0016, Qi Jiang 0001, Junwei Zhang 0001, Danping Li, Jianfeng Ma 0001, Jian Ren 0001 |
Pervasive Mob. Comput. | 7 |
| 2017 | ExpSOS: Secure and Verifiable Outsourcing of Exponentiation Operations for Mobile Cloud ComputingabstractDiscrete exponential operation, such as modular exponentiation and scalar multiplication on elliptic curves, is a basic operation of many public-key cryptosystems. However, the exponential operations are considered prohibitively expensive for resource-constrained mobile devices. In this paper, we address the problem of secure outsourcing of exponentiation operations to one single untrusted server. Our proposed secure outsourcing scheme for general exponential (ExpSOS) only requires a very limited number of modular multiplications at local mobile environment, and thus it can achieve significant computational performance gain. ExpSOS also provides a secure verification scheme with probability approximately 1 to ensure that the mobile end users can always receive valid results. The comprehensive analysis as well as the simulation results in real mobile device demonstrates that our proposed ExpSOS can significantly improve the existing schemes in efficiency, security, and result verifiability. We apply ExpSOS to securely outsource several cryptographic protocols to show that ExpSOS can be widely applied to many computation-intensive applications and achieve significant performance improvement. Kai Zhou 0001, M. H. Afifi, Jian Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2017 | Optimal Construction of Regenerating Code Through Rate-Matching in Hostile NetworksabstractRegenerating code is a class of distributed storage codes that can optimally trade the bandwidth required to repair a failed node with the amount of data stored per node. There are two optimal points in the regeneration tradeoff curve: the minimum storage regeneration code and the minimum bandwidth regeneration code. However, in hostile networks where the storage nodes may be compromised, the storage capacity of the network can be significantly affected. In this paper, we propose two optimal regenerating code constructions through rate-matching to combat this kind of adversarial attacks in hostile networks. We first develop a two-layer rate-matched regenerating code construction. By matching the parameters of the full rate code and the partial rate code, we can optimize the overall storage efficiency while maintaining the corrupted node detection probability. Through comprehensive analysis, we show that the two-layer rate-matched regenerating code can achieve 70% higher storage efficiency than the universally resilient regenerating code. We then propose an optimal m-layer regenerating code construction. While the principle remains the same as the two-layer code, it is designed to optimize the total number of detectable corrupted nodes of m layers from which the errors can be corrected under the constraint of any given code efficiency. Compared with the universally resilient regenerating code with the same rate, our m-layer code can detect 50% more corrupted nodes. Jian Li 0007, Tongtong Li, Jian Ren 0001 |
IEEE Trans. Inf. Theory | 3 |
| 2016 | Robust CDMA receiver design under disguised jammingabstractThis paper considers robust CDMA receiver design and jamming evaluation under disguised jamming, where the jammer generates a fake signal using the same spreading code, constellation and pulse shaping filter as that of the authorized signal. First, we analyze the performance of conventional CDMA systems under disguised jamming, and show that due to the symmetricity between the authorized signal and the jamming interference, the receiver cannot really distinguish the authorized signal from jamming, leading to complete communication failure. Second, by exploiting the small time difference between the authorized signal and the jamming interference, the conventional CDMA receiver can be redesigned to achieve robust performance under disguised jamming. More specifically, we propose to estimate the authorized signal, the phase and power level or range of the jamming interference by minimizing the MSE between the received signal and the jammed signal, which is the sum of the authorized signal and the disguised jamming. The effectiveness of the proposed approach is demonstrated through simulation examples. It is shown that with the proposed receiver design, the BER performance of CDMA can be improved significantly under disguised jamming, and an analytical evaluation about jamming can also be obtained. Kai Zhou 0001, Tianlong Song, Jian Ren 0001, Tongtong Li |
ICASSP | 3 |
| 2016 | Secure outsourcing of scalar multiplication on elliptic curvesabstractCloud computing enables resource-constrained end-users to outsource their computational tasks to the cloud in a flexible manner. One major concern of computation outsourcing is the security of the outsourced data as well as the results. In this paper, we propose a secure outsourcing scheme (SecMul) for one basic and expensive computation in cryptography, that is scalar multiplication of points on elliptic curves. The basic idea of the proposed SecMul is to transfer computations in a finite field to computations in a ring. The scheme is designed in such a way that without the secret key, it is computationally infeasible for the cloud to recover the input and the output. The proposed SecMul is highly efficient in that it enables the end-users to outsource a scalar multiplication at the cost of only a few multiplications. Especially, the performance gain of outsourcing is O(log(s)), where s is the multiplier. Our comprehensive security and complexity analysis demonstrate that the proposed SecMul scheme is both secure and efficient. Kai Zhou 0001, Jian Ren 0001 |
ICC | 2 |
| 2016 | LinSOS: Secure outsourcing of linear computations based on affine mappingabstractLinear computational problems emerge from various fields such as engineering and finance. Due to the large scale of these problems, they are often hard to be processed by resource-constrained devices. Thus, outsourcing becomes a natural solution. In this paper, we propose a Secure OutSourcing scheme (LinSOS) for Linear computations. The proposed scheme (LinSOS) is based on affine mapping and imposes only linear operations at local environment. As a result, the end-users can enjoy impressive computational gains from outsourcing. We also provide a verification scheme such that end-users can always receive valid results. Our extensive security and complexity analysis and performance comparison with existing schemes show that LinSOS is both secure and efficient. Kai Zhou 0001, Jian Ren 0001 |
ICC | 2 |
| 2016 | Secure Fine-Grained Access Control of Mobile User Data through Untrusted CloudabstractCloud computing enables data owners to outsource their computationally intensive tasks and store private data to the shared cloud. To enhance the security while preserving the flexibility of data sharing, Attribute Based Encryption (ABE) was introduced to provide a fine-grained access control. A key issue in ABE based systems is the high computational overhead, which could be prohibitive for resource constrained mobile devices. In this paper, we propose a scheme to securely and efficiently outsource the computationally intensive access control operations of ABE to the shared cloud, thus reliving the computational burden of mobile users which can greatly improve the battery lifetime. In a high level view, data owners only need to specify access policies on the encrypted data so that access control can be done automatically by the cloud. Our proposed scheme guarantees that it is computationally infeasible for the untrusted cloud to recover the encrypted file and that the cloud is enforced to complete the full functionality of access control, even in situations where the cloud may be compromised by malicious data users. Our theoretical analysis and experiment results both demonstrate that our scheme can achieve high performance gain for resource constrained mobile devices. Kai Zhou 0001, Jian Ren 0001 |
ICCCN | 2 |
| 2016 | Recent advances in security and privacy in large-scale networksabstractWe are pleased to present to you 13 technical papers dealing with cutting-edge research and technology related to this topic. These papers were selected out of the significantly extended versions of the 149 submissions from 18 countries in the 3rd IEEE International Workshop on Large-Scale Network Security (LSNS 2014) and a large number of open submissions. The selection has been very rigorous, and only the best papers were selected. In the first paper, ‘An Error-Tolerant Keyword Search Scheme Based on Public-Key Encryption in Secure Cloud Computing’ 1, Yang et al. first present a general framework for searching on error-tolerant keywords based on a public-key encryption scheme. Then a concrete scheme is proposed based on the Cramer–Shoup cryptosystem. The scheme is chosen ciphertext attack secure, and suitable for all similarity metrics including Hamming distance metric, edit distance metric, and set difference metric. Because it does not require the user to construct and store anything in advance, very different from those cryptosystems used to calculate the trapdoor of keywords and to encrypt data documents, the new scheme tremendously eases the users' burden. In the second paper, ‘A Lightweight Privacy-Preserving Scheme with Data Integrity for Smart Grid Communications’ 2, Bao and Chen propose a lightweight data report scheme for smart grid communications, which can achieve privacy preservation and data integrity simultaneously. Specifically, an efficient pseudonym identity-based privacy-preserving report approach is proposed for the control center to obtain the fine-grained usage data of all the users while protecting user's privacy. An online/offline hash tree-based mechanism is also designed to check and assure data integrity of communications. Furthermore, a topology-independent data report architecture is also structured, which is adaptable for dynamic residential users to spontaneously form clusters and efficiently report data in flocks. Extensive performance evaluation demonstrates that the proposed scheme can achieve less communication overhead and dramatically reduce computational cost in comparison with the existing schemes. Secure biometric authentication aims to replace an encryption key or an identity certificate with biometrics to complete authentication. In the third paper, ‘A Secure Biometric Authentication Based on PEKS’ 3, Zhang et al. present a generic transformation from searchable encryption to secure biometric authentication and construct a specific secure biometric authentication scheme based on public key encryption with keyword search. Compared with some existing authentication schemes, the proposed scheme is more efficient in the practical application. Furthermore, the transformation from searchable encryption to secure biometric authentication presents a new direction of constructing authentication scheme. Certificateless aggregate signature schemes are required to satisfy the applications in certificateless environment. In the fourth paper, ‘A New Certificateless Signature with Enhanced Security and Aggregation Version’ 4, Deng et al. present an improved certificateless signature scheme and use it to construct a new certificateless signature scheme with enhanced security and aggregation. Compared with other schemes, the proposed scheme is more suitable for realistic applications. In the fifth paper, ‘Worm Propagation Model in Mobile Network’ 5, Chen et al. focus on mobile worm propagation model that allows to control and detect potential worm threat, according to the characteristics of worm's outbreak. Chen et al. put forward a worm propagation model based on the mobile network environment. After analyzing the model, it gives the simulation for controlling factors affecting worm propagation. This model allows us to have a certain understanding for the spread on the size and speed of the mobile worm, providing effective methods to control the spread of the mobile worm. In the sixth paper, ‘Efficient Privacy-Preserving Temporal and Spacial Data Aggregation for Smart Grid Communications’ 6, Dong et al. propose an efficient privacy-preserving temporal and spacial data aggregation from one-way functions in smart grid communications, which also allows special data aggregation from multiple users. The proposed construction can guarantee the unconditional security of users' metering power data privacy from the community gateway and the operation center, and the adaptive chosen ciphertext attack security of the aggregation result that can only be accessed by the authorized operation center. Both temporal and spacial data aggregation only require computing the underlying one-way function once. The provable multiple-replication data-possession protocol with full dynamics aims to realize efficient integrity verification and full dynamic data updates for cloud storage. In the seventh paper, ‘Provable Multiple Replication Data Possession with Full Dynamics for Secure Cloud Storage’ 7, Zhang et al. present a new multiple replication data possession scheme with full dynamics, in which a novel multiple replication Merkle hash tree with rank is used. The proposed scheme improves the efficiency of verifying updates for cloud storage with multiple replicas, which satisfies robust security properties. The eighth paper, ‘Efficient Group Key Management for Secure Big Data in Predictable Large-scale Networks’ 8, by He et al. focuses on secure group communication in large-scale social networks in which the entire social network may have millions of users but a concrete group is usually small. The paper proposes a new dynamic group key agreement protocol by using a novel dual-ring approach in which two rings of nodes are established, one active and one dummy. When some nodes leave, the remaining nodes can replace these nodes with dummy nodes, minimizing the required communications and computations after the protocol is set up and thus provides significant advantage over existing group key management protocols. The thorough analysis by the authors demonstrates provable security of the protocol and the superiority of computation and communication overload. The ninth paper, ‘Delegation of Signing Rights for Emerging 5G Networks’ 9, Ge et al. address the issue of delegating authentication in 5G networks by proposing a new proxy signature scheme. In their proposal, the original signer delegates his or her signing right by signing an exposure-free chameleon hash value as a warrant, and the proxy signer can generate a proxy signature on a message only by finding a chameleon hash collision instead of calculating a new digital signature, which can dramatically reduce computation cost of the proxy signer. With the emergence of cloud storage, searchable encryption technique that enables cloud clients to securely search over ciphertext through keywords and selectively retrieve records of interest has been extensively studied in both industry and academia. Unfortunately, most of the existing searchable encryption schemes cannot preserve keyword privacy and user privacy in multi-user setting simultaneously. For this end, in the 10th paper, ‘Revocable and Anonymous Searchable Encryption in Multi-user Setting’ 10, Miao et al. designed a secure and scalable cryptographic primitive based on identity-based encryption. As a further contribution, this proposed scheme can effectively resist decryption key exposure threat and achieve anonymous-revocable-ID-chosen plaintext attack (CPA) secure in the standard model. The location-based service (LBS) privacy protection scheme aims to solve the user's location privacy disclosure issue when the user initiates an LBS request. In the 11th paper, ‘DALP: A Demand-aware Location Privacy Protection Scheme in Continuous Location-based Services’ 11, Li et al. present a new anonymity-based scheme for continuous LBS queries, which allows a user to customize not only location privacy but also QoS requirement. The proposed scheme can maximize the demands-aware query sequence and minimize the constructed cloaking regions, thereby reducing the query latency and the server's workload. In the 12th paper, ‘Security Analysis of a Privacy-preserving Decentralized Ciphertext-Policy Attribute-based Encryption Scheme’ 12, Wang et al. point out the security weakness of a privacy-preserving decentralized ciphertext-policy attribute-based encryption scheme proposed 13, by Han et al. in ESORICS 2014. They present a collusion attack on the underlying decentralized ciphertext policy attribute based encryption (CP-ABE) scheme and additionally show that the privacy protection of attributes in the privacy-preserving key extraction protocol cannot be provided. The 13th paper, ‘Partner Selection of Agricultural Products Supply Chain Based on Data Mining’ 14, puts forward supply chain partner selection model and partner evaluation index system. With BP neural network, the agricultural products' supply chain partner-selection example analysis is made. The results show that the established supply chain partner-selection model has better generalization ability and can be effectively used to supply chain partner selection. We sincerely hope that you will enjoy reading these papers in this special issue. We thank all the international reviewers for their professional services. We deeply thank Professor Geoffrey Fox, the Editor-in-Chief, for providing this opportunity to publish this special issue. With his continuous support, encouragement, and guidance throughout this publishing project, this special issue has been very successful. Yong Yu 0002, Yi Mu 0001, Rongxing Lu, Jian Ren 0001 |
Concurr. Comput. Pract. Exp. | 4 |
| 2016 | STaR: design and quantitative measurement of source-location privacy for wireless sensor networksabstractAbstract Wireless sensor networks (WSNs) can provide the world with a technology for real‐time event monitoring. One of the primary concerns that hinder the successful deployment of WSNs is source‐location privacy (SLP). The privacy of the source location is vital and highly jeopardized by the usage of wireless communications. Although message content privacy can be ensured through message encryption, it is much more difficult to adequately address the SLP. For WSNs, SLP service is further complex by the fact that sensors consist of low‐cost and energy‐efficient radio devices. Therefore, using computationally intensive cryptographic algorithms (such as public‐key cryptosystems) and large‐scale broadcasting‐based protocols are not suitable for WSNs. In this paper, we analyze the quantitatively measure source‐location information leakage in routing‐based SLP protection schemes for WSNs. Through this model, we identify vulnerabilities of some well‐known SLP protection schemes. We also propose a routing technique, called the Sink Toroidal Region (STaR), to provide adequate SLP with low energy consumption. With this routing technique, the source node randomly selects an intermediate node within a designed STaR area located around the sink node. Furthermore, this routing protocol ensures that the intermediate node is neither too close, nor too far from the sink node in relations to the entire network. While ensuring SLP, our simulation results show that the proposed scheme is very efficient and can be used for practical applications. Copyright © 2012 John Wiley & Sons, Ltd. Leron Lightfoot, Yun Li 0011, Jian Ren 0001 |
Secur. Commun. Networks | 3 |
| 2016 | Anonymous communication in overlay networksabstractAbstract Communication anonymity is becoming an increasingly important, or even indispensable, security requirement for many applications. The existing research in anonymous communications can largely be divided into two categories: mix‐based systems and secure multiparty computation‐based systems, originating from mixnet and DC‐net, respectively. However, they either cannot provide provable anonymity or suffer from transmission collision problem. In this paper, we first propose a novel unconditionally secure source anonymous message authentication code that can be applied to any messages without relying on any trusted third parties. While ensuring message sender anonymity, secure source anonymous message authentication code can also provide message content authenticity. We then propose a novel communication protocol that can hide the senders and the recipients from each other and thus can be used for secure file sharing. The security analysis demonstrates that the proposed protocol is secure against various attacks. Our analysis also shows that it is efficient and practical. Copyright © 2012 John Wiley & Sons, Ltd. Jian Ren 0001, Yun Li 0011, Tingting Jiang 0005, Tongtong Li |
Secur. Commun. Networks | 1 |
| 2015 | Reliable Communications over Multihop Networks under Routing AttacksabstractThis paper considers reliable multihop transmission under routing attacks, where a malicious relay can modify or drop a packet as it is being forwarded to the destination. We propose a transmission scheme that detects malicious nodes launching routing attacks through incorporating diversity over multi-layer relays, where each relay can establish a direct connection with relays at preceding and succeeding hop levels. We prove that the proposed approach can efficiently detect malicious nodes, provided that there is at least one honest relay at each hop level. We highlight the trade-off between network efficiency and security, and show the impact of the diversity level and the number of hops on the network performance through theoretical analysis and simulation examples. Our results provide insights on general network architecture development and topology design. Mai Abdelhakim, Leonard E. Lightfoot, Jian Ren 0001, Tongtong Li |
GLOBECOM | 3 |
| 2015 | Rate-matched regenerating code in hostile networksabstractRegenerating code is a class of code very suitable for distributed storage systems, which can maintain optimal bandwidth and storage space. Two types of important regenerating code have been constructed: the minimum storage regeneration (MSR) code and the minimum bandwidth regeneration (MBR) code. However, in hostile networks where adversaries can compromise storage nodes, the storage capacity of the network can be significantly affected. In this paper, we propose a rate-matched MSR code that can combat against this kind of adversaries in hostile networks. We optimize the code parameters for given system requirements. Our comprehensive analysis shows that our code can detect and correct malicious nodes with higher storage efficiency compared to the normal error correction MSR code. Jian Li 0007, Tongtong Li, Jian Ren 0001 |
ICC | 3 |
| 2015 | R-STaR destination-location privacy schemes in wireless sensor networksabstractWireless sensor networks (WSNs) can provide the world with a technology for real-time event monitoring for both military and civilian applications. One of the primary concerns that hinder the successful deployment of wireless sensor networks is providing adequate location privacy. Many protocols have been proposed to provide location privacy but most are based on public-key cryptosystems, while others are either energy inefficient or have certain security flaws. In this paper, after analyzing security weakness of the existing schemes, we propose an architecture that addresses the security flaw for destination location privacy in WSNs based on energy-aware two phase routing protocol. We call this scheme the R-STaR routing protocol. In the first routing phase of R-STaR routing, the source node transmits the the message to a randomly selected intermediate node located in a pre-determined region surrounding the source node, which we call the R-STaR area. In the second routing phase, the message is routed to the destination node using shortest path mix with fake message injections. We show that R-STaR routing provides a exceptional balance between security and energy consumption in comparison to existing well-known proposed schemes. Leron Lightfoot, Jian Ren 0001 |
ICC | 2 |
| 2015 | A delay-aware and secure data forwarding scheme for urban sensing networksabstractPeople-centric urban sensing is envisioned as a novel urban sensing paradigm. Communication delay and security are two important design issues in urban sensing network. To address these two issues concurrently, we propose a novel DElay-Aware secuRe (DEAR) forwarding scheme by combining secret sharing and two-phase message forward. In DEAR scheme, the collected data is first split into pieces. Each piece is being relayed to the application data server through a randomly selected delivery node. The combination of secret sharing scheme and two-phase message forward ensures confidentiality of the collected data and anonymity of the participating users. It also makes it infeasible for the application data server to estimate the source node identity. Moreover, DEAR provides redundancy in message forwarding to achieve high message delivery ratio. This design makes the trade-off between security and communication delay adjustable based on selection of the (k, n) scheme. Jian Ren 0001 |
ICC | 2 |
| 2015 | Security in big dataabstractThe phrase ‘Big Data’ refers to large, diverse, complex, longitudinal, and/or distributed data sets generated from instruments, sensors, Internet transactions, email, video, click streams, and/or all other digital sources available today and in the future, as defined by U.S. National Science Foundation in its recent solicitation. The research of Big Data will accelerate the progress of scientific discovery and innovation; lead to new fields of inquiry that would not otherwise be possible, encourage the development of new data analytic tools and algorithms; facilitate scalable, accessible, and sustainable data infrastructure; increase understanding of human and social processes and interactions; and promote economic growth and improved health and quality of life. The new knowledge, tools, practices, and infrastructures produced will enable breakthrough discoveries and innovation in science, engineering, medicine, commerce, education, and national security. Big Data presents critical requirements for security in data collection and transmission of selected data through a communication network. This special issue contains 11 papers selected from submissions to the open call for papers on Security in Big Data. These papers highlight some of the current research interests and achievements in the area of security in Big Data. The wide use of high-performance image acquisition devices and powerful image-processing software has made it easy to tamper images for malicious purposes. The paper by Zhang et al. proposes an effective framework for revealing image-splicing forgery. The experiment results show that the proposed method can perform better than some state-of-the-art methods in terms of the detection performance over the Columbia image-splicing detection evaluation data set. Network coding has emerged some exciting future because of its smart technology in wireless sensor networks. At the same time, it is facing security attacks, especially conspiracy attack. The paper by Du et al. proposes a weakly secure scheme from the perspective of topology. Considering the performance of this scheme, an advanced scheme is put forward later. Simulations show that the two strategies can prevent cooperative eavesdroppers from acquiring any useful information transmitted from source node to sink node, and the performance of advanced scheme is better. Traditionally, jamming to the wireless system is a fatal threat to the security of home area networks (HANs), which impedes the two-way data transmission between electric devices and the smart meter and thus deteriorates the reliability of the in-home communication of Smart Grid. The paper by Li et al. incorporates the power line system into the HAN and proposes a hybrid architecture of orthogonal frequency-division multiplexing-based wireless communication and power line communication for the Smart Grid security application. With this new solution, the channel diversity of the HAN is realized, and the communication reliability is still guaranteed even when the wireless channel suffers from jamming. Information of multi-cells is big data because of the enormous quantities of various cells as well as their parameters and status. To securely and efficiently integrate all the cells' information and trace multi-cells are challenging because of varying number of the multi-cells, as well as the complicacy of the multi-cells' movement. The paper by Yin and Sun proposes an automatic big data integration algorithm based on the optical transfer function. The experimental results show that the algorithm can securely and efficiently integrate all the cell information and simultaneously track a large quantity of cells. Real-time digital video presents great challenges on processing and storage and is a typical example in Big Data. How to secure and efficiently transmit digital video is critical. The paper by Zhang et al. uses the distributed compressed sensing to deal with video coding. To reduce the orthogonal matching pursuit algorithm computational complexity, quantum-behaved particle swarm optimization algorithm is used to reconstruct video signal. Simulation results demonstrate that it can obtain the better reconstructed video with low sample value and it can guarantee safety performance. Wireless image sensor network generates a large number of images from the distributed camera sensors. The image data need to be delivered securely and efficiently to the sink in many circumstances. The current node-disjoint multipath and dispersive routings cannot provide enough security and efficiency for the image data collection and transportation. The paper by Su and Hu proposes an ellipse batch dispersive routing algorithm to address the secure and efficient data collection issue in wireless image sensor network. The smart grid system is composed of the power infrastructure and communication infrastructure and thus is characterized by the flow of electric power and information, respectively. The 24/7 information collection and transmission in smart grid is a good example of Big Data. The transmission of Big Data in smart grid needs wireless network, which introduces additional vulnerabilities, given the scale of potential threats. Therefore, the physical layer security issue is of first priority in the study of smart grid and has already attracted substantial attention in the industry and academia. The paper by Wang et al. aims to present a general overview of the physical layer security in wireless smart grid and covers the effective countermeasures proposed in the literature of smart grid to date. Security is a very broad topic; particular attention has been paid in communications, networking on security issues. However, in practical applications, providing security services increases the computation and the occupation of system resources. This problem is particularly important when energy is a limited resource for mobile communication devices operating on battery. Thus, energy-efficient security devices are very necessary for the communication. The paper by Yuan and Liang designed a new low voltage, low power consumption comparator for successive approximation register analog to digital converter to improve the energy efficiency in the problem of secure communication. Big data presents critical requirements for security in data collection and transmission of selected data through a communication network. The paper by Chen et al. presents a new secure transmission for big data based on nested sparse sampling and coprime sampling. With nested sampling and coprime sampling, besides the advantage of higher spectrum efficiency, big data could also achieve higher power spectral density for binary frequency shift keying signal. It proves that both nested sampling and coprime sampling could be used in big data transmission to resist interference, while guaranteeing the transmission performance. With the rapid adoption of cloud storage services, a great deal of data is being stored at remote servers, so a new technology, client-side deduplication, which stores only a single copy of repeating data, is proposed to identify the client's deduplication and save the bandwidth of uploading copies of existing files to the server. It was recently found, however, that this promising technology is vulnerable to a new kind of attack in which by learning just a small piece of information about the file, namely, its hash value, an attacker is able to obtain the entire file from the server. The paper by Yang et al. proposes a cryptographically secure and efficient scheme for a client to prove to the server his ownership on the basis of actual possession of the entire original file instead of only partial information about it. The paper by Wang et al. presents the definitions of big data and anomaly detection. The theory of ultra-wideband radar and the through-wall detection of a human model based on ultra-wideband radar are briefly introduced. The target criterion with wavelet packet transform is deduced, and the procedure for the through-wall human detection with statistical process control is constructed. The radar echo signals are collected at stationary and moving statuses of a human being for three types of walls. The experimental results demonstrate the effective of through-wall target detection based on the proposed algorithm. We would like to thank all authors for contributing papers to the special issue. We appreciate the staff of Security and Communication Networks for their support in editing this special issue. Qilian Liang is a University Distinguished Scholar Professor in the Department of Electrical Engineering, University of Texas at Arlington. He received the BS degree from Wuhan University in 1993, MS degree from Beijing Uni- versity of Posts and Telecommunica- tions in 1996, and PhD degree from University of Southern California (USC) in May 2000, all in Electrical Engineering. Prior to joining UTA in August 2002, he was a Member of Technical Staff in Hughes Network Systems Inc. at San Diego, California. His research interests include wireless sensor networks, wireless communications, signal processing, information theory, radar systems, and wireless networks. Dr. Liang has published more than 270 journal and conference papers. He received 2002 IEEE Transactions on Fuzzy Systems Outstanding Paper Award, 2003 U.S. Office of Naval Research (ONR) Young Investigator Award, 2005 UTA College of Engineering Outstanding Young Faculty Award, 2007, 2009, 2010 U.S. Air Force Summer Faculty Fellowship Program Award, 2012 UTA College of Engineering Excellence in Research Award, 2013 UTA Outstanding Research Achievement or Creative Activity Award, and was inducted into UTA Academy of Distinguished Scholars in 2015. Jian Ren received the BS and MS degrees both in mathematics from Shaanxi Normal University and received the PhD degree in EE from Xidian University, China. He is an Associate Professor in the Department of ECE at Michigan State University. His current research interests include cryptography, network security, energy efficient sensor network security protocol design, privacy-preserving communications, secure and efficient cloud computing, and cognitive networks. He is a recipient of the US National Science Foundation Faculty Early Career Development (CAREER) award in 2009. Dr. Ren is a senior member of the IEEE. Jing Liang received the BS and MS degrees from Beijing University of Posts and Telecommunications, China in 2003 and 2006, respectively, and PhD degree from University of Texas at Arlington in August 2009, all in Electrical Engineering. She is currently a Professor in the Department of Electrical Engineering at University of Electronic Science and Technology of China. Her current research interests include radar sensor networks, collaborative and distributed signal processing, wireless communications, wireless networks, and fuzzy logic systems. Baoju Zhang is a Professor at the College of Physical and Electrical Information, Tianjin Normal Uni- versity. She received the BS degree from Tianjin Normal University in 1990, MS degree from Tianjin Nor- mal University in 1993, and PhD degree from Tianjin University in 2002. She was a Postdoctoral Fellow at Tianjin University from 2002 to 2004. Her research interests include radar sensor networks, digital audio and video technology, image compressing and coding, and compressive sensing. Yiming Pi was born in 1968 in China. He obtained PhD degree in Electronic Engineering from University of Electronic Science and Technology of China in 1993. Since 2002, he has been a Professor of Department of EE, University of Electronic Science and Technology of China. He is a councilor of Signal Processing Society in the Chinese Institute of Electronics and has served in organizing several international conferences in the field of Signal Processing and Radar Systems. He became IEEE Senior Member in 2011. He had been the leaders of some Natural Science Funding of China. He has more than 100 publications in the conferences and journals of IEEE/IET. His research interests are radar imaging, signal processing and terahertz technology, and so on. Chenglin Zhao received his BS degree in Tianjin University in 1986, MS degree and PhD degree in Beijing University of Posts and Telecommu- nications in 1993 and 1997, respec- tively. He is a Professor of the Key Lab of the ubiquitous wireless of Education Ministry, Information and Telecommunication engineering college, Beijing University of Post and Telecommunication. His main research areas include radar sensor networks, wireless broadband interconnection, wireless sensor network, and digital signal processing and its applications. Qilian Liang, Jian Ren 0001, Jing Liang 0002, Baoju Zhang, Yiming Pi, Chenglin Zhao |
Secur. Commun. Networks | 2 |
| 2015 | Provable ownership of files in deduplication cloud storageabstractAbstract With the rapid adoption of cloud storage services, a great deal of data is being stored at remote servers, so a new technology, client‐side deduplication, which stores only a single copy of repeating data, is proposed to identify the client's deduplication and save the bandwidth of uploading copies of existing files to the server. It was recently found, however, that this promising technology is vulnerable to a new kind of attack in which by learning just a small piece of information about the file, namely its hash value, an attacker is able to obtain the entire file from the server. In this paper, to solve this problem, we propose a cryptographically secure and efficient scheme for a client to prove to the server his ownership on the basis of actual possession of the entire original file instead of only partial information about it. Our scheme utilizes the technique of spot checking in which the client only needs to access small portions of the original file, dynamic coefficients and randomly chosen indices of the original files. Our extensive security analysis shows that the proposed scheme can generate provable ownership of the file and maintain high detection probability of client misbehavior. Both performance analysis and simulation results demonstrate that our proposed scheme is much more efficient than the existing schemes, especially in reducing the burden of the client. Copyright © 2013 John Wiley & Sons, Ltd. Chao Yang 0016, Jian Ren 0001, Jianfeng Ma 0001 |
Secur. Commun. Networks | 2 |
| 2015 | Cost-Aware SEcure Routing (CASER) Protocol Design for Wireless Sensor NetworksabstractLifetime optimization and security are two conflicting design issues for multi-hop wireless sensor networks (WSNs) with non-replenishable energy resources. In this paper, we first propose a novel secure and efficient Cost-Aware SEcure Routing (CASER) protocol to address these two conflicting issues through two adjustable parameters: energy balance control (EBC) and probabilistic-based random walking. We then discover that the energy consumption is severely disproportional to the uniform energy deployment for the given network topology, which greatly reduces the lifetime of the sensor networks. To solve this problem, we propose an efficient non-uniform energy deployment strategy to optimize the lifetime and message delivery ratio under the same energy resource and security requirement. We also provide a quantitative security analysis on the proposed routing protocol. Our theoretical analysis and OPNET simulation results demonstrate that the proposed CASER protocol can provide an excellent tradeoff between routing efficiency and energy balance, and can significantly extend the lifetime of the sensor networks in all scenarios. For the non-uniform energy deployment, our analysis shows that we can increase the lifetime and the total number of messages that can be delivered by more than four times under the same assumption. We also demonstrate that the proposed CASER protocol can achieve a high message delivery ratio while preventing routing traceback attacks. Tongtong Li, Jian Ren 0001, Jie Wu 0001 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2014 | Throughput analysis and routing security discussions of mobile access coordinated wireless sensor networksabstractIn this paper, we analyze the throughput of a novel mobile access coordinated wireless sensor network architecture (MC-WSN) under single path and multipath routing. The obtained throughput expressions highlight the trade-off between achieving high throughput performance and improving the network security strength. The results reveal the importance of: (i) minimizing the number of hops in maximizing the throughput, and (ii) adopting routing diversity in combating malicious attacks and network failure conditions. We control the number of hops in data transmission through optimal topology design and active network deployment achieved by the mobile access point (MA). To combat routing attacks, we propose a secure routing path selection approach, and show the impact of the proposed approach on improving the throughput performance under malicious attacks. Mai Abdelhakim, Jian Ren 0001, Tongtong Li |
GLOBECOM | 2 |
| 2014 | Secure regenerating codeabstractDistributed storage plays a crucial role in the current cloud computing framework. After the theoretical bound for distributed storage was derived by the pioneer work of the regenerating code, Reed-Solomon code based regenerating codes, including the minimum storage regeneration (MSR) code and the minimum bandwidth regeneration (MBR) code, were developed. However, in the hostile network with passive eavesdroppers and active attackers, the data confidentiality and storage capacity of the network can be significantly affected. In this paper, we propose a secure MSR code that can combat against the passive eavesdroppers and active attackers in the network. We also provide theoretical analyses showing that our code can provide better security with less computational cost and bandwidth overhead. Jian Li 0007, Tongtong Li, Jian Ren 0001 |
GLOBECOM | 3 |
| 2014 | Precoding for OFDM under disguised jammingabstractThis paper considers jamming-resistant OFDM system design under full-band disguised jamming, where the jamming symbols are taken from the same constellation as the information symbols over each subcarrier. First, we analyze the impact of disguised jamming on OFDM systems. It is shown that due to the symmetricity between the authorized signal and jamming, the BER of OFDM systems without symbol-level precoding or only with repeated symbol-level coding is lower bounded by a modulation specific constant, which cannot be improved by increasing SNR. Second, we develop an optimal precoding scheme which minimizes the BER of OFDM systems under full-band disguised jamming. It is shown that the most efficient way to combat full-band disguised jamming in OFDM systems is to concentrate the total available power and distribute it uniformly over a particular number of subcarriers instead of the entire spectrum. The underlying argument is that for a particular subcarrier, when the signal-to-jamming ratio is large enough, then the receiver can distinguish the authorized signal from disguised jamming under the presence of noise. Both theoretical analysis and numerical results demonstrate that the BER performance of OFDM systems under full-band disguised jamming can be improved significantly with the proposed precoding scheme. Tianlong Song, Zhaoxi Fang, Jian Ren 0001, Tongtong Li |
GLOBECOM | 3 |
| 2014 | Beyond the MDS bound in distributed cloud storageabstractDistributed storage plays a crucial role in the current cloud computing framework. After the theoretical bound for distributed storage was derived by the pioneer work of the regenerating code, Reed-Solomon code based regenerating codes were developed. The RS code based minimum storage regeneration code (RS-MSR) and the RS code based minimum bandwidth regeneration code (RS-MBR) can achieve the theoretical bounds on the MSR point and the MBR point respectively in code regeneration. They can also maintain the MDS property in code reconstruction. However, in the hostile network where the storage nodes can be compromised and the packets can be tampered with, the storage capacity of the network can be significantly affected. In this paper, we propose a Hermitian code based regenerating (H-MSR) code. We first prove that this code can achieve the theoretical MSR bound. We then propose data regeneration and reconstruction algorithms for the H-MSR code in both error-free network and hostile network. Theoretical evaluation shows that our proposed schemes can detect the erroneous decodings and correct more errors in the hostile network than the RS-MSR code with the same code rate. Our analysis also demonstrates that the proposed H-MSR code has a lower complexity than the RS-MSR code in both code regeneration and code reconstruction. Jian Li 0007, Tongtong Li, Jian Ren 0001 |
INFOCOM | 3 |
| 2014 | Improvement of a Remote Data Possession Checking Protocol from Algebraic Signatures
Yong Yu 0002, Jianbing Ni, Jian Ren 0001, Wei Wu 0001, Lanxiang Chen, Qi Xia 0001 |
ISPEC | 3 |
| 2014 | Defense Against Primary User Emulation Attacks in Cognitive Radio Networks Using Advanced Encryption StandardabstractThis paper considers primary user emulation attacks in cognitive radio networks operating in the white spaces of the digital TV (DTV) band. We propose a reliable AES-assisted DTV scheme, in which an AES-encrypted reference signal is generated at the TV transmitter and used as the sync bits of the DTV data frames. By allowing a shared secret between the transmitter and the receiver, the reference signal can be regenerated at the receiver and used to achieve accurate identification of the authorized primary users. In addition, when combined with the analysis on the autocorrelation of the received signal, the presence of the malicious user can be detected accurately whether or not the primary user is present. We analyze the effectiveness of the proposed approach through both theoretical analysis and simulation examples. It is shown that with the AES-assisted DTV scheme, the primary user, as well as malicious user, can be detected with high accuracy under primary user emulation attacks. It should be emphasized that the proposed scheme requires no changes in hardware or system structure except for a plug-in AES chip. Potentially, it can be applied directly to today's DTV system under primary user emulation attacks for more efficient spectrum sharing. Ahmed Alahmadi, Mai Abdelhakim, Jian Ren 0001, Tongtong Li |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Distributed Detection in Mobile Access Wireless Sensor Networks under Byzantine AttacksabstractThis paper explores reliable data fusion in mobile access wireless sensor networks under Byzantine attacks. We consider the q-out-of-m rule, which is popular in distributed detection and can achieve a good tradeoff between the miss detection probability and the false alarm rate. However, a major limitation with it is that the optimal scheme parameters can only be obtained through exhaustive search, making it infeasible for large networks. In this paper, first, by exploiting the linear relationship between the scheme parameters and the network size, we propose simple but effective sub-optimal linear approaches. Second, for better flexibility and scalability, we derive a near-optimal closed-form solution based on the central limit theorem. Third, subjecting to a miss detection constraint, we prove that the false alarm rate of q-out-of-m diminishes exponentially as the network size increases, even if the percentage of malicious nodes remains fixed. Finally, we propose an effective malicious node detection scheme for adaptive data fusion under time-varying attacks; the proposed scheme is analyzed using the entropy-based trust model, and shown to be optimal from the information theory point of view. Simulation examples are provided to illustrate the performance of proposed approaches under both static and dynamic attacks. Mai Abdelhakim, Leonard E. Lightfoot, Jian Ren 0001, Tongtong Li |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2014 | Hop-by-Hop Message Authenticationand Source Privacy in WirelessSensor NetworksabstractMessage authentication is one of the most effective ways to thwart unauthorized and corrupted messages from being forwarded in wireless sensor networks (WSNs). For this reason, many message authentication schemes have been developed, based on either symmetric-key cryptosystems or public-key cryptosystems. Most of them, however, have the limitations of high computational and communication overhead in addition to lack of scalability and resilience to node compromise attacks. To address these issues, a polynomial-based scheme was recently introduced. However, this scheme and its extensions all have the weakness of a built-in threshold determined by the degree of the polynomial: when the number of messages transmitted is larger than this threshold, the adversary can fully recover the polynomial. In this paper, we propose a scalable authentication scheme based on elliptic curve cryptography (ECC). While enabling intermediate nodes authentication, our proposed scheme allows any node to transmit an unlimited number of messages without suffering the threshold problem. In addition, our scheme can also provide message source privacy. Both theoretical analysis and simulation results demonstrate that our proposed scheme is more efficient than the polynomial-based approach in terms of computational and communication overhead under comparable security levels while providing message source privacy. Jian Li 0007, Yun Li 0011, Jian Ren 0001, Jie Wu 0001 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2013 | Mitigating primary user emulation attacks in cognitive radio networks using advanced encryption standardabstractThis paper considers primary user emulation attacks (PUEA) in cognitive radio networks operating in the white spaces of the digital TV (DTV) band. We propose a reliable AES-encrypted DTV scheme, in which an AES-encrypted reference signal is generated at the TV transmitter and used as the sync bytes of each DTV data frame. By allowing a shared secret between the transmitter and the receiver, the reference signal can be regenerated at the receiver and be used to achieve accurate identification of authorized primary users. We analyze the effectiveness of the proposed approach through both theoretical derivation and simulation examples. It is shown that with the AES-encrypted DTV scheme, the primary user can be detected with high accuracy and low false alarm rate under primary user emulation attacks. It should be emphasized that the proposed scheme requires no changes in hardware or system structure except of a plug-in AES chip. Potentially, it can be applied to today's DTV system directly to mitigate primary user emulation attacks, and achieve efficient spectrum sharing. Ahmed Alahmadi, Mai Abdelhakim, Jian Ren 0001, Tongtong Li |
GLOBECOM | 3 |
| 2013 | Combating network pollution attacks: A cascaded error-control coding approachabstractLinear network coding provides a new communication diagram to significantly increase the network capacity by allowing the relay nodes to encode the incoming messages. However, this communication diagram is fragile to communication errors and node compromising attacks. How to combat errors while maintaining the network efficiency is a challenging research problem. In this paper, we characterize a linear network coding through a series of cascaded linear error-control codes. This representation enables us to determine the independent source of errors in the cascaded network level. It could lead to a successful decoding of the original message and locating of the malicious network nodes. We provide comprehensive theoretical analysis on network coding in both unicast and multicast scenarios. Our research provides a new approach to understand network coding schemes and also a novel methodology to develop network coding schemes that can combat node compromising attacks and locate the malicious nodes. Jian Li 0007, Tongtong Li, Jian Ren 0001 |
GLOBECOM | 3 |
| 2013 | Provable ownership of file in de-duplication cloud storageabstractThe rapid adoption of cloud services has propelled network data sharing and storage. Client-side deduplication is proposed to minimize bandwidth and space needed to upload and store duplicated data. The existing solutions, however, were recently found to be vulnerable to attacks that enable the attackers to get full access to the entire file stored on the server after learning just a small piece of information about the file, namely its hash value. In this paper, to solve the problem mentioned above, we propose a cryptographically secure and efficient scheme for a client to prove to the server based on actual possession of the entire file instead of only partial information about it. Our scheme utilizes the technique of spot checking in which the client only needs to access small portions of the original file, dynamic coefficients and randomly chosen indices of the original files. Our extensive security analysis shows that the proposed scheme can generate provable ownership of the file (POF) and maintain a high detection probability of the client misbehavior. Both performance analysis and simulation results demonstrate that our proposed scheme is much more efficient than the existing schemes, especially in reducing the burden of the client. Chao Yang 0016, Jian Ren 0001, Jianfeng Ma 0001 |
GLOBECOM | 2 |
| 2013 | Architecture design of mobile access coordinated wireless sensor networksabstractThis paper considers architecture design of mobile access coordinated wireless sensor networks (MC-WSN) for reliable and efficient information exchange. In sensor networks with mobile access points (SENMA), the mobile access points collect information directly from individual sensors as they traverse the network, such that no routing is needed in data transmission. While being energy efficient, a major limitation with SENMA is the large delay in data collection, making it undesirable for timesensitive applications. In the proposed MC-WSN architecture, the sensor network is coordinated by powerful mobile access points (MA), such that the number of hops from each sensor to the MA is minimized and limited to a prespecified number through active network deployment and network topology design. Unlike in SENMA, where the data collection delay depends on the physical speed of the MA, in MC-WSN, the delay depends on the number of hops and the electromagnetic wave speed, and is independent of the physical speed of the MA. This innovative architecture is energy efficient, resilient, fast reacting and can actively prolong the lifetime of sensor networks. Our simulations show that the proposed MC-WSN can achieve higher energy-efficiency and orders of magnitude lower delay over SENMA, especially for large-scale networks. Mai Abdelhakim, Leonard E. Lightfoot, Jian Ren 0001, Tongtong Li |
ICC | 3 |
| 2013 | An Efficient Threshold Anonymous Authentication Scheme for Privacy-Preserving CommunicationsabstractAnonymous authentication enables any user to be authenticated without being identified. (t,n)-threshold ring signatures, introduced by Bresson et. al., are ring signature schemes that allow a group of t members to jointly sign a message anonymously in a ring of n members. Threshold ring signature schemes provide a nice tradeoff between anonymity and creditability since it allows multiple ring members to sign a message jointly. The complexity in both signature generation and signature verification of the threshold ring signature scheme proposed by Bresson et. al. is O(n2). They also proposed an efficient threshold ring signature scheme based on an (n,t)-complete fair partition, with complexity O(n log n). In this paper, a new efficient (t,n)-threshold ring signature scheme is proposed. This scheme is constructed through a system of t linear equations and n variables, where t is generally a fixed number that is much smaller than n. The proposed threshold ring signature scheme can provide unconditional signer ambiguity, threshold unforgeability and provable security in the random oracle model. The complexity of signature generation and signature verification of the proposed threshold ring signature scheme are O(t log22t) and O(n), respectively. Furthermore, the length of the threshold ring signature is the same as the regular ring signature introduced by Rivest et. al., which is 2n+2, while the length of the threshold ring signature scheme proposed by Bresson et. al. is 3n-t+3. Jian Ren 0001, Lein Harn |
IEEE Trans. Wirel. Commun. | 1 |
| 2012 | Reliable OFDM system design under hostile multi-tone jammingabstractAlong with the advent of reconfigurable radios, hostile jamming is no longer limited to military applications, but has become a serious threat for civilian wireless communications, where OFDM has been identified as one of the most efficient transmission technologies. In this paper, we consider reliable transmission of OFDM systems under multi-tone jamming. We propose to enhance the jamming resistance of OFDM through symbol level precoding. Our approach is to find the optimal precoder and decoder that can minimize the MSE between the transmitted and the estimated symbols, subject to a given transmit power constraint. Closed-form solutions are derived, and further demonstrated through simulation examples. It is observed that adding controlled redundancy at symbol level is an effective way to mitigate hostile jamming in OFDM systems. Mai Abdelhakim, Jian Ren 0001, Tongtong Li |
GLOBECOM | 2 |
| 2012 | Characterization of linear network coding for pollution detectionabstractWhile linear network coding can improve the throughput significantly in network environment with little additional computational overhead, it is fragile to communication errors and node compromising attacks. To combat the errors in network coding, both error-detection and error-correction based schemes have been proposed. In this paper, we provide a novel methodology to characterize linear network coding through error-control coding. Our main idea is to represent each linear network coding with an error-control coding. We provide comprehensive theoretical analysis on the relationships between linear network coding and error-control coding in both unicast and multicast scenarios. We find that these two codes are essentially identical in algebraic aspects. Our research provides a new approach to understand network coding schemes and also a novel methodology to develop network coding schemes that can combat communication errors and also node compromising attacks. Jian Li 0007, Chao Yang 0016, Tongtong Li, Jian Ren 0001 |
GLOBECOM | 5 |
| 2012 | Quantitative security and efficiency analysis of SEAR in wireless sensor networksabstractSEAR is a novel secure and energy aware routing protocol proposed to address the energy balance and routing security through a balanced energy consumption and probabilistic random walking. Recently, a quantitative security measurement scheme for source-location privacy based on source-location disclosure index (SDI) and source-location space index (SSI) has been proposed. In this paper, we first derive a numerical formula to quantitatively estimate the routing efficiency through the number of routing hops for a given routing security level. We then consider the reverse problem: For a given routing cost factor, how to determine the maximum security level for a message to be transmitted. Our simulation results demonstrate that the theoretical results provide a very tight estimation of the actual routing hops for various security parameters. Finally, we prove that the SEAR scheme can provide provable security under the quantitative security measurement criteria. Tongtong Li, Jian Ren 0001 |
ICC | 3 |
| 2012 | Providing hop-by-hop authentication and source privacy in wireless sensor networksabstractMessage authentication is one of the most effective ways to thwart unauthorized and corrupted traffic from being forwarded in wireless sensor networks (WSNs). To provide this service, a polynomial-based scheme was recently introduced. However, this scheme and its extensions all have the weakness of a built-in threshold determined by the degree of the polynomial: when the number of messages transmitted is larger than this threshold, the adversary can fully recover the polynomial. In this paper, we propose a scalable authentication scheme based on elliptic curve cryptography (ECC). While enabling intermediate node authentication, our proposed scheme allows any node to transmit an unlimited number of messages without suffering the threshold problem. In addition, our scheme can also provide message source privacy. Both theoretical analysis and simulation results demonstrate that our proposed scheme is more efficient than the polynomial-based approach in terms of communication and computational overhead under comparable security levels while providing message source privacy. Yun Li 0011, Jian Li 0007, Jian Ren 0001, Jie Wu 0001 |
INFOCOM | 3 |
| 2012 | Reliable Cooperative Sensing in Cognitive Networks - (Invited Paper)
Mai Abdelhakim, Jian Ren 0001, Tongtong Li |
WASA | 2 |
| 2012 | Quantitative Measurement and Design of Source-Location Privacy Schemes for Wireless Sensor NetworksabstractWireless sensor networks (WSNs) have been widely used in many areas for critical infrastructure monitoring and information collection. While confidentiality of the message can be ensured through content encryption, it is much more difficult to adequately address source-location privacy (SLP). For WSNs, SLP service is further complicated by the nature that the sensor nodes generally consist of low-cost and low-power radio devices. Computationally intensive cryptographic algorithms (such as public-key cryptosystems), and large scale broadcasting-based protocols may not be suitable. In this paper, we first propose criteria to quantitatively measure source-location information leakage in routing-based SLP protection schemes for WSNs. Through this model, we identify vulnerabilities of some well-known SLP protection schemes. We then propose a scheme to provide SLP through routing to a randomly selected intermediate node (RSIN) and a network mixing ring (NMR). Our security analysis, based on the proposed criteria, shows that the proposed scheme can provide excellent SLP. The comprehensive simulation results demonstrate that the proposed scheme is very efficient and can achieve a high message delivery ratio. We believe it can be used in many practical applications. Yun Li 0011, Jian Ren 0001, Jie Wu 0001 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2011 | An Efficient Error-Detection and Error-Correction (EDEC) Scheme for Network CodingabstractNetwork coding is being viewed to have the potential for significant throughput improvement in network environment. However, these expected benefits are very fragile to malicious attacks, including message block content corruption and node compromise attacks. To solve these problems, both pollution detection and pollution correction based schemes have been proposed. These schemes are only effective in some limited scenarios. In this paper, we propose a new scheme that combines the benefits of the existing error-detection and error-correction (EDEC) schemes. The proposed scheme is similar in structure to the existing error-control based schemes. However, by appropriately modifying the rate of the underlying error-control scheme, we can improve the network throughput and robustness significantly. Our scheme can detect the malicious attacks by computing whether the syndromes are all zeros. By collecting all the non-zero syndromes, the malicious attacks within the error-decoding capacity of the underlying linear network coding can be removed and the original message can be recovered. Our theoretical analysis and simulation results demonstrate that the proposed EDEC scheme can improve the overall network performance dramatically with only a very moderate increase of the computational overhead. Wenbo Qiao, Jian Li 0007, Jian Ren 0001 |
GLOBECOM | 3 |
| 2011 | Combining Source-Location Privacy and Routing Efficiency in Wireless Sensor NetworksabstractWireless sensor networks (WSNs) have been widely used in various applications for continuous event monitoring and detection. The WSNs communication is generally event-driven. While confidentiality of the message content can be ensured through content encryption, it is much more difficult to adequately protect the source-location information of the event. For WSNs, source-location privacy service is further complicated by the fact that the sensor nodes consist of low-cost and low-power radio devices, computationally intensive cryptographic algorithms (such as public-key cryptosystems) and large scale broadcasting-based protocols are not suitable for WSNs. On the other hand, exposure of the source-location can jeopardize the successful deployment of WSNs. In this paper, we propose a scheme to provide both source-location privacy and routing efficiency through routing to an intermediate node selected from a hierarchical connected dominating set (CDS) of the network. The CDS represents the backbone of the network and the nodes in the CDS are located in different regions of the network. As a result, choosing nodes from the CDS can ensure the intermediate node to be away from the actual message source node. The selection of the intermediate node can effectively prevent the adversary from performing routing trace back attack to identify the message source node. In addition, this design guarantees a high message delivery ratio and a high message delivery efficiency. Jian Ren 0001 |
GLOBECOM | 1 |
| 2011 | Cooperative sensing in cognitive networks under malicious attackabstractThis paper considers cooperative sensing in cognitive networks under Spectrum Sensing Data Falsification attack (SSDF) in which malicious users can intentionally send false sensing information. One effective method to deal with the SSDF attack is the q-out-of-m scheme, where the sensing decision is based on q sensing reports out of m polled nodes. The major limitation with the q-out-of-m scheme is its high computational complexity due to exhaustive search. In this paper, we prove that for a fixed percentage of malicious users, the detection accuracy increases almost exponentially as the network size increases. Motivated by this observation, as well as the linear relationship between the scheme parameters and the network size, we propose a simple but accurate approach that significantly reduces the complexity of the q-out-of-m scheme. The proposed approach can easily be applied to the large scale networks, which can be much more reliable under malicious attacks. Mai Abdelhakim, Lei Zhang 0025, Jian Ren 0001, Tongtong Li |
ICASSP | 3 |
| 2011 | Generalized Digital Certificate for User Authentication and Key Establishment for Secure CommunicationsabstractPublic-key digital certificate has been widely used in public-key infrastructure (PKI) to provide user public key authentication. However, the public-key digital certificate itself cannot be used as a security factor to authenticate user. In this paper, we propose the concept of generalized digital certificate (GDC) that can be used to provide user authentication and key agreement. A GDC contains user's public information, such as the information of user's digital driver's license, the information of a digital birth certificate, etc., and a digital signature of the public information signed by a trusted certificate authority (CA). However, the GDC does not contain any user's public key. Since the user does not have any private and public key pair, key management in using GDC is much simpler than using public-key digital certificate. The digital signature of the GDC is used as a secret token of each user that will never be revealed to any verifier. Instead, the owner proves to the verifier that he has the knowledge of the signature by responding to the verifier's challenge. Based on this concept, we propose both discrete logarithm (DL)-based and integer factoring (IF)-based protocols that can achieve user authentication and secret key establishment. Lein Harn, Jian Ren 0001 |
IEEE Trans. Wirel. Commun. | 2 |
| 2010 | Preserving Source-Location Privacy in Wireless Sensor Network Using STaR RoutingabstractIn wireless sensor networks (WSNs), providing source-location privacy through secure routing is one of the most prosperous techniques. In this paper, we propose a routing technique to provide adequate source-location privacy with low energy consumption. We introduce this technique as the Sink Toroidal Region (STaR) routing. With this technique, the source node randomly selects an intermediate node within a designed STaR area located around the SINK node. The STaR area is large enough to make it unpractical for an adversary to monitor the entire region. Furthermore, this routing protocol ensures that the intermediate node is neither too close, nor too far from the SINK node in relations to the entire network. While ensuring source location privacy, our simulation results show that the proposed scheme is very efficient and can be used for practical applications. Leron Lightfoot, Yun Li 0011, Jian Ren 0001 |
GLOBECOM | 3 |
| 2010 | Secure and Energy Aware Routing (SEAR) in Wireless Sensor NetworksabstractLifetime optimization and security are two important design issues for multi-hop wireless sensor networks with non-replenishable energy resources. In this research, we propose a novel secure and energy aware (SEAR) routing protocol to address these two issues concurrently through balanced energy consumption and probabilistic random walking. SEAR is designed with two configurable parameters, energy balance control (EBC) and security level. EBC is used to enforce energy balance and increase the lifetime. Security level is designed to determine the probabilistic distribution of the random walking that provides routing security. The security level can be defined by the message source on a message level, or on a system level. Theoretical analysis and OPNET simulation results show that the proposed SEAR can provide excellent balance between routing efficiency and energy consumption while preventing routing traceback attacks. Tingting Jiang 0005, Jian Ren 0001 |
GLOBECOM | 3 |
| 2010 | Resource Allocation with Load Balancing for Cognitive Radio NetworksabstractThis paper considers channel and power allocation for cognitive radio (CR) networks. We assume that the total available spectrum is divided into several bands, each consisting of a group of channels. A centralized base station, enabled by spectrum sensing, is assumed to have the knowledge of all vacant channels, which will be assigned to various CRs according to their requests. The objective of resource allocation is to maximize the sum data rate of all CRs. Since the activities of primary users may cause heavy traffic in some bands while leaving other bands idle, load balancing is first performed to equalize the traffic. A multi-level subset sum algorithm as well as a simpler greedy algorithm is proposed to achieve excellent load balancing performance. After that, an algorithm incorporated with constant-power water filling is proposed to maximize the sum data rate. Simulation results are presented to illustrate the effectiveness of the proposed algorithms. Huahui Wang, Jian Ren 0001, Tongtong Li |
GLOBECOM | 2 |
| 2010 | Source-Location Privacy through Dynamic Routing in Wireless Sensor NetworksabstractWireless sensor networks (WSNs) have the potential to be widely used in many areas for unattended event monitoring. Mainly due to lack of a protected physical boundary, wireless communications are vulnerable to unauthorized interception and detection. Privacy is becoming one of the major issues that jeopardize the successful deployment of wireless sensor networks. While confidentiality of the message can be ensured through content encryption, it is much more difficult to adequately address the source-location privacy. For WSNs, source-location privacy service is further complicated by the fact that the sensor nodes consist of low-cost and low-power radio devices, computationally intensive cryptographic algorithms and large scale broadcasting-based protocols are not suitable for WSNs. In this paper, we propose source-location privacy schemes through routing to randomly selected intermediate node(s) before the message is transmitted to the SINK node. We first describe routing through a single a single randomly selected intermediate node away from the source node. Our analysis shows that this scheme can provide great local source-location privacy. We also present routing through multiple randomly selected intermediate nodes based on angle and quadrant to further improve the global source location privacy. While providing source-location privacy for WSNs, our simulation results also demonstrate that the proposed schemes are very efficient in energy consumption, and have very low transmission latency and high message delivery ratio. Our protocols can be used for many practical applications. Yun Li 0011, Jian Ren 0001 |
INFOCOM | 2 |
| 2010 | A Spectrally Efficient Anti-Jamming Technique Based on Message Driven Frequency Hopping
Lei Zhang 0025, Jian Ren 0001, Tongtong Li |
WASA | 2 |
| 2010 | Survey on anonymous communications in computer networks
Jian Ren 0001, Jie Wu 0001 |
Comput. Commun. | 1 |
| 2009 | Jamming Mitigation Techniques Based on Message-Driven Frequency HoppingabstractThis paper considers spectrally efficient antijamming system design based on message-driven frequency hopping (MDFH). As a highly efficient frequency hopping scheme, MDFH is particularly robust under strong jamming. However, disguised jamming from sources of similar power strength can cause performance losses. To overcome this drawback, in this paper, first, we propose an anti-jamming MDFH (AJ-MDFH) system. The main idea is to transmit an ID sequence along with the information stream. The ID sequence is generated through a cryptographic algorithm using the shared secret between the transmitter and the receiver. It is then exploited by the receiver for effective signal detection and extraction. It is shown that AJ-MDFH is robust under strong jamming, and can effectively reduce the performance degradation caused by disguised jamming. Second, we extend AJ-MDFH to a multicarrier scheme, named MC-AJ-MDFH, which can increase the system efficiency and jamming resistance significantly through jamming randomization and enriched frequency diversity. Moreover, by assigning different carriers to different users, MC-AJ-MDFH can readily be used as a collision-free multiple access system. Simulation examples are provided to demonstrate the performance of the proposed approaches. Lei Zhang 0025, Jian Ren 0001, Tongtong Li |
GLOBECOM | 2 |
| 2009 | Routing-Based Source-Location Privacy in Wireless Sensor NetworksabstractWireless sensor networks (WSN) have the potential to be widely used in many areas for unattended event monitoring. Mainly due to lack of a protected physical boundary, wireless communications are vulnerable to unauthorized interception and detection. Privacy is becoming one of the major issues that jeopardize the successful deployment of wireless sensor networks. While confidentiality of the message can be ensured through content encryption, it is much more difficult to adequately address the source-location privacy. For WSN, source-location privacy service is further complicated by the fact that the sensor nodes consist of low-cost and low-power radio devices, computationally intensive cryptographic algorithms (such as public-key cryptosystems) and large scale broadcasting-based protocols are not suitable for WSN. In this paper, we propose a scheme to provide both content confidentiality and source-location privacy through routing to a randomly selected intermediate node (RRIN). While being able to provide source-location privacy for WSN, our simulation results also demonstrate that the proposed scheme is very efficient and can be used for practical applications. Jian Ren 0001, Yun Li 0011, Tongtong Li |
ICC | 1 |
| 2009 | Spectrally Efficient Anti-Jamming System Design Using Message-Driven Frequency HoppingabstractThis paper considers spectrally efficient anti-jamming system design based on message-driven frequency hopping (MDFH). We first analyze the performance of the MDFH system under different jamming scenarios. It is observed that MDFH is particularly robust under strong jamming. However, it experiences a performance bottleneck under disguised jamming, for which the jamming power is close to the signal power. To overcome this drawback, we propose an anti-jamming MDFH (AJ-MDFH) system. The main idea is to transmit an ID sequence along with the information stream. The ID sequence is generated through a cryptographic algorithm using the shared secret between the transmitter and the receiver. It is then exploited by the receiver for effective signal detection and extraction. It was shown that AJ-MDFH is robust under strong jamming, and can effectively reduce the performance degradation caused by disguised jamming. Simulation examples are provided to demonstrate the performance of the proposed approaches. Lei Zhang 0025, Jian Ren 0001, Tongtong Li |
ICC | 2 |
| 2009 | Mixing Ring-Based Source-Location Privacy in Wireless Sensor NetworksabstractWireless sensor networks consist of low-cost and low- power radio devices and are deployed in open and unprotected areas. Privacy is becoming one of the major issues that jeopardize the successful deployment of wireless sensor networks. While confidentiality of the message can be ensured through content encryption, it is much more difficult to adequately address the source-location privacy. For wireless sensor networks, computationally intensive cryptographic algorithms (such as public-key cryptosystems) and large scale broadcasting-based protocols are not suitable. In this paper, we propose a scheme to provide source-location privacy through a three-phase routing: routing to a randomly selected intermediate node, routing in a network mix ring, and message forwarding to the SINK node. While being able to provide source-location privacy for WSN, our simulation results also demonstrate that the proposed scheme is very efficient and can be used for practical applications. Yun Li 0011, Jian Ren 0001 |
ICCCN | 2 |
| 2009 | Providing Source Privacy in Mobile Ad Hoc NetworksabstractCommunication privacy is becoming an essential security requirement for mission critical communications and communication infrastructure protection. This is especially true for mobile ad hoc networks (MANETs) due to mobility of the communication nodes and the nature of wireless communications. Existing research in privacy-preserving communications can largely be divided into two categories: cryptosystem-based techniques and broadcasting-based techniques. The cryptosystem-based techniques include mix-based systems and secure multiparty computation-based systems, originating from mixnet and DC-net respectively. All mix-based approaches require a trusted third party to provide the mix and are not quite feasible in MANET. However, DC-net based approaches suffer from transmission collision problem that cannot be easily resolved practically. Broadcasting based schemes provide communication privacy by mixing the real messages with dummy packets so that it is infeasible for the adversaries to identify the real packets and track the message source. However, the transmission of dummy messages not only increases the energy consumption significantly, but also increases the network collisions and decreases the packet delivery ratio. In this paper, we first propose a novel unconditionally secure source anonymous message authentication scheme (SAMAS) that enables messages to be released without relying on any trusted third parties. While providing source privacy, the proposed scheme can also provide message content authenticity. We then propose a novel communication protocol for MANET that can ensure communication privacy of both communication parties and their end-to-end routing. The proposed protocol can be used for critical infrastructure protection and secure file sharing. The security analysis demonstrates that the proposed protocol is secure against various attacks. The theoretical analysis and simulation show that the proposed scheme is efficient and can ensure high message delivery ratio. Jian Ren 0001, Yun Li 0011, Tongtong Li |
MASS | 1 |
| 2009 | Preserving Source-Location Privacy in Wireless Sensor NetworksabstractWireless sensor networks (WSN) have the potential to be widely used in many areas for unattended event monitoring. Mainly due to lack of a protected physical boundary, wireless communications are vulnerable to unauthorized interception and detection. Privacy is becoming one of the major issues that jeopardize the successful deployment of wireless sensor networks. While confidentiality of the message can be ensured through content encryption, it is much more difficult to adequately address the source-location privacy. For WSN, source-location privacy service is further complicated by the fact that the sensor nodes consist of low-cost and low-power radio devices, computationally intensive cryptographic algorithms (such as public-key cryptosystems) and large scale broadcasting-based protocols are not suitable for WSN. In this paper, we propose a scheme to provide both content confidentiality and source-location privacy through routing to a randomly selected intermediate node (RRIN) and a network mixing ring (NMR), where the RRIN provides local source- location privacy and NMR yields network-level (global) source- location privacy. While being able to provide source-location privacy for WSN, our simulation results also demonstrate that the proposed scheme is very efficient and can be used for practical applications. Yun Li 0011, Jian Ren 0001 |
SECON | 2 |
| 2009 | Providing Source-Location Privacy in Wireless Sensor Networks
Yun Li 0011, Jian Ren 0001 |
WASA | 2 |
| 2009 | Design of DL-based certificateless digital signatures
Lein Harn, Jian Ren 0001, Changlu Lin |
J. Syst. Softw. | 2 |
| 2009 | An identity-based single-sign-on scheme for computer networksabstractAbstract Conventionally, no user identification is required for a user to log into a security‐protected system. User authentication is based on what the user knows, or what the user has, which can be easily shared among others. Moreover, when multiple systems are involved, the user is then required to authenticate to each system individually and repeatedly. In this paper, we present a scheme to achieve secure user identification and authentication to multiple security‐protected systems simultaneously through a single operation. The proposed scheme is based on the well‐known RSA cryptosystem, the discrete logarithm problem, and the subset‐sum NP‐complete problem. Security analysis shows that the proposed scheme is secure to all known security attacks and can be easily implemented in various environments including very resource constrained environment such as Smart Cards. Copyright © 2008 John Wiley & Sons, Ltd. Jian Ren 0001 |
Secur. Commun. Networks | 1 |
| 2008 | Spectrally Efficient Spread Spectrum System Design: Message-Driven Frequency HoppingabstractOriginally developed for secure communications in military applications, frequency hopping systems possess anti-jamming and anti-interception features by exploiting time- frequency diversity over large spectrum. However, the spectral efficiency of existing FH systems is very low due to inappropriate use of the total available bandwidth. To improve the system capacity, in this paper, we propose an innovative message-driven frequency hopping (MDFH) scheme. Unlike in traditional FH systems where the hopping pattern of each user is determined by a pre-assigned pseudo-random (PN) sequence, in MDFH, part of the message stream will be acting as the PN sequence for hopping frequency selection. Essentially, transmission of information through hopping frequency control introduces another dimension to the signal space, and the corresponding coding gain increases system efficiency by multiple times. The MDFH scheme can be further enhanced by allowing simultaneous transmissions over multiple frequency bands. Including both MDFH and OFDM as special cases, the enhanced MDFH scheme, named E-MDFH, can achieve high spectral efficiency while providing excellent design flexibility. E-MDFH can readily be extended to a FH-based collision-free multiple access scheme. Qi Ling 0002, Jian Ren 0001, Tongtong Li |
ICC | 2 |
| 2008 | Anonymous Communication Protocol in Overlay NetworksabstractCommunication anonymity is becoming an increasingly important, or even indispensable security requirement for many applications. The existing research in anonymous communications can largely be divided into two categories: mix- based systems and secure multi-party computation-based systems, originating from mixnet and DC-net respectively. However, they either cannot provide provable anonymity, or suffer from transmission collision problem. In this paper, we first propose a novel unconditionally secure source anonymous message authentication code (SA-MAC) that can be applied to any messages without relying on any trusted third parties. While ensuring message sender anonymity, SM-MAC can also provide message content authenticity. We then propose a novel communication protocol that can hide the senders and the receivers from each other, and thus can be used for secure file sharing. The security analysis demonstrates that the proposed protocol is secure against various attacks. Our analysis also shows it is efficient and practical. Jian Ren 0001, Tongtong Li, Keesook Han |
ICC | 1 |
| 2008 | Message-Driven Frequency Hopping - Design and Analysis
Qi Ling 0002, Jian Ren 0001, Tongtong Li |
WASA | 2 |
| 2008 | Privacy-Preserving Communication Algorithms and Network Protocols
Jian Ren 0001 |
WASA | 1 |
| 2008 | Efficient identity-based RSA multisignatures
Lein Harn, Jian Ren 0001 |
Comput. Secur. | 2 |
| 2008 | Generalized Ring SignaturesabstractRing signature was first introduced in 2001. In a ring signature, instead of revealing the actual identity of the message signer, it specifies a set of possible signers. The verifier can be convinced that the signature was indeed generated by one of the ring members, however, she is unable to tell which member actually produced the signature. In this paper, we propose a generalized ring signature scheme and a generalized multi-signer ring signature based on the original ElGamal signature scheme. The proposed ring signature can achieve unconditional signer ambiguity and is secure against adaptive chosen-message attacks in the random oracle model. Comparing to ring signature based on RSA algorithm, the proposed generalized ring signature scheme has three advantages: (1) all ring members can share the same prime number and all operations can be performed in the same domain; (2) by combining with multi-signatures, we can develop the generalized multi-signer ring signature schemes to enforce cross-organizational involvement in message leaking. It may result in a higher level of confidence or broader coverage on the message source; and (3) the proposed ring signature is a convertible ring signature. It enables the actual message signer to prove to a verifier that only she is capable of generating the ring signature. Jian Ren 0001, Lein Harn |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2007 | A Spectrally Efficient Frequency Hopping SystemabstractFrequency hopping systems have been widely used in military communications to prevent hostile jamming, interception and detection. In traditional frequency hopping (FH) systems, the transmitter hops in a pseudo-random manner among available frequencies according to a pre-specified algorithm, and the receiver operates accordingly in exact synchronization with the transmitter's hopping pattern. In multiple access systems, a collision may happen when more than one users transmit in the same frequency band simultaneously. Two major limitations with the conventional frequency hopping systems are: strict requirement on frequency acquisition/synchronization, and very low spectral efficiency due to inefficient utilization of the available bandwidth. In this paper, we introduce a new concept - collision-free frequency hopping (CFFH). Based on the OFDM framework and the secure subcarrier assignment algorithm, the proposed CFFH system can achieve high information capacity through collision-free multiple access, and can successfully resolve the strict synchronization limitation. At the same time, as each user still transmits through a pseudo-random frequency hopping scheme, CFFH can maintain the inherent anti-jamming, anti-interception security features of the conventional FH system. Tongtong Li, Qi Ling 0002, Jian Ren 0001 |
GLOBECOM | 3 |
| 2006 | Non-uniform Information Transmission for Minimum Distortion in Wireless Networks
Tongtong Li, Huahui Wang, Jian Ren 0001 |
WASA | 3 |
| 2006 | Ring Signature Based on ElGamal Signature
Jian Ren 0001, Lein Harn |
WASA | 1 |
| 2005 | Physical layer built-in security enhancement of DS-CDMA systems using secure block interleavingabstractAs shown in Daemen, J. et al, (1999) and Zhang, M. et al, (2000), the physical layer built-in information privacy of the conventional CDMA system, provided by pseudo-random scrambling, is far from adequate and can be improved by applying cryptographic techniques in the scrambling process. Motivated by the fact that after scrambling, chips spread from one symbol still cluster together and could be fragile to strong burst errors and fading effects, in this paper, a chip-level secure interleaving procedure is proposed to improve the system performance while enhancing the security measure. More specifically, the AES algorithm is combined with block interleaving. It should be noted that interleaving is in fact a special case of scrambling. Security analysis is provided to demonstrate the effectiveness of the proposed secure interleaving scheme under exhaustive search attack. Simulation examples are presented to illustrate the robustness of chip-level interleaving over channels with severe fading or strong burst errors. Qi Ling 0002, Tongtong Li, Jian Ren 0001 |
GLOBECOM | 3 |
| 2004 | Design of pseudo-random spreading sequences for CDMA systemsabstractPseudo-random sequences with good correlation properties and large linear complexity are widely used in code-division multiple-access (CDMA) communication systems and cryptology for reliable and secure information transmission. In this paper sequences with long period, large complexity, balance statistics and low correlation properties are constructed from addition of m-sequences with pairwise-prime periods (AMPP). Using m-sequences as building blocks, the proposed method proved to be an efficient and flexible approach to construct long period pseudo-random sequences with desirable properties from short period sequences. Applying the proposed method to two Gold sequences, a signal set ((2/sup n/ - 1) (2/sup m/ - 1), (2/sup n/ + 1)(2/sup m/ + 1), (2/sup (n+1)/2/ + 1)(2/sup (m+1)/2/ + 1)) is constructed. Jian Ren 0001, Tongtong Li |
GLOBECOM | 1 |
| 2004 | On the Structure of Hermitian Codes and Decoding for Burst ErrorsabstractIn this paper, it is proved that Hermitian code is a direct sum of concatenated Reed-Solomon codes over GF(q/sup 2/). Based on this discovery, first, a new method for computing the dimension and tightly estimating the minimum distance of the Hermitian code is derived. Secondly, a new decoding algorithm, which is especially effective in dealing with burst errors with complexity O(n/sup 5/3/), is described. Finally, some possible approaches for optimization of Hermitian codes are discussed. Jian Ren 0001 |
IEEE Trans. Inf. Theory | 1 |
| 2003 | On the structure of Hermitian codes and decoding for burst errorsabstractIn this paper, we first prove that every Hermitian code is a direct sum of concatenated Reed-Solomon codes over GF(q/sup 2/), which provides a new method to calculate the dimension of the Hermitian code. Based on this, we present a new decoding algorithm for Hermitian code. Our algorithm is especially efficient in decoding burst errors. Finally, a method to optimize Hermitian code is obtained. The optimized code maintains the same dimension and error correctability, but the complexity for burst error correction can be reduced from O(n/sup 5/3/) to O(n). Jian Ren 0001 |
GLOBECOM | 1 |