EDBT 2026 Demo / reviewers in the wild / expert
Xiaodong Lin 0001
dblp:59/554
· DBLP profile ↗
240ranked-venue papers
19as first author
68since 2021 · last 2026
0000-0001-8916-6645ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 146 · 15 first-author · 23 since 2021Security and privacy · 52 · 3 first-author · 27 since 2021Systems, architecture and hardware · 18 · 8 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 3 since 2021Software engineering, systems software and programming languages · 5 · 4 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards integration of privacy enhancing technologies in explainable artificial intelligenceabstractExplainable artificial intelligence (XAI) plays a crucial role in mitigating the risks associated with the non-transparency of black-box artificial intelligence (AI) systems. However, despite its advantages, XAI methods have been shown to expose the privacy of individuals whose data are used to train or query the underlying models. Prior research has demonstrated privacy attacks that exploit explanations to infer sensitive personal information of individuals. At present, there is a lack of effective defenses against such privacy attacks targeting explanations, particularly when vulnerable XAI techniques are deployed in production environments or used in machine learning as a service systems. To address this gap, this study investigates the use of privacy enhancing technologies (PETs) as a defense mechanism against attribute inference attacks on explanations generated by feature-based XAI methods. We empirically evaluate three types of PETs, i.e., synthetic training data, differentially private training and noise addition, across two categories of feature-based XAI. Our findings reveal varying levels of effectiveness among the mitigation strategies, as well as trade-offs between privacy, utility and system performance. In the best scenario, integrating PETs into the explanation process reduced attack success by 49.47% while preserving model utility and explanation quality. Based on our evaluation, we propose strategies for effectively integrating PETs into XAI to maximize privacy protection and minimize the risk of sensitive information leakage. Sonal Allana, Rozita Dara 0001, Xiaodong Lin 0001, Pulei Xiong |
Knowl. Based Syst. | 3 |
| 2026 | A Log-Likelihood Chain Framework for Defending Against LDP Data Poisoning AttacksabstractLocal differential privacy (LDP) provides strict privacy guarantee in a distributed environment. Recent studies demonstrated that LDP protocols are vulnerable to data poisoning attacks where an attacker can manipulate the perturbed result on the local side and send bogus data to skew the final estimate on the server. Unfortunately, existing attack detections do not create an effective attack indicator and rely on particular characteristics of LDP protocols. As a result, they typically exhibit limited detection performance. In this paper, we use log-likelihood as the attack indicator and propose a chain-style detection to enhance the detection effectiveness, in which the attack impact could propagate along the chain and exhibit clear anomaly signal even under stealthy attack scenarios. The experimental results show that our detection consistently outperforms the existing methods. Using four datasets containing categorical and numerical data separately, our detection achieves an F1 score exceeding 96% in most cases. It even remains above 0.9 under stealthy attack settings, outperforming the state-of-the-art detection by up to 0.25. Yuxin Wen, Haonan Yan, Yahong Chen, Zhe Sun 0005, Hui Li 0006, Xiaodong Lin 0001 |
IEEE Trans. Knowl. Data Eng. | 8 |
| 2025 | Fuzzy Private Hash Matching for Harmful Media Moderation in End-to-End Encrypted CommunicationabstractEnd-to-End Encryption (E2EE) effectively prevents messaging platforms from accessing media content but limits the automatic detection of harmful media using popular perceptual hash-matching methods. Recently, Private Hash Matching (PHM) techniques have shown great potential for moderating harmful content in E2EE. However, many state-of-the-art PHM schemes either focus solely on exact hash matching, neglecting the more practical fuzzy hash matching, or fail to balance privacy, efficiency, and robustness. In this paper, we present an efficient and robust Fuzzy Private Hash Matching (FPHM) scheme for harmful media moderation in E2EE. Our scheme comprises two steps: 1) coarse matching on the client side that filters out the legal media using an index structure based on a Dynamic-Encoding-Tree Locality-Sensitive Hash (DET-LSH), 2) fine-grained, distance-aware fuzzy matching through client-server interaction on the filtered data. Security analyses confirm that the scheme robustly protects both user media information and the server's harmful hash set from unauthorized disclosure. The experiment indicates that FPHM enhances inspection efficiency and robustness with negligible false negatives. Yating Li 0003, Le Wang 0010, Xiaodong Lin 0001 |
ICC | 6 |
| 2025 | A Generic Framework for Privacy Risk Assessment of Machine Learning ModelsabstractPrivacy attacks on machine learning (ML) models pose significant risks to individuals whose personal data is used for training or querying these models. Although concerns about the potential exposure of sensitive information through ML models continue to grow, existing safeguard mechanisms primarily focus on security threats, often neglecting privacy risks. In this paper, we examine existing tools to assess privacy risks of ML models and provide an overview of various privacy attacks and defense strategies. Given the lack of a comprehensive framework for assessing privacy vulnerabilities, we propose a generic framework for evaluating the privacy of ML systems and establish a set of tailored evaluation metrics for different types of privacy attacks. In addition, we develop a dedicated testbed to implement our framework and present experimental results that demonstrate the impact of various privacy attacks on different ML models. Le Wang 0010, Sonal Allana, Xiaodong Lin 0001, Rozita Dara 0001, Pulei Xiong |
PST | 5 |
| 2025 | Enhancing Adversarial Robustness of IoT Intrusion Detection via SHAP-Based Attribution Fingerprinting
Dilli P. Sharma, Xiaodong Lin 0001, Pulei Xiong |
TrustCom | 4 |
| 2025 | ADA-FInfer: Inferring Face Representations From Adaptive Select Frames for High-Visual-Quality Deepfake DetectionabstractInterpretable deepfake detection is gaining attention for providing explainable, trustworthy results, avoiding the limitations of ‘black-box’ models. Current interpretable methods focus on visible artifacts in low-visual-quality deepfakes, but these artifacts become less apparent in high-visual-quality deepfakes generated by advanced models. With advancements in deep generative models, producing high-visual-quality deepfakes has become a strategy to evade detection. To address this, we propose${\sf ADA-FInfer}$, an adaptive frame selection and interpretable face representation inference method for detecting high-visual-quality deepfakes.${\sf ADA-FInfer}$adaptively selects frames by analyzing optical flow to reveal manipulations. We also introduce an adaptive attack method that manipulates specific frames, and our adaptive selection strategy shows resistance to such attacks.${\sf ADA-FInfer}$uses an encoder to learn face representations from source and target faces, applying a representation-prediction loss to maximize the distinction between real and fake videos. To provide further insights, we employ the joint entropy, mutual information, and conditional entropy analyses to explain the method's effectiveness. Extensive experiments and ablation studies demonstrate that${\sf ADA-FInfer}$achieves promising performance in detecting high-visual-quality deepfakes. Jinwen Liang, Zheng Qin 0001, Xin Liao 0001, Wenbo Zhou 0004, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Accurate, Secure, and Efficient Semi-Constrained Navigation Over Encrypted City MapsabstractNavigation services enable users to find the shortest path from a starting point$S$to a destination$D$, reducing time, gas, and traffic congestion. Still, navigation users risk the exposure of their sensitive location data. Our motivation arises from how users can accurately, securely, and efficiently navigate from$S$to$D$while passing through$k$unordered stops, i.e., midway locations with a non-fixed visiting order. In this work, we formally define Semi-Constrained Navigation (SCN) and present a novel scheme Hermes to achieve accurate, secure, and efficient SCN. Specifically, we propose a divide-and-conquer approach to strike a good balance between accuracy and efficiency. It recursively depth-first-searches the whole area (a navigation tree) and invokes five carefully-crafted strategies stop-by-stop to compute three subpaths in three sequential subareas. We construct a path-distance oracle to encrypt the road graph and securely implement the strategies by using homomorphic encryption and garble circuits. We formally prove the security in the random oracle model and analyze the search complexity to be less than$O(k^{2})$. We experiment over a real-world city map and compare with six baselines. Results show that path search with$k=4$among$N=1000$intersections requires 5.58 seconds with a 3.2% distance deviation rate and an 82.5% path similarity. Meng Li 0006, Yifei Chen 0005, Jingyu Wu, Zijian Zhang 0001, Jialing He, Liehuang Zhu, Mauro Conti, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 9 |
| 2025 | A Proactive Defense Against Model Poisoning Attacks in Federated LearningabstractModel poisoning attacks greatly jeopardize the application of federated learning (FL). The effectiveness of existing defenses is susceptible to the latest model poisoning attacks, leading to a decrease in prediction accuracy. Besides, these defenses are intractable to distinguish benign outliers from malicious gradients, which further compromises the model generalization. In this work, we propose a novel proactive defense named${\sf RECESS}$against model poisoning attacks. Different from the passive analysis in previous defenses,${\sf RECESS}$proactively queries each participating client with a delicately constructed aggregation gradient, accompanied by the detection of malicious clients according to their responses with higher accuracy. Furthermore, RECESS uses a new trust scoring mechanism to robustly aggregate gradients. Unlike previous methods that score each iteration, RECESS considers clients’ performance correlation across multiple iterations to estimate the trust score, substantially increasing fault tolerance. Finally, we extensively evaluate${\sf RECESS}$on typical model architectures and four datasets under various settings. We also evaluated the defensive effectiveness against other types of poisoning attacks, the sensitivity of hyperparameters, and adaptive adversarial attacks. Experimental results show the superiority of${\sf RECESS}$in terms of reducing accuracy loss caused by the latest model poisoning attacks over five classic and two state-of-the-art defenses. Haonan Yan, Chengbo Zheng, Qian Chen 0032, Bin Wang 0062, Hui Li 0006, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Fed$n$nP: Federated Unlearning With Multiple Client Set PartitionsabstractFederated learning (FL) has garnered increased attention in the field of distributed machine learning and privacy computing. In the FL setup, effective and efficient unlearning algorithms are required to remove the impact of specific training data from the trained model, called federated unlearning. However, traditional machine unlearning algorithms face limitations in FL systems because the client data is private and even non-IID. In this paper, we propose a new federated unlearning algorithm called FednP. Our approach involves dividing the client set into subsets using multiple different partitions. We then train constituent models for each client subset within these partitions using existing FL algorithms and aggregate the results of constituent models for predictions. With multiple partitions, FednP limits the influence of the data to be erased within its belonging subsets, while it also improves the accuracy of the aggregated prediction. Based on the multiple-partition framework, we design partition creation methods to effectively enhance the prediction accuracy. Furthermore, we propose a cost reduction method to reduce the cost of training/retraining. Our extensive experiments on various datasets and model architectures demonstrate that FednP improves prediction accuracy while well-controls the additional cost. Juncheng Jia, Weipeng Zhu, Bing Luo 0002, Xiaodong Lin 0001, Liuchen Ma |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Efficient and Privacy-Enhancing Non-Interactive Periocular Authentication for Access Control Services
Yating Li 0003, Le Wang 0010, Xiaodong Lin 0001 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | DeFedGCN: Privacy-Preserving Decentralized Federated GCN for Recommender SystemabstractFederated recommender system (RS), a prevailing distributed paradigm, has been spawning significant interest in exploiting locally stored but tremendous data to predict items best aligned with clients. However, federated RS suffers severely from a single point of failure due to the dependency on the central server, leading to potential denial of service (DoS) attacks. To address this security weakness, in this paper, we propose a decentralized privacy-preserving federated graph convolutional network for RS, dubbed DeFedGCN. Specifically, DeFedGCN aggregates local updates by a decentralized consensus-reaching process and customizes local models for personalized recommendation, where the aggregation is enhanced by local differential privacy to resist model inversion attacks. More importantly, to promote the recommendation performance, DeFedGCN conducts asub-graph expansionbased on the private set interaction to explore high-order interactions among clients and items. Theoretical analysis confirms the effectiveness and privacy guarantee of DeFedGCN. Additionally, we conduct extensive experiments on four widespread real-world databases. The recommendation performance of DeFedGCN outperforms the state-of-the-art federated RS algorithms without security protection against DoS attacks by up to 7.4%. Qian Chen 0032, Zilong Wang 0001, Mengqing Yan, Haonan Yan, Xiaodong Lin 0001, Jianying Zhou 0001 |
IEEE Trans. Serv. Comput. | 5 |
| 2024 | DeFiAligner: Leveraging Symbolic Analysis and Large Language Models for Inconsistency Detection in Decentralized Finance
Rundong Gan, Liyi Zhou, Le Wang 0010, Kaihua Qin, Xiaodong Lin 0001 |
AFT | 5 |
| 2024 | Federated Unlearning with Multiple Client PartitionsabstractFederated learning (FL) has recently received more and more attention in the joint field of distributed machine learning (ML) and privacy computing. Similar to the traditional ML systems, there exists the need of effective and efficient unlearning algorithms to unlearn certain training data from the FL model. The traditional machine unlearning algorithms have limitations for the FL systems, since the data of clients are both private and non-IID. In this paper, we propose a new algorithm for federated unlearning called FedUMP to improve the model performance and accelerate the unlearning process. Its main idea is to first create multiple different client partition strategies, each of which divides the clients into several subsets. Then we independently train subset models for all client subsets and aggregate the results of subset models for predictions. Furthermore, we propose a retraining acceleration method to reduce the time consumption with multiple partitions, and a partition strategy design method to search for good partition strategies efficiently. Extensive experiments on various datasets and model architectures demonstrate that FedUMP improves both model performance and unlearning speed. Weipeng Zhu, Juncheng Jia, Bing Luo 0002, Xiaodong Lin 0001 |
ICC | 4 |
| 2024 | Proactive Audio Authentication Using Speaker Identity WatermarkingabstractGenerative AI, particularly through “deep fake” technology, stands at the crossroads of innovation and ethical dilemma. On one hand, it brings unprecedented advancements, transforming how we interact with digital content. On the other hand, it significantly compromises privacy and security, casting a shadow over the reliability of speaker recognition systems and fueling misuse in telecommunication fraud and manipulation of public opinion. This stark contrast not only raises legitimate concerns over the safety of sharing personal audio and video but also questions the very authenticity of digital media. To address the challenges of traceability in deepfake content and guarantee the integrity of audio, we propose a new solution specifically designed to counteract voice conversion and synthetic speech attacks. Leveraging cutting-edge deep learning technology, three extension strategies and ensemble learning of synthesis layer, this approach not only overcomes the inherent limitations of existing forensic methods but also resolves the issues associated with high-capacity watermarks. It achieves exceptionally high accuracy and imperceptibility across multiple speech datasets, various synthetic forgery methods, and numerous speech processing algorithms. Qi Li 0033, Xiaodong Lin 0001 |
PST | 2 |
| 2024 | ALIF: Low-Cost Adversarial Audio Attacks on Black-Box Speech Platforms using Linguistic FeaturesabstractExtensive research has revealed that adversarial examples (AE) pose a significant threat to voice-controllable smart devices. Recent studies have proposed black-box adversarial attacks that require only the final transcription from an automatic speech recognition (ASR) system. However, these attacks typically involve many queries to the ASR, resulting in substantial costs. Moreover, AE-based adversarial audio samples are susceptible to ASR updates. In this paper, we identify the root cause of these limitations, namely the inability to construct AE attack samples directly around the decision boundary of deep learning (DL) models. Building on this observation, we propose ALIF, the first black-box adversarial linguistic feature-based attack pipeline. We leverage the reciprocal process of text-to-speech (TTS) and ASR models to generate perturbations in the linguistic embedding space where the decision boundary resides. Based on the ALIF pipeline, we present the ALIF-OTL and ALIF-OTA schemes for launching attacks in both the digital domain and the physical playback environment on four commercial ASRs and voice assistants. Extensive evaluations demonstrate that ALIF-OTL and -OTA significantly improve query efficiency by 97.7% and 73.3%, respectively, while achieving competitive performance compared to existing methods. Notably, ALIF-OTL can generate an attack sample with only one query. Furthermore, our test-of-time experiment validates the robustness of our approach against ASR updates. Peng Cheng 0007, Yuwei Wang 0009, Zhongjie Ba, Xiaodong Lin 0001, Feng Lin 0004, Li Lu 0008, Kui Ren 0001 |
SP | 5 |
| 2024 | PAGE: Equilibrate Personalization and Generalization in Federated LearningabstractFederated learning (FL) is becoming a major driving force behind machine learning as a service, where customers (clients) collaboratively benefit from shared local updates under the orchestration of the service provider (server). Representing clients' current demands and the server's future demand, local model personalization and global model generalization are separately investigated, as the ill-effects of data heterogeneity enforce the community to focus on one over the other. However, these two seemingly competing goals are of equal importance rather than black and white issues, and should be achieved simultaneously. In this paper, we propose the first algorithm to balance personalization and generalization on top of game theory, dubbed PAGE, which reshapes FL as a co-opetition game between clients and the server. To explore the equilibrium, PAGE further formulates the game as Markov decision processes, and leverages the reinforcement learning algorithm, which simplifies the solving complexity. Extensive experiments on four widespread datasets show that PAGE outperforms state-of-the-art FL baselines in terms of global and local prediction accuracy simultaneously, and the accuracy can be improved by up to 35.20% and 39.91%, respectively. In addition, biased variants of PAGE imply promising adaptiveness to demand shifts in practice. Qian Chen 0032, Zilong Wang 0001, Jiaqi Hu 0003, Haonan Yan, Jianying Zhou 0001, Xiaodong Lin 0001 |
WWW | 6 |
| 2024 | QP-LDP for Better Global Model Performance in Federated LearningabstractFederated learning (FL) enhanced by local differential privacy (LDP) has gained promising privacy-preserving capabilities against privacy attacks on local contributions. In this context, noise-discounting LDP methods have been widely investigated to provide better model performance and stronger privacy guarantees. However, prior art calibrate privacy guarantees by distinct LDP definitions, resulting in nonuniform privacy-preserving capabilities. In this article, aligned with the standard LDP definition, we proposed QP-LDP, a noise-discounting algorithm for FL, which can yield better model performance without any privacy loss. Specifically, QP-LDP precisely disturbs noncommon components of quantized local contributions, which are selected by an extended multiparty private set intersection process. In particular, QP-LDP can comprehensively protect two types of local contributions, i.e., local models and gradients for prevailing FedAvg and FedSGD, respectively. Through theoretical analysis, QP-LDP provides component-level indistinguishability for clients’ private local contributions and rigorous convergence guarantees for the global model. Extensive experiments on four widespread databases show that, compared to the standard LDP method, the global model prediction accuracy and convergence rate achieved by QP-LDP can be improved by up to 14.99% and 23.08%, respectively. More importantly, QP-LDP achieves the same level of privacy-preserving capabilities against privacy attacks as the standard LDP method. Qian Chen 0032, Zilong Wang 0001, Haonan Yan, Xiaodong Lin 0001, Jianying Zhou 0001 |
IEEE Internet Things J. | 5 |
| 2024 | The Achilles' Heel of License Plate Recognition Parking Enforcement: Balancing Privacy Protection and EnforcementabstractParking enforcement is crucial for addressing illegal parking in urban areas. In smart cities, the license plate recognition (LPR) systems have been adopted to enhance parking enforcement by enabling automated monitoring and detection of parking violations. However, the extensive information collection raises public privacy concerns about how the data are processed and stored on a central server. To address the privacy issue during parking enforcement and enable flexible data access control with the user consent, we propose a novel privacy-preserving and access-control-enhanced parking enforcement scheme, where the central server cannot obtain the license plate information of vehicles that follow the parking rules and can provide encrypted evidence for detected violations in case of disputes. Specifically, by utilizing the keyed-hash message authentication code, parking enforcement vehicles can generate a parking record based on the location and the license plate number of a vehicle, which is then used to identify whether there is a parking violation for the vehicle. Moreover, by integrating the designed time-based conditional proxy re-encryption scheme, the distributed key generation technique, and the blockchain technology, a central server can provide encrypted and tamper-proof evidence for violations. The evidence can only be decrypted by the corresponding vehicle owners (VOs), and the owners can grant the decryption permission to a judge when there is a dispute. The security analysis demonstrates that our scheme can achieve the privacy preservation of VOs and consent-based data access control. Simulation results show the efficiency and practicability of the proposed scheme. Rundong Gan, Xiaodong Lin 0001 |
IEEE Internet Things J. | 3 |
| 2024 | CODER: Protecting Privacy in Image Retrieval With Differential PrivacyabstractImage retrieval techniques can be easily abused to violate personal privacy with images containing individuals' sensitive information. For example, people's identity information can be inferred from their face photos. Therefore, images should be sanitized before being shared or transmitted. However, previous works on image privacy protection suffer from either no provable privacy protection or poor utility with privacy guarantee. In this work, we proposeCODER, a privacy protection mechanism in image retrieval, with provable privacy guarantee as well as improved utility. In particular,CODERachieves metric differential privacy and adopts a newly proposed distortion metric definition which measures the distance more precisely to improve utility. The novel distortion metric can be applied to an arbitrary k-dimensional metric space with stronger image privacy protection. We theoretically analyze the privacy guarantee and rigorous utility bound ofCODER. We also experimentally compare its performance with two state-of-the-art works on two widely used face datasets. The results show thatCODERsignificantly improves the utility of the protected images and demonstrates its superiority in terms of the privacy-utility trade-off over the compared works. Finally, we perform reliability verification on both discriminative and generative models to demonstrate the practicality ofCODER Haonan Yan, Wenjing Zhang 0002, Qian Chen 0032, Bin Wang 0062, Hui Li 0006, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | Automatic Evasion of Machine Learning-Based Network Intrusion Detection SystemsabstractNetwork intrusion detection systems (IDS) are often considered effective to thwart cyber attacks. Currently, state-of-the-art (SOTA) IDSs are mainly based on machine learning (ML) including deep learning (DL) models, which suffer from their own security issues, especially evasion attacks by using adversarial examples. However, previous studies mostly focus on extracted features rather than the traffic sample itself, and/or assume that the adversary knows the information of the target model more or less, which severely restricts attack feasibility in practice. In this paper, we re-investigate this problem in a more realistic label-only black-box scenario and propose a practical evasion attack strategy to solve the above limitations. In this newly considered case that the adversary morphs the traffic sample and only obtains the results accepted or rejected without other knowledge, we successfully leverage the model extraction and transfer attack to evade the detection. The entire attack strategy is automated and a comprehensive evaluation is performed. Final results show that the proposed strategy effectively evades seven typical ML-based IDSs and one SOTA DL-based IDS with an average success rate of over$75\%$. We also discuss the corresponding countermeasures against our attack, which finally highlight the need for effective defenses against our attack. Haonan Yan, Wenjing Zhang 0002, Hui Li 0006, Xingwen Zhao, Fenghua Li 0001, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2024 | PrivGrid: Privacy-Preserving Individual Load Forecasting Service for Smart GridabstractSmart meter-based individual load forecasts are more and more widely deployed to serve smart grid and home energy management. Customary load forecasting systems collect a massive amount of fine-grained electrical data from people’s smart meters in plaintext, inevitably raising privacy concerns and even anti-smart-meter initiatives. Current privacy solutions either compromise accuracy and efficacy or require the redeployment of trusted infrastructure. In this paper, we present PrivGrid, the first systematic solution for smart grids that collects, clusters, trains, and forecasts customers’ load data in a privacy-preserving way. Moreover, we highlight the technical contribution of our building block: a novel and fast arithmetic multiplication triple via secure inner product protocol outperforms the existing methods and may be included in other privacy computing modules. Then, we develop efficient secure protocols to enable the arithmetic operations of individual load forecasting in a server-aided model and utilize the best alternatives to nonlinear functions. Besides, aggregating all of our individual forecasts can produce a more accurate estimate of the system-level load than the typical aggregate technique. We rigorously prove that the servers cannot obtain the user’s historical load data and short-term load forecast values while providing services. PrivGrid is also tested on real residential smart meter data to show its efficiency, and the relevant code has been made available to the community for further research. Jing Lei 0007, Le Wang 0010, Qingqi Pei, Wenhai Sun, Xiaodong Lin 0001, Xuefeng Liu 0002 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Decentralized Threshold Signatures With Dynamically Private AccountabilityabstractThreshold signature is a fundamental cryptographic primitive used in many practical applications. As proposed by Boneh and Komlo (CRYPTO’22), TAPS is a threshold signature that is a hybrid of privacy and accountability. It enables a combiner to combine$t$signature shares while revealing nothing about the threshold$t$or signing quorum to the public and asks a tracer to track a signature to the quorum that generates it. However, TAPS has three disadvantages: it 1) structures upon a centralized model, 2) assumes that both combiner and tracer are honest, and 3) leaves the tracing unnotarized and static. In this work, we introduce Decentralized, Threshold, dynamically Accountable and Private Signature (DeTAPS) that provides decentralized combining and tracing, enhanced privacy against untrusted combiners (tracers), and notarized and dynamic tracing. Specifically, we adopt Dynamic Threshold Public-Key Encryption (DTPKE) to dynamically notarize the tracing process, design non-interactive zero knowledge proofs to achieve public verifiability of notaries, and utilize the Key-Aggregate Searchable Encryption to bridge TAPS and DTPKE so as to awaken the notaries securely and efficiently. In addition, we formalize the definitions and security requirements for DeTAPS. Then we present a concrete construction and formally prove its security and privacy. To evaluate the performance, we build a prototype based on SGX2 and Ethereum. Meng Li 0006, Hanni Ding, Qing Wang 0060, Weizhi Meng 0001, Liehuang Zhu, Zijian Zhang 0001, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2024 | Exposing Stealthy Wash Trading on Automated Market Maker ExchangesabstractDecentralized Finance (DeFi), a pivotal component of the emerging Web3 landscape, is gaining popularity but remains vulnerable to market manipulations, such as wash trading. Wash trading is an illegal practice, where traders buy and sell assets to themselves within cryptocurrency exchanges to artificially inflate trading volumes and distort market perceptions. However, current research primarily focuses on traditional exchanges based on the Order-book mechanism (similar to stock markets), while ignoring the Automated Market Maker (AMM) exchanges, which dominate over 75% of the market and represent a significant innovation within the DeFi. This study utilizes entity recognition technology to detect wash trading on AMM exchanges within Ethereum-like systems, based on the understanding that colluding addresses (perceived as the same entity) must use ETH for transaction fees and exhibit direct or indirect ETH transfer links. We identify wash trading when addresses with transfer connections almost simultaneously buy and sell assets while their total asset holdings remain nearly constant. This comprehensive blockchain network analysis, compared to focusing solely on transactions within exchanges, unveils covert wash trading activities. Our detection method achieves a 95.9% recall and a 96.7% true negative rate in identifying pools affected by wash trading, demonstrating its superiority over existing methods. Furthermore, we apply our method to 98,945 pools from Uniswap V2 & V3 (the most popular AMM exchanges on Ethereum) and identify 1,070,626 abnormal transactions, totaling $27.51 billion in trading volume. Analysis of these transactions uncovers insights into wash traders’ behaviors, including the utilization of multiple addresses and the dual roles of certain addresses as wash traders and liquidity providers. These insights are crucial for developing more effective strategies to combat fraudulent activities in the DeFi ecosystem and enhance financial scrutiny. Rundong Gan, Le Wang 0010, Xiaodong Lin 0001 |
ACM Trans. Internet Techn. | 4 |
| 2024 | Confidential Distributed Ledgers for Online Syndicated LendingabstractOnline syndicated lending offers quick and convenient financing support to individuals, while diversifying risks by pooling funds from multiple lenders into loan projects. It has experienced explosive growth, reaching a multibillion-dollar market. Establishing transparency is essential for constructing a trusted, fair, and regulation-compliant financial collaboration model. Meanwhile, confidentiality must be maintained to protect the sensitive financial information of individual lenders. Multi-party computation (MPC) can protect the input privacy of lenders, but it cannot safeguard the sensitive information revealed by the fund flow itself. To address these challenges, we propose a new collaborative financial ledger for online syndicated lending. It leverages homomorphic encryption/commitment to enable the reuse of intermediary states without compromising privacy throughout the entire lifecycle of a loan. This system also supports efficient regulation-compliant auditing. We streamline the framework design to optimize performance and develop a prototype system. Even with a large syndicate of 100 lenders, the system still achieves low-latency performance. Xuefeng Liu 0002, Le Wang 0010, Wenhai Sun, Qingqi Pei, Xiaodong Lin 0001, Huizhong Li |
IEEE Trans. Serv. Comput. | 6 |
| 2023 | Class Attention Transfer Based Knowledge DistillationabstractPrevious knowledge distillation methods have shown their impressive performance on model compression tasks, however, it is hard to explain how the knowledge they transferred helps to improve the performance of the student network. In this work, we focus on proposing a knowledge distillation method that has both high interpretability and competitive performance. We first revisit the structure of mainstream CNN models and reveal that possessing the capacity of identifying class discriminative regions of input is critical for CNN to perform classification. Furthermore, we demonstrate that this capacity can be obtained and enhanced by transferring class activation maps. Based on our findings, we propose class attention transfer based knowledge distillation (CAT-KD). Different from previous KD methods, we explore and present several properties of the knowledge transferred by our method, which not only improve the interpretability of CAT-KD but also contribute to a better understanding of CNN. While having high interpretability, CAT-KD achieves state-of-the-art performance on multiple benchmarks. Code is available at: https://github.com/GzyAftermath/CAT-KD. Ziyao Guo, Haonan Yan, Hui Li 0006, Xiaodong Lin 0001 |
CVPR | 4 |
| 2023 | RECESS Vaccine for Federated Learning: Proactive Defense Against Model Poisoning AttacksabstractModel poisoning attacks greatly jeopardize the application of federated learning (FL). The effectiveness of existing defenses is susceptible to the latest model poisoning attacks, leading to a decrease in prediction accuracy. Besides, these defenses are intractable to distinguish benign outliers from malicious gradients, which further compromises the model generalization. In this work, we propose a novel defense including detection and aggregation, named RECESS, to serve as a “vaccine” for FL against model poisoning attacks. Different from the passive analysis in previous defenses, RECESS proactively queries each participating client with a delicately constructed aggregation gradient, accompanied by the detection of malicious clients according to their responses with higher accuracy. Further, RECESS adopts a newly proposed trust scoring based mechanism to robustly aggregate gradients. Rather than previous methods of scoring in each iteration, RECESS takes into account the correlation of clients’ performance over multiple iterations to estimate the trust score, bringing in a significant increase in detection fault tolerance. Finally, we extensively evaluate RECESS on typical model architectures and four datasets under various settings including white/black-box, cross-silo/device FL, etc. Experimental results show the superiority of RECESS in terms of reducing accuracy loss caused by the latest model poisoning attacks over five classic and two state-of-the-art defenses. Haonan Yan, Wenjing Zhang 0002, Qian Chen 0032, Wenhai Sun, Hui Li 0006, Xiaodong Lin 0001 |
NeurIPS | 7 |
| 2023 | Write Blocker for Internet of Things Flash TechnologiesabstractWrite Blockers are an important tool preserving digital evidence integrity and protecting the data chain of custody during a digital forensics investigation, which is crucial to the admissibility and reliability of evidence in court. One area in which write blocking tools are lacking is the Internet of Things (IoT) space. There are unique challenges to the IoT storage technologies and write-blocking them, mainly the lack of standardization in the IoT space. To address it, in this paper, we propose the design of novel write blocking tools for IoT flash technologies. We first develop a set of requirements inspired by the existing requirements for hard drive write blockers as defined by the National Institute of Standards and Technology (NIST). Afterwards, we implement a Serial Peripheral Interace (SPI) flash write blocker in both hardware and software. Furthermore, a demonstration is presented to show effectiveness of the proposed write blocking systems, and the future work is proposed. Matthew Roffel, Xiaodong Lin 0001 |
PST | 2 |
| 2023 | SIDS: A federated learning approach for intrusion detection in IoT using Social Internet of Things
Mohammad Amiri-Zarandi, Rozita Dara 0001, Xiaodong Lin 0001 |
Comput. Networks | 3 |
| 2023 | PPT: A privacy-preserving global model training protocol for federated learning in P2P networks
Qian Chen 0032, Zilong Wang 0001, Wenjing Zhang 0002, Xiaodong Lin 0001 |
Comput. Secur. | 4 |
| 2023 | Blockchains for Artificial Intelligence of Things: A Comprehensive SurveyabstractWith the rapid advances in information and communication technologies, the Internet of Things (IoT) has become large and complex, bearing tremendous amounts of data and running devices in various scenarios. Leveraging artificial intelligence (AI) technologies, IoT can achieve superior information extraction, data analytics, and decision making, which has resulted in the revolutionized AI of Things (AIoT). AIoT can alleviate the pressure of storage, computation, and communication. Despite the promising features brought by combining AI technologies into IoT infrastructure, AIoT systems still face some serious challenges including inadequate efficiency, violation of security and privacy, lack of trust, and insufficient incentive. Blockchain featured by its distributed consensus and incentive mechanisms can be a promising technology for addressing the challenges in AIoT. AIoT employing blockchain is evolving with expectations of achieving efficient, secure, and trusted network activities. In this article, we first introduce the background of AIoT and blockchain. Then, we discuss the motivations for employing blockchain with its characteristics in AIoT. Furthermore, we comprehensively review existing solutions on blockchain for AIoT systems from the aspects of efficiency, security, privacy, trust, and incentive. Finally, we discuss the challenges and future research directions on blockchain for AIoT. Meng Shen 0001, Aijing Gu, Jiawen Kang 0001, Xiangyun Tang, Xiaodong Lin 0001, Liehuang Zhu, Dusit Niyato |
IEEE Internet Things J. | 5 |
| 2023 | Blockchain-Based Fair and Fine-Grained Data Trading With Privacy PreservationabstractIn this article, we propose a blockchain-based fair and privacy-preserving data trading scheme that supports fine-grained data selling. First, to achieve fairness for trading participants, by incorporating attribute-based credentials, encryption, and zero-knowledge proof, we design a data trading scheme where a buyer first publishes the required data attributes on the blockchain, and a data seller can demonstrate data availability in ciphertext by only disclosing the required attributes to a data buyer and proving the authenticity of data. A data buyer transfers funds only if the correct key material is uploaded to the blockchain. Second, to guarantee fine-grained data trading and preserve identity privacy, we build a Merkle hash tree on the ciphertexts of data with a signature on its root node, which allows a data seller to split data into blocks and remove the sensitive information from the data without affecting data availability verification. The public key of the data seller is not leaked to the data buyer during the trading. Moreover, different trading transactions from the same data seller cannot be linked. We formally prove that our scheme achieves the desired security properties: fairness and privacy preservation. Simulation results demonstrate the feasibility and efficiency of the proposed scheme. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Computers | 4 |
| 2023 | Enabling Regulatory Compliance and Enforcement in Decentralized Anonymous PaymentabstractDecentralized anonymous payment (DAP) enables users to directly transfer cryptocurrencies privately without passing through a central authority. Anonymous cryptocurrencies have been proposed to improve the privacy degree of DAP systems, such as Zerocash and Monero. However, the strong degree of privacy may cause new regulatory concerns, i.e., the anonymity of transactions can be used for illegal activities, such as money laundering. In this paper, we propose a novel DAP scheme that supports regulatory compliance and enforcement. We first introduce regulators into the system, who define regulatory policies for anonymous payment, and the policies are enforced through commitments and non-interactive zero-knowledge proofs for compostable statements. By doing so, users can prove that transactions are valid and comply with regulations. A tracing mechanism is embedded in the scheme to allow regulators to recover the real identities of users when suspicious transactions are detected. The formal security model and proof are provided to demonstrate that the proposed scheme can achieve desired security properties, and the performance evaluation shows its high efficiency. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | FedDual: Pair-Wise Gossip Helps Federated Learning in Large Decentralized NetworksabstractThere is a significant recent interest in collaboratively training a machine learning (ML) model without collecting data to a central server. Federated learning (FL) emerges as an efficient solution mitigating systemic privacy risks and communication costs. However, conventional FL inherited from parameter server designs relies too much on a central server, which may lead to privacy risks, communication bottlenecks, or a single point of failure. In this paper, we propose an asynchronous and hierarchical local gradient aggregation and global model update algorithm, FedDual, under three different security considerations for FL in large decentralized networks. Particularly, FedDual preserves privacy by introducing local differential privacy (LDP) and aggregates local gradients asynchronously and hierarchically via a pair-wise gossip algorithm, which is more competitive than previous gossip-based decentralized FL methods in terms of privacy preservation and communication efficiency, and offers more computational efficiency compared to existing blockchain-assisted decentralized FL methods. Further, we devise a noise cutting trick based on Private Set Intersection (PSI) to mitigate the prediction performance loss of the global model caused by the leveraged LDP. Rigorous analyses show that FedDual helps decentralized FL achieve the same convergence rate of$\mathcal {O}\left({\frac {1}{T}}\right) $as centralized ML theoretically. Ingenious experiments on MNIST, CIFAR-10, and FEMNIST confirm that the model prediction performance gained from FedDual is close to centralized ML. More importantly, the proposed noise cutting trick helps FedDual to train better global models than LDP-based FL methods in terms of prediction performance and convergence rate. Qian Chen 0032, Zilong Wang 0001, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Dual-Anonymous Off-Line Electronic Cash for Mobile PaymentabstractMobile devices have become near-ubiquitous tools in our daily lives. Following this trend, mobile commence is developed rapidly which in turns stimulates interests in mobile payment. Some prominent examples include Google’s Wallet, WeChat Pay, and Apple Pay. Most of these technologies, however, are designed for users to be able to pay conveniently to the business. In other words, they are designed with the business to user model in mind. Besides, an active network connection with an external payment server is required either from payer or payee during transaction. Our work intends to supplement existing solutions, which allows payment to be made in an off-line and dual-anonymous manner. In doing so, a dual-anonymous off-line electronic cash scheme is proposed by utilizing BBS+ signature. The feature of our scheme is dual-anonymous payment, which means that both the payer and the payee in any transaction cannot be identified even all other users and the payment server collude. Through security proof and performance analysis, we also demonstrate that the security of the proposed scheme can be reduced to standard assumptions and it is suitable for applications in mobile commerce. Jianbing Ni, Man Ho Au, Wei Wu 0001, Xiapu Luo, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | TokenAware: Accurate and Efficient Bookkeeping Recognition for Token Smart ContractsabstractTokens have become an essential part of blockchain ecosystem, so recognizing token transfer behaviors is crucial for applications depending on blockchain. Unfortunately, existing solutions cannot recognize token transfer behaviors accurately and efficiently because of their incomplete patterns and inefficient designs. This work proposes TokenAware , a novel online system for recognizing token transfer behaviors. To improve accuracy, TokenAware infers token transfer behaviors from modifications of internal bookkeeping of a token smart contract for recording the information of token holders (e.g., their addresses and shares). However, recognizing bookkeeping is challenging, because smart contract bytecode does not contain type information. TokenAware overcomes the challenge by first learning the instruction sequences for locating basic types and then deriving the instruction sequences for locating sophisticated types that are composed of basic types. To improve efficiency, TokenAware introduces four optimizations. We conduct extensive experiments to evaluate TokenAware with real blockchain data. Results show that TokenAware can automatically identify new types of bookkeeping and recognize 107,202 tokens with 98.7% precision. TokenAware with optimizations merely incurs 4% overhead, which is 1/345 of the overhead led by the counterpart with no optimization. Moreover, we develop an application based on TokenAware to demonstrate how it facilitates malicious behavior detection. Zheyuan He, Shuwei Song, Yang Bai 0011, Xiapu Luo, Ting Chen 0002, Hongwei Li 0001, Xiaodong Lin 0001, Xiaosong Zhang 0001 |
ACM Trans. Softw. Eng. Methodol. | 9 |
| 2023 | Dap-FL: Federated Learning Flourishes by Adaptive Tuning and Secure AggregationabstractFederated learning (FL), an attractive and promising distributed machine learning paradigm, has sparked extensive interest in exploiting tremendous data stored on ubiquitous mobile devices. However, conventional FL suffers severely from resource heterogeneity, as clients with weak computational and communication capabilities may be unable to complete local training using the same local training hyper-parameters. In this article, we propose Dap-FL, a deep deterministic policy gradient (DDPG)-assisted adaptive FL system, in which local learning rates and local training epochs are adaptively adjusted by all resource-heterogeneous clients through locally deployed DDPG-assisted adaptive hyper-parameter selection schemes. Particularly, the rationality of the proposed hyper-parameter selection scheme is confirmed through rigorous mathematical proof. Besides, due to the thoughtlessness of security consideration of adaptive FL systems in previous studies, we introduce the Paillier cryptosystem to aggregate local models in a secure and privacy-preserving manner. Rigorous analyses show that the proposed Dap-FL system could protect clients’ private local models against chosen-plaintext attacks and chosen-message attacks in a widely used honest-but-curious participants and active adversaries security model. More importantly, through ingenious and extensive experiments, the proposed Dap-FL achieves higher model prediction accuracy than two state-of-the-art RL-assisted FL methods, i.e., 6.03% higher than DDPG-based FL and 7.85% higher than DQN-based FL. In addition, experimental results also show that the proposed Dap-FL achieves higher global model prediction accuracy and faster convergence rates than conventional FL, and the comprehensiveness of the adjusted local training hyper-parameters is validated. Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Haonan Yan, Xiaodong Lin 0001 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2022 | Understanding Flash-Loan-based Wash TradingabstractFlash Loan, a popular lending service in the decentralized finance (DeFi) ecosystem, allows users to borrow a large number of virtual assets without any collateral. It can be leveraged to support many financial activities (such as arbitrage, collateral swap, self-liquidation, etc.), but unfortunately, it is often abused for malicious intent. One example of abusing flash loan servicing is to simultaneously sell and buy the same crypto currency on the same exchange to mislead the market, aka wash trading. It can manipulate the crypto currency market at a very low cost (anecdotally average around 0.033 ETH gas fee for each transaction on Ethereum mainnet), thereby dramatically damaging the stability and fairness of the market. More seriously, attackers can amplify the market impact by borrowing more assets from Flash Loan platforms. Until now, there has been little attention paid to Flash-Loan-based wash trading, but meanwhile, we have started to witness significant wash trading activities using Flash Loan. In this research, we analyze the properties of Flash-Loan-based wash trading in detail and propose a heuristic-based detection method. The real-world Flash Loan transaction data from Ethereum is used to verify our proposed detection method and more than 6,000 wash transactions were found. Moreover, we analyze the relationship between wash transactions and fluctuations in the price and volume of targeted assets. Finally, we evaluate the cost difference between traditional wash trading and Flash-Loan-based wash trading to reveal the attackers' motivation. Rundong Gan, Le Wang 0010, Xiangyu Ruan, Xiaodong Lin 0001 |
AFT | 4 |
| 2022 | A Heterogeneous Feature Ensemble Learning based Deepfake Detection MethodabstractThe Deepfake technique can swap the face of a person with the face of another person in an image or a video which may cause a public security problem. Recently, researchers have focused on detecting deepfake images by deep learning. However some recent works have observed that detectors trained on images produced by one deepfake model perform poorly when tested on others. In this paper we propose to detect deepfake images through heterogeneous feature ensemble learning. We first extract gray gradient features, spectrum features and texture features from real and fake face images, then integrate them into an ensemble feature vector through a flatten process, and finally adopt a back-propagation neural network to train a deepfake detector with the feature vector. Experimental results show that our approach achieves better detection accuracy compared with several state-of-the-art deepfake detectors. Jixin Zhang, Giuliano Sovernigo, Xiaodong Lin 0001 |
ICC | 4 |
| 2022 | Blockchain-based Health Data Sharing for Continuous Disease Surveillance in Smart EnvironmentsabstractThe Covid-19 pandemic ushered in multiple paradigms of personal health data sharing with particular emphasis on Person-to-Institution sharing and Institution-toInstitution sharing. While the data aggregated by technology companies and health authorities was instrumental in the development of vaccines and ultimately flattening the curve of infection rates, egregious abuses of privacy occurred. In many instances acceptable guarantees of appropriate utility for the data were not made available. Personal health data sharing for the containment of infections with privacy limitations present a classic case of collaboration among mutually distrustful entities. In this regard the blockchain network and attendant protocols for data integrity, transaction transmission and provenance can prove useful. Thus, in this paper we present a blockchain-based method for disease surveillance in a smart environment where smart contracts are deployed to monitor public locations instead of individuals. The data aggregated is analysed and tagged with a lifetime commensurate with the time for infection. Once the data utility period has elapsed the monitored data are removed from the active surveillance pool and the entities involved can be notified. Such a method of continual surveillance protects privacy by shifting the emphasis from individuals to locations. Experimental data suggests this method is efficient and can be implemented on top of existing disease surveillance strategies for later pandemics. Sandro Amofa, Xiaodong Lin 0001, Qi Xia 0001, Hu Xia, Jianbin Gao |
ICPADS | 2 |
| 2022 | ARCANE: An Efficient Architecture for Exact Machine UnlearningabstractRecently users’ right-to-be-forgotten is stipulated by many laws and regulations. However, only removing the data from the dataset is not enough, as machine learning models would memorize the training data once the data is involved in model training, increasing the risk of exposing users’ privacy. To solve this problem, currently, the straightforward method, naive retraining, is to discard these data and retrain the model from scratch, which is reliable but brings much computational and time overhead. In this paper, we propose an exact unlearning architecture called ARCANE. Based on ensemble learning, we transform the naive retraining into multiple one-class classification tasks to reduce retraining cost while ensuring model performance, especially in the case of a large number of unlearning requests not considered by previous works. Then we further introduce data preprocessing methods to reduce the retraining overhead and speed up the unlearning, which includes representative data selection for redundancy removal, training state saving to reuse previous calculation results, and sorting to cope with unlearning requests of different distributions. We extensively evaluate ARCANE on three typical datasets with three common model architectures. Experiment results show the effectiveness and superiority of ARCANE over both the naive retraining and the state-of-the-art method in terms of model performance and unlearning speed. Haonan Yan, Ziyao Guo, Hui Li 0006, Fenghua Li 0001, Xiaodong Lin 0001 |
IJCAI | 6 |
| 2022 | CFL: Cluster Federated Learning in Large-Scale Peer-to-Peer Networks
Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Dan Xiao, Xiaodong Lin 0001 |
ISC | 6 |
| 2022 | QP-LDP for better global model performance in federated learningabstractWith the deployment of local differential privacy (LDP), federated learning (FL) has gained stronger privacy-preserving capability against inference-type attacks. However, existing LDP methods reduce global model performance. In this paper, we propose a QP-LDP algorithm for FL to obtain a better-performed global model without losing privacy guarantees defined by the original LDP. Different from previous LDP methods for FL, QP-LDP improves the global model performance by precisely disturbing the non-common components of quantized local contributions. In addition, QP-LDP comprehensively protects two types of local contributions. Through security analysis, QP-LDP provides the probability indistinguishability of clients' private local contributions at a component-level. More importantly, ingenious experiments show that with the deployment of QP-LDP, the global model outperforms that in the original LDP-based FL in terms of prediction accuracy and convergence rate. Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Haonan Yan, Xiaodong Lin 0001 |
MSN | 6 |
| 2022 | LLDP: A Layer-wise Local Differential Privacy in Federated LearningabstractFederated learning (FL) combined with local differential privacy (LDP) has attracted considerable attention due to its privacy-preserving capability against inference-type attacks, e.g., model inversion attacks and membership inference attacks. However, the noise introduced by LDP reduces the global model performance, while decreasing the noise by setting a larger privacy budget sacrifices the privacy guarantees. In this paper, we propose a layer-wise LDP for the FL system, dubbed LLDP, which disturbs various layers of a local model according to clients’ self-assigned privacy budgets. With the deployment of LLDP, clients could train a highly accurate and rapid-converged global model without loosing privacy guarantees. Through extensive security analyses, the proposed LLDP scheme helps the entire local model achieve (ε,δ)-LDP, and the probability indistinguishability of the local model is achieved under the widespread semi-honest threat model. Ingenious experiments show that LLDP improves the global model prediction and convergence rate by 3.38% and 4.76% on the CIFAR-10 dataset compared to the state-of-the-art LDP method with the same privacy budget. In addition, given the same training target (loss value), LLDP requires a 26.67% lower privacy budget, providing stronger privacy guarantees against model inversion attacks. Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Haonan Yan, Xiaodong Lin 0001 |
TrustCom | 6 |
| 2022 | Everything you control is not everything: Achieving intention-concealed visit on social networks
Helin Li, Hui Zhu 0001, Xiaodong Lin 0001, Rongxing Lu |
Comput. Secur. | 3 |
| 2022 | Toward Vehicular Digital Forensics From Decentralized Trust: An Accountable, Privacy-Preserving, and Secure RealizationabstractWith the increasing number of traffic accidents and terrorist attacks by modern vehicles, vehicular digital forensics (VDF) has gained significant attention in identifying evidence from the related digital devices. Ensuring the law enforcement agency to accurately integrate various kinds of data is a crucial point to determine the facts. However, malicious attackers or semi-honest participants may undermine the digital forensic procedures. Enabling accountability and privacy preservation while providing secure data access control in VDF is a nontrivial challenge. To mitigate this issue, in this article, we propose a blockchain-based decentralized solution for VDF named BB-VDF, in which the accountable protocols and privacy-preserving algorithm are constructed. The desirable security properties and fine-grained data access control are achieved based on smart contract and the customized cryptographic construction. Specifically, we design a distributed key-policy attribute-based encryption scheme with partially hidden access structures, named DKP-ABE-H, to realize the secure fine-grained forensics data access control. Further, a novel smart contract is designed to model the forensics procedures as a finite state machine, which guarantees accountability that each participant performs auditable cooperation under tamper resistant and traceable transactions. Systematic security analysis and extensive experimental results show the feasibility and practicability of our proposed BB-VDF scheme. Ming Li 0049, Jian Weng 0001, Jia-Nan Liu, Xiaodong Lin 0001, Charlie Obimbo |
IEEE Internet Things J. | 4 |
| 2022 | Privacy-Preserving Keyword Similarity Search Over Encrypted Spatial Data in Cloud ComputingabstractWith the proliferation of cloud computing, data owners can outsource the spatial data from the Internet of Things devices to a cloud server to enjoy the pay-as-you-go storage resources and location-based services. However, the outsourced services may raise privacy concerns, since the cloud server may not be fully trusted for both data owners and search users. If the data owners and search users conventionally encrypt the spatial data and query requests, the efficiency and functionality of query processing are weakened. Most of the existing works only focus on spatial data search or keyword search and do not consider spatial keyword search over encrypted data. In this article, we first design a geometric range query (GRQ) scheme, which can generate an arbitrary geometric range to fit the search user’s desired spatial data while protecting location privacy. Furthermore, based on GRQ, we propose a multidimensional spatial keyword similarity search scheme with access control (MSSAC) by integrating the polynomial function and matrix transformation. Specifically, an access control strategy is defined by a role-based polynomial function, which is embedded in the vectors of indices and trapdoors to achieve efficient and lightweight access control. Moreover, MSSAC enables the cloud server to execute compute-then-compare operations for spatial keyword search in a privacy-preserving manner by leveraging techniques of randomizable permutation and matrix multiplication. The formal security analyses and extensive experiments demonstrate that GRQ and MSSAC preserve the privacy of data owners and search users while achieving efficient spatial keyword search. Fuyuan Song, Zheng Qin 0001, Jixin Zhang, Xiaodong Lin 0001, Xuemin Shen |
IEEE Internet Things J. | 5 |
| 2022 | DLP: Achieve Customizable Location Privacy With Deceptive Dummy Techniques in LBS ApplicationsabstractAs a straightforward consequence of advances in the Internet of Things (IoT), location-based service (LBS) applications have been pervasive in our daily lives. Nevertheless, since those LBS applications will continuously collect and disclose users’ location data, major concerns on privacy leakage are raised. Aiming at the challenge, in this article, we first build up a detect module (DM) and employ it to investigate more than 80% of LBS applications are keen on tracking users. Then, to thwart the threats from those LBS applications, we exploit the deceptive dummy techniques and design a dummy-based location privacy preserving scheme, named dummy location provider (DLP), which comprises three algorithms, namely, Spread, Shift, and Switch. Specifically, Spread and Shift are in charge of generating deceptive dummies and trajectories. And with Switch, users’ real locations are replaced with dummy trajectories before being submitted to LBS applications. As a result, users can not only prevent applications from accessing location data arbitrarily, but also avoid being questioned by applications in terms of honesty. Furthermore, to guarantee necessary functions of LBS, DLP offers customizable privacy-preserving strategies for users, which can achieve flexible location data usage control. Finally, our DLP can also attain achievable and effortless deployment over smart devices. Detailed security analysis indicates that DLP resists inference attacks even facing skeptical applications. In addition, for performance evaluation, a DLP application (DLPA) is developed on the Android platform and tested in the real environment, and the extensive experimental results demonstrate that the DLPA is indeed effective and high efficiency in practice. Jiezhen Tang, Hui Zhu 0001, Rongxing Lu, Xiaodong Lin 0001, Hui Li 0006, Fengwei Wang |
IEEE Internet Things J. | 4 |
| 2022 | Characterizing Heterogeneous Internet of Things Devices at Internet Scale Using Semantic ExtractionabstractAlong with the rapid-growth number of Internet of Things (IoT) devices, significant security concerns are raised due to the hidden vulnerabilities among them. Illuminating the characteristics of online devices would shed a light on protecting these potential vulnerable devices. State-of-arts methodologies enumerate devices characteristics as keywords and rules and match them with IoT network data. However, the heterogeneous implementations of IoT devices introduce intricate characteristics features, which impede the large-scale identification. In this work, we close this gap and present a semantic extraction-based approach that can automatically and effectively characterize online devices. We leverage the observation that IoT devices can be identified by analyzing the semantic information of the network packets. Specifically, we first collect the network data of IoT devices and utilize a co-training algorithm to annotate the data. We propose a residual dilate gated convolutional neural network (RDGCNN)-based encoder to extract semantic features from the annotated data. Then, we put forward an entity relationship-based decoder to generate the characteristic triplet (type, brand, and model) of IoT devices by decoding extracted features. We have implemented the prototype of the system and conducted real-world experiments to evaluate the performance. Results show that our approach achieves 92.16% precision and 86.79% recall. In addition, we apply our proposed method to characterize 15 millions IoT devices on the Internet. Kai Yang 0037, Xiaodong Lin 0001, Zhi Li 0018, Limin Sun 0001 |
IEEE Internet Things J. | 3 |
| 2022 | Blockchain-Cloud Transparent Data Marketing: Consortium Management and FairnessabstractData are generated by Internet of Things (IoT) devices and centralized at a cloud server, that can later be traded with third parties, i.e., data marketing, to enable various data-intensive applications. However, the centralized approach is recently under debate due to the lack of (1) transparent and distributed marketplace management, and (2) marketing fairness for both IoT users (data sellers) and third parties (data buyers). In this paper, we propose a Blockchain-Cloud Transparent Data Marketing (Block-DM) with consortium management and executable fairness. First, we introduce a hybrid data-marketing architecture, where the cloud acts as an efficient data management unit and a consortium blockchain serves as a transparent marketing controller. Under the architecture, consent-based secure data trading and identity privacy for data owners are achieved with the distributed credential issuance and threshold credential openings. Second, with a consortium committee, we design a fair on/off-chain data marketing protocol. By financial incentives and succinct ‘commitments’ of marketing operations, the protocol can achieve the marketing fairness and effective detection of unfair marketing operations. We demonstrate the security of Block-DM with thorough analysis. We conduct extensive experiments with a consortium blockchain network on Hyperledger Fabric to show the feasibility and practicality of Block-DM. Cheng Huang 0001, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Computers | 4 |
| 2022 | DNA Similarity Search With Access Control Over Encrypted Cloud DataabstractDNA similarity search has been widely applied in human genomic studies including DNA marking, genomic sequencing and genetic disease prediction. Meanwhile, with the explosive growth of data, users are increasingly inclining to store DNA data on the cloud for saving local cost. However, the high sensitivity of DNA data has forced the government to strictly control its acquisition and utilization. One potential solution is to encrypt DNA data before outsourcing them to the cloud. Nevertheless, private DNA similarity query has been an active research issue, state-of-the-art results are still defective in security, functionality, and efficiency. In this article, we propose EFSS, an efficient and fine-grained similarity search scheme over encrypted DNA data. In specific, first, we design an approximation algorithm to efficiently calculate the edit distances between two sequences. Second, we put forward a novel Boolean search strategy to achieve complicated logic queries such as mixed “AND” and “NO” operations on genes. Third, data access control is also supported in our EFSS through a variant of polynomial based design. Moreover, the K-means clustering algorithm is exploited to further improve the efficiency of execution. In the end, security analysis and extensive experiments demonstrate the high performance of EFSS compared with existing schemes. Guowen Xu, Hongwei Li 0001, Hao Ren 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Cloud Comput. | 4 |
| 2022 | Heterogeneous Computation and Resource Allocation for Wireless Powered Federated Edge Learning SystemsabstractFederated learning (FL) is a popular edge learning approach that utilizes local data and computing resources of network edge devices to train machine learning (ML) models while preserving users’ privacy. Nevertheless, performing efficient learning tasks on the devices and achieving longer battery life are primary challenges faced by federated learning. In this paper, we are the first to study the application of heterogeneous computing (HC) and wireless power transfer (WPT) to federated learning to address these challenges. Especially, we propose a heterogeneous computation and resource allocation framework based on a heterogeneous mobile architecture to achieve effective implementation of FL. To minimize the energy consumption of smart devices and maximize their harvesting energy simultaneously, we formulate an optimization problem featuring multidimensional control, which jointly considers time splitting for WPT, dataset size allocation, transmit power allocation and subcarrier assignment during communications, and processor frequency of processing units (central processing unit (CPU) and graphics processing unit (GPU)). However, the major obstacle is how to design a proper algorithm to solve this optimization problem efficiently. For this purpose, we decouple the optimization variables so as to achieve high efficiency in deriving its solution. Particularly, we first compute the optimal processor frequency and dataset size allocation via employing the Lagrangian dual method, followed by finding the closed-form solution to the optimal time splitting allocation, and finally attain the optimal subcarrier assignment as well as transmit power for transmissions through an iteration algorithm. To evaluate the performance of our proposed scheme, we set up four baseline schemes as comparison, and simulation results show that the proposed scheme converges quite fast and better enhance the energy efficiency of the wireless powered FL system compared with the baseline schemes. Jie Feng 0004, Wenjing Zhang 0002, Qingqi Pei, Jinsong Wu 0001, Xiaodong Lin 0001 |
IEEE Trans. Commun. | 5 |
| 2022 | ShadowPLCs: A Novel Scheme for Remote Detection of Industrial Process Control AttacksabstractIndustrial Control System (ICS) security has become increasingly important as attacks targeting ICSs are more prominent. Although many off-the-shelf industrial network intrusion detection mechanisms have been presented in the past, attackers have always found unique disguisable ways to bypass detections and disrupt actual industrial control processes. To mitigate this deficiency, we present a novel scheme for the detection of industrial process control attacks, calledShadowPLCs. Specifically, the scheme first automatically analyzes the PLC control code, then extracts key parameters of the PLCs including valid register addresses, valid range of values, and control logic rules as a basis for evaluating attacks. The attack behavior is detected in real-time from different perspectives through active communication with PLCs and passive monitoring of the network traffic. We implemented a prototype system with Siemens S7-300 series PLCs as a case study. Our scheme was evaluated using two Siemens S7-300 PLCs deployed on a gas pipeline network platform. Experiments demonstrate that the presented scheme can accurately detect process control attacks in real-time without affecting the normal operations of PLCs. Compared with the other four representative detection models, our scheme has better detection performance with detection accuracy of 97.3 percent. Junjiao Liu, Xiaodong Lin 0001, Xin Chen 0123, Hui Wen 0001, Hong Li 0004, Zhiqiang Shi, Limin Sun 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Enabling Efficient, Secure and Privacy-Preserving Mobile Cloud StorageabstractMobile cloud storage (MCS) provides clients with convenient cloud storage service. In this article, we propose an efficient, secure and privacy-preserving mobile cloud storage scheme, which protects the data confidentiality and privacy simultaneously, especially the access pattern. Specifically, we propose an oblivious selection and update (OSU) protocol as the underlying primitive of the proposed mobile cloud storage scheme. OSU is based on onion additively homomorphic encryption with constant encryption layers and enables the client to obliviously retrieve an encrypted data item from the cloud and update it with a fresh value by generating a small encrypted vector, which significantly reduces the client’s computation as well as the communication overheads. Compared with previous works, our presented work has valuable properties, such as fine-grained data structure (small item size), lightweight client-side computation (a few of additively homomorphic operations) and constant communication overhead, which make it more suitable for MCS scenario. Moreover, by employing the “verification chunks” method, our scheme can be verifiable to resist malicious cloud. The comparison and evaluation indicate that our scheme is more efficient than existing oblivious storage solutions with the aspects of client and cloud workloads, respectively. Jia-Nan Liu, Xizhao Luo, Jian Weng 0001, Anjia Yang, Xu An Wang 0014, Ming Li 0049, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2022 | Privacy-Preserving Aggregate Mobility Data Release: An Information-Theoretic Deep Reinforcement Learning ApproachabstractIt is crucial to protect users’ location traces against inference attacks on aggregate mobility data collected from multiple users in various real-world applications. Most of the existing works on aggregate mobility data are focusing on inference attacks rather than designing privacy-preserving release mechanisms, and a few differential private release mechanisms suffer from poor utility-privacy tradeoffs. In this paper, we propose optimal centralized privacy-preserving aggregate mobility data release mechanisms (PAMDRMs) that minimize the leakage from an information-theoretic perspective by releasing perturbed versions of the raw aggregate location. Specifically, we use mutual information to measure user-level and aggregate-level privacy leakage separately, and formulate leakage minimization problems under utility constraints. As directly solving the optimization problems incur exponential complexity w.r.t. users’ trace length, we transform them into belief state Markov Decision Processes (MDPs), with a focus on the MDP formulation for the user-level privacy problem. We build reinforcement learning (RL) models and leverage the efficient Asynchronous Advantage Actor-Critic RL algorithm to derive the solutions to the MDPs as our optimal PAMDRMs. We compare them with two state-of-the-art privacy protection mechanisms PDPR (context-aware local design) and DMLM (context-free centralized design) in terms of mutual information leakage and adversary’s attack success (evaluated by her expected estimation error and Jensen-Shannon Divergence-based error). Extensive experimental results on both synthetic and real-world datasets demonstrate that the user-level PAMDRM performs the best on both measures thanks to its context-aware property and centralized design. Even though the aggregate-level PAMDRM achieves better privacy-utility tradeoff than the other two, it does not always perform better than them on adversarial success, highlighting the necessity of considering privacy measures from different perspectives to avoid overestimating the level of privacy offered to users. Lastly, we discuss an alternative, fully data-driven approach to derive the optimal PAMDRM by leveraging adversarial training on limited data samples. Wenjing Zhang 0002, Bo Jiang 0015, Ming Li 0003, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Understanding and Detecting Mobile Ad Fraud Through the Lens of Invalid TrafficabstractAlong with gaining popularity of Real-Time Bidding (RTB) based programmatic advertising, the click farm based invalid traffic, which leverages massive real smartphones to carry out large-scale ad fraud campaigns, is becoming one of the major threats against online advertisement. In this study, we take an initial step towards the detection and large-scale measurement of the click farm based invalid traffic. Our study begins with a measurement on the device's features using a real-world labeled dataset, which reveals a series of features distinguishing the fraudulent devices from the benign ones. Based on these features, we develop EvilHunter, a system for detecting fraudulent devices through ad bid request logs with a focus on clustering fraudulent devices. EvilHunter functions by 1) building a classifier to distinguish fraudulent and benign devices; 2) clustering devices based on app usage patterns; and 3) relabeling devices in clusters through majority voting. EvilHunter demonstrates 97% precision and 95% recall on a real-world labeled dataset. By investigating a super click farm, we reveal several cheating strategies that are commonly adopted by fraudulent clusters. We further reduce the overhead of EvilHunter and discuss how to deploy the optimized EvilHunter in a real-world system. We are in partnership with a leading ad verification company to integrate EvilHunter into their industrial platform. Suibin Sun, Le Yu 0002, Xiaokuan Zhang, Minhui Xue 0001, Ren Zhou, Haojin Zhu, Shuang Hao 0001, Xiaodong Lin 0001 |
CCS | 8 |
| 2021 | An Efficient and Privacy-Preserving Multi-User Multi-Keyword Search Scheme without Key SharingabstractMulti-keyword search, aiming to search the objects by a query request that consists of multiple keywords, has wide applications in personalized recommendation services. Mean-while, the fast development of cloud technology has given rise to a new trend that data are encrypted before being outsourced to a public cloud for users to enjoy pay-as-you-go services. However, most of the existing works primarily focus on the single keyword search, and consider a general scenario with a single owner and a single user. In this paper, we propose an efficient and Privacy-preserving Multi-user Multi-keyword Search (PMMS) scheme, which can support user scalability without key sharing. In particular, based on the matrix decomposition, a key derivation approach is integrated into our PMMS to generate secret keys and re-encryption keys. Furthermore, by employing threshold predicate encryption and leveraging the techniques of matrix transformation and proxy re-encryption, PMMS guarantees that only the comparison result of an inner product of two vectors and a pre-defined threshold is revealed, and enables the cloud server to perform multi-keyword search in an efficient and privacy-preserving manner. Security analysis shows that the confidentiality of owners’ data and users’ queries can be guaranteed. Extensive experiments on a real-world dataset demonstrate that PMMS is efficient in terms of multi-keyword search. Fuyuan Song, Zheng Qin 0001, Jinwen Liang, Xiaodong Lin 0001 |
ICC | 4 |
| 2021 | Voxstructor: Voice Reconstruction from Voiceprint
Panpan Lu, Qi Li 0033, Hui Zhu 0001, Giuliano Sovernigo, Xiaodong Lin 0001 |
ISC | 5 |
| 2021 | Traceable and Privacy-Preserving Non-Interactive Data Sharing in Mobile CrowdsensingabstractData sharing is one of the key technologies, which provides the practice of making data collected from a crowd of mobile devices available to others using a cloud infrastructure, known as mobile crowdsensing (MCS). However, the collected data may contain sensitive information, and sharing them in public clouds without proper protection could cause serious security problems, such as privacy leakage, unauthorized access, and secret key abuse. To address the above issues, in this paper, we propose a Traceable and privacy-preserving non-Interactive Data Sharing (TIDS) scheme in mobile crowdsensing. Specifically, to achieve privacy-preserving fine-grained data sharing, an attribute-based access policy is generated by a data owner without interacting with data users in the TIDS. Furthermore, we design a ciphertext conversion mechanism to support flexible data sharing. Also, by utilizing traceable Ciphertext-Policy Attribute-Based Encryption (CP-ABE), TIDS supports a trusted authority to trace malicious users who abuse their secret keys without incurring additional computational overhead. Security analysis demonstrates that TIDS can protect the confidentiality of the outsourced data. Experimental results show that TIDS can achieve efficient data sharing in mobile crowdsensing applications. Fuyuan Song, Zheng Qin 0001, Jinwen Liang, Pulei Xiong, Xiaodong Lin 0001 |
PST | 5 |
| 2021 | CShield: Enabling code privacy for Cyber-Physical systems
Kai Yang 0037, Xiaodong Lin 0001, Limin Sun 0001 |
Future Gener. Comput. Syst. | 2 |
| 2021 | A Multikernel and Metaheuristic Feature Selection Approach for IoT Malware Threat Hunting in the Edge LayerabstractInternet-of-Things (IoT) devices are increasingly targeted, partly due to their presence in a broad range of applications (including home and corporate environments). In this article, we propose a multikernel support vector machine (SVM) for IoT cloud-edge gateway malware hunting, using the gray wolves optimization (GWO) technique. This metaheuristic approach is used for optimum selection of features distinguishing between malicious and benign applications at the IoT cloud-edge gateway. The model is trained with the Opcode and Bytecode of IoT malware samples (i.e., the training data set comprises 271 benign and 281 malicious Cortex A9 samples) and evaluated using the K-fold cross-validation technique. We validate the robustness of the proposed model, in terms of its ability to detect previously unseen IoT malware samples. We achieve an accuracy of 99.72% on the combination of the radial basis function (RBF) and polynomial kernels. Moreover, our proposed model only requires 20 s for training in comparison to the previous deep neural network (DNN) model that requires over 80 s to be trained on the same data. Overall, the proposed multikernel SVM approach outperforms DNNs and fuzzy-based IoT malware hunting techniques, in terms of accuracy, while significantly reducing the computational cost and the training time. Hamed Haddad Pajouh, Alireza Mohtadi, Ali Dehghantanha, Hadis Karimipour, Xiaodong Lin 0001, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 5 |
| 2021 | Efficient and Privacy-Preserving Speaker Recognition for Cybertwin-Driven 6GabstractWith the introduction of cybertwin, a new approach to represent human or things in the cyberspace, it is foreseeable that vehicles will be able to offer more and more services in the future. Naturally, considering the safety of drivers, speaker recognition will be widely used in vehicle scenarios. Speaker recognition technologies are experiencing increasing popularity due to the unique and indissoluble link between individuals and their voices. However, the coming cybertwin-driven 6G brings speaker recognition technologies unprecedented challenges, especially in preventing the disclosure of voiceprint. To address these challenges, an efficient and privacy-preserving speaker recognition scheme for cybertwin-driven 6G, referred to as NEATEN, is proposed in this article. With NEATEN, the speaker identity can be recognized at multiple security levels without leaking the voiceprint data. More concretely, based on the random projection data perturbation, voiceprint perturbation algorithms in two phases and the corresponding ciphertext-based similarity computation algorithm are proposed. By using these algorithms, our efficient and accurate speaker recognition scheme can be achieved. Orthogonal to the previous works of biometric identification based on the Euclidean distance, NEATEN makes progress on the non-Euclidean distance, such as cosine distance and complicated distance. Detailed analysis shows that NEATEN can resist various known security threats. Experiments conducted on TIMIT and Voxceleb data sets have demonstrated that NEATEN is highly accurate and efficient, and can be flexibly deployed in a real cybertwin-driven 6G vehicle environment. Qi Li 0033, Xiaodong Lin 0001 |
IEEE Internet Things J. | 2 |
| 2021 | Efficient and Privacy-Preserving Decision Tree Classification for Health Monitoring SystemsabstractDue to the increasing healthcare costs and the advance of wireless technology, health monitoring systems have been widely adopted recently. In health monitoring systems, a hospital outsources a clinical decision model to a cloud service provider, which receives biomedical data from remote clients and produces clinical decisions based on the outsourced model. Due to critical privacy concerns, both the clinical decision model and biomedical data should be protected. In this article, we propose an efficient and privacy-preserving decision tree (PPDT) classification scheme for health monitoring systems. Specifically, we first transform a decision tree classifier (i.e., the clinical decision model) into the Boolean vectors. Then, we leverage symmetric key encryption to encrypt the Boolean vectors as encrypted indices. The PPDT classification is achieved by searching the encrypted indices with encrypted tokens. We formulate a leakage function and provide the security definition and simulation-based proof for PPDT. The performance analyses demonstrate that PPDT is very efficient in terms of computation, communication, and storage. Experimental evaluations show that PPDT only requires microsecond-level execution time, kilobyte-level communication costs, and kilobyte-level storage costs on the test data set. Jinwen Liang, Zheng Qin 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Internet Things J. | 4 |
| 2021 | Verifiable and Secure SVM Classification for Cloud-Based Health Monitoring ServicesabstractIn cloud-based health monitoring services, support vector machine (SVM) classification techniques are often utilized by medical institutes to build medical decision models, which can be outsourced to a cloud server for producing medical decisions based on medical features from remote clients. In this article, we propose a verifiable and secure SVM classification scheme ($\mathsf {VSSVMC}$) for cloud-based health monitoring services in a malicious setting, where the cloud server may return invalid decisions. By constructing verifiable indices,$\mathsf {VSSVMC}$ensures the verifiability of medical decisions, which enables clients to detect whether the cloud server returns incorrect or incomplete medical decisions. Symmetric key encryption is leveraged to ensure the confidentiality of the medical decision model and medical data with computational efficiency. We give security and verifiability definitions and provide formal security and verifiability proofs for$\mathsf {VSSVMC}$. Performance analyses show that$\mathsf {VSSVMC}$is extremely efficient in terms of computation, communication, and storage. Experimental evaluations demonstrate that$\mathsf {VSSVMC}$achieves microsecond-level execution time with kilobyte-level communication and storage overheads on the tested data set. Jinwen Liang, Zheng Qin 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Internet Things J. | 4 |
| 2021 | Application-Oriented Block Generation for Consortium Blockchain-Based IoT Systems With Dynamic Device ManagementabstractDue to its salient features, such as immutability and auditability, blockchain is becoming more integrated into the Internet of Things (IoT) for enhancing security and developing a decentralized IoT framework. However, different IoT applications require different transaction processing performance, which brings challenges to the convergence of blockchains in IoT. Moreover, the membership of a distributed IoT system may fluctuate when an IoT device joins or leaves the system. The dynamic nature of IoT systems also introduces new challenges for device management. Accordingly, we propose an application-oriented block generation (AOBG) scheme for blockchain-enabled IoT with dynamic device management and conditional traceability. Specifically, we first construct a framework for a consortium blockchain-based IoT system, including structures for application-oriented transactions and blocks, and consensus mechanism. We present different miners, respectively, for processing urgent and ordinary transactions adaptively with applications. Then, an AOBG protocol is proposed for this framework based on group signature. The group signature is used to achieve anonymity, traceability, and nonframeability. Combining time-bound keys in group signature with node accounts in blockchain, the proposed scheme can realize efficient transaction verification, dynamic device management, conditional traceability with data security, and privacy preservation. Extensive experiments demonstrate high efficiency of the proposed scheme. Aiqing Zhang, Peiyun Zhang, Huaqun Wang, Xiaodong Lin 0001 |
IEEE Internet Things J. | 4 |
| 2021 | Practical and Secure SVM Classification for Cloud-Based Remote Clinical Decision ServicesabstractSupport vector machine (SVM) classification techniques have been widely adopted for building clinical decision models. In cloud-based remote clinical decision services, a healthcare center outsources the clinical decision model to a cloud server, which then provides remote clinical decision services to end users. In this article, we propose a practical and secure SVM classification scheme (${\sf SSVMC}$) for cloud-based remote clinical decision services. Specifically, we first extract SVM decision rules from an SVM classifier. Then, we leverage symmetric key encryption to protect the confidentiality of medical data and prevent the cloud service provider from misusing intellectual property of the outsourced clinical model. Finally, we build encrypted indexes to achieve efficient SVM classification. We define a leakage function, formulate a security definition, and provide a simulation-based security proof for${\sf SSVMC}$. The performance analysis demonstrates that${\sf SSVMC}$achieves linear computational complexity when an SVM classifier (a.k.a., the clinical decision model) is pre-trained. The simulations evaluate the impact of several parameters on time costs. The experimental evaluations show the performance differences between${\sf SSVMC}$and several existing schemes in terms of time costs, storage costs, communication costs, and precisions in a real-world clinical dataset, which demonstrate that${\sf SSVMC}$is computationally efficient with high decision accuracy. Jinwen Liang, Zheng Qin 0001, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Computers | 4 |
| 2021 | Blockchain-Based Public Integrity Verification for Cloud Storage against Procrastinating AuditorsabstractThe deployment of cloud storage services has significant benefits in managing data for users. However, it also causes many security concerns, and one of them is data integrity. Public verification techniques can enable a user to employ a third-party auditor to verify the data integrity on behalf of her/him, whereas existing public verification schemes are vulnerable toprocrastinating auditorswho may not perform verifications on time. Furthermore, most of public verification schemes are constructed on the public key infrastructure (PKI), and thereby suffer from certificate management problem. In this paper, we propose acertificatelesspublicverification scheme againstprocrastinatingauditors (CPVPA) by usingblockchain technology. The key idea is to require auditors to record each verification result into a transaction on a blockchain. Because transactions on the blockchain are time-sensitive, the verification can be time-stamped after the transaction is recorded into the blockchain, which enables users to check whether auditors perform the verifications at the prescribed time. Moreover, CPVPA is built on certificateless cryptography, and is free from the certificate management problem. We present rigorous security proofs to demonstrate the security of CPVPA, and conduct a comprehensive performance evaluation to show that CPVPA is efficient. Yuan Zhang 0006, Chunxiang Xu, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Cloud Comput. | 3 |
| 2021 | Efficient and Secure Decision Tree Classification for Cloud-Assisted Online Diagnosis ServicesabstractDecision tree classification has become a prevailing technique for online diagnosis services. By outsourcing computation intensive tasks to a cloud server, cloud-assisted online diagnosis services are better ways for cases that the storage and computation requirements exceed the capability of medical institutions. With privacy concerns as well as intellectual property protection issues, the valuable diagnosis classifier and the sensitive user data should be protected against the cloud server. In this paper, we identify a work-flow for cloud-assisted online diagnosis services. We propose an efficient and secure decision tree classification scheme in the proposed work-flow. Specifically, the medical institution transforms a locally pre-trained decision tree classifier to a decision table, and later uses searchable symmetric encryption to encrypt the decision table. Then, the encrypted table is outsourced to the cloud server, and a user can submit encrypted physiological features to the cloud server and obtain an encrypted diagnosis prediction back. We provide formal security proofs to demonstrate that our scheme protects the confidentiality of the decision tree classifier and the user's data. The performance analysis shows that our scheme achieves faster-than-linear classification speed. Experimental evaluations show that our scheme requires several micro-seconds to process a diagnosis request in the tested datasets. Jinwen Liang, Zheng Qin 0001, Sheng Xiao, Lu Ou, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Privacy-Preserving Traffic Monitoring with False Report Filtering via Fog-Assisted Vehicular CrowdsensingabstractTraffic monitoring system empowers cloud server and drivers to collect real-time driving information and acquire traffic conditions. However, drivers are more interested in local traffic, and sending driving reports to a faraway cloud server wastes a lot of bandwidth and incurs a long response delay. Recently, fog computing is introduced to provide location-sensitive and latency-aware local data management in vehicular crowdsensing, but it incurs new privacy concerns since drivers’ information could be disclosed. Although these messages are encrypted before transmission, malicious drivers can upload false reports to sabotage the systems, and filtering out false encrypted reports remains a challenging issue. To address the problems, we define a new security model and propose a privacy preserving traffic monitoring scheme. Specifically, we utilize short group signature to authenticate drivers in a conditionally anonymous way, adopt a range query technique to acquire driving information in a privacy-preserving way, and integrate it to the construction of a weighted proximity graph at each fog node through a WiFi challenge handshake to filter out false reports. Moreover, we use variant Bloom filters to achieve fast traffic conditions storage and retrieval. Finally, we prove security and privacy, evaluate performance with real-world cloud servers. Meng Li 0006, Liehuang Zhu, Xiaodong Lin 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2020 | Ring Selection for Ring Signature-Based Privacy Protection in VANETsabstractMany cryptography techniques have been used to protect the privacy of vehicular ad hoc networks(VANETs). For example, the ring signature, one of the anonymous techniques by virtue of its unconditional anonymity, is widely used in VANETs for privacy protection. However, some of their cryptographic properties may have been weakened due to the characteristic of VANETs. In this paper, we study the impact of the influences of ring selection on the anonymity property of ring signature when applied to privacy protection in VANETs. Specifically, we introduce a novel ring selection attack aimed to compromise the anonymity of vehicles in VANETs. We then propose a ring selection algorithm based on the analysis of the ring selection attack. Furthermore, by taking the information entropy as the privacy metric, we develop a privacy analytic model to quantitatively investigate the privacy level achieved in the solution. Finally, the analytical results indicate that better privacy protection can be achieved when selecting ring members according to our ring selection algorithm. Xiaodong Lin 0001, Lijun Qu, Chunguang Ma |
ICC | 2 |
| 2020 | Consent-based Privacy-preserving Decision Tree EvaluationabstractDecision trees are prevalent machine learning models used for data classification. Cloud servers can build their decision tree models and provide users with many classification services, such as remote medical diagnosis. Moreover, users would also like to share the classification results with third-party applications for customized services. For example, the medical diagnosis results can be further utilized by a nutrition application to provide users with dietary recommendations. However, as stringent privacy regulations of personal data, such as GDPR, takes effect, the decision tree evaluation must comply with the following requirements. First, the model parameters and user data (input and output) should be protected from public disclosure. Second, different applications should obtain the classification results with users' consent in the context of user-customised services. In this paper, we propose a consent-based privacy-preserving decision tree evaluation scheme, named CPDE. Specifically, to achieve model parameter privacy and user data privacy, the original decision tree evaluation is conducted in a private manner in CPDE. As a result, all operations can be performed in the encrypted domain using an additively homomorphic encryption primitive and a secure comparison protocol. In addition, by integrating a proxy re-encryption technique, CDPE enables user-authorized applications to obtain the user's classification results even if the user is offline. The security analysis shows that CPDE achieves the desirable security properties and performance evaluation demonstrates CPDE is efficient and is suitable for real-world implementations. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
ICC | 4 |
| 2020 | A Deep Learning Framework Supporting Model Ownership Protection and Traitor TracingabstractCloud-based deep learning (DL) solutions have been widely used in applications ranging from image recognition to speech recognition. Meanwhile, as commercial software and services, such solutions have raised the need for intellectual property rights protection of the underlying DL models. Watermarking is the mainstream of existing solutions to address this concern, by primarily embedding pre-defined secrets in a model's training process. However, existing efforts almost exclusively focus on detecting whether a target model is pirated, without considering traitor tracing. In this paper, we present SecureMark_DL, which enables a model owner to embed a unique fingerprint for every customer within parameters of a DL model, extract and verify the fingerprint from a pirated model, and hence trace the rogue customer who illegally distributed his model for profits. We demonstrate that SecureMark_DL is robust against various attacks including fingerprints collusion and network transformation (e.g., model compression and model fine-tuning). Extensive experiments conducted on MNIST and CIFAR10 datasets, as well as various types of deep neural network show the superiority of SecureMark_DL in terms of training accuracy and robustness against various types of attacks. Guowen Xu, Hongwei Li 0001, Yuan Zhang 0006, Xiaodong Lin 0001, Robert H. Deng, Xuemin Shen |
ICPADS | 4 |
| 2020 | SODA: A Generic Online Detection Framework for Smart Contracts
Ting Chen 0002, Rong Cao, Xiapu Luo, Guofei Gu, Yufei Zhang 0002, Zhou Liao, Zheyuan He, Yuxing Tang, Xiaodong Lin 0001, Xiaosong Zhang 0001 |
NDSS | 12 |
| 2020 | Secure and Efficient Distributed Network Provenance for IoT: A Blockchain-Based ApproachabstractNetwork provenance is essential for Internet-of-Things (IoT) network administrators to conduct the network diagnostics and identify root causes of network errors. However, the distributed nature of the IoT network results in the management of the provenance data at different trust domains, which poses concerns on the security and trustworthiness of the cross-domain network diagnostics. In this article, we propose a blockchain-based architecture for secure and efficient distributed network provenance (SEDNP) in the IoT. Instead of directly storing and querying the whole provenance data on the blockchain with prohibitive implementation cost, we introduce a unified provenance query model and develop a provenance digest strategy that: 1) enables compact (constant size) on-blockchain digests of provenance data and a multilevel index regardless of provenance data volume and 2) ensures the correctness and integrity of provenance query results through the verification of the on-blockchain digests. We formally define the security requirements as Archiving Security along with thorough security analysis. Moreover, we conduct extensive experiments with the integration of a verifiable computation (VC) framework and a blockchain testing network. The experimental results are provided as performance benchmarks to demonstrate the application feasibility of SEDNP. Jianbing Ni, Cheng Huang 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Internet Things J. | 4 |
| 2020 | iFinger: Intrusion Detection in Industrial Control Systems via Register-Based FingerprintingabstractNowadays, the industrial control system (ICS) plays a vital role in critical infrastructures like the power grid. However, there is an increasing security concern that ICS devices are being vulnerable to malicious users/attackers, where any subtle changing or tampering attack would cause significant damage to industrial manufacturing. In this paper, we propose the iFinger, a novel detection approach designed to mitigate ICS attacks adapting to various industrial scenes. We take advantage of an important insight that industrial protocol packets include register status values that are used to reflect the physical characteristics of ICS controllers. The iFinger utilizes register states to generate ICS fingerprints to detect malicious attacks on industrial networks. Specifically, the boolean logic represents every register state sequence of the ICS controller, and the deterministic finite automaton (DFA) generates a device fingerprint. To discover the ICS attacks, we propose two detection approaches based on device fingerprints, including passive and active detection. We present a prototype of the iFinger and conduct real-world experiments to validate its performance. Results show that our approach achieves 97.1% F1 score in ICS device identification. Furthermore, we simulate two typical ICS attacks (replacement and code modification) to validate the effectiveness of our iFinger in industrial networks. Our device fingerprints would detect those malicious attacks within 2s latency at 98.0% recall. Kai Yang 0037, Qiang Li 0007, Xiaodong Lin 0001, Xin Chen 0123, Limin Sun 0001 |
IEEE J. Sel. Areas Commun. | 3 |
| 2020 | The Security of Autonomous Driving: Threats, Defenses, and Future DirectionsabstractAutonomous vehicles (AVs) have promised to drastically improve the convenience of driving by releasing the burden of drivers and reducing traffic accidents with more precise control. With the fast development of artificial intelligence and significant advancements of the Internet of Things technologies, we have witnessed the steady progress of autonomous driving over the recent years. As promising as it is, the march of autonomous driving technologies also faces new challenges, among which security is the top concern. In this article, we give a systematic study on the security threats surrounding autonomous driving, from the angles of perception, navigation, and control. In addition to the in-depth overview of these threats, we also summarize the corresponding defense strategies. Furthermore, we discuss future research directions about the new security threats, especially those related to deep-learning-based self-driving vehicles. By providing the security guidelines at this early stage, we aim to promote new techniques and designs related to AVs from both academia and industry and boost the development of secure autonomous driving. Kui Ren 0001, Qian Wang 0002, Cong Wang 0001, Zhan Qin, Xiaodong Lin 0001 |
Proc. IEEE | 5 |
| 2020 | MARP: A Distributed MAC Layer Attack Resistant Pseudonym Scheme for VANETabstractModern vehicles are equipped with wireless communication technologies, allowing them to communicate with each other and forming large self-organized ad hoc networks (or vehicular ad hoc networks (VANETs)). VANETs, while promising new approaches for improving road safety, require privacy of vehicles (or drivers) to be protected from a variety of threats. Although pseudonym schemes have provided a promising solution at the upper layers, privacy attacks could still be carried out from medium access control (MAC) layer. In this paper, we first introduce a new MAC layer context linking attack, which could link the old and new pseudonyms of a vehicle by analyzing its transmission characteristics. To deal with the attack, we propose a time division multiple access based MAC-layer-Attack-Resistant Pseudonym (MARP) scheme. Unlike traditional approaches that design the MAC protocols and pseudonym schemes separately, MARP allows vehicles to change their transmission slots and pseudonyms collaboratively. Thus, the unlinkability is guaranteed. Taking the pseudonym age, anonymity set size and time-to-confusion as the location privacy metrics, we derive an analytical model to quantify location privacy achieved in MARP. The analytical model is general to be applied for other pseudonym schemes. Extensive simulation results have validated the analytical model, showed that MARP can resist the MAC context linking attack and guarantee location privacy and efficient transmission for vehicles in VANETs. Zishan Liu, Zhenyu Liu 0002, Lin Zhang 0013, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | Providing Task Allocation and Secure Deduplication for Mobile Crowdsensing via Fog ComputingabstractMobile crowdsensing enables a crowd of individuals to cooperatively collect data for special interest customers using their mobile devices. The success of mobile crowdsensing largely depends on the participating mobile users. The broader participation, the more sensing data are collected; nevertheless, the more replicate data may be generated, thereby bringing unnecessary heavy communication overhead. Hence it is critical to eliminate duplicate data to improve communication efficiency, a.k.a., data deduplication. Unfortunately, sensing data is usually protected, making its deduplication challenging. In this paper, we propose a fog-assisted mobile crowdsensing framework, enabling fog nodes to allocate tasks based on user mobility for improving the accuracy of task assignment. Further, a fog-assisted secure data deduplication scheme (Fo-SDD) is introduced to improve communication efficiency while guaranteeing data confidentiality. Specifically, a BLS-oblivious pseudo-random function is designed to enable fog nodes to detect and remove replicate data in sensing reports without exposing the content of reports. To protect the privacy of mobile users, we further extend the Fo-SDD to hide users' identities during data collection. In doing so, Chameleon hash function is leveraged to achieve contribution claim and reward retrieval for anonymous mobile users. Finally, we demonstrate that both schemes achieve secure, efficient data deduplication. Jianbing Ni, Kuan Zhang 0001, Yong Yu 0002, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | VerifyNet: Secure and Verifiable Federated LearningabstractAs an emerging training model with neural networks, federated learning has received widespread attention due to its ability to update parameters without collecting users' raw data. However, since adversaries can track and derive participants' privacy from the shared gradients, federated learning is still exposed to various security and privacy threats. In this paper, we consider two major issues in the training process over deep neural networks (DNNs): 1) how to protect user's privacy (i.e., local gradients) in the training process and 2) how to verify the integrity (or correctness) of the aggregated results returned from the server. To solve the above problems, several approaches focusing on secure or privacy-preserving federated learning have been proposed and applied in diverse scenarios. However, it is still an open problem enabling clients to verify whether the cloud server is operating correctly, while guaranteeing user's privacy in the training process. In this paper, we propose VerifyNet, the first privacy-preserving and verifiable federated learning framework. In specific, we first propose a double-masking protocol to guarantee the confidentiality of users' local gradients during the federated learning. Then, the cloud server is required to provide the Proof about the correctness of its aggregated results to each user. We claim that it is impossible that an adversary can deceive users by forging Proof, unless it can solve the NP-hard problem adopted in our model. In addition, VerifyNet is also supportive of users dropping out during the training process. The extensive experiments conducted on real-world data also demonstrate the practical performance of our proposed scheme. Guowen Xu, Hongwei Li 0001, Sen Liu 0007, Kan Yang 0001, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | Balancing Privacy and Accountability for Industrial Mortgage ManagementabstractIndustrial mortgage enables companies to acquire loan for business venture or investment purposes by pledging their industrial assets to financial institutions. To prevent double-mortgage fraud of borrowers, information exchange among different financial institutions is necessary. On the other hand, it results in the privacy leakage of borrowers. In this article, we construct a blockchain-based accountable and privacy-preserving industrial mortgage scheme (BAPIM). BAPIM enables financial institutions to share the mortgage data of borrowers in an efficient and secure manner, that achieves the borrower identity privacy and accountability at the same time. Specifically, borrower identity is concealed on the blockchain by anonymous identity credential, while financial institutions can still uncover the identity of a misbehaving borrower if he pledges the same asset for multiple mortgages. We demonstrate that BAPIM achieves the desirable security properties and has high computational efficiency, so as to be suitable for the industrial mortgage management. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Ind. Informatics | 4 |
| 2020 | Enabling Strong Privacy Preservation and Accurate Task Allocation for Mobile CrowdsensingabstractMobile crowdsensing engages a crowd of individuals to use their mobile devices to cooperatively collect data about social events and phenomena for customers with common interest. It can reduce the cost on sensor deployment and improve data quality with human intelligence. To enhance data trustworthiness, it is critical for the service provider to recruit mobile users based on their personal features, e.g., mobility pattern and reputation, but it leads to the privacy leakage of mobile users. Therefore, how to resolve the contradiction between user privacy and task allocation is challenging in mobile crowdsensing. In this paper, we propose SPOON, a strong privacy-preserving mobile crowdsensing scheme supporting accurate task allocation based on geographic information and credit points of mobile users. In SPOON, the service provider enables to recruit mobile users based on their locations, and select proper sensing reports according to their trust levels without invading user privacy. By utilizing proxy re-encryption and BBS+ signature, sensing tasks are protected and reports are anonymized to prevent privacy leakage. In addition, a privacy-preserving credit management mechanism is introduced to achieve decentralized trust management and secure credit proof for mobile users. Finally, we show the security properties of SPOON and demonstrate its efficiency in terms of computation and communication. Jianbing Ni, Kuan Zhang 0001, Qi Xia 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Mob. Comput. | 4 |
| 2020 | Understanding Ethereum via Graph AnalysisabstractEthereum, a blockchain, supports its own cryptocurrency named Ether and smart contracts. Although more than 8M smart contracts have been deployed on Ethereum, little is known about the characteristics of its users, smart contracts, and the relationships among them. We conduct the first systematic study on Ethereum by leveraging graph analysis to characterize three major activities on Ethereum, namely money transfer, smart contract creation, and smart contract invocation. We collect all transaction data, construct three graphs from the data to characterize major activities via graph analysis, and discover new insights. Moreover, we address three security issues based on graphs. Ting Chen 0002, Zihao Li 0001, Yuxiao Zhu, Jiachi Chen, Xiapu Luo, John C. S. Lui, Xiaodong Lin 0001, Xiaosong Zhang 0001 |
ACM Trans. Internet Techn. | 7 |
| 2019 | Towards Secure and Fair IIoT-Enabled Supply Chain Management via Blockchain-Based Smart ContractsabstractIntegrating the Industrial Internet of Things (IIoT) into supply chain management enables flexible and efficient on-demand exchange of goods between merchants and suppliers. However, realizing a fair and transparent supply chain system remains a very challenging issue due to the lack of mutual trust among the suppliers and merchants. Furthermore, the current system often lacks the ability to transmit trade information to all participants in a timely manner, which is the most important element in supply chain management for the effective supply of goods between suppliers and the merchants. This paper presents a blockchain-based supply chain management system in the IIoT. The proposed system takes advantage of blockchain technology in terms of its transparency and tamper-proof nature to support fair goods exchange between merchants and suppliers. Additionally, the decentralization and pseudonymity property will play a significant role in preserving the privacy of participants in the blockchain. In particular, fairness in the IIoT is first defined. Then, a design for a smart contract for fair goods exchange is presented to prevent malicious behavior through imposing penalties. The proposed system was prototyped on Ethereum and experiments were conducted to demonstrate its feasibility. Amal Alahmadi, Xiaodong Lin 0001 |
ICC | 2 |
| 2019 | Efficient and Privacy-Preserving Outsourced SVM Classification in Public CloudabstractData classification has become an important and prevailing technique for big data analytics. Typically, a data classifier is designed and outsourced to a public cloud. A service provider then can easily provide various services and handle frequent and massive classification requests from users. With privacy concerns as well as Intellectual Property(IP) protection issues, the valuable classifier and the sensitive user data cannot be directly exposed to the public cloud. In this paper, we focus on the Support Vector Machine (SVM), one of the most popular classifiers, and propose an efficient and privacy-preserving outsourcing scheme for SVM classification in public clouds. Specifically, the service provider is allowed to transform the traditional SVM classifier to fixed hyper-rectangles and the order-preserving encryption is utilized to encrypt these hyper-rectangles as the encrypted classifier. Afterwards, the encrypted classifier is outsourced to the public cloud, and a user can submit an encrypted range query to the cloud and obtain the classification results back. Security analysis and extensive experimental evaluation demonstrate that our scheme can protect the confidentiality of classifier and users' data and achieves efficient SVM classification in terms of computational cost. Jinwen Liang, Zheng Qin 0001, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
ICC | 4 |
| 2019 | Towards Private and Efficient Ad Impression Aggregation in Mobile AdvertisingabstractIn the secure mobile advertising, mobile users privately select advertisements of interest for displaying without exposing their preferences to the ad network. However, the strong privacy guarantee has uncovered limitations on gathering aggregated ad impression statistics for the ad network to enforce correct billing on the merchants who run their ad campaigns. Early efforts integrated cryptographic voting mechanism to address this challenge, which introduces additional bandwidth overhead on mobile devices due to the construction of the ballot proof. In this paper, we propose a private and efficient ad impression aggregation scheme in mobile advertising to protect the individual ad impression statistics while preventing the ad-fraud attack. The main idea of the proposed scheme is the design of an efficient cryptographic voting mechanism based on the compact hamming weight proof technique and additive homomorphic encryption. The proposed scheme has better bandwidth efficiency by reducing the ballot proof size from O(logN) to O(1), where N denotes the dimension of the ballot. Security analysis demonstrates the confidentiality of the individual impression statistics and the verifiability of the ballot proof under standard cryptographic assumptions. Experimental results consolidate that the proposed scheme is feasible for real-world implementations on mobile devices. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
ICC | 3 |
| 2019 | Against Pilot Spoofing Attack with Double Channel Training in Massive MIMO NOMA SystemsabstractTo combat the pilot spoofing attack in non-orthogonal multiple access (NOMA) systems, we propose a double channel training scheme in this paper. Specifically, we consider two users in each cluster and both users send the training sequence in the first uplink training phase, while one of them keeps silent in the second phase. By exploiting channel estimation results in the two phases, more accurate legitimate channel estimation can be obtained by removing the contamination from the eavesdropping channel. Thus, the pilot spoofing attack can be mitigated effectively. We then analyze the achievable downlink secrecy rate with matched filter precoding scheme. Simulation results demonstrate that the achievable secrecy rate can be improved dramatically with the proposed scheme even under very strong pilot attack power. Wei Wang 0100, Zhisheng Yin, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
ICC | 4 |
| 2019 | Forward Secure and Fine-grained Data Sharing for Mobile CrowdsensingabstractSecure task-driven data sharing can improve the sensing data usage and protect data confidentiality in mobile crowdsensing (MCS). However, the existing data sharing schemes lack efficient support of forward secrecy, i.e., if the secret key of a data requester is compromised, all the historically shared data will be leaked. In this paper, we propose a forward secure and fine-grained data sharing scheme in mobile crowdsensing to provide a strong security guarantee and flexible access control over the sensing data. Specifically, by incorporating puncturable encryption and attribute based encryption, a shared symmetric key for data sharing can be encrypted by an access structure over the attributes of data requesters and the introduced Bloom filter attributes. Moreover, the shared key establishment between the MCS server and data requesters can be done jointly with the both sides authentication. By utilizing the structure of the Bloom filter, the update of a private key which is used to achieve forward secrecy only needs several deletion operations and no communication with the key distributor is involved. The security proof shows our scheme is provably secure under the security model. Experiment results demonstrate the practicability of the scheme. Jianbing Ni, Cheng Huang 0001, Xiaodong Lin 0001, Xuemin Shen |
PST | 4 |
| 2019 | CoRide: A Privacy-Preserving Collaborative-Ride Hailing Service Using Blockchain-Assisted Vehicular Fog Computing
Meng Li 0006, Liehuang Zhu, Xiaodong Lin 0001 |
SecureComm (2) | 3 |
| 2019 | PTAS: Privacy-preserving Thin-client Authentication Scheme in blockchain-based PKI
Wenbo Jiang 0001, Hongwei Li 0001, Guowen Xu, Mi Wen, Guishan Dong, Xiaodong Lin 0001 |
Future Gener. Comput. Syst. | 6 |
| 2019 | Efficient and Privacy-Preserving Carpooling Using Blockchain-Assisted Vehicular Fog ComputingabstractCarpooling enables passengers to share a vehicle to reduce traveling time, vehicle carbon emissions, and traffic congestion. However, the majority of passengers lean to find local drivers, but querying a remote cloud server leads to an unnecessary communication overhead and an increased response delay. Recently, fog computing is introduced to provide local data processing with low latency, but it also raises new security and privacy concerns because users' private information (e.g., identity and location) could be disclosed when these information are shared during carpooling. While they can be encrypted before transmission, it makes user matching a challenging task and malicious users can upload false locations. Moreover, carpooling records should be kept in a distributed manner to guarantee reliable data auditability. To address these problems, we propose an efficient and privacy-preserving carpooling scheme using blockchain-assisted vehicular fog computing to support conditional privacy, one-to-many matching, destination matching, and data auditability. Specifically, we authenticate users in a conditionally anonymous way. Also, we adopt private proximity test to achieve one-to-many proximity matching and extend it to efficiently establish a secret communication key between a passenger and a driver. We store all location grids into a tree and achieve get-off location matching using a range query technique. A private blockchain is built to store carpooling records. Finally, we analyze the security and privacy properties of the proposed scheme, and evaluate its performance in terms of computational costs and communication overhead. Meng Li 0006, Liehuang Zhu, Xiaodong Lin 0001 |
IEEE Internet Things J. | 3 |
| 2019 | Enabling Efficient and Geometric Range Query With Access Control Over Encrypted Spatial DataabstractAs a basic query function, range query has been exploited in many scenarios such as SQL retrieves, location-based services, and computational geometry. Meanwhile, with explosive growth of data volume, users are increasingly inclining to store data on the cloud for saving local storage and computational cost. However, a long-standing problem is that the user's data may be completely revealed to the cloud server because it has full data access right. To cope with this problem, a frequently-used method is to encrypt raw data before outsourcing them, but the availability and operability of data will be reduced significantly. In this paper, we propose an efficient and geometric range query scheme (EGRQ) supporting searching and data access control over encrypted spatial data. We employ secure KNN computation, polynomial fitting technique, and order-preserving encryption to achieve secure, efficient, and accurate geometric range query over cloud data. Then, we propose a novel spatial data access control strategy to refine user's rights in our EGRQ. To improve the efficiency, R-tree is adopted to reduce the searching space and matching times in whole search process. Finally, we theoretically prove the security of our proposed scheme in terms of confidentiality of spatial data, privacy protection of index and trapdoor, and the unlinkability of trapdoors. In addition, extensive experiments demonstrate the high efficiency of our proposed model compared with existing schemes. Guowen Xu, Hongwei Li 0001, Yuan-Shun Dai, Kan Yang 0001, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2019 | Anonymous Reputation System for IIoT-Enabled Retail Marketing Atop PoS BlockchainabstractIndustrial Internet of Things (IIoT) is revolutionizing the retail industry for manufacturers, suppliers, and retailers to improve operational efficiency and consumer experience. In IIoT-enabled retail marketing, reputation systems play a critical role to boost mutual trust among industrial entities and build consumer confidence. In this paper, we focus on reputation management in the consumer–retailer channel, where retailers can accumulate reputations from consumer feedbacks. To encourage consumers to post feedbacks without worrying about being tracked or retaliated, we propose an anonymous reputation system that preserves consumer identities and individual review confidentialities. To increase system transparency and reliability, we further exploit the tamper-proof nature and the distributed consensus mechanism of the blockchain technology. With system designs based on various cryptographic primitives and a Proof-of-Stake consensus protocol, our blockchain-based reputation system is more efficient to offer high levels of privacy guarantees compared with existing ones. Finally, we explore the implementation challenges of the blockchain-based architecture and present a proof-of-concept prototype system by Parity Ethereum. We measure the on/off -chain performance with the scalability discussion to demonstrate the feasibility of the proposed system. Amal Alahmadi, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Ind. Informatics | 4 |
| 2018 | A Privacy-Preserving Thin-Client Scheme in Blockchain-Based PKIabstractTraditional centralized PKIs are vulnerable due to the single point of failure. A feasible solution is to build a decentralized PKI without certificate authority (CA). Web of Trust is the first step toward realizing a decentralized PKI, but it still has some limitations such as missing incentive and leaking user's privacy. Blockchain's numerous desirable properties, such as cryptographical security, decentralized nature and unalterable transaction record, make it a suitable tool to implement a decentralized PKI. However, the latest research findings about blockchain-based PKI are still incompatible with the thin-clients which have limited storage ability to download the entire blockchain. To combat that, we firstly present a Privacy-preserving Thin-client Scheme (PTS) utilizing the idea of k-anonymity, which enables thin-clients to run normally as full node users and protect user's privacy simultaneously. After that, in order to reduce cost, we further propose an Efficient Privacy preserving Thin-client Scheme (EPTS) employing the method of PIR (private information retrieval). Then security analysis and functional comparison are performed to demonstrate the high security and comprehensive functionality of EPTS compared with existing schemes. Finally, extensive experiments are undertaken to confirm that EPTS can reduce computational cost and communication cost impressively. Wenbo Jiang 0001, Hongwei Li 0001, Guowen Xu, Mi Wen, Guishan Dong, Xiaodong Lin 0001 |
GLOBECOM | 6 |
| 2018 | EFRS: Enabling Efficient and Fine-Grained Range Search on Encrypted Spatial DataabstractRange search of spatial data, has been applied in many scenarios such as geometric queries, location-based services, and computational geometry, etc. Due to the increasing amount of spatial data, which are usually outsourced to the cloud for saving storage and computational overhead. However, a common privacy issue is that the cloud server may steal user's sensitive information utilizing its powerful computing advantages. A feasible way of managing this bottleneck is to encrypt spatial data before outsourcing it. Nevertheless, the availability of data will be significantly reduced because of the query difficulty over the encrypted cloud data. In this paper, we propose an Efficient Range Search scheme (EFRS) which can achieve fine- grained query over encrypted spatial data. We original contributions are threefold. First, polynomial fitting technique and orderpreserving encryption are introduced to realize the efficient and fine- grained range query over encrypted cloud data. Then, in order to improve the search efficiency, we exploit the Rtree to significantly decreased the search space. Finally, we theoretically proved the security of our proposed scheme in terms of confidentially of spatial data, privacy protection of index and trapdoor, and the unlinkability of trapdoor. Besides, extensive experiments demonstrate the high efficiency of our proposed model compared with existing schemes. Guowen Xu, Hongwei Li 0001, Yuan-Shun Dai, Xiaodong Lin 0001 |
ICC | 5 |
| 2018 | Blockchain-Based Secure Data Provenance for Cloud Storage
Yuan Zhang 0006, Xiaodong Lin 0001, Chunxiang Xu |
ICICS | 2 |
| 2018 | Understanding Ethereum via Graph AnalysisabstractBeing the largest blockchain with the capability of running smart contracts, Ethereum has attracted wide attention and its market capitalization has reached 20 billion USD. Ethereum not only supports its cryptocurrency named Ether but also provides a decentralized platform to execute smart contracts in the Ethereum virtual machine. Although Ether's price is approaching 200 USD and nearly 600K smart contracts have been deployed to Ethereum, little is known about the characteristics of its users, smart contracts, and the relationships among them. To fill in the gap, in this paper, we conduct the first systematic study on Ethereum by leveraging graph analysis to characterize three major activities on Ethereum, namely money transfer, smart contract creation, and smart contract invocation. We design a new approach to collect all transaction data, construct three graphs from the data to characterize major activities, and discover new observations and insights from these graphs. Moreover, we propose new approaches based on cross-graph analysis to address two security issues in Ethereum. The evaluation through real cases demonstrates the effectiveness of our new approaches. Ting Chen 0002, Yuxiao Zhu, Zihao Li 0001, Jiachi Chen, Xiaoqi Li 0001, Xiapu Luo, Xiaodong Lin 0001, Xiaosong Zhang 0001 |
INFOCOM | 7 |
| 2018 | Efficient and Privacy-Preserving Ad Conversion for V2X-Assisted Proximity MarketingabstractVehicle-to-Everything (V2X) assisted proximity marketing is one of the most promising V2X services due to its huge potential, and has attracted a lot of research efforts recently. In proximity marketing, roadside merchants rely on third-party ad networks to target their advertisements to nearby vehicles or pedestrians with related interests, and pay ad networks according to some pricing mechanisms, such as cost per-view. It is therefore important for merchants to learn ad conversion rate (how much of their revenue can be attributed to proximity marketing) such that merchants can adjust their advertising strategy. For ad conversion, two-party private set intersection (PSI) technique has been widely adopted, where ad networks and merchants can jointly compute ad conversion rate without leaking sensitive customer information. However, state-of-art literature on PSI either assumes the involved two parties honestly follow the protocol or only tolerates limited adversarial behaviors. In this paper, we first design a novel and efficient PSI scheme that is secure in the presence of malicious adversaries, where two parties can arbitrarily deviate from the scheme. By integrating an efficient input certification mechanism into the designed PSI scheme, we propose a privacy-preserving ad conversion protocol for V2X-assisted proximity marketing, that can achieve input privacy, unlinkability, unforgeability, and output verifiability. Security analysis demonstrates that the proposed ad conversion protocol is secure under cryptographic assumptions. Finally, we show that the proposed ad conversion protocol outperforms the state-of-art approaches when considering both security strength and computation complexity. Jianbing Ni, Hongwei Li 0001, Xiaodong Lin 0001, Xuemin Shen |
MASS | 4 |
| 2018 | Enabling Efficient and Fine-Grained DNA Similarity Search with Access Control over Encrypted Cloud Data
Hongwei Li 0001, Guowen Xu, Qiang Tang 0005, Xiaodong Lin 0001, Xuemin Shen |
WASA | 4 |
| 2018 | Efficient and Secure Service-Oriented Authentication Supporting Network Slicing for 5G-Enabled IoTabstract5G network is considered as a key enabler in meeting continuously increasing demands for the future Internet of Things (IoT) services, including high data rate, numerous devices connection, and low service latency. To satisfy these demands, network slicing and fog computing have been envisioned as the promising solutions in service-oriented 5G architecture. However, security paradigms enabling authentication and confidentiality of 5G communications for IoT services remain elusive, but indispensable. In this paper, we propose an efficient and secure service-oriented authentication framework supporting network slicing and fog computing for 5G-enabled IoT services. Specifically, users can efficiently establish connections with 5G core network and anonymously access IoT services under their delegation through proper network slices of 5G infrastructure selected by fog nodes based on the slice/service types of accessing services. The privacy-preserving slice selection mechanism is introduced to preserve both configured slice types and accessing service types of users. In addition, session keys are negotiated among users, local fogs and IoT servers to guarantee secure access of service data in fog cache and remote servers with low latency. We evaluate the performance of the proposed framework through simulations to demonstrate its efficiency and feasibility under 5G infrastructure. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
IEEE J. Sel. Areas Commun. | 2 |
| 2018 | HealthDep: An Efficient and Secure Deduplication Scheme for Cloud-Assisted eHealth SystemsabstractIn this paper, we analyze the inherent characteristic of electronic medical records (EMRs) from actual electronic health (eHealth) systems, where we found that first, multiple patients would generate large amounts of duplicate EMRs and second, cross-patient duplicate EMRs would be generated numerously only in the case that the patients consult doctors in the same department. We then propose the first efficient and secure encrypted EMRs deduplication scheme for cloud-assisted eHealth systems (HealthDep). With the integration of our analysis results, HealthDep allows the cloud server to efficiently perform the EMRs deduplication, and enables the cloud server to reduce storage costs by more than 65% while ensuring the confidentiality of EMRs. Security analysis shows that HealthDep provides a stronger security guarantee than Marforio et al.'s scheme (NDSS 2014) and Bellare et al.'s scheme (USENIX Security 2013). Algorithm implementation and performance analysis demonstrate the feasibility and high efficiency of HealthDep. Yuan Zhang 0006, Chunxiang Xu, Hongwei Li 0001, Kan Yang 0001, Jianying Zhou 0001, Xiaodong Lin 0001 |
IEEE Trans. Ind. Informatics | 6 |
| 2017 | An Efficient Compromised Node Revocation Scheme in Fog-Assisted Vehicular CrowdsensingabstractIn this paper, we propose an efficient compromised node revocation scheme for enhancing security in road surface condition monitoring system (RSCMS) using fog computing. On the basis of certificateless aggregate signcryption scheme (CLASC), a data transmission protocol for monitoring road surface conditions is designed with security properties including reports confidentiality, integrity, mutual authenticity, privacy, revocation functionality and key escrow resilience. Extensive simulations are conducted to validate the proposed protocol. It is demonstrated that the proposed protocol outperfroms counterparts in terms of scalability, user revocation and signature verification efficiency. Sultan Basudan, Xiaodong Lin 0001, Karthik Sankaranarayanan |
GLOBECOM | 2 |
| 2017 | Privacy-Preserving Data Forwarding in VANETs: A Personal-Social Behavior Based ApproachabstractVehicular communications enable a variety of applications to improve road safety, driving experience, and traffic management. Many of these applications require data to be routed through multiple hops until they reach to the destination. Unfortunately, due to highly dynamic driving patterns of vehicles, it is challenging to achieve effective and time-sensitive data forwarding in vehicular ad hoc networks (VANETs). Both social- based and trajectory-assisted data forwarding strategies have been proposed to improve packet delivery performance in VANETs. The former reaches limited data delivery ratio and the latter leaks location privacy of drivers. In this paper, we propose a privacy-preserving data forwarding protocol based on personal-social behaviors of drivers to achieve highly reliable transmissions and privacy preservation for drivers in VANETs. Specifically, by observing the phenomenon that vehicles regularly visit some social spots, such as shopping malls, museums and busy intersections, we can obtain the personal-social behaviors of drivers. Based on these behaviors, the messages can be delivered to roadside units (RSUs) at the social spots frequently visited by vehicles. Later, once a vehicle visits the social spots, it can successfully retrieve the messages destined for it from the RSUs anonymously. In addition, the identities of senders are conditionally preserved and the personal-social behaviors of drivers are protected against a global adversary. Performance evaluation demonstrates its efficiency in terms of high delivery ratio and low average delay. Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen |
GLOBECOM | 2 |
| 2017 | A privacy-preserving and truthful tendering framework for vehicle cloud computingabstractIn this paper, we propose a novel secure and privacy-preserving incentive mechanism in vehicular cloud. The proposed incentive mechanism employs a tendering framework to model the interaction between vehicle cloud server and vehicles. With the proposed incentive mechanism, the cloud server can select participated vehicles to collaborate for its announced tasks, and the selected vehicles can earn payments from participating in and completing the announced tasks. Our mechanism ensures the truthfulness of all the participants and presents an assignment rule that enables VCC to select optimal resources for the tasks. Further, by exploiting homomorphic encryption technique, VCC and RSU cooperate together to run an effective tendering process but without knowing the sensitive information of vehicles. Abdulrahman Alamer, Yong Deng 0004, Xiaodong Lin 0001 |
ICC | 3 |
| 2017 | Dual-anonymous reward distribution for mobile crowdsensingabstractMobile crowdsensing enables individuals to collect data from social events and phenomena for performing tasks released by customers using their mobile devices. It removes the necessity of sensors deployment and hence supports large-scale sensing applications efficiently. Nevertheless, incentive and privacy remain as the major obstacles that need additional attention. If privacy is not presered or no benefit obtains, no mobile user prefers to participate in crowdsensing activities. In this paper, we propose DARD, a dual-anonymous reward distribution scheme to achieve the incentive for mobile users and privacy protection for both customers and mobile users in mobile crowdsensing. Specifically, we design a reward sharing incentive mechanism to encourage mobile users to participate in tasks and employ randomizable techniques to protect the identities of customers and mobile users during reward claim, distribution and deposit. Our analysis further shows that DARD achieves reward balance and cheater detection with low computational and communication overhead. Jianbing Ni, Xiaodong Lin 0001, Qi Xia 0001, Xuemin Shen |
ICC | 2 |
| 2017 | Privacy-preserving mobile crowdsensing for located-based applicationsabstractMobile crowdsensing is a new paradigm which explores the mobility and intelligence of mobile users to collect high-quality data from social events and phenomena for conducting complex sensing tasks. Nevertheless, privacy preservation and task allocation become main obstacles that need additional attention. To achieve accurate task allocation, it is inevitable to share some sensitive information of mobile users and customers, such as identities, location and points of interest. In this paper, we propose a privacy-preserving mobile crowdsensing framework (PPMC) for location-based applications to balance the tradeoff between privacy preservation and task allocation. In PPMC, we develop a matrix-based location matching mechanism for the service provider to achieve location-based task allocation without disclosing the location of mobile users and the sensing area of tasks. We also extend BBS+ signature and proxy reencryption to preserve identity privacy and data privacy for both customers and mobile users under the condition that they are honest to release and perform tasks, respectively. Finally, we discuss security properties and demonstrate the efficiency of PPMC in terms of computational and communication overhead. Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Qi Xia 0001, Xuemin Shen |
ICC | 3 |
| 2017 | Cloud-based parallel concolic executionabstractPath explosion is one of the biggest challenges hindering the wide application of concolic execution. Although several parallel approaches have been proposed to accelerate concolic execution, they neither scale well nor properly handle resource fluctuations and node failures, which often happen in practice. In this paper, we propose a novel approach, named PACCI, which parallelizes concolic execution and adapts to the drastic changes of computing resources by leveraging cloud infrastructures. PACCI tailors concolic execution to the MapReduce programming model and takes into account the features of cloud infrastructures. In particular, we tackle several challenging issues, such as making the exploration of different program paths independently and constructing an extensible path exploration module to support the prioritization of test inputs from a global perspective. Preliminary experimental results show that PACCI is scalable (e.g., gaining about 20× speedup using 24 nodes) and its efficiency declines slightly about 5% and 6.1% under resource fluctuations and node failures, respectively. Ting Chen 0002, Youzheng Feng, Xiapu Luo, Xiaodong Lin 0001, Xiaosong Zhang 0001 |
SANER | 4 |
| 2017 | A Privacy-Preserving Data-Sharing Framework for Smart GridabstractDistributed energy resources (ERs), featured with small-scale power generation technologies and renewable energy sources, are considered as necessary supplements for smart grid. To ensure that merged resources contribute effectively to the grid, data generated by consumer side should be shared among the ERs. However, it also introduces challenges of the protection of consumer privacy. To address these difficulties, we propose a new framework to share data in smart grid by leveraging new advances in homomorphic encryption and proxy re-encryption. Our proposed framework allows ERs to analyze consumer data while ensuring consumer privacy. An additional benefit of our proposed framework is that consumer data is transmitted over the smart grid only once. Furthermore, we present a concrete scheme falling into the proposed framework. Extensive analysis shows that the concrete scheme is secure and efficient. Khalid Nawaf Alharbi, Xiaodong Lin 0001, Jun Shao 0001 |
IEEE Internet Things J. | 2 |
| 2017 | A Privacy-Preserving Vehicular Crowdsensing-Based Road Surface Condition Monitoring System Using Fog ComputingabstractIn the recent past, great attention has been directed toward road surface condition monitoring. As a matter of fact, this activity is of critical importance in transportation infrastructure management. In response, multiple solutions have been proposed which make use of mobile sensing, more specifically contemporary applications and architectures that are used in both crowdsensing and vehicle-based sensing. This has allowed for automated control as well as analysis of road surface quality. These innovations have thus encouraged and showed the importance of cloud to provide reliable transport services to clients. Nonetheless, these initiatives have not been without challenges that range from mobility support, locational awareness, low latency, as well as geo-distribution. As a result, a new term has been coined for this novel paradigm, called, fog computing. In this paper, we propose a privacy-preserving protocol for enhancing security in vehicular crowdsensing-based road surface condition monitoring system using fog computing. At the onset, this paper proposes a certificateless aggregate signcryption scheme that is highly efficient. On the basis of the proposed scheme, a data transmission protocol for monitoring road surface conditions is designed with security aspects such as information confidentiality, mutual authenticity, integrity, privacy, as well as anonymity. In analyzing the system, the ability of the proposed protocol to achieve the set objectives and exercise higher efficiency with respect to computational and communication abilities in comparison to existing systems is also considered. Sultan Basudan, Xiaodong Lin 0001, Karthik Sankaranarayanan |
IEEE Internet Things J. | 2 |
| 2017 | Light-Weight and Robust Security-Aware D2D-Assist Data Transmission Protocol for Mobile-Health SystemsabstractWith the rapid advancement of technology, healthcare systems have been quickly transformed into a pervasive environment, where both challenges and opportunities abound. On the one hand, the proliferation of smart phones and advances in medical sensors and devices have driven the emergence of wireless body area networks for remote patient monitoring, also known as mobile-health (M-health), thereby providing a reliable and cost effective way to improving efficiency and quality of health care. On the other hand, the advances of M-health systems also generate extensive medical data, which could crowd today’s cellular networks. Device-to-device (D2D) communications have been proposed to address this challenge, but unfortunately, security threats are also emerging because of the open nature of D2D communications between medical sensors and highly privacy-sensitive nature of medical data. Even, more disconcerting is healthcare systems that have many characteristics that make them more vulnerable to privacy attacks than in other applications. In this paper, we propose a light-weight and robust security-aware D2D-assist data transmission protocol for M-health systems by using a certificateless generalized signcryption (CLGSC) technique. Specifically, we first propose a new efficient CLGSC scheme, which can adaptively work as one of the three cryptographic primitives: signcryption, signature, or encryption, but within one single algorithm. The scheme is proved to be secure, simultaneously achieving confidentiality and unforgeability. Based on the proposed CLGSC algorithm, we further design a D2D-assist data transmission protocol for M-health systems with security properties, including data confidentiality and integrity, mutual authentication, contextual privacy, anonymity, unlinkability, and forward security. Performance analysis demonstrates that the proposed protocol can achieve the design objectives and outperform existing schemes in terms of computational and communication overhead. Aiqing Zhang, Lei Wang 0009, Xinrong Ye, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2016 | Proxy Re-encryption with Delegatable Verifiability
Xiaodong Lin 0001, Rongxing Lu |
ACISP (2) | 1 |
| 2016 | FSSR: Fine-Grained EHRs Sharing via Similarity-Based Recommendation in Cloud-Assisted eHealthcare SystemabstractWith the evolving of ehealthcare industry, electronic health records (EHRs), as one of the digital health records stored and managed by patients, have been regarded to provide more benefits. With the EHRs, patients can conveniently share health records with doctors and build up a complete picture of their health. However, due to the sensitivity of EHRs, how to guarantee the security and privacy of EHRs becomes one of the most important issues concerned by patients. To tackle these privacy challenges such as how to make a fine-grained access control on the shared EHRs, how to keep the confidentiality of EHRs stored in cloud, how to audit EHRs and how to find the suitable doctors for patients, in this paper, we propose a fine-grained EHRs sharing scheme via similarity-based recommendation accelerated by Locality Sensitive Hashing (LSH) in cloud-assisted ehealthcare system, called FSSR. Specifically, our proposed scheme allows patients to securely share their EHRs with some suitable doctors under fine-grained privacy access control. Detailed security analysis confirms its security prosperities. In addition, extensive simulations by developing a prototype of FSSR are also conducted, and the performance evaluations demonstrate the FSSR's effectiveness in terms of computational cost, storage and communication cost while minimizing the privacy disclosure. Cheng Huang 0001, Rongxing Lu, Hui Zhu 0001, Jun Shao 0001, Xiaodong Lin 0001 |
AsiaCCS | 5 |
| 2016 | Efficient and Privacy-Preserving Smart Grid Downlink Communication Using Identity Based SigncryptionabstractIn this paper, we propose an efficient, secure and privacy-preserving scheme for smart grid downlink communication. Specifically, we propose an efficient identity based signcryption scheme, called EIBSC, providing privacy preservation in downlink communication for smart grids. The proposed scheme is characterized by employing the concealing destination technique on a tree network topology to protect consumer privacy in downlink communication. Moreover, the proposed scheme employs identity based signcryption to efficiently achieve downlink message source authentication, data integrity and encryption. Additionally, compared to other identity-based signcryption schemes, the proposed scheme is more efficient in regards to computational overhead and ciphertext size. Furthermore, our security analysis illustrates that the proposed scheme is resilient against various security threats to smart grids. Khalid Nawaf Alharbi, Xiaodong Lin 0001 |
GLOBECOM | 2 |
| 2016 | Silent Battery Draining Attack against Android Systems by Subverting Doze ModeabstractDoze mode, which was introduced from Android 6.0 aiming at reducing battery consumption when the device is unused for a long time. This work firstly reveals the internal details of the battery-saving feature, especially about the state transitions. Furthermore, we discover several defects in Android's device drivers associated with doze mode. By exploiting the defects, we implement various proof-of-concept attacks that could drain battery without acquiring any permissions by subverting doze mode. The proposed attacks are silent (hardly discerned by normal users), because they keep hidden when the smartphone is in use, while letting benign applications do battery-intensive work when the smartphone is unused rather than consuming excessive power by the attacks themselves. Google has confirmed that our attacks can reduce battery life. Finally, we discuss how to defend against the proposed attacks. Ting Chen 0002, Haiyang Tang, Xiaodong Lin 0001, Kuang Zhou, Xiaosong Zhang 0001 |
GLOBECOM | 3 |
| 2016 | PTVC: Achieving Privacy-Preserving Trust-Based Verifiable Vehicular Cloud ComputingabstractWith the development of intelligent transport systems (ITS) and vehicular ad hoc network (VANET), vehicular cloud computing (VCC) has been proposed to bring essential and potential benefits, such as improving traffic safety and offering computational services to road users. To make such computational services reliable and secure, the computation results from the vehicular cloud (VC) should be verifiable and the trustworthy vehicles need to be selected to form the VC with disclosure-minimizing privacy. To address these challenges, a privacy-preserving trust-based verifiable vehicular cloud computing scheme has been proposed in this paper, named PTVC. Specifically, the proposed PTVC scheme integrates the unique features of VCC and the requirements of privacy into traditional reputation system based on beta distribution, which can help differentiate the trust levels of the vehicles and preserve location privacy in the meantime. Moreover, by using the verifiable techniques, the cloud users can verify the correctness of outsourced computation while guaranteeing the privacy of their outsourced data. Detailed security analysis shows that the proposed PTVC scheme is secure and robust against several sophisticated attacks. In addition, performance evaluations via extensive simulations are also conducted, demonstrating its effectiveness. Cheng Huang 0001, Rongxing Lu, Hui Zhu 0001, Hao Hu 0017, Xiaodong Lin 0001 |
GLOBECOM | 5 |
| 2016 | A Secure and Privacy-Preserving Incentive Framework for Vehicular Cloud on the RoadabstractVehicular cloud, which is constituted by gathering the under-utilized on-board capabilities on the road, has received considerable attention in recent years. In this paper, we propose a novel secure and privacy-preserving incentive mechanism in vehicular cloud, which employs the Stackelberg Game to model the interaction between the leader and follower vehicles. With the proposed incentive mechanism, the leader vehicle which represents the task announcement server can select competent follower vehicles to collaborate for the announced task, and the selected follower vehicles can earn payments from participating in and completing the announced tasks. By exploiting the group signature technique, the leader and follower vehicles can achieve mutual verification with each other without privacy-related information disclosure. To show the efficiency of the proposed scheme, numerical analysis are conducted, and the derived results demonstrate that the proposed incentive mechanism can bring benefits to both parties, in terms of the utilities of the involved vehicles. Qinglei Kong, Rongxing Lu, Hui Zhu 0001, Abdulrahman Alamer, Xiaodong Lin 0001 |
GLOBECOM | 5 |
| 2016 | Secure and Deduplicated Spatial Crowdsourcing: A Fog-Based ApproachabstractWith the proliferation of mobile devices, spatial crowdsourcing is rising as a new paradigm that enables individuals to participate in tasks related to some locations in the physical world. Nevertheless, how to allocate these tasks to proper mobile users and improve communication efficiency are critical in spatial crowdsourcing. In this paper, we propose Fo-DSC, a fog-based deduplicated spatial crowdsourcing framework to achieve precise task allocation and secure data deduplication. Specifically, by integrating fog computing, we design a two-step task allocation mechanism to improve the accuracy of tasks allocation in spatial crowdsourcing. The fog nodes can detect and erase the repeated data in crowdsensing reports without learning any information about the reports. Furthermore, Fo-DSC efficiently records the contributions of mobile users whose data are reduplicated and deleted. As a result, these users do not become discouraged. Finally, we demonstrate that Fo-DSC satisfies the properties of fog-based task allocation and secure data deduplication with low computational and communication overheads. Jianbing Ni, Xiaodong Lin 0001, Kuan Zhang 0001, Yong Yu 0002 |
GLOBECOM | 2 |
| 2016 | A Fairness-Aware and Privacy-Preserving Online Insurance Application SystemabstractDue to health information sensitivity, privacy-preserving is a crucial issue in electronic health record systems. Users must provide their health information to insurance companies for their applications. This introduces potential threats to user privacy. In this paper, we propose the fairness-aware and privacy-preserving (FAPP) protocol for online health insurance systems. In the FAPP protocol, a user's health condition is encapsulated into a ciphertext with random numbers and sent to the health insurance company. The company will be unable to access the plaintext without prior user permission. However, the company will still be able to verify user integrity based on the ciphertext. In contrast to current health insurance schemes where insurance quotes are calculated by the company, the quote is calculated by the user based on the company's public policy in the proposed FAPP protocol. Additionally, the company is able to determine whether users have cheated when generating quotes. Furthermore, we propose a concept of privacy-preserving quote, which ensures that user health details cannot be derived from a generated quote. Security analysis demonstrates that the proposed FAPP protocol can achieve privacy-preservation and transparency. Aiqing Zhang, Abel Bacchus, Xiaodong Lin 0001 |
GLOBECOM | 3 |
| 2016 | EPPD: Efficient and privacy-preserving proximity testing with differential privacy techniquesabstractWith the ubiquity of mobile devices, location-based social networking applications have been widely used in people's daily life. However, due to the importance and sensitivity of location information, these applications may lead to serious security issues for user's location privacy. To handle these location privacy challenges, in this paper, we propose an efficient and privacy-preserving proximity testing scheme, called EPPD, for location-based services. With EPPD, a group of users can test whether they are within a given distance with minimal privacy disclosure. In specific, EPPD is comprised of two phases: first, users periodically upload their encrypted locations to service provider; and later, users can send requests to service provider for proximity testing and obtain the final testing results. Detailed security analysis shows that EPPD can achieve privacy-preserving proximity testing. In addition, performance evaluations via extensive simulations also demonstrate the efficiency and effectiveness of EPPD in term of low computational cost and communication overhead. Cheng Huang 0001, Rongxing Lu, Hui Zhu 0001, Jun Shao 0001, Abdulrahman Alamer, Xiaodong Lin 0001 |
ICC | 6 |
| 2016 | EDAT: Efficient data aggregation without TTP for privacy-assured smart meteringabstractSmart meters are integral to power dispatch in the emerging smart grid, by periodically collecting and reporting the electricity consumption of users to the control center to satisfy practical requirements. However, the real-time electricity measurements of individual households may contain plenty of users' privacy, e.g., activities and habits. To resist the privacy exposure from the individual measurements, we propose an Efficient Data AggregaTion (EDAT) scheme, in which every smart meter in the residential area uses a random noise to protect the concrete reading from being exposed to the attackers and the local gateway aggregates the individual measurements into a compact report before forwarding to the control center. In EDAT scheme, we remove the trusted third party and allow the smart meters to negotiate and generate the sum of the noise using polynomials, by which the control center can recover the power consumption of a residential area, other than a specific household. The security of the EDAT scheme can be reduced to the Decisional Diffie-Hellman assumption, and both the computational and communication overhead of each smart meter are small. Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Xuemin Shen |
ICC | 3 |
| 2016 | AMA: Anonymous mutual authentication with traceability in carpooling systemsabstractCarpooling, as an effective and eco-friendly travel mode, becomes a kind of public spontaneous behavior with multiple travellers sharing a vehicle to reduce individuals' travel cost, carbon emissions and traffic congestion. Although ubiquitous network access offers great convenience for travellers to find carpools, the safety becomes a big obstacle for them to accept this emerging travel mode. To address the safety concern, it seems inevitable to sacrifice the identity privacy for both drivers and passengers. In this paper, we propose an Anonymous Mutual Authentication (AMA) protocol to solve the contradiction between safety and privacy preservation by utilizing the BBS+ signature. In AMA, the passenger and the driver can mutually authenticate the identities without exposing their actual identities, but showing their membership of a trustable group. The AMA also allows to trace the identity of the driver (the passenger) on behalf of a judger if the passenger (the driver) complains the misbehavior of the driver (the passenger). The AMA is secure and efficient for real applications. Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Haomiao Yang, Xuemin Shen |
ICC | 3 |
| 2016 | SQLite Forensic Analysis Based on WAL
Ming Xu 0001, Jian Xu 0001, Ning Zheng 0001, Xiaodong Lin 0001 |
SecureComm | 5 |
| 2016 | Cloud-Based Privacy-Preserving Parking Navigation Through Vehicular Communications
Jianbing Ni, Kuan Zhang 0001, Xiaodong Lin 0001, Yong Yu 0002, Xuemin Shen |
SecureComm | 3 |
| 2016 | Privacy-Preserving Real-Time Navigation System Using Vehicular CrowdsourcingabstractTraffic congestions cause not only the time- consuming and frustrating experiences to drivers, but also other critical problems, such as fuel waste, air pollution and accidents. Real-time traffic information exchange can avoid vehicles being congested on roads. However, when the drivers are acquiring the traffic information, their privacy is inevitable to be disclosed. To preserve the driver's privacy, in this paper, we propose a privacy-preserving real-time navigation system (PRIN) using vehicular crowdsourcing. In PRIN, the RSUs cooperatively find an optimal path for the querying vehicle to the destination according to the real-time traffic information crowdsourced by the vehicles in their coverage areas. The querying vehicle retrieves the navigation result from each RSU successively when entering its coverage area, and follows the proper driving route to the next RSU, until reaching its destination. During these querying, crowdsourcing and retrieving processes, the driver's personal information, such as location, identity, is protected from being disclosed to attackers. In addition, a trusted authority can trace the drivers' identities if they upload false traffic information. Finally, we discuss the properties of conditional privacy preservation and demonstrate the efficiency of PRIN. Jianbing Ni, Xiaodong Lin 0001, Kuan Zhang 0001, Xuemin Shen |
VTC Fall | 2 |
| 2016 | Towards collusion-attack-resilient group key management using one-way function tree
Min Chen 0003, Abel Bacchus, Xiaodong Lin 0001 |
Comput. Networks | 4 |
| 2016 | Secure bidirectional proxy re-encryption for cryptographic cloud storage
Jun Shao 0001, Rongxing Lu, Xiaodong Lin 0001, Kaitai Liang |
Pervasive Mob. Comput. | 3 |
| 2016 | Consent-based access control for secure and privacy-preserving health information exchangeabstractElectronic health record exchanges are crucial functions of modern healthcare systems. These components are fundamental in providing quality care and enable for a larger spectrum of services. A framework which protects patient information during data exchanges is essential for healthcare systems. To achieve security and privacy-preservation for information exchange, we propose a consent-based access control (CBAC) mechanism for healthcare systems. A consent is an authorization initiated by a patient for an intended data requester via an agreement between them. After obtaining the consent from the patient, a healthcare organization can gain access to the data, which is encrypted by a healthcare provider. This is achieved by a cryptographic primitive: conditional proxy re-encryption. By doing so, patient medical data is protected against access of unauthorized parties, including public data center. Additionally, the proposed scheme achieves collusion resistance. Furthermore, mutual authentication and contextual privacy are attained. Performance evaluation demonstrates that the proposed CBAC scheme can achieve security and privacy preservation with high computational efficiency. Copyright © 2016 John Wiley & Sons, Ltd. Aiqing Zhang, Abel Bacchus, Xiaodong Lin 0001 |
Secur. Commun. Networks | 3 |
| 2015 | A Novel Privacy-Preserving Set Aggregation Scheme for Smart Grid CommunicationsabstractIn this paper, we propose a novel privacy- preserving set aggregation scheme for smart grid communications. The proposed scheme is characterized by employing a group G of composite order n=pq to achieve two-subset aggregation from a single aggregated data. With the proposed set aggregation scheme, the control center in smart grid is able to obtain more fine- grained data aggregation results for better monitoring and controlling smart grid. Detailed security analysis shows that the proposed scheme can achieve privacy-preserving property with formal proof in the random oracle model. In addition, extensive experiments are conducted, and the results demonstrate the proposed scheme is also efficient in terms of low computational costs and communication overheads. Rongxing Lu, Khalid Nawaf Alharbi, Xiaodong Lin 0001, Cheng Huang 0001 |
GLOBECOM | 3 |
| 2015 | Security-Enhanced Data Aggregation against Malicious Gateways in Smart GridabstractIn smart grid, to monitor, predict and control the power consumption in real time, energy usage data have to be periodically collected through publicly accessible communication channels, and are stored in a centralized operation center. However, electricity consumption data may disclose the privacy information of users. Therefore, protecting privacy of users and validity of power usage reports becomes a crucial security issue. In this paper, we propose a security-enhanced data aggregation scheme for smart grid communications based on homomorphic cryptosystem, trapdoor hash functions and homomorphic authenticators. Our scheme can achieve data confidentiality and integrity against the malicious aggregator (e.g. gateway), meaning that the aggregator is not able to access users' private information or corrupt the power consumption reports during the aggregation process. Through extensive analysis, we demonstrate that our scheme can resist potential threats and be proved secure under cryptographic hard assumptions. It has less computational and communication overheads than existing approaches. Jianbing Ni, Khalid Nawaf Alharbi, Xiaodong Lin 0001, Xuemin Shen |
GLOBECOM | 3 |
| 2015 | Effective Data Rate Based Rank Adaptive Receive Antenna SelectionabstractIn LTE-A downlink, beamforming is adopted to improve spectral efficiency and system capacity. Antenna selection in beamforming selects the proper receive signal subspace on different resource blocks (RBs), which can further improve system performance. In this paper, we first define the concept of effective data rate. Based on such concept, we propose a low complexity antenna selection algorithm for beamforming technology. Different from existing algorithms, the proposed algorithm first determines the data layer number of each user by considering both channel quality and user requirements, and based on the data layer number, it selects a corresponding number of receive antennas to form the receive signal subspace. As a result, dynamic switching between single-layer and dual-layer beamforming can be realized so that user requirements can be better satisfied. Then, the proposed algorithm calculates the spatial correlation to assign proper antennas on different RBs to reduce inter-layer interference. Simulation results show that the effective data rate of the proposed algorithm is higher than other algorithms when user number is bigger than 20 so that the requirements of more users can be satisfied, and user fairness can also be improved. Xuanli Wu, Zheming Ma, Xiaodong Lin 0001 |
GLOBECOM | 3 |
| 2015 | Efficient e-health data release with consistency guarantee under differential privacyabstractE-health data release, which answers the statistical queries of the Electronic Health Records (EHRs), has been widely adopted in modern health care services. However, since the EHRs contain sensitive information of the patients, the data release procedure may lead to the leakage of the privacy of patients if it is done without necessary protection measures in place. On addressing this, existing research literature introduces differential privacy to provide the necessary privacy guarantee. However, it is not suitable in sensitive e-health environments because it lacks the efficiency for data processing and updating. In this paper, we propose an efficient e-health data release scheme with consistency guarantee under differential privacy. Specifically, we improve the performance of the previous work by designing a new private partition algorithm of histogram and also proposing a heuristic hierarchical query method. We conduct real experiments and compare our scheme with the existing one to show that the proposal is more efficient in terms of data processing and updating. Moreover, we increase the accuracy of data release through consistency and give proof of privacy to show that the proposed algorithm is under ϵ-differential privacy. Hongwei Li 0001, Yuan-Shun Dai, Xiaodong Lin 0001 |
HealthCom | 3 |
| 2015 | Achieving authorized and ranked multi-keyword search over encrypted cloud dataabstractIn cloud computing, it is important to protect user data. Thus, data owners usually encrypt their data before outsourcing them to the cloud server for security and privacy concerns. At the same time, very often users need to find data for specific keywords of interest to them. This motivates the research on the searchable encryption technique, which allows the search user to search over the encrypted data. Many mechanisms have been proposed, and are mainly focusing on the symmetric searchable encryption (SSE) technique. However, they do not consider the search authorization problem that requires the cloud server only to return the search results to authorized users. In this paper, we propose an authorized and ranked multi-keyword search scheme (ARMS) over encrypted cloud data by leveraging the ciphertext policy attribute-based encryption (CP-ABE) and SSE techniques. Security analysis demonstrates that the proposed ARMS scheme can achieve confidentiality of documents, trapdoor unlinkability and collusion resistance. Extensive experiments show that the ARMS is more superior and efficient than existing approaches in terms of functionalities and computational overhead. Hongwei Li 0001, Xiaodong Lin 0001 |
ICC | 4 |
| 2015 | Blurred License Plate Recognition based on single snapshot from drive recorderabstractNowadays, drive recorders are becoming a popular form of evidences used by drivers and accepted by court. One common investigation task is to identify vehicles of interest and recognize their license plates (LPs). In this paper, we focus on License Plate Recognition (LPR) based on single snapshot from a drive recorder. As drive recorders are installed on moving vehicles, snapshots by drive recorders usually suffer from serious blur, and the key issue is recognizing the Blurred License Plate (BLP) from single image. A straightforward method is first deblurring the BLP and then recognizing it. However, the first problem with this method is that general image deblurring methods are designed to get a good overall visual effect and the deblurred results may be not good for LPR. The second problem is that general image deblurring methods don't use the features of the LPs, which could be important priors for the deblurring process. To overcome these issues, this paper proposes a novel method that integrates deblurring and recognizing in a closed-loop. The proposed method utilizes characters and patterns of LPs as priors, and the deblurring and recognizing process will stop when a reliable recognition result is obtained from the deblurred image. Furthermore, by analyzing the features of BLPs, this paper proposes a ℓ0-norm based deblurring method. Experiments show that, compared to other LPR methods, the proposed method can achieve higher recognition rate on the BLPs. Chunhe Song, Xiaodong Lin 0001 |
ICC | 2 |
| 2015 | A uniform framework for network selection in Cognitive Radio NetworksabstractWith the development of secondary spectrum markets, it is anticipated that multiple Primary Networks (PRNs) who own underutilized spectrum resources will be incorporated into Cognitive Radio Networks (CRNs). In this scenario, CRNs will have a greatly enhanced choice of accessible spectrum resources to support large volumes of Secondary Users (SUs), and guarantee the QoS reliability. Network selection problem, i.e. choosing which PRN to access, is essential for CRNs in a multi-PRN environment. However, to the best of our knowledge, there is still lack of a unified method to address the network selection problem. In this paper, we aim to present a uniform framework to investigate and evaluate network selection strategies for CRNs. First, we model the interactive process of SUs and PUs as a Continuous Time Markov Decision Process (CTMDP), and abstract the network selection strategy into the set of decision variables with respect to system states in the CTMDP. Second, under the proposed framework, we discuss multiple existing strategies, such as random, greedy, and statistically-weighted. Third, to achieve a more effective method, we derive the performance gradient of CRNs' utility function with respect to the network selection strategy, and propose a gradient-based optimal network selection strategy by using the theory of Markov performance potential. At last, simulations are conducted to validate the correctness of the proposed analytical framework, and the effectiveness of the proposed network selection scheme. Ye Wang 0002, Jia Yu 0006, Xiaodong Lin 0001, Qinyu Zhang 0001 |
ICC | 3 |
| 2015 | QoS oriented heterogeneous traffic scheduling in LTE downlinkabstractIn this paper, Rate-Level-Based Scheduling (RLBS) Algorithm is proposed to support the heterogeneous traffic in downlink of Long Time Evolution (LTE) system. The proposed scheduling algorithm aims to minimize the packet loss ratio of real-time traffic while guaranteeing Quality of Service (QoS) requirements. We compares the performance of the proposed scheduling algorithm with Modified Largest Weighted Delay First (M-LWDF) algorithm, Exponential PF (EXP/PF) algorithm and Z-Based QoS Scheduler (ZBQoS) algorithm. Simulation shows that compared with other algorithms, the proposed scheduling algorithm can achieve a good tradeoff between satisfaction of QoS requirement and fairness, meanwhile, it can can satisfy the requirement of Guaranteed Bit Rate (GBR) traffic preferably and improve the Packet Loss Ratio (PLR) performance significantly. Xuanli Wu, Xingling Han, Xiaodong Lin 0001 |
ICC | 3 |
| 2015 | EVOC: More efficient verifiable outsourced computation from any one-way trapdoor functionabstractVerifiable outsourced computation enables a computational resource-constrained mobile device to outsource the computation of a function F on multiple inputs x1, …, xnto the cloud that is generally assumed to possess abundant powers. The most existing work depends on Yao's Garbled Circuit and fully homomorphic encryptions that took considerable computational overhead on weak clients. In this paper, a more efficient verifiable outsourced computation of encrypted data EVOC supporting any functions from any one-way trapdoor function is proposed, based on our newly-devised privacy preserving data aggregation supporting both addition and multiplication operations without exploiting fully homomorphic encryption (FHE). It solves the open problem suggested by Gennaro et al. that how to devise a verifiable computation scheme that used a more efficient primitive than FHE. Finally, the formal security proof and extensive efficiency evaluations demonstrate our proposed EVOC satisfies the target security and privacy requirements and far outperforms the state-of-the-art in terms of computational and communication complexity. Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Xiaodong Lin 0001 |
ICC | 4 |
| 2015 | Fine-grained data sharing in cloud computing for mobile devicesabstractDue to the convenience, the data sharing in cloud computing via mobile devices has become more and more popular. However, data confidentiality and online computational cost still present practical concerns to the deployment of data sharing in cloud computing for mobile devices. Existing data sharing protocols in cloud computing either cannot support the flexible sharing style for the encrypted data, or suffer from massive online computational cost that scales with the complexity of the access policy. In this paper, to cope with these challenging concerns, we propose a new data sharing protocol for cloud computing by using a new cryptographic primitive named online/offline attribute-based proxy re-encryption and the transform key technique. To the best of our knowledge, the proposed data sharing protocol is the first one featuring with fine-grained access control, flexible sharing, data confidentiality, and minimum online computational cost on the user side at the same time. Furthermore, the proposed online/offline attribute-based proxy re-encryption scheme may be of independent interest. At last, extensive analysis shows that our proposed data sharing protocol is secure in terms of data confidentiality, and suitable for mobile devices in terms of online computational cost. Jun Shao 0001, Rongxing Lu, Xiaodong Lin 0001 |
INFOCOM | 3 |
| 2015 | TR-MABE: White-box traceable and revocable multi-authority attribute-based encryption and its applications to multi-level privacy-preserving e-healthcare cloud computing systemsabstractCloud-assisted e-healthcare systems significantly facilitate the patients to outsource their personal health information (PHI) for medical treatment of high quality and efficiency. Unfortunately, a series of unaddressed security and privacy issues dramatically impede its practicability and popularity. In e-healthcare systems, it is expected that only the primary physicians responsible for the patients treatment can not only access the PHI content but verify the real identity of the patient. Secondary physicians participating in medical consultation and/or research tasks, however, are only permitted to view or use the content of the protected PHI, while unauthorized entities cannot obtain anything. Existing work mainly focuses on patients conditional identity privacy by exploiting group signatures, which are very computationally costly. In this paper, we propose a white-box traceable and revocable multi-authority attribute-based encryption named TR-MABE to efficiently achieve multilevel privacy preservation without introducing additional special signatures. It can efficiently prevent secondary physicians from knowing the patients identity. Also, it can efficiently track the physicians who leak secret keys used to protect patients identity and PHI. Finally, formal security proof and extensive simulations demonstrate the effectiveness and practicability of our proposed TR-MABE in e-healthcare cloud computing systems. Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Xiaodong Lin 0001 |
INFOCOM | 4 |
| 2015 | MuDA: Multifunctional data aggregation in privacy-preserving smart grid communications
Rongxing Lu, Zhenfu Cao, Khalid Nawaf Alharbi, Xiaodong Lin 0001 |
Peer-to-Peer Netw. Appl. | 5 |
| 2015 | ReDD: recommendation-based data dissemination in privacy-preserving mobile social networksabstractAbstract Mobile social network (MSN), which is built upon popular smart phone devices and enables mobile users with similar interests to connect with one another, has received considerable attention in recent years. A common phenomenon that makes the MSN vivid today is mobile users often like to share attractive things to their friends in MSN. In this paper, based on this common phenomenon, we propose an efficient recommendation‐based data dissemination (ReDD) protocol for MSN, which can efficiently disseminate high‐quality messages in a privacy‐preserving way. Specifically, in the proposed ReDD protocol, each mobile user, based on both his or her own view and his or her friends' recommendations, will form his or her personal estimation on the quality of a message. Only if the estimation of quality reaches a threshold, the message will be disseminated. In this way, high‐quality messages can be widely spread in the network and occupy more network resources than low‐quality ones. In order to check the validity of friends' recommendations, ReDD also employs an efficient anonymous authentication technique, which ensures that only the friends of a user can verify recommendations made by the user. Detailed security analysis demonstrates that ReDD can effectively resist various attacks launched by attackers and ensure identity privacy of nodes, confidentiality of shared keys and integrity of data packets. In addition, extensive simulations are also conducted to evaluate the performance of ReDD in terms of the number of active nodes and the average active time, and the simulation results show that high‐quality messages can be disseminated widely and efficiently, while low‐quality ones will be eliminated shortly to avoid occupying network resources. Copyright © 2014 John Wiley & Sons, Ltd. Rongxing Lu, Khalid Nawaf Alharbi, Xiaodong Lin 0001, Zhenfu Cao |
Secur. Commun. Networks | 4 |
| 2015 | An empirical investigation into path divergences for concolic execution using CRESTabstractAbstract Recently, concolic execution has become a hotspot in the domain of software testing and program analysis. However, a practical challenge, called path divergence, impairs the soundness and completeness of concolic execution. A path divergence indicates the tested program runs an unpredicted path. In this work, we carry out a comprehensive empirical study on path divergences using an open‐source concolic execution tool, named CREST. To make the investigation representative, we select 120 test units randomly from 21 different open‐source programs. The results are interesting, and will provide insight to solve the challenging path‐divergence problem. First, about one‐half of test units suffer from path divergences, indicating path divergences are so prevalent that the issue is worthy of great attention. Second, quite a number of generated test inputs drive test units to take divergent paths. This means testers need considerable effort to eliminate the misleading test inputs before aggregating them to a test suite. Third, we dig out ten divergent patterns through manual analysis of each path divergence. Among them, the three most prevalent ones, which are exceptions, external calls, and type casts, lead to almost 82% of path divergences. Finally, we discuss several countermeasures to overcome path divergences. Copyright © 2015 John Wiley & Sons, Ltd. Ting Chen 0002, Xiaodong Lin 0001, Jin Huang 0011, Abel Bacchus, Xiaosong Zhang 0001 |
Secur. Commun. Networks | 2 |
| 2015 | Duth: a user-friendly dual-factor authentication for Android smartphone devicesabstractAbstract With the pervasiveness of smartphones and the richness of mobile apps, many people are storing increasingly sensitive data on them, in greater quantities. In order to protect this sensitive information from misuse due to loss, or other accidental reasons, strong smartphone authentication has become imperative and has received considerable attention in recent years. However, when we directly implement traditional authentication schemes in smartphone devices, the balance between security and user‐friendliness of authentication becomes challenging, mainly because of the input‐in‐motion environments. In this paper, without adding extra hardware devices, we present a user‐friendly, dual‐factor authentication scheme called Duth, for Android smartphone devices. Specifically, the proposed Duth scheme is characterized by utilizing the spatial and time features of the user‐writing process as two factors of authentication; a user can be authenticated only if these two features are fulfilled. We implement Duth in Java as a library, which we make publicly available. With extensive discussions on parameter selection, we choose proper parameters and implement Duth on a smartphone with Android 2.3 for experiments, and the experiment results demonstrate that Duth can indeed achieve efficient and effective dual‐factor authentication. Copyright © 2014 John Wiley & Sons, Ltd. Hui Zhu 0001, Xiaodong Lin 0001, Rongxing Lu |
Secur. Commun. Networks | 2 |
| 2015 | An effective behavior-based Android malware detection systemabstractAbstract With the rapid growth of Android applications and malware, it has become a challenge to distinguish malware from a huge number of applications. The use of behavioral analytics is one of the most promising approaches because of its accuracy and resilience to malware variants. In this paper, we propose a behavior‐based malware detection system. Firstly, it uses Android APIs and libc (Bionic libc) function calls along with their arguments to describe sensitive application behaviors. Secondly, it conducts behavior analysis and malware detection using machine learning techniques, including Support Vector Machine, Naïve Bayes, and Decision Tree. The experiments are conducted with 1136 real‐world samples that are composed of various types of malware and benign applications. The evaluation results show that our system can effectively detect Android malware. In addition, we compare our system with the other behavior‐based malware detection system, and the comparison results show the advantage of our system on malware detection. Copyright © 2014 John Wiley & Sons, Ltd. Shihong Zou, Xiaodong Lin 0001 |
Secur. Commun. Networks | 3 |
| 2015 | White-Box Traceable Ciphertext-Policy Attribute-Based Encryption Supporting Flexible AttributesabstractCiphertext-policy attribute-based encryption (CP-ABE) enables fine-grained access control to the encrypted data for commercial applications. There has been significant progress in CP-ABE over the recent years because of two properties called traceability and large universe, greatly enriching the commercial applications of CP-ABE. Traceability is the ability of ABE to trace the malicious users or traitors who intentionally leak the partial or modified decryption keys for profits. Nevertheless, due to the nature of CP-ABE, it is difficult to identify the original key owner from an exposed key since the decryption privilege is shared by multiple users who have the same attributes. On the other hand, the property of large universe in ABE enlarges the practical applications by supporting flexible number of attributes. Several systems have been proposed to obtain either of the above properties. However, none of them achieve the two properties simultaneously in practice, which limits the commercial applications of CP-ABE to a certain extent. In this paper, we propose two practical large universe CP-ABE systems supporting white-box traceability. Compared with existing systems, both the two proposed systems have two advantages: 1) the number of attributes is not polynomially bounded and 2) malicious users who leak their decryption keys could be traced. Moreover, another remarkable advantage of the second proposed system is that the storage overhead for traitor tracing is constant, which are suitable for commercial applications. Jianting Ning, Xiaolei Dong, Zhenfu Cao, Lifei Wei, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2015 | Secure and Reliable Routing Protocols for Heterogeneous Multihop Wireless NetworksabstractWe propose E-STAR for establishing stable and reliable routes in heterogeneous multihop wireless networks. E-STAR combines payment and trust systems with a trust-based and energy-aware routing protocol. The payment system rewards the nodes that relay others’ packets and charges those that send packets. The trust system evaluates the nodes’ competence and reliability in relaying packets in terms of multi-dimensional trust values. The trust values are attached to the nodes’ public-key certificates to be used in making routing decisions. We develop two routing protocols to direct traffic through those highly-trusted nodes having sufficient energy to minimize the probability of breaking the route. By this way, E-STAR can stimulate the nodes not only to relay packets, but also to maintain route stability and report correct battery energy capability. This is because any loss of trust will result in loss of future earnings. Moreover, for the efficient implementation of the trust system, the trust values are computed by processing the payment receipts. Analytical results demonstrate that E-STAR can secure the payment and trust calculation without false accusations. Simulation results demonstrate that our routing protocols can improve the packet delivery ratio and route stability. Mohamed Mahmoud 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2015 | PSMPA: Patient Self-Controllable and Multi-Level Privacy-Preserving Cooperative Authentication in Distributedm-Healthcare Cloud Computing SystemabstractDistributed m-healthcare cloud computing system significantly facilitates efficient patient treatment for medical consultation by sharing personal health information among healthcare providers. However, it brings about the challenge of keeping both the data confidentiality and patients’ identity privacy simultaneously. Many existing access control and anonymous authentication schemes cannot be straightforwardly exploited. To solve the problem, in this paper, a novel authorized accessible privacy model (AAPM) is established. Patients can authorize physicians by setting an access tree supporting flexible threshold predicates. Then, based on it, by devising a new technique of attribute-based designated verifier signature, a patient self-controllable multi-level privacy-preserving cooperative authentication scheme (PSMPA) realizing three levels of security and privacy requirement in distributed m-healthcare cloud computing system is proposed. The directly authorized physicians, the indirectly authorized physicians and the unauthorized persons in medical consultation can respectively decipher the personal health information and/or verify patients’ identities by satisfying the access tree with their own attribute sets. Finally, the formal security proof and simulation results illustrate our scheme can resist various kinds of attacks and far outperforms the previous ones in terms of computational, communication and storage overhead. Jun Zhou 0018, Xiaodong Lin 0001, Xiaolei Dong, Zhenfu Cao |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2014 | Large Universe Ciphertext-Policy Attribute-Based Encryption with White-Box Traceability
Jianting Ning, Zhenfu Cao, Xiaolei Dong, Lifei Wei, Xiaodong Lin 0001 |
ESORICS (2) | 5 |
| 2014 | An ElGamal-based efficient and privacy-preserving data aggregation scheme for smart gridabstractSmart Grid technologies are ever-increasingly being adopted by nations and governments, primarily for a huge technological advancement in the areas of power management and information and communications. The smart meters deployed in a household can monitor electricity usage in real-time, and aggregate the data for further analysis and control; however, the existing solutions mainly depend on Paillier's additive homomorphic encryptions, which are of high computational complexity. This inefficiency makes them impracticable in smart grid, which embraces thousands of users and requires frequent data aggregation. In this paper, we propose a privacy-preserving aggregation framework, followed by a concrete construction using Elgamal encryption, which is secure under chosen plaintext attack (CPA) but not chosen ciphertext attack (CCA). Then, we further extend the concrete construction into a CCA-secure counterpart. In addition to efficient data aggregation, the proposed scheme can protect the user's meter data from sophisticated attacks, which are sponsored by the community gateway and the users. The formal security proof and performance evaluations illustrate the efficiency and the practicability of our scheme as well as its strong security. Xiaolei Dong, Jun Zhou 0018, Khalid Nawaf Alharbi, Xiaodong Lin 0001, Zhenfu Cao |
GLOBECOM | 4 |
| 2014 | Toward secure user-habit-oriented authentication for mobile devicesabstractMobile device security has become increasingly important as we become more dependent on mobile devices. One fundamental security problem is user authentication, and if not executed correctly, leaves the mobile user vulnerable to harm like impersonation. Although many user authentication mechanisms have presented in the past, studies have shown mobile users prefer usability over security and, unfortunately, a higher level of security often entails sacrificing usability. Moreover, mobile users often unlock their devices in public spaces, inevitably resulting in a high possibility of user credentials disclosure. Motivated by the above, we introduce a novel user-habit-oriented authentication model, where mobile users can integrate their own habits with user authentication on mobile devices. The user-habit-oriented authentication turns a tedious security action into an enjoyable experience. Also, we propose a rhythm based authentication scheme, providing the first proof of concept toward secure user-habit-oriented authentication for mobile devices. Experimental results show that the proposed scheme has high accuracy in terms of false rejection rate. Also, the proposed scheme is able to protect from attacks caused by credential disclosure, which could be fatal to the traditional schemes. Jamie Seto, Ye Wang 0002, Xiaodong Lin 0001 |
GLOBECOM | 3 |
| 2014 | Cooperative sensing scheduling in Cognitive Radio Networks with multiple Primary NetworksabstractWith the emergence of secondary spectrum markets, it is envisioned that multiple Primary Networks (PRNs) with non-overlapping spectrum pools will be incorporated into Cognitive Radio Networks (CRNs). As a result, CRNs will have a greatly enhanced choice of accessible spectrum resources available to them, which, in turn, brings a significant increase in the diversity of available PRNs; this can greatly increase reliability and stability in the system performance experienced by secondary users (SUs) on the network. However, due to the nature of dynamic network environments, it is hard to meet the requirements of sensing task when the sensing resources, such as the number of participating SUs and A/D sampling capability, are limited. In this paper, we address this issue by studying the problem of cooperative sensing scheduling of CRNs for a dynamic multi-PRN environment. By jointly considering the dynamics of spectrum usage, and the channel conditions of SUs, cooperative spectrum sensing scheduling is formulated as two optimization problems, from the perspectives of primary users (PUs) and SUs, respectively. To solve these problems, two straightforward scheduling schemes are discussed: Random Scheduling and SNR-based Greedy Scheduling. To further improve the sensing performance, a cross entropy (CE) method-based sensing scheduling scheme is proposed. At last, simulation results validate the effectiveness of the proposed CE-based sensing scheduling scheme. Ye Wang 0002, Xiaodong Lin 0001 |
GLOBECOM | 2 |
| 2014 | Separate-combine recovery for compressed sensing of large imagesabstractCompressed sensing (CS) based image processing is a important branch of CS based signal processing. However, the high complexity involved in CS based large-size image processing is a challenging issue. In this paper, an orthogonal matching pursuit enabled two-stage CS recovery scheme with low complexity yet high performance, termed separate-combine recovery method is proposed for separable image sensing operators. Specifically, at the separate stage, both compressed row and column data is estimated as intermediates. Based on these estimates, two sparse representations of the original image, called row-first-recovery result and column-first-recovery result, are respectively obtained. At the combine stage, the final result is achieved by weighted aggregating these two sparse representations. The complexity and performance of the proposed method are evaluated through extensive numerical results, showing that the presented scheme outperforms existing methods in terms of recovery speed and computational complexity. Shaohua Wu 0002, Jia Yu 0006, Xiaodong Lin 0001 |
ICC | 4 |
| 2014 | User-satisfaction-based weighted SLNR beamforming in TD-LTE-A systemabstractIn TD-LTE-A system, the objective of conventional non-codebook beamforming algorithms is to maximize sum capacity to accommodate more users. However, fairness among users is not considered by these algorithms, and the performance of users with poor channel quality will always be bad. To relax the fairness requirement in resource allocation, this paper first introduces two parameters of user satisfaction into TD-LTE-A system for Guaranteed Bit Rate (GBR) and Non-GBR traffics, respectively. Then a user-satisfaction-based beamforming algorithm is proposed. This algorithm employs user satisfaction parameter to adjust the weights for weighted Signal-to-Leakage-plus-Noise Ratio (SLNR) algorithm. Finally, the weights of different traffics are also considered in the proposed beamforming algorithm so that average user satisfaction across different types of traffics can be modified according to the requirement of telecommunication operators. Simulation results show that the proposed algorithm can improve user satisfaction and user fairness, and average user satisfaction of GBR and Non-GBR traffics can be adjusted by changing of GBR priority parameter. Xuanli Wu, Lukuan Sun, Jia Yu 0006, Xiaodong Lin 0001, Ye Wang 0002 |
ICC | 4 |
| 2014 | Power allocation for CoMP system with backhaul limitationabstractCoordinated multipoint (CoMP) is proposed recently as a promising technique to improve the performance of cellular networks and meet the increasing demand for digital service. However it faces several constraints to perform CoMP scheme in real systems. In this paper, we consider a downlink CoMP system and formulate the resource allocation problem of it in terms of resource block (RB) scheduling and power allocation (PA) under the constraints of both transmit power at each transmit point (TP) and backhaul capacity. Combining with existing scheduling methods, we propose a PA algorithm to solve the formulated problem. The proposed PA method decouples the problem into independent sub-problems in order to reduce the involved variables. Then, to further reduce the computation, suboptimal solutions are approached instead of the optimal ones. Simulation results verify that the proposed algorithm is able to improve the network throughput and save transmit power of TPs with reasonable computational complexity. Jia Yu 0006, Ye Wang 0002, Xiaodong Lin 0001, Qinyu Zhang 0001 |
ICC | 3 |
| 2014 | Assessment of multi-hop interpersonal trust in social networks by Three-Valued Subjective LogicabstractAssessing multi-hop interpersonal trust in online social networks (OSNs) is critical for many social network applications such as online marketing but challenging due to the difficulties of handling complex OSN topology, in existing models such as subjective logic, and the lack of effective validation methods. To address these challenges, we for the first time properly define trust propagation and combination in arbitrary OSN topologies by proposing 3VSL (Three-Valued Subjective Logic). The 3VSL distinguishes the posteriori and priori uncertainties existing in trust, and the difference between distorting and original opinions, thus be able to compute multi-hop trusts in arbitrary graphs. We theoretically proved the capability based on the Dirichlet distribution. Furthermore, an online survey system is implemented to collect interpersonal trust data and validate the correctness and accuracy of 3VSL in real world. Both experimental and numerical results show that 3VSL is accurate in computing interpersonal trust in OSNs. Guangchi Liu, Qing Yang 0003, Honggang Wang 0001, Xiaodong Lin 0001, Mike P. Wittie |
INFOCOM | 4 |
| 2014 | PLAM: A privacy-preserving framework for local-area mobile social networksabstractIn this paper, we propose a privacy-preserving framework, called PLAM, for local-area mobile social networks. The proposed PLAM framework employs a privacy-preserving request aggregation protocol with k-Anonymity and l-Diversity properties while without involving a trusted anonymizer server to keep user preference privacy when querying location-based service (LBS), and integrates unlinkable pseudo-ID technique to achieve user identity privacy, location privacy. Moreover, the proposed PLAM framework also introduces the privacy-preserving and verifiable polynomial computation to keep LBS provider's functions private while preventing the provider from cheating in computation. Detailed security analysis shows that the proposed PLAM framework can not only achieve desirable privacy requirements but also resist outside attacks on source authentication, data integrity and availability. In addition, extensive simulations are also conducted, and simulation results guide us on how to set proper thresholds for k-anonymity, l-diversity to make a tradeoff between the desirable user preference privacy level and the request delay in different scenarios. Rongxing Lu, Xiaodong Lin 0001, Zhiguo Shi 0001, Jun Shao 0001 |
INFOCOM | 2 |
| 2014 | FINE: A fine-grained privacy-preserving location-based service framework for mobile devicesabstractIn this paper, we propose a fine-grained privacy-preserving location-based service (LBS) framework, called FINE, for mobile devices. It adopts the data-as-a-service (DaaS) model, where the LBS provider publishes its data to a third party (e.g., cloud server) who executes users' LBS queries. The proposed FINE framework employs a ciphertext-policy anonymous attribute-based encryption technique to achieve fine-grained access control, location privacy, confidentiality of the LBS data and its access policy, and accurate LBS query result while without involving any trusted third party. Moreover, the proposed FINE framework also integrates the transformation key and proxy re-encryption to migrate most of computation-intensive tasks from the LBS provider and users to the cloud server. This property keeps mobile devices away from massive resource-consuming operations. Extensive analysis shows that our proposed FINE framework is secure and highly efficient for mobile devices in terms of computation and communication cost. Jun Shao 0001, Rongxing Lu, Xiaodong Lin 0001 |
INFOCOM | 3 |
| 2014 | RCCA-Secure Multi-use Bidirectional Proxy Re-encryption with Master Secret Security
Rongxing Lu, Xiaodong Lin 0001, Jun Shao 0001, Kaitai Liang |
ProvSec | 2 |
| 2014 | Wireless Technology for Pervasive Healthcare
Giancarlo Fortino, Xu Li 0001, Xiaodong Lin 0001, Oscar Mayora-Ibarra, Enrico Natalizio, Mehmet R. Yuce |
Mob. Networks Appl. | 3 |
| 2014 | PPNA special issue on "the green, reliability and security of machine-to-machine communications"
Xu Li 0001, Xiaodong Lin 0001, Wenye Wang, Nathalie Mitton |
Peer-to-Peer Netw. Appl. | 2 |
| 2014 | Exploiting Geo-Distributed Clouds for a E-Health Monitoring System With Minimum Service Delay and Privacy PreservationabstractIn this paper, we propose an e-health monitoring system with minimum service delay and privacy preservation by exploiting geo-distributed clouds. In the system, the resource allocation scheme enables the distributed cloud servers to cooperatively assign the servers to the requested users under the load balance condition. Thus, the service delay for users is minimized. In addition, a traffic-shaping algorithm is proposed. The traffic-shaping algorithm converts the user health data traffic to the nonhealth data traffic such that the capability of traffic analysis attacks is largely reduced. Through the numerical analysis, we show the efficiency of the proposed traffic-shaping algorithm in terms of service delay and privacy preservation. Furthermore, through the simulations, we demonstrate that the proposed resource allocation scheme significantly reduces the service delay compared to two other alternatives using jointly the short queue and distributed control law. Qinghua Shen, Xiaohui Liang 0002, Xuemin Shen, Xiaodong Lin 0001, Henry Y. Luo |
IEEE J. Biomed. Health Informatics | 4 |
| 2014 | EPPDR: An Efficient Privacy-Preserving Demand Response Scheme with Adaptive Key Evolution in Smart GridabstractSmart grid has recently emerged as the next generation of power grid due to its distinguished features, such as distributed energy control, robust to load fluctuations, and close user-grid interactions. As a vital component of smart grid, demand response can maintain supply-demand balance and reduce users' electricity bills. Furthermore, it is also critical to preserve user privacy and cyber security in smart grid. In this paper, we propose an efficient privacy-preserving demand response (EPPDR) scheme which employs a homomorphic encryption to achieve privacy-preserving demand aggregation and efficient response. In addition, an adaptive key evolution technique is further investigated to ensure the users' session keys to be forward secure. Security analysis indicates that EPPDR can achieve privacy-preservation of electricity demand, forward secrecy of users' session keys, and evolution of users' private keys. In comparison with an existing scheme which also achieves forward secrecy, EPPDR has better efficiency in terms of computation and communication overheads and can adaptively control the key evolution to balance the trade-off between the communication efficiency and security level. Hongwei Li 0001, Xiaodong Lin 0001, Haomiao Yang, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2014 | Enabling Trustworthy Service Evaluation in Service-Oriented Mobile Social NetworksabstractIn this paper, we propose a Trustworthy Service Evaluation (TSE) system to enable users to share service reviews in service-oriented mobile social networks (S-MSNs). Each service provider independently maintains a TSE for itself, which collects and stores users' reviews about its services without requiring any third trusted authority. The service reviews can then be made available to interested users in making wise service selection decisions. We identify three unique service review attacks, i.e., linkability, rejection, and modification attacks, and develop sophisticated security mechanisms for the TSE to deal with these attacks. Specifically, the basic TSE (bTSE) enables users to distributedly and cooperatively submit their reviews in an integrated chain form by using hierarchical and aggregate signature techniques. It restricts the service providers to reject, modify, or delete the reviews. Thus, the integrity and authenticity of reviews are improved. Further, we extend the bTSE to a Sybil-resisted TSE (SrTSE) to enable the detection of two typical sybil attacks. In the SrTSE, if a user generates multiple reviews toward a vendor in a predefined time slot with different pseudonyms, the real identity of that user will be revealed. Through security analysis and numerical results, we show that the bTSE and the SrTSE effectively resist the service review attacks and the SrTSE additionally detects the sybil attacks in an efficient manner. Through performance evaluation, we show that the bTSE achieves better performance in terms of submission rate and delay than a service review system that does not adopt user cooperation. Xiaohui Liang 0002, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | Selectively iterative particle filtering and its applications for target tracking in WSNsabstractParticle filters (PF) have been widely used in the estimation of the state transition and observation of non-linear/non-Gaussian systems, and samples degeneracy is the main issue of particle filters. In this paper, a novel PF - selectively iterative particle filter (SIPF) is proposed for target tracking in wireless sensor networks (WSNs). There are two novel strategies in SIPF, the statistics based threshold and particles refining. The key insight of SIPF is from an experimental observation that, the more suitable divergence of particles can yield the better estimation. The performance of the proposed SIPF is tested on two theoretical models, and then it is used in a target tracking issue in WSN in the distributed model. Experimental results show that the proposed SIPF can greatly improve the accuracy of object tracking, and in theoretical models the estimation error is only about 10%, while in practical models is only about 25% compared to other existing 9 filtering methods. Hai Zhao 0002, Xiaodong Lin 0001, Xuemin Shen |
GLOBECOM | 3 |
| 2013 | Detecting GPS information leakage in Android applicationsabstractLocation Based Service(LBS) becomes very popular in mobile computing platforms, such as Android. However, it could also leak highly personal information about the phone owner if used by Malwares. It has been witnessed that an increased number of malicious Android applications use LBS to obtain users' locations and transmit them to attackers without users' acknowledgement, causing users' privacy breach. In this paper, we first discuss the common way in which privacy can be breached in Android applications, and then define a classification algorithm for GPS information leakage. Furthermore, we develop a location information leakage detection tool named Brox. Brox is based on dalvik-opcode specification, which uses data flow analysis framework equipped with flow-sensitive, context-sensitive, and inter-procedure techniques to detect potential information leakage path in Android malicious applications. Specifically, Brox uses inter-procedure analysis and dependency calculation to understand the intention for each sensitive operation; by using reachable analysis, connection between privacy access operation and leakage operation is established. More importantly, Brox confirms whether the sending out operation contains location information or not using static taint analysis. At last, we classify the detection results with the help of identification of interaction and non-user interaction entry points in order to discover stealthy leaks of GPS location. The extensive experiments results show that the proposed method can effectively detect privacy leakage in Android applications with a high accuracy rate. Zhushou Tang, Qiuyu Xiao, Jiafa Liu, Tran Triet Duong, Xiaodong Lin 0001, Haojin Zhu |
GLOBECOM | 6 |
| 2013 | RECCE: A reliable and efficient cloud cooperation scheme in E-healthcareabstractE-healthcare is an emerging and promising healthcare system to meet the increasing medical demand from aging population. It requires extensive data storage, pervasive data access, and reliable computing resources to support the real-time communication of critical health information and the real-time diagnosis. Recently, cloud computing, including public cloud and private cloud, with both scalability and accessibility is proposed to be integrated in the e-healthcare system. However, in meeting stringent medical requirements, private clouds lack necessary reliability, whereas public clouds suffer from communication delay. In this paper, we first introduce a cooperation framework to address the distinct challenger facing different clouds. It is inspired by the fact that private clouds are geographically deployed and public clouds can be regarded to possess infinite computing resources. In our framework, private clouds are designed to serve parts of local requests to public clouds, and rewarded by receiving help with excess requests. We adopt stochastic control theory to address the failure minimization issues for private clouds under random demand process. We prove the optimality of a policy constructed through recursion. Numerical and simulation results are presented to demonstrate that our proposed scheme can improve the reliability of private clouds, as well as reduce average delay of public clouds. Qinghua Shen, Xiaohui Liang 0002, Xuemin Shen, Xiaodong Lin 0001, Henry Y. Luo |
GLOBECOM | 4 |
| 2013 | Secure and effective image storage for cloud based e-healthcare systemsabstractFor a cloud based system, storage volume, users' privacy and computing capacity are three key issues. In this paper we propose a secure and effective cloud based image storage framework for e-healthcare systems with images transmission and storage. The main contribution of the proposed framework is a high compression ratio method for encrypted images. We first analyze the difficulties of encrypted image compression and discuss the drawbacks of current compressive sensing (CS) based encrypted image compression. Then we propose a novel lossy encrypted image compression method, which is based on the CS, dictionary coding, and recent sparse couple reconstruction theories. The experiment results show that compared to state-of-the-art encrypted image compression methods and classical JPEG/JPEG2000 compression methods, the proposed scheme can achieve much higher compression ratio of JPEG2000 with the similar reconstruction quality, meanwhile can obtain much better reconstruction quality than CS based methods with a similar compression ratio. Chunhe Song, Xiaodong Lin 0001, Xuemin Shen |
GLOBECOM | 2 |
| 2013 | Joint optimization of spectrum sensing and dynamic spectrum access systemabstractThis paper investigates the effects of spectrum sensing errors on the performance of cognitive radio based dynamic spectrum access system (CR-DSA). We first analyze the DSA process with imperfect sensing information by a continuous-time Markov chain (CTMC) model, and then derive the performance metrics with respect to the sensing errors. To alleviate effect of errors in the spectrum sensing process on the system performance, we propose a joint optimization of the spectrum sensing and DSA process. The design is based on the observation that there exists the unique optimal false alarm (FA) probability/miss detection (MD) probability such that the achievable throughput of secondary system maximal. To find the optimal FA probability, a gradient information based algorithm is proposed, and simulation results reveal a significant performance improvement by virtue of the proposed algorithm. Ye Wang 0002, Bin Cao 0003, Xiaodong Lin 0001, Qinyu Zhang 0001 |
GLOBECOM | 3 |
| 2013 | Analysis on dynamic of node storage in space delay/disruption tolerant networkingabstractDelay/Disruption Tolerant Networking (DTN) architecture is expected to play a promising role in future deep space missions. Scientific data interactions over space DTN involve several hops inevitable, since simultaneous and direct connectivity among all intermediate nodes are becoming more difficult in space scenarios. Therefore, the characteristics and capabilities of the node storage are vital factors for the quality of data delivery over space DTN. This paper proposes an analytical framework based on multi-dimension Markov chain to evaluate the dynamic on storage of intermediate nodes in space DTN. According to the proposed framework, we develop a delay model and consequently a success probability model for bundles delivery over space DTN, both of which are dependent closely on the sojourn time in node storages. The numerical results show that: a) dividing source-file data into bigger bundles can bring longer high-storage-occupancy time on intermediary nodes; b) the shorter storage occupation time of node is more susceptible to the bundle sizes than to LTP segment sizes. c) the delivery success probability of the bundles is more dependent on smaller DTN bundles than on LTP segment sizes given the constrains on Time-to-live of bundles in space missions. Hongbing Li, Zhihua Yang, Jian Jiao 0001, Qinyu Zhang 0001, Ruhai Wang, Xiaodong Lin 0001 |
ICC | 6 |
| 2013 | Effective epidemic control and source tracing through mobile social sensing over WBANsabstractAccurate and real-time tracing of epidemic sources is critical for epidemic origin analyses and control when outbreaks of epidemic diseases occur. Such tracing requires the simultaneous availability of information about social interactions among people as well as their body vital signs. Existing epidemic control methods are limited due to their inability to collect the above two types of information at the same time. In this paper, for the first time, we propose integrating wireless body area networks (WBANs) for body vital signs collection with mobile phones for social interaction sensing to achieve the desired epidemic source tracing. In particular, we design a mobile phone capability driven hierarchical social interaction detection framework integrated with WBANs. With this framework, we further propose a set of epidemic source tracing and control algorithms including genetic algorithm based search and dominating set identification algorithms to effectively identify epidemic sources and inhibit epidemic spread. We have also conducted extensive simulations, analyses, and case studies based on real data sets, which demonstrate the accuracy and effectiveness of our proposed solutions. Zhaoyang Zhang 0001, Honggang Wang 0001, Xiaodong Lin 0001, Hua Fang 0001, Dong Xuan |
INFOCOM | 3 |
| 2013 | On optimal communication strategies for cooperative cognitive radio networkingabstractThis work is concerned with enhancement of spectrum-energy efficiency whereby a primary user (PU) engages secondary users (SUs) to relay its transmission in an energy-aware cognitive radio network, i.e., forming a cooperative cognitive radio network (CCRN). The cooperation framework in CCRN can be multiple two-hop relaying with or without PU's direct link transmission using an amplify-and-forward or decode-and-forward mode. In the energy-aware CCRN, an individual cooperating partner attempts to maximize its own utility. The partner selection and parameter optimization, led by the PU, are formulated as two Stackelberg games, namely a sum-constrained power allocation game for two-phase cooperation and a power control game for three-phase cooperation, respectively. Unique Nash Equilibrium is proved and achieved in analytical format for each game. The optimal communication strategy is chosen which achieves the maximum PU utility among different optimal communication strategies. Moreover, an implementation scheme is presented to perform the partner selection and parameter optimization based on the analytical results. Theoretical analysis and performance evaluation show that the proposed CCRN model is a promising framework under which the PU's utility is maximized, while the relaying SUs can attain acceptable utilities. Bin Cao 0003, Jon W. Mark, Qinyu Zhang 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
INFOCOM | 5 |
| 2013 | IPAD: An incentive and privacy-aware data dissemination scheme in opportunistic networksabstractOpportunistic network (OPPNET) is characterized by the intermittent connectivity among mobile nodes from their unpredictable mobility. Although it is promising, there still exist many security and privacy challenges. In this paper, we present an incentive and privacy-aware data dissemination (IPAD) scheme for OPPNETs, not only to exploit how to protect mobile node's identity privacy, location privacy and social profile privacy, but also to provide a secure incentive for privacy-aware data dissemination. Through extensive incentive analysis, we show that only if a source provides a secure incentive strategy, can a data packet be efficiently disseminated in OPPNETs. Rongxing Lu, Xiaodong Lin 0001, Zhiguo Shi 0001, Bin Cao 0003, Xuemin Shen |
INFOCOM | 2 |
| 2013 | EATH: An efficient aggregate authentication protocol for smart grid communicationsabstractThe increasing demands for improving transmission reliability and efficiency have brought us a wide interest in smart grid. In current smart grid research, one of challenges is its security issue. If the security is not well addressed, the concept of smart grid cannot be widely accepted. In this paper, in order to simultaneously resolve the security and efficiency challenges in smart grid communications, we propose an efficient aggregate authentication protocol, called EATH, which is characterized by eliminating the Map-To-Hash hash and reducing the pairing operations in aggregation and verification to improve the computational efficiency. Detailed security analysis has shown that the proposed EATH protocol is secure in terms of source authentication and data integrity in smart grid communications. In addition, performance evaluation also demonstrates its efficiency in terms of low computation and communication overheads. Rongxing Lu, Xiaodong Lin 0001, Zhiguo Shi 0001, Xuemin Shen |
WCNC | 2 |
| 2013 | On symbol mapping for FQPSK modulation enabled Physical-layer Network CodingabstractThe Feher quadrature phase shift keying (FQPSK) modulation based Physical-layer Network Coding (PNC) is investigated in this paper, by which the nonlinear distortion effects resulted from the high power amplifier (HPA) in the system can be avoided. In our presented framework, a novel remapping rule for the FQPSK modulation in the PNC system is proposed to make a better bit error rate (BER) performance. Moreover, a joint demapping-and-demodulation scheme based on Low Density Parity Check (LDPC) is employed to recover the data bits with a low computational burden. Numerical results demonstrate the efficiency of the proposed method. Jiao Qin, Zhihua Yang, Jian Jiao 0001, Qinyu Zhang 0001, Xiaodong Lin 0001, Bin Cao 0003 |
WCNC | 5 |
| 2013 | Fully Anonymous Profile Matching in Mobile Social NetworksabstractIn this paper, we study user profile matching with privacy-preservation in mobile social networks (MSNs) and introduce a family of novel profile matching protocols. We first propose an explicit Comparison-based Profile Matching protocol (eCPM) which runs between two parties, an initiator and a responder. The eCPM enables the initiator to obtain the comparison-based matching result about a specified attribute in their profiles, while preventing their attribute values from disclosure. We then propose an implicit Comparison-based Profile Matching protocol (iCPM) which allows the initiator to directly obtain some messages instead of the comparison result from the responder. The messages unrelated to user profile can be divided into multiple categories by the responder. The initiator implicitly chooses the interested category which is unknown to the responder. Two messages in each category are prepared by the responder, and only one message can be obtained by the initiator according to the comparison result on a single attribute. We further generalize the iCPM to an implicit Predicate-based Profile Matching protocol (iPPM) which allows complex comparison criteria spanning multiple attributes. The anonymity analysis shows all these protocols achieve the confidentiality of user profiles. In addition, the eCPM reveals the comparison result to the initiator and provides only conditional anonymity; the iCPM and the iPPM do not reveal the result at all and provide full anonymity. We analyze the communication overhead and the anonymity strength of the protocols. We then present an enhanced version of the eCPM, called eCPM+, by combining the eCPM with a novel prediction-based adaptive pseudonym change strategy. The performance of the eCPM and the eCPM+ are comparatively studied through extensive trace-based simulations. Simulation results demonstrate that the eCPM+ achieves significantly higher anonymity strength with slightly larger number of pseudonyms than the eCPM. Xiaohui Liang 0002, Xu Li 0001, Kuan Zhang 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
IEEE J. Sel. Areas Commun. | 5 |
| 2013 | SPOC: A Secure and Privacy-Preserving Opportunistic Computing Framework for Mobile-Healthcare EmergencyabstractWith the pervasiveness of smart phones and the advance of wireless body sensor networks (BSNs), mobile Healthcare (m-Healthcare), which extends the operation of Healthcare provider into a pervasive environment for better health monitoring, has attracted considerable interest recently. However, the flourish of m-Healthcare still faces many challenges including information security and privacy preservation. In this paper, we propose a secure and privacy-preserving opportunistic computing framework, called SPOC, for m-Healthcare emergency. With SPOC, smart phone resources including computing power and energy can be opportunistically gathered to process the computing-intensive personal health information (PHI) during m-Healthcare emergency with minimal privacy disclosure. In specific, to leverage the PHI privacy disclosure and the high reliability of PHI process and transmission in m-Healthcare emergency, we introduce an efficient user-centric privacy access control in SPOC framework, which is based on an attribute-based access control and a new privacy-preserving scalar product computation (PPSPC) technique, and allows a medical user to decide who can participate in the opportunistic computing to assist in processing his overwhelming PHI data. Detailed security analysis shows that the proposed SPOC framework can efficiently achieve user-centric privacy access control in m-Healthcare emergency. In addition, performance evaluations via extensive simulations demonstrate the SPOC's effectiveness in term of providing high-reliable-PHI process and transmission while minimizing the privacy disclosure during m-Healthcare emergency. Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2012 | EDR: An efficient demand response scheme for achieving forward secrecy in smart gridabstractCompared with traditional power grid, smart grid has several distinguished features, i.e., distributed energy, large-capacity, robust to load fluctuations, and close consumer-grid interactions. Demand response is vital for smart grid, which is expected to save energy, maintain supply-demand balance, and reduce consumers' electricity bills. Meanwhile, it is paramount important to preserve consumers privacy and cyber security in smart grid. To tackle these challenging issues, in this paper, we propose an efficient demand response (EDR) scheme which utilizes the homomorphic encryption to achieve privacy-preserving demand aggregation and efficient response. Unlike existing schemes, the proposed EDR scheme can also achieve forward secrecy in addition to security features including confidentiality, authenticity and integrity. Extensive analysis demonstrates its security, and efficiency in terms of the computation and communication overhead. Hongwei Li 0001, Xiaohui Liang 0002, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
GLOBECOM | 4 |
| 2012 | Towards addressing group selfishness of cluster-based collaborative spectrum sensing in cognitive radio networksabstractCollaborative spectrum sensing has been recognized as a promising way to ameliorate the sensing performance in cognitive radio networks. Unfortunately, it also introduces some system overhead to users, and as a result some selfish secondary users might be unwilling to contribute to collaborative spectrum sensing. In this paper, we propose a new selfishness model in cluster-based collaborative spectrum sensing, which is referred to Overclaim Selfishness (OS). An OS group may gain benefit by sharing nominally equal but actually much less sensing reports than it declares. To deal with this problem, we propose an Overclaim Selfishness Detection Scheme (OSDS) to detect the potential OS groups. We find that a single secondary user tends to have one special type of sensing reports correlated with his physical location, thus the cluster number estimated by OSDS should be no much less than the number of users the group contains. Further, we adopt an incentive scheme to stimulate rational groups to behave honestly. Finally, a real world experiment is adopted to demonstrate the effectiveness of our proposed scheme OSDS. Yiyong Sun, Zhaoyu Gao, Suguo Du, Haojin Zhu, Xiaodong Lin 0001 |
GLOBECOM | 6 |
| 2012 | A privacy-preserving proximity friend notification scheme with opportunistic networkingabstractRecently, smartphones have revolutionized mobile and pervasive computing around the world, and many smartphone-based applications have been developed to enrich our daily lives, such as location-based application which offers various useful services to its users based on users' current locations like Google Latitude. However, the attractive features of smartphone-based applications inevitably incur higher risks for abuse if such applications and services do not take security and privacy consideration into account prior to it being widely deployment. In this paper, to simultaneously find the proximity friends and protect smartphone users' identity privacy, we utilize the opportunistic networking to propose an efficient privacy-preserving proximity friend notification (PFN) scheme. Specifically, by combining the Bluetooth and 3G techniques of smartphones, a smartphone user can first send his privacy-preserving friend notification packet in a physical proximity area, then once a friend nearby receives and identifies the packet with opportunistic networking, the friend can directly phone back to the user. Detailed security analysis with provable security technique demonstrates the security of the proposed PFN scheme. In addition, extensive simulations have also been conducted to examine its effectiveness in terms of friend notification delay. Chris Carver, Xiaodong Lin 0001 |
ICC | 2 |
| 2012 | Towards a game theoretical modeling of rational collaborative spectrum sensing in Cognitive Radio networksabstractCollaborative spectrum sensing has been proposed recently to improve the sensing performance in Cognitive Radio networks. However, cooperative sensing will also introduce extra cost to the collaborator, such as the cooperative time and energy consumption. In reality, whether the rational secondary users have incentive to join the collaboration depends upon whether the benefit of the collaboration could outweigh the cost. In this paper, we model it as the Cooperative Spectrum Sensing Game (CSSG). In this game, every secondary user could choose to collaborate or not in each time slot, and the payoff is measured in terms of data throughput. Since the effectiveness of collaboration is proportional to the number of the collaborators, secondary users' decisions are based on how many users will choose to collaborate. Thus, CSSG could be modeled as the classic game: the Stag Hunt Game. In addition, to avoid the cooperation failure, we propose Cooperative Communication Incentive Scheme (CCIS) to enhance the collaborative sensing. At last, the numerical analysis about CSSG as well as the proposed scheme CCIS is given. Haojin Zhu, Bo Yang 0006, Cailian Chen, Xin-Ping Guan, Xiaodong Lin 0001 |
ICC | 6 |
| 2012 | Enabling pervasive healthcare with privacy preservation in smart communityabstractSmart community is an emerging Internet of Things application. It supports a variety of high-value automated services such as pervasive healthcare through a multi-hop community network of smart homes in a local residential region. In this paper, we study privacy preserving data communication between patients and an online healthcare provider (referred to as vendor) for efficient remote healthcare monitoring (RHM) in a smart community environment. We adopt patients' attribute structures instead of their identities for authentication and preserve identity privacy during patient-to-vendor communication, and we build a receiver chain among smart homes to enable vendor-to-patient communication and achieve location privacy. The privacy preserving properties of the proposed data communication scheme are analyzed, and its effectiveness and efficiency are demonstrated through extensive simulations. Xiaohui Liang 0002, Xu Li 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
ICC | 4 |
| 2012 | SEER: A Secure and Efficient Service Review System for Service-Oriented Mobile Social NetworksabstractIn this paper, we consider service-oriented mobile social networks (S-MSNs) and propose a Secure and Efficient service Review (SEER) system to enable user feedback. Each service provider independently maintains a SEER system for itself, which collects and stores user reviews about its services without requiring any central trusted authority. The service reviews can then be made available to interested users in making wise service selection decisions. We identify three unique service review attacks and then develop sophisticated security mechanisms for SEER to deal with these attacks. Specifically, SEER enables users to distributedly and cooperatively submit their reviews in an integrated chain form by using hierarchical and aggregate signature techniques. It discourages service providers to reject, modify or delete their reviews. The integrity of reviews is therefore improved. Through security analysis and performance evaluation, we show that SEER effectively resists the service review attacks and achieves significantly better performance in terms of submission rate and delay than a service review system that does not adopt user cooperation or the chain review structure. Xiaohui Liang 0002, Xu Li 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
ICDCS | 4 |
| 2012 | Exploiting prediction to enable Secure and Reliable routing in Wireless Body Area NetworksabstractIn this paper, we propose a distributed Prediction-based Secure and Reliable routing framework (PSR) for emerging Wireless Body Area Networks (WBANs). It can be integrated with a specific routing protocol to improve the latter's reliability and prevent data injection attacks during data communication. In PSR, using past link quality measurements, each node predicts the quality of every incidental link, and thus any change in the neighbor set as well, for the immediate future. When there are multiple possible next hops for packet forwarding (according to the routing protocol used), PSR selects the one with the highest predicted link quality among them. Specially-tailored lightweight source and data authentication methods are employed by nodes to secure data communication. Further, each node adaptively enables or disables source authentication according to predicted neighbor set change and prediction accuracy so as to quickly filter false source authentication requests. We demonstrate that PSR significantly increases routing reliability and effectively resists data injection attacks through in-depth security analysis and extensive simulation study. Xiaohui Liang 0002, Xu Li 0001, Qinghua Shen, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen, Weihua Zhuang |
INFOCOM | 5 |
| 2012 | PReFilter: An efficient privacy-preserving Relay Filtering scheme for delay tolerant networksabstractWithout direct path, information delivery in sparse delay tolerant networks (DTNs) typically relies on intermittent relays, making the transmission not only unreliable but also time consuming. To make the matter even worse, the source nodes may transmit some encrypted “junk” information, similar as the spam emails in current mail systems, to the destinations; without effective control, the delivery of encrypted junk information would significantly consume the precious resource of DTN and accordingly throttle the network efficiency. To address this challenging issue, we propose PReFilter, an efficient privacy-preserving relay filter scheme to prevent the relay of encrypted junk information early in DTNs. In PReFilter, each node maintains a specific filtering policy based on its interests, and distributes this policy to a group of “friends” in the network in advance. By applying the filtering policy, the friends can filter the junk packets which are heading to the node during the relay. Note that the keywords in the filtering policy may disclose the node's interest/preference to some extent, harming the privacy of nodes, a privacy-preserving filtering policy distribution technique is introduced, which will keep the sensitive keywords secret in the filtering policy. Through detailed security analysis, we demonstrate that PReFilter can prevent strong privacy-curious adversaries from learning the filtering keywords, and discourage a weak privacy-curious friend to guess the filtering keywords from the filtering policy. In addition, with extensive simulations, we show that PReFilter is not only effective in the filtering of junk packets but also significantly improve the network performance with the dramatically reduced delivery cost due to the junk packets. Rongxing Lu, Xiaodong Lin 0001, Tom H. Luan, Xiaohui Liang 0002, Xu Li 0001, Xuemin Shen |
INFOCOM | 2 |
| 2012 | HealthShare: Achieving secure and privacy-preserving health information sharing through health social networks
Xiaohui Liang 0002, Mrinmoy Barua, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
Comput. Commun. | 4 |
| 2012 | Public key distribution scheme for delay tolerant networks based on two-channel cryptography
Zhongtian Jia, Xiaodong Lin 0001, Seng-Hua Tan, Lixiang Li 0001, Yixian Yang |
J. Netw. Comput. Appl. | 2 |
| 2012 | Security and privacy in emerging information technologiesabstractAdvances in communication and information technologies including pervasive computer applications, rapid deployments of new wireless networks like 3G, Wifi, WiMAX and their tight coupling to the Internet, have revolutionised our society and really changed every aspect of our lives through a variety of new applications. The rapidly evolving technologies have become ubiquitous, for example, allowing people to stay connected anywhere, anytime via social media services accessed by smartphones, such as Facebook and Twitter. While we experience tremendous benefits from adopting the new technologies, we also continue to face challenges and the biggest challenge is always: how to address security and privacy issues, which may be caused by new technology adoption. This special issue consists of seven papers addressing the security and privacy issues in emerging information technologies such as delay tolerant networking, vehicular communication systems and smartphones and mobile devices. In the first paper, D. Damopoulos, S.A. Menesidou, G. Kambourakis, M. Papadaki, N. Clarke and S. Gritzalis present an evaluation study of anomaly-based IDS for mobile devices using machine learning classifiers. A dataset consisting of iPhone users data log files has been created and various classification and validation methods have been evaluated to assess their effectiveness in detecting misuses. The experimental procedure includes and cross-evaluates four machine learning algorithms (i.e. Bayesian Networks, Radial Basis Function, K-Nearest Neighbours and Random Forest), which classify the behaviour of the end-user in terms of Telephone calls, SMS and Web browsing history. The results acquired are very promising, showing the ability of at least one classifier to detect intrusions with a high True Positive Rate of 99.8%. The second paper, “User Identification and Anonymization in 802.11 Wireless LANs” by D. Xu, Y. Wang, X. Shi, and X. Yin, deals with privacy issues for 802.11 Wireless LAN users. It first proposes a new 802.11 user identification approach through enhanced feature selection and generation. Then, it further studies how to provide user anonymity by introducing a set of 802.11 user anonymisation approaches based on bogus traffic injection. Accountability is a very important topic for computer and networking systems, and a key to achieve accountability is a better logging system, which can capture not only the activities but also their relationships. The third paper, “Accountability using Flow-net: Design, Implementation, and Performance Evaluation” by Y. Xiao, K. Meng and D. Takahashi extends the flow-net methodology, which is a logging mechanism for accountability previously proposed by the authors, and presents its design and implementation in wireless networks. They also evaluate the performance of flow-net and compare it to that of audit log files. The fourth paper, “Modelling Security Message Propagation in Delay Tolerant Networks ” by Z. Jia, S. Li, H. Peng, Y. Yang and S. Guo, proposes a security message propagation model for delay tolerant networks formed by vehicles on the road. The goal of the paper is to evaluate how many public keys should be maintained by each node in order to achieve fast message propagation while single hop authentication scheme is used. Network coding provides an excellent solution to maximise throughput in various networks. Because of its simplicity and high efficiency, the idea of network coding can also be used for designing lightweight key distribution schemes for wireless ad hoc network. The fifth paper, “A key distribution scheme using network coding for mobile ad hoc network” by J. Liu, R. Du, J. Chen and K. He, presents a key distribution scheme that exploits the inherent security properties of network coding. The new scheme relies on simple XOR network coding operations to provide data confidentiality and as well use message authentication codes to guarantee the integrity of the distributed keys. Recently, vehicular ad-hoc network (VANET) has emerged as a promising approach to increasing road safety and efficiency. However, the attractive features of VANET inevitably incur higher risks for abuse if we do not take into account security and privacy considerations before the wide deployment of such network. It would jeopardise the public safety and become the main barrier to the acceptance of such a new technology. The last two papers focus on the security and privacy issues in VANETs. In the sixth paper, “LPA: A New Location-based Privacy-preserving Authentication Protocol in VANET” by X. Xue and J. Ding, a novel location-based authentication protocol for conditional privacy preservation in VANETs is proposed. By utilising location information and layered security scheme, the large storage overhead problem in anonymous certificates-based protocols and the long verification time problem in group signature-based protocols are solved. The seventh paper, “An Efficient Distributed Key Management Scheme for Group Signature based Anonymous Authentication in VANET” by Y. Sun, Z. Feng, Q. Hu and J. Su, proposes a distributed key management (DKM) scheme based on Group Signature for anonymous authentication in VANETs. The goal of the paper is to prevent vehicles from leaking the value of the updated group secret key to the regional group manager during the group key updating process. Subsequently, it can avoid the buck-passing between vehicles and regional group managers when the malicious messages are detected. In closing, we would like to thank all the authors who have submitted their research work to this special issue. We would also like to acknowledge the contribution of many experts in the field who have participated in the review process and provided helpful suggestions to the authors on improving the content and presentation of the papers. We would also like to express our gratitude to the Editor-in-Chief, Dr. Hsiao-Hwa Chen for his support and help in bringing forward this special issue. We hope you will enjoy the papers in this collection. Prof. Xiaodong Lin received the Ph.D. degree in information engineering from Beijing University of Posts and Telecommunications, Beijing, China, in 1998 and the Ph.D. degree (with Outstanding Achievement in Graduate Studies Award) in electrical and computer engineering from the University of Waterloo, Waterloo, ON, Canada, in 2008. He is currently an assistant professor of information security with the Faculty of Business and Information Technology, University of Ontario Institute of Technology, Oshawa, ON, Canada. His research interests include wireless network security, computer forensics, software security, and applied cryptography. Dr. Lin was the recipient of a Natural Sciences and Engineering Research Council of Canada (NSERC) Canada Graduate Scholarships (CGS) Doctoral and the Best Paper Awards of the 18th International Conference on Computer Communications and Networks (ICCCN 2009), the 5th International Conference on Body Area Networks (BodyNets 2010), the 3rd International Conference on Forensic Applications and Techniques in Telecommunications, Information and Multimedia (e-Forensics 2010), and IEEE International Conference on communications (ICC 2007). He is a member of IEEE. Prof. Jianwei Liu received his Ph.D. in communication engineering from Xidian University, China in 1998, and his B.S. and M.S. degrees in electronic engineering from Shandong University, China in 1985 and 1988. He is currently a professor and vice dean of School of Electronic and Information Engineering of Beihang University. His current research interests include the security of wireless and mobile communication network and computer network. He is a senior member of the Chinese Institute of Electronics and director of the Chinese Association for Cryptologic Research. Prof. Stefanos Gritzalis is a Professor at the Dept. of Information and Communication Systems Engineering, University of the Aegean, Greece and the Director of the Lab. of Information and Communication Systems Security. He also serves as the Special Secretary at the Greek Ministry of Administrative Reform and Electronic Governance. He holds a BSc in Physics, an MSc in Electronic Automation, and a PhD in Information and Communications Security from the Dept. of Informatics and Telecommunications, University of Athens, Greece. He has been involved in several national and EU funded R&D projects. His published scientific work includes 30 books or book chapters, 90 journals and more than 120 international refereed conference and workshop papers. The focus of these publications is on Information and Communications Security and Privacy. His most highly cited papers have more than 1,000 citations. He has been involved in more than 30 international conferences and workshops as General Chair or Program Committee Chair. He has served on more than 230 Program Committees of international conferences and workshops. He is an Editor-in-Chief or Editor or Editorial Board member for 15 journals. He has supervised 10 PhD dissertations. He was an elected Member of the Board (Secretary General, Treasurer) of the Greek Computer Society. His professional experience includes senior consulting and researcher positions in a number of private and public institutions. He is a Member of the ACM, and the IEEE. Xiaodong Lin 0001, Jianwei Liu 0001, Stefanos Gritzalis |
Secur. Commun. Networks | 1 |
| 2012 | A Dynamic Privacy-Preserving Key Management Scheme for Location-Based Services in VANETsabstractIn this paper, to achieve a vehicle user's privacy preservation while improving the key update efficiency of location-based services (LBSs) in vehicular ad hoc networks (VANETs), we propose a dynamic privacy-preserving key management scheme called DIKE. Specifically, in the proposed DIKE scheme, we first introduce a privacy-preserving authentication technique that not only provides the vehicle user's anonymous authentication but enables double-registration detection as well. We then present efficient LBS session key update procedures: 1) We divide the session of an LBS into several time slots so that each time slot holds a different session key; when no vehicle user departs from the service session, each joined user can use a one-way hash function to autonomously update the new session key for achieving forward secrecy. 2) We also integrate a novel dynamic threshold technique in traditional vehicle-to-vehicle (V-2-V) and vehicle-to-infrastructure (V-2-I) communications to achieve the session key's backward secrecy, i.e., when a vehicle user departs from the service session, more than a threshold number of joined users can cooperatively update the new session key. Performance evaluations via extensive simulations demonstrate the efficiency and effectiveness of the proposed DIKE scheme in terms of low key update delay and fast key update ratio. Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2012 | EPPA: An Efficient and Privacy-Preserving Aggregation Scheme for Secure Smart Grid CommunicationsabstractThe concept of smart grid has emerged as a convergence of traditional power system engineering and information and communication technology. It is vital to the success of next generation of power grid, which is expected to be featuring reliable, efficient, flexible, clean, friendly, and secure characteristics. In this paper, we propose an efficient and privacy-preserving aggregation scheme, named EPPA, for smart grid communications. EPPA uses a superincreasing sequence to structure multidimensional data and encrypt the structured data by the homomorphic Paillier cryptosystem technique. For data communications from user to smart grid operation center, data aggregation is performed directly on ciphertext at local gateways without decryption, and the aggregation result of the original data can be obtained at the operation center. EPPA also adopts the batch verification technique to reduce authentication cost. Through extensive analysis, we demonstrate that EPPA resists various security threats and preserve user privacy, and has significantly less computation and communication overhead than existing competing approaches. Rongxing Lu, Xiaohui Liang 0002, Xu Li 0001, Xiaodong Lin 0001, Xuemin Shen |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2012 | BECAN: A Bandwidth-Efficient Cooperative Authentication Scheme for Filtering Injected False Data in Wireless Sensor NetworksabstractInjecting false data attack is a well known serious threat to wireless sensor network, for which an adversary reports bogus information to sink causing error decision at upper level and energy waste in en-route nodes. In this paper, we propose a novel bandwidth-efficient cooperative authentication (BECAN) scheme for filtering injected false data. Based on the random graph characteristics of sensor node deployment and the cooperative bit-compressed authentication technique, the proposed BECAN scheme can save energy by early detecting and filtering the majority of injected false data with minor extra overheads at the en-route nodes. In addition, only a very small fraction of injected false data needs to be checked by the sink, which thus largely reduces the burden of the sink. Both theoretical and simulation results are given to demonstrate the effectiveness of the proposed scheme in terms of high filtering probability and energy saving. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Xiaohui Liang 0002, Xuemin Shen |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2011 | An Efficient and Secure User Revocation Scheme in Mobile Social NetworksabstractMobile social network (MSN) is a promising networking and communication platform for users having similar interests (or attributes) to connect and interact with one another. For many recently introduced secure MSN data communication schemes, attribute-based encryption is often adopted to preserve user privacy and prevent outside attackers from eavesdropping. In this paper, we propose an efficient and secure user revocation scheme to address inside attacks based on an attribute-based encryption technique. The proposed scheme enables a trusted authority (TA) to flexibly control the data decryption capability of mobile social users. It disables malicious users from decrypting any data packet. As a result, proper user behavior is encouraged, inside attacks are reduced, and network security is enhanced. Through the analysis, we demonstrate that the proposed user revocation scheme is able to resist attribute collusion attacks and revoke collusion attacks. Extensive simulation results further confirm that the proposed scheme has much smaller communication overhead and much shorter delay than the existing solution [1]. Xiaohui Liang 0002, Xu Li 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
GLOBECOM | 4 |
| 2011 | EVSE: An Efficient Vehicle Social Evaluation Scheme with Location Privacy Preservation for Vehicular CommunicationsabstractSocial-aware data diffusion can improve the dissemination performance in vehicular ad hoc networks (VANETs). However, if some vehicles lie their social claims and vehicle location information is not protected, social-aware data diffusion may not work well. In this paper, to tackle the security and privacy challenges existing in social-aware data diffusion, we propose an efficient vehicle social evaluation (EVSE) scheme, which enables each vehicle to show its authentic social evaluation to others while without disclosing its past location information. As a result, it can meet the prerequisites for the success of social-aware data diffusion in VANET. Abdulelah Alganas, Xiaodong Lin 0001, Ali Grami |
ICC | 2 |
| 2011 | Fine-Grained Identification with Real-Time Fairness in Mobile Social NetworksabstractMutual user identification is a necessary step for trust establishment among users in an unattended mobile social network (MSN). Directly exposing identity information to others unknown may cause total unfairness in identity loss when the other party of the identification process misbehaves. Using an on-line trusted third party (TTP) for user identification will cause communication and security problems, while a traditional off-line TTP solution will generate delay in fairness enforcement. In this paper, we propose a novel fine-grained identification protocol, which provides confidentiality, unlinkability, and real-time fairness without the involvement of TTP. In the protocol, identification is carried out by an iterative identification information exchange process, where two participating users have to disclose part of their identification information to each other in each iteration. The process terminates whenever one of them fails to do so. In this way, if a user loses part of its identification information to another user, then it must have obtained an approximately equal amount of identification information of that user. Therefore, misbehavior is discouraged, and fairness is improved. Through analysis we demonstrate that fairness can be well guaranteed as long as users strictly follow the protocol rules. Extensive simulation results further confirm that the proposed protocol can significantly reduce fairness loss in MSN environment. Xiaohui Liang 0002, Xu Li 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
ICC | 4 |
| 2011 | Anonymity Analysis on Social Spot Based Pseudonym Changing for Location Privacy in VANETsabstractLocation privacy is one of the Quality of Privacies (QoP) in vehicular ad hoc network (VANET) and imperative for the VANET's full flourish. Frequent pseudonym changing can provide a promising solution to achieve location privacy, however if the pseudonyms are changed in an improper occasion, the solution is ineffective. In this paper, to improve the effectiveness of this kind of solution, we first introduce the social spot where many vehicles could aggregate, e.g., a road intersection when the traffic light is red or a free parking lot near a shopping mall. We then propose a social spot based pseudonyms changing technique to achieve the location privacy. By taking the anonymity set size as the privacy metric, we develop two anonymity analytic models to quantitatively investigate the location privacy achieved in the technique. The analytical results show that better location privacy can be achieved when a vehicle changes its pseudonyms at some highly social spots, and as a result, the proposed models can be used to assist vehicles to change their pseudonyms for better location privacy at the right moment and place. Rongxing Lu, Xiaodong Lin 0001, Tom H. Luan, Xiaohui Liang 0002, Xuemin Shen |
ICC | 2 |
| 2011 | STAP: A social-tier-assisted packet forwarding protocol for achieving receiver-location privacy preservation in VANETsabstractReceiver-location privacy is an important security requirement in privacy-preserving Vehicular Ad hoc Networks (VANETs), yet the unavailable receiver's location information makes many existing packet forwarding protocols inefficient in VANETs. To tackle this challenging issue, in this paper, we propose an efficient social-tier-assisted packet forwarding protocol, called STAP, for achieving receiver-location privacy preservation in VANETs. Specifically, by observing the phenomena that vehicles often visit some social spots, such as well-traversed shopping malls and busy intersections in a city environment, we deploy storage-rich Roadside Units (RSUs) at social spots and form a virtual social tier with them. Then, without knowing the receiver's exact location information, a packet can be first forwarded and disseminated in the social tier. Later, once the receiver visits one of social spots, it can successfully receive the packet. Detailed security analysis shows that the proposed STAP protocol can protect the receiver's location privacy against an active global adversary, and achieve vehicle's conditional privacy preservation as well. In addition, performance evaluation via extensive simulations demonstrates its efficiency in terms of high delivery ratio and low average delay. Xiaodong Lin 0001, Rongxing Lu, Xiaohui Liang 0002, Xuemin Shen |
INFOCOM | 1 |
| 2011 | A clique-based secure admission control scheme for mobile ad hoc networks (MANETs)
Zubair Md Fadlullah, Xiaodong Lin 0001, Nei Kato |
J. Netw. Comput. Appl. | 3 |
| 2011 | A Secure Handshake Scheme with Symptoms-Matching for mHealthcare Social Network
Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen |
Mob. Networks Appl. | 2 |
| 2011 | A provably secure threshold signature scheme based on DDH assumptionabstractAbstract Threshold signature is an important cryptographic primitive, which was introduced by Desmedt and Frankel in 1991. In a (t, n) threshold signature scheme, a group secret key is distributed among n parties. Later, any t or more parties can use their shares of secret key to generate valid signatures on behalf of the group, while any t−1 or less parties cannot. Over the past years, many excellent threshold signature schemes have been proposed, but few of them provide the provable security proof. Therefore, in this paper, based on Decisional Diffie–Hellman (DDH) assumption, we present a new (t, n) threshold signature scheme and use the techniques from provable security to analyze its security. Copyright © 2010 John Wiley & Sons, Ltd. Xiaodong Lin 0001 |
Secur. Commun. Networks | 1 |
| 2011 | An efficient and provably secure public key encryption scheme based on coding theoryabstractAbstract Although coding‐based public key encryption schemes such as McEliece and Niederreiter cryptosystems have been well studied, it is not a trivial task to design an efficient coding‐based cryptosystem with semantic security against adaptive chosen ciphertext attacks (IND‐CCA2). To tackle this challenging issue, in this paper, we first propose an efficient IND‐CCA2‐secure public key encryption scheme based on coding theory. We then use the provable security technique to formally prove the security of the proposed scheme is tightly related to the syndrome decoding (SD) problem in the random oracle model. Compared with the previously reported schemes, the proposed scheme is merited with simple construction and fast encryption speed. Copyright © 2010 John Wiley & Sons, Ltd. Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen |
Secur. Commun. Networks | 2 |
| 2011 | A secure and efficient RSU-aided bundle forwarding protocol for vehicular delay tolerant networksabstractAbstract Recently, vehicularad hocnetwork (VANET) has emerged as a promising approach for road safety and traffic efficiency improvement through a variety of vehicle applications enabled by communications between vehicles such as emergency braking warning, etc. However, due to its unique characteristics, such as intermittent connectivity due to high‐speed mobility of the network nodes (or vehicles), also known as vehicular delay tolerant network, it poses a major challenge to the realization of those applications. In this paper, we propose a new roadside unit (RSU) aided bundle forwarding protocol for vehicular delay tolerant networks. Furthermore, with the assistance from those RSUs deployed at some critical points on the road, for example, intersections, the proposed protocol can increase the network performance in terms of delivery ratio. At the same time, since vehicle‐to‐vehicle (V2V) and vehicle‐to‐RSU (V2R) privacy‐preserving authentications are guaranteed, the black (gray) hole attacks can be avoided. Extensive simulations demonstrate the effectiveness of the proposed protocol. Copyright © 2010 John Wiley & Sons, Ltd. Xiaodong Lin 0001, Hsiao-Hwa Chen |
Wirel. Commun. Mob. Comput. | 1 |
| 2010 | Secure provenance: the essential of bread and butter of data forensics in cloud computingabstractSecure provenance that records ownership and process history of data objects is vital to the success of data forensics in cloud computing, yet it is still a challenging issue today. In this paper, to tackle this unexplored area in cloud computing, we proposed a new secure provenance scheme based on the bilinear pairing techniques. As the essential bread and butter of data forensics and post investigation in cloud computing, the proposed scheme is characterized by providing the information confidentiality on sensitive documents stored in cloud, anonymous authentication on user access, and provenance tracking on disputed documents. With the provable security techniques, we formally demonstrate the proposed scheme is secure in the standard model. Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen |
AsiaCCS | 2 |
| 2010 | Preventing Traffic Explosion and Achieving Source Unobservability in Multi-Hop Wireless Networks Using Network CodingabstractPrivacy threat is a very serious issue in multi-hop wireless networks (MWNs) since open wireless channels are vulnerable to malicious attacks. Source unobservability is an attractive and desirable security property for many privacy-sensitive applications, and dummy messages are most commonly used to achieve this property. However, dummy messages may incur severe performance degradation or even service denial due to the explosion of network traffic. In this paper, we propose a novel scheme, called SUNC (Source Unobservability by Network Coding), to prevent traffic explosion while achieving source unobservability. With SUNC, specially designed dummy messages can be absorbed at intermediate nodes, and, thus, traffic explosion can be naturally prevented. In addition, SUNC can offer forwarder blindness, which is an important privacy property for thwarting internal attackers. Security analysis and performance evaluation demonstrate the efficacy and efficiency of the proposed SUNC. Yanfei Fan, Jiming Chen 0001, Xiaodong Lin 0001, Xuemin Shen |
GLOBECOM | 3 |
| 2010 | Message Authentication with Non-Transferability for Location Privacy in Mobile Ad hoc NetworksabstractMessage authentication is an effective solution to prevent notorious bogus messages and worm-hole attacks in mobile ad hoc networks (MANET). However, it could also be a double-edge sword threatening mobile users privacy, e.g., location privacy, if the authenticity proofs used in message authentication were abused. In this paper, to prevent such kind of abuse, we first propose a novel efficient message authentication scheme, which can achieve not only users identity privacy but also non-transferability. We then introduce an information theoretical model to gauge the privacy level that the proposed scheme can attain. Extensive simulation results demonstrate the proposed scheme can significantly reduce the violation of mobile users' privacy in MANET. Xiaohui Liang 0002, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
GLOBECOM | 3 |
| 2010 | Sacrificing the Plum Tree for the Peach Tree: A Socialspot Tactic for Protecting Receiver-Location Privacy in VANETabstractIn this paper, to simultaneously protect the receiver-location privacy and improve the performance of packet delivery in VANET, we utilize ``Sacrificing the Plum Tree for the Peach Tree" - one of the Thirty-Six Strategies of Ancient China, to propose a socialspot-based packet forwarding (SPF) protocol, where each vehicle receiver only reveals a non-sensitive socialspot, e.g., a shopping mall, that he often visits as a relay node to help packet forwarding and protect his other sensitive locations privacy. Detailed security analysis demonstrates the security of the proposed SPF protocol. In addition, extensive simulations have also been conducted to examine its good efficiency in terms of packet delivery ratio and average delay. Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen |
GLOBECOM | 2 |
| 2010 | FLIP: An Efficient Privacy-Preserving Protocol for Finding Like-Minded Vehicles on the RoadabstractVehicle chatting is one of the most promising applications in VANETs, which allows like-minded vehicles to chat on the topics of common interest on the road. However, there exist some newly emerging privacy challenging issues in vehicle chatting application, such as how to find a like-minded vehicle on the road and how to prevent one's interest privacy (IP) from others who are not like-minded? In this paper, to tackle these challenging issues, we propose an efficient privacy-preserving \underline{f}inding \underline{l}ike-minded veh\underline{i}cle \underline{p}rotocol (FLIP), and apply the provable security technique to demonstrate its security. In addition, extensive simulations are also conducted to examine its practical considerations, i.e., the relation between the expected IP-preserving level and the delay of finding like-minded vehicles on the road. Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen |
GLOBECOM | 2 |
| 2010 | TESP2: Timed Efficient Source Privacy Preservation Scheme for Wireless Sensor NetworksabstractSource privacy preservation against global eavesdroppers' traffic analysis attack is one of the most challenge issues in wireless sensor networks. In this paper, we present a new timed efficient source privacy preservation (TESP2) scheme. In the TESP2 scheme, each sensor node broadcasts timed data collection request to its upstream nodes, and then each upstream node will return the real data's ciphertext if it has detected something, or a dummy data's ciphertext if it hasn't. After receiving ciphertexts from upstream nodes, the sensor node will filter the dummy data, re-encrypt and forward the real data's ciphertexts to its downstream node to achieve the source privacy preservation. Security analysis and extensive simulation results demonstrate the proposed TESP2 scheme can resist the traffic analysis attack and achieve high source privacy preservation with some tolerant latency. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Xuemin Shen |
ICC | 2 |
| 2010 | A Secure and Efficient Revocation Scheme for Anonymous Vehicular CommunicationsabstractIn this paper, we propose a secure and efficient revocation scheme for anonymous vehicular communications, named SEA. SEA is a pseudonymous authentication scheme, but unlike traditional pseudonymous schemes, its CRL size is linear in terms of the number of revoked vehicles and unrelated to the size of vehicle pseudonymous certificate set. SEA supports certificate regional management and keeps the service overhead of RSUs very low. Furthermore, SEA provides strong privacy preservation against the RSUs so that the adversaries can not trace any vehicle even all RSUs have been compromised. Extensive analysis demonstrates that the proposed scheme outperforms previously reported ones in terms of the revocation cost and the RSUs service overhead. Yipin Sun, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen, Jinshu Su |
ICC | 3 |
| 2010 | Roadside Units Deployment for Efficient Short-Time Certificate Updating in VANETsabstractRoadside Units (RSUs) aided distributed certificate service is a promising approach for ensuring security and privacy preservation in vehicular ad hoc networks (VANETs), where the existence of RSUs is critical for such a scheme in order to allow On-Board Units (OBUs) to update their short-time certificates on time. However, RSUs may only be deployed at some critical points along roads due to the cost. In this paper, we propose a cost-efficient RSUs deployment scheme to guarantee that OBUs at any place could communicate with RSUs in certain driving time (DT), and the extra overhead time (ET) of adjusting routes to update short-time certificate is small. Based on a real-world map, several deployment examples are given illustrating the influence of key factors in RSUs deployment such as wireless communication range, DT and ET. Furthermore, extensive analysis demonstrates that our RSUs deployment scheme can meet the required design goals. Yipin Sun, Xiaodong Lin 0001, Rongxing Lu, Xuemin Shen, Jinshu Su |
ICC | 2 |
| 2010 | SPRING: A Social-based Privacy-preserving Packet Forwarding Protocol for Vehicular Delay Tolerant NetworksabstractIn this paper, we propose a social-based privacy- preserving packet forwarding protocol, called SPRING, for vehicular delay tolerant networks (DTNs). With SPRING, Roadside Units (RSUs) deployed along the roadside can assist in packet forwarding to achieve highly reliable transmissions. In specific, we first heuristically define how to evaluate each traffic intersection's social degree in a vehicular DTN. Based on the social degree information, we then strategically place RSUs at some high-social intersections. As a result, these RSUs can provide tremendous assistance in temporarily storing packets and helping packet forwarding to achieve high delivery ratio. Performance evaluations via extensive simulations demonstrate the SPRING's efficiency. In addition, detailed security analyses show that the proposed SPRING can achieve conditional privacy preservation and resist most attacks existing in vehicular DTNs. Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
INFOCOM | 2 |
| 2010 | An Opportunistic Batch Bundle Authentication Scheme for Energy Constrained DTNsabstractBundle Authentication is a critical security service in Delay Tolerant Networks (DTNs) that ensures authenticity and integrity of bundles during multi-hop transmissions. Public key signatures, which have been suggested in existing bundle security protocol specification, achieve bundle authentication at the cost of an increased computational, transmission overhead and a higher energy consumption, which is not desirable for energy-constrained DTNs. On the other hand, the unique ``store-carry-and-forward'' transmission characteristic of DTNs implies that bundles from distinct/common senders can be buffered opportunistically at some common intermediate nodes. This ``buffering'' characteristic distinguishes DTN from any other traditional wireless networks, for which an intermediate cache is not supported. To exploit such a buffering characteristic, in this paper, we propose an Opportunistic Batch Bundle Authentication Scheme (OBBA) to achieve efficient bundle authentication. The proposed scheme adopts batch verification techniques, allowing a computational overhead to be bounded by the number of opportunistic contacts instead of the number of messages. Furthermore, we introduce a novel concept of a fragment authentication tree to minimize communication cost by choosing an optimal tree height. Finally, we implement OBBA in a specific DTN scenario setting: packet-switched networks on campus. The simulation results in terms of computation time, transmission overhead and power consumption are given to demonstrate the efficiency and effectiveness of the proposed schemes. Haojin Zhu, Xiaodong Lin 0001, Rongxing Lu, Xuemin Shen, Dongsheng Xing, Zhenfu Cao |
INFOCOM | 2 |
| 2010 | PPC: Privacy-Preserving Chatting in Vehicular Peer-to-Peer NetworksabstractIn this paper, a privacy-preserving chatting scheme is proposed to secure vehicular communication and achieve user privacy preservation in vehicular peer- to-peer networks. In specific, we first introduce identity-based-encryption technique which can protect the confidentiality of chatting content. Furthermore, to preserve user privacy, our scheme employs ring signature technique, which not only provides message authentication but also guarantees unconditional source anonymity. With the proposed scheme, vehicles change their pseudo identities periodically and make attackers unable to link users' transactions in different periods. As a result, the proposed scheme can achieve data confidentiality, efficient authentication, and privacy violation elimination. In addition, through detailed security and efficiency analyses, it is demonstrated the proposed scheme resists most of existing attacks in vehicular peer-to-peer networks and provides efficient sending and receiving operations. Xiaohui Liang 0002, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen |
VTC Fall | 3 |
| 2010 | REACT: An RFID-based privacy-preserving children tracking scheme for large amusement parks
Xiaodong Lin 0001, Rongxing Lu, Davis Kwan, Xuemin Shen |
Comput. Networks | 1 |
| 2010 | Pi: a practical incentive protocol for delay tolerant networksabstractDelay Tolerant Networks (DTNs) are a class of networks characterized by lack of guaranteed connectivity, typically low frequency of encounters between DTN nodes and long propagation delays within the network. As a result, the message propagation process in DTNs follows a store-carryand- forward manner, and the in-transit bundle messages can be opportunistically routed towards the destinations through intermittent connections under the hypothesis that each individual DTN node is willing to help with forwarding. Unfortunately, there may exist some selfish nodes, especially in a cooperative network like DTN, and the presence of selfish DTN nodes could cause catastrophic damage to any well designed opportunistic routing scheme and jeopardize the whole network. In this paper, to address the selfishness problem in DTNs, we propose a practical incentive protocol, called Pi, such that when a source node sends a bundle message, it also attaches some incentive on the bundle, which is not only attractive but also fair to all participating DTN nodes. With the fair incentive, the selfish DTN nodes could be stimulated to help with forwarding bundles to achieve better packet delivery performance. In addition, the proposed Pi protocol can also thwart various attacks, which could be launched by selfish DTN nodes, such as free ride attack, layer removing and adding attacks. Extensive simulation results demonstrate the effectiveness of the proposed Pi protocol in terms of high delivery ratio and lower average delay. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Xuemin Shen, Bruno R. Preiss |
IEEE Trans. Wirel. Commun. | 2 |
| 2010 | MDPA: multidimensional privacy-preserving aggregation scheme for wireless sensor networksabstractAbstract In this paper, we propose a novel multidimensional privacy‐preserving data aggregation scheme for improving security and saving energy consumption in wireless sensor networks (WSNs). The proposed scheme integrates the super‐increasing sequence and perturbation techniques into compressed data aggregation, and has the ability to combine more than one aggregated data into one. Compared with the traditional data aggregation schemes, the proposed scheme not only enhances the privacy preservation in data aggregation, but also is more efficient in terms of energy costs due to its unique multidimensional aggregation. Extensive analyses and experiments are given to demonstrate its energy efficiency and practicability. Copyright © 2009 John Wiley & Sons, Ltd. Xiaodong Lin 0001, Rongxing Lu, Xuemin Shen |
Wirel. Commun. Mob. Comput. | 1 |
| 2009 | A Group-Based Key Management Protocol for Mobile Ad Hoc NetworksabstractDue to the dynamic topology and non infrastructure, network participants cooperate with their neighbors to route packets. The lack of centralized services allows mobile ad hoc networks to be easily and swiftly deployed, but make it difficult to check others' identities on the other hand. Cryptographic tools have been introduced to secure group communications, such as private and public key infrastructure. The autonomous and distributed nature of mobile ad hoc network demands a decentralized authentication service, where public key infrastructure is considered a better solution. Public key infrastructure can ensure both confidentiality and authenticity, but it is impractical to provide an online trusted third party as certificate authority (CA) for mobile ad hoc network. In this paper, we proposed a new key management protocol which utilizes certificate graphs and distributed certificate authorities. Certificate graph maintained by each user represents the trust among his neighbors, then the maximum clique of certificate graph is selected to be CAs. Based on the assumption that initial certificate graph building is secure, good users have more friends while bad ones have less, thus a reliable group can be constructed. The most trustful subset of these good users -the maximum clique - is elected as the governor of this group, which takes the responsibility of certificate authentication. Xiaodong Lin 0001, Xuemin Shen, Kazuo Hashimoto, Nei Kato |
GLOBECOM | 2 |
| 2009 | CAT: Building Couples to Early Detect Node Compromise Attack in Wireless Sensor NetworksabstractNode compromise attack is a serious threat to the successful deployment of wireless sensor networks. It is a multiple-stage attack, which usually consists of three stages: physically capturing and compromising sensor nodes; redeploying the compromised nodes back to the sensor network; and compromised sensor nodes rejoining the network and launching attack. Over the last few years, much previous work has tackled the node compromise attack in the late stage, either in the second stage or in the third stage. As a result, the protection measures are often ineffective. In this paper, we will make the first effort on addressing the node compromise problem in the first stage, and present a new couple-based scheme to detect the node compromise attack in early stage. Specifically, after sensor nodes are deployed, they first build couples in ad hoc pattern. Then, the nodes within the same couple can monitor each other to detect any node compromise attempt. Extensive simulation results are given to demonstrate the high detection rate of the proposed scheme. Xiaodong Lin 0001 |
GLOBECOM | 1 |
| 2009 | Location-Release Signature for Vehicular CommunicationsabstractIn this paper, we propose a location-release signature scheme based on bilinear pairings for vehicular ad hoc networks (VANETs). Location-release signature is a capsule signature signed by a source location server that becomes valid after the signature arrives at a specific destination location, where a location server publishes some trapdoor information associated with such a destination location. The scheme can efficiently and effectively resolve the fairness problem in Store-Carry-Forward (S-C-F) communication, which is a very important issue in VANETs. With the provable security techniques, we also demonstrate the proposed scheme is provably secure in the random oracle model. Xiaodong Lin 0001, Rongxing Lu, Xuemin Shen |
ICCCN | 1 |
| 2009 | SPARK: A New VANET-Based Smart Parking Scheme for Large Parking LotsabstractSearching for a vacant parking space in a congested area or a large parking lot and preventing auto theft are major concerns to our daily lives. In this paper, we propose a new smart parking scheme for large parking lots through vehicular communication. The proposed scheme can provide the drivers with real-time parking navigation service, intelligent anti-theft protection, and friendly parking information dissemination. Performance analysis via extensive simulations demonstrates its efficiency and practicality. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Xuemin Shen |
INFOCOM | 2 |
| 2009 | Sage: a strong privacy-preserving scheme against global eavesdropping for ehealth systemsabstractThe eHealth system is envisioned as a promising approach to improving health care through information technology, where security and privacy are crucial for its success and largescale deployment. In this paper, we propose a strong privacy-preserving Scheme against Global Eavesdropping, named SAGE, for eHealth systems. The proposed SAGE can achieve not only the content oriented privacy but also the contextual privacy against a strong global adversary. Extensive analysis demonstrates the effectiveness and practicability of the proposed scheme. Xiaodong Lin 0001, Rongxing Lu, Xuemin Shen, Yoshiaki Nemoto, Nei Kato |
IEEE J. Sel. Areas Commun. | 1 |
| 2008 | BBA: An Efficient Batch Bundle Authentication Scheme for Delay Tolerant NetworksabstractTo realize efficient in-transit messages (bundles) authentication in delay tolerant networks (DTNs), this paper introduces a novel batch bundle authentication (BBA) scheme to validate the bundles in a batch instead of authenticating them one by one. We take the advantage of identity based cryptography to dramatically reduce the transmission cost, and adopt batch signature technique to realize the efficient bundle signature verification. Compared with existing message authentication approaches, our scheme has the superiority on improved efficiency even under the invalid signature attack. Simulation results demonstrate that the proposed scheme can be an enhancement for current bundle security protocol specification. Haojin Zhu, Xiaodong Lin 0001, Rongxing Lu, Xuemin Shen, Pin-Han Ho |
GLOBECOM | 2 |
| 2008 | Provably Secure Self-Certified Partially Blind Signature Scheme from Bilinear PairingsabstractTo enable the practical electronic cash systems, significant attention has been paid to the partially blind signature because of its unlinkability and unforgeability. To the best of our knowledge, most of partially blind signature schemes are constructed under either the traditional public key certificate based system or the ID-based system, which may incur significant efforts in certification management and/or revocation. In this paper, we introduce a novel approach for partially blind signature with self-certified public keys. This is the first research effort for significantly reducing the certificate management and revocation in partially blind signature, and is characterized by the adoption of bilinear pairings and the analytic techniques of provable security. Xiaodong Lin 0001, Rongxing Lu, Haojin Zhu, Pin-Han Ho, Xuemin Shen |
ICC | 1 |
| 2008 | AICN: An Efficient Algorithm to Identify Compromised Nodes in Wireless Sensor NetworkabstractWireless sensor networking is an emerging technology, which potentially supports many emerging applications for both civilian and military purposes, ranging from environmental monitoring to battlefield surveillance. However, since sensor nodes are inexpensive devices, which could be easily compromised and controlled by an adversary, the compromised nodes could report false sensed results and degrade the reliability of the whole network. Therefore, how to identify these compromised nodes in a wireless sensor network is a very important security issue. To solve this problem, we propose an efficient algorithm, called AICN, to logically identify the compromised nodes in an efficient and effective way. Based on the network reliability estimation (NRE), we also present its enhanced version to further improve the efficiency. Rongxing Lu, Xiaodong Lin 0001, Chenxi Zhang 0002, Haojin Zhu, Pin-Han Ho, Xuemin Shen |
ICC | 2 |
| 2008 | RAISE: An Efficient RSU-Aided Message Authentication Scheme in Vehicular Communication NetworksabstractAddressing security and privacy issues is a prerequisite for a market-ready vehicular communication network. Although recent related studies have already addressed most of these issues, few of them have taken scalability issues into consideration. When the traffic density becomes larger, a vehicle cannot verify all signatures of the messages sent by its neighbors in a timely manner, which results in message loss. Communication overhead as another issue has also not been well addressed in previously reported studies. To deal with these issues, this paper introduces a novel RSU-aided messages authentication scheme, called RAISE. With RAISE, roadside units (RSUs) are responsible for verifying the authenticity of the messages sent from vehicles and for notifying the results back to vehicles. In addition, our scheme adopts the k-anonymity approach to protect user identity privacy, where an adversary cannot associate a message with a particular vehicle. Extensive simulations are conducted to verify the proposed scheme, which demonstrates that RAISE yields much better performance than any of the previously reported counterparts in terms of message loss ratio and delay. Chenxi Zhang 0002, Xiaodong Lin 0001, Rongxing Lu, Pin-Han Ho |
ICC | 2 |
| 2008 | AEMA: An Aggregated Emergency Message Authentication Scheme for Enhancing the Security of Vehicular Ad Hoc NetworksabstractTo achieve efficient authentication on emergency events in vehicular ad hoc networks, we introduce a novel aggregated emergency message authentication (AEMA) scheme to validate an emergency event. We make use of syntactic aggregation and cryptographic aggregation techniques to dramatically reduce the transmission cost, and adopt batch verification technique for efficient emergency messages verification. Compared with existing emergency message authentication approaches, our scheme shows the superiority on generality, enhanced security and efficiency. Haojin Zhu, Xiaodong Lin 0001, Rongxing Lu, Pin-Han Ho, Xuemin Shen |
ICC | 2 |
| 2008 | ECPP: Efficient Conditional Privacy Preservation Protocol for Secure Vehicular CommunicationsabstractWe introduce an efficient conditional privacy preservation (ECPP) protocol in vehicular ad hoc networks (VANETs) to address the issue on anonymous authentication for safety messages with authority traceability. The proposed protocol is characterized by the generation of on-the-fly short-time anonymous keys between on-board units (OBUs) and roadside units (RSUs), which can provide fast anonymous authentication and privacy tracking while minimizing the required storage for short-time anonymous keys. We demonstrate the merits gained by the proposed protocol through extensive analysis. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Pin-Han Ho, Xuemin Shen |
INFOCOM | 2 |
| 2008 | An Efficient Identity-Based Batch Verification Scheme for Vehicular Sensor NetworksabstractWith the adoption of state-of-the-art telecommunication technologies for sensing and collecting traffic related information, Vehicular Sensor Networks (VSNs) have emerged as a new application scenario that is envisioned to revolutionize the human driving experiences and traffic flow control systems. To avoid any possible malicious attack and resource abuse, employing a digital signature scheme is widely recognized as the most effective approach for VSNs to achieve authentication, integrity, and validity. However, when the number of signatures received by a Roadside Unit (RSU) becomes large, a scalability problem emerges immediately, where the RSU could be difficult to sequentially verify each received signature within 300 ms interval according to the current Dedicated Short Range Communications (DSRC) broadcast protocol. We introduce an efficient batch signature verification scheme for communications between vehicles and RSUs (or termed vehicle- to-Infrastructure (V2I) communications), in which an RSU can verify multiple received signatures at the same time such that the total verification time can be dramatically reduced. We demonstrate that the proposed scheme can achieve conditional privacy preservation that is essential in VSNs, where each message launched by a vehicle is mapped to a distinct pseudo identity, while a trust authority can always retrieve the real identity of a vehicle from any pseudo identity. With the proposed scheme, since identity-based cryptography is employed in generating private keys for pseudo identities, certificates are not needed and thus transmission overhead can be significantly reduced. Chenxi Zhang 0002, Rongxing Lu, Xiaodong Lin 0001, Pin-Han Ho, Xuemin Shen |
INFOCOM | 3 |
| 2008 | A New Dynamic Group Key Management Scheme with Low Rekeying CostabstractTo achieve secure group communications, it is critical to develop a secure group key management strategy to guarantee security of the group keys. In this paper, based on the forward security and secret sharing techniques, we propose a new dynamic group key management scheme to minimize the rekeying cost. The forward security technique reduces the rekeying operations in joining event, while the secret sharing technique ensures the scalability in leaving event. In addition, the proposed scheme can provide anonymous authentication as well as forward and backward confidentiality. Theoretical analysis also confirms the efficiency of the proposed scheme. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Pin-Han Ho, Xuemin Shen, Zhenfu Cao |
WCNC | 2 |
| 2008 | A Novel Fair Incentive Protocol for Mobile Ad Hoc NetworksabstractTo enhance the overall performance of a mobile ad hoc network (MANET), people have tried to solve the issue of node selfishness, which has sparked a surge of research interests in credit-based incentive protocols. The core idea of credit-based incentive is to provide incentives for selfish nodes to faithfully forward packets in a MANET. Recently, several credit-based incentive protocols have been proposed. However, the fairness issue in those reported credit-based incentive protocols has never been well addressed yet. Without the fairness guarantees, the whole network still cannot reach its optimum cooperative status. Therefore, in this paper, aiming at fairness, we first define the fairness principle for credit-based incentive protocol, and then present a novel fair incentive protocol (FIP) for MANETs. Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Chenxi Zhang 0002, Pin-Han Ho, Xuemin Shen |
WCNC | 2 |
| 2008 | RADAR: A ReputAtion-Based Scheme for Detecting Anomalous Nodes in WiReless Mesh NetworksabstractAs one of the backup measures of intrusion prevention techniques, intrusion detection system (IDS) plays a paramount role in the second defense line of computer networks. Due to the special infrastructure and communication mode, intrusion detection in wireless mesh networks (WMNs) is especially challenging and requires particular design considerations. In this paper, we propose a novel anomaly detection scheme, called RADAR, to detect anomalous mesh nodes in WMNs. Firstly, we introduce a general concept of reputation to characterize and quantify the mesh node's behavior/status in terms of fine-grained performance metrics. This enables us to construct a robust baseline for leveraging and measuring the derivation between normal and anomalous behavior of each mesh node. Secondly, based on reputation management, we develop a cooperative anomaly detection scheme by fully exploring the spatio-temporal properties of mesh nodes' behavior. Our current scheme is specified and implemented with a reactive routing protocol, aiming at detecting malicious mesh nodes which intentionally violate normal routing mechanisms. The simulation results show that our scheme performs well in terms of detection accuracy, false positive rate, computational overhead, and scalability. Zonghua Zhang, Farid Naït-Abdesselam, Pin-Han Ho, Xiaodong Lin 0001 |
WCNC | 4 |
| 2008 | New (t, n) threshold directed signature scheme with provable security
Rongxing Lu, Xiaodong Lin 0001, Zhenfu Cao, Jun Shao 0001, Xiaohui Liang 0002 |
Inf. Sci. | 2 |
| 2008 | TUA: A Novel Compromise-Resilient Authentication Architecture for Wireless Mesh NetworksabstractUser authentication is essential in service-oriented communication networks to identify and reject any unauthorized network access. The state-of-the-art practice in securing wireless networks is based on the authentication, authorization and accounting (AAA) framework where one or multiple identical and duplicated AAA servers are adopted to authenticate mobile users (MUs), handle authorization requests, and collect accounting data. However, the conventional AAA framework cannot tolerate a server compromise event due to misuse, misconfiguration, and malicious access, etc., which may cause serious damages and resource abuses to the network operation. In this paper, we propose a novel design paradigm toward a compromise-resilient authentication architecture in service-oriented wireless mesh networks (WMNs) based on the (t, n) threshold signature technique, termed Threshold User Authentication (TUA) scheme. With the TUA scheme, only t or more out of n AAA servers in the WMN can cooperatively grant the network access to a MU, while any t-1 or less cannot. Detailed protocol-aspect design and implementations are presented. Extensive analysis on efficiency and reliability of authentication functionality is conducted to gain a deeper understanding on the parameter settings and optimization, which demonstrates the effectiveness of the TUA scheme. We conclude that the proposed authentication scheme can contribute to the WMN network design in metropolitan areas where numerous mesh points (MPs) coexist and are managed under a single control plane with multiple distributed AAA servers. Xiaodong Lin 0001, Rongxing Lu, Pin-Han Ho, Xuemin Shen, Zhenfu Cao |
IEEE Trans. Wirel. Commun. | 1 |
| 2008 | TSVC: timed efficient and secure vehicular communications with privacy preservingabstractIn this paper, we propose a Timed Efficient and Secure Vehicular Communication (TSVC) scheme with privacy preservation, which aims at minimizing the packet overhead in terms of signature overhead and signature verification latency without compromising the security and privacy requirements. Compared with currently existing public key based packet authentication schemes for security and privacy, the communication and computation overhead of TSVC can be significantly reduced due to the short message authentication code (MAC) tag attached in each packet for the packet authentication, by which only a fast hash operation is required to verify each packet. Simulation results demonstrate that TSVC maintains acceptable packet latency with much less packet overhead, while significantly reducing the packet loss ratio compared with that of the existing public key infrastructure (PKI) based schemes, especially when the road traffic is heavy. Xiaodong Lin 0001, Xiaoting Sun, Xiao-Yu Wang 0010, Chenxi Zhang 0002, Pin-Han Ho, Xuemin Shen |
IEEE Trans. Wirel. Commun. | 1 |
| 2008 | SLAB: A secure localized authentication and billing scheme for wireless mesh networksabstractThe future metropolitan-area wireless mesh networks (WMNs) are expected to contain compromise-prone Mesh Access Points (MAPs) with a high frequency of inter-domain roaming/handoff events. This paper introduces a novel secure localized authentication and billing (SLAB) scheme, which aims to address both security guarantee and performance in terms of system compromise resilience capability, inter-domain handoff authentication latency, and workload of the roaming broker (RB). With extensive analysis and simulation, we demonstrate that the proposed scheme can be a practical solution for achieving secure roaming and billing in metropolitan-area WMNs. Haojin Zhu, Xiaodong Lin 0001, Rongxing Lu, Pin-Han Ho, Xuemin Shen |
IEEE Trans. Wirel. Commun. | 2 |
| 2007 | Performance Enhancement for Secure Vehicular CommunicationsabstractIn this paper, we propose a new TESLA (timed efficient stream loss-tolerant authentication) based secure vehicular communication (TSVC) protocol with privacy preserving, aiming to achieve less communication overhead without compromising the security and privacy requirements. With TSVC, the communication overhead can be significantly reduced due to the message authentication code (MAC) tag attached in each packet and only a fast hash operation is required to verify each packet. Simulation results show that TSVC maintains acceptable message latency with much smaller packet size while significantly reducing the message loss ratio compared with that by the existing PKI-based protocols especially when the traffic is denser. Xiaodong Lin 0001, Chenxi Zhang 0002, Xiaoting Sun, Pin-Han Ho, Xuemin Shen |
GLOBECOM | 1 |
| 2007 | Secure Localized Authentication and Billing for Wireless Mesh NetworksabstractThe future metropolitan-area wireless mesh networks (WMNs) are expected to have compromise-prone mesh access points (MAPs) with high frequency of inter-domain roaming/handoff events. To achieve security without losing efficiency, this paper introduces a novel secure localized authentication and billing (SLAB) scheme. Our scheme aims to address both security guarantee and performance in terms of system compromise resilience capability, inter-domain handoff authentication latency, and workload of the roaming broker (RB). We demonstrate that the proposed scheme can be a practical solution for achieving secure roaming and billing in metropolitan-area WMNs. Haojin Zhu, Xiaodong Lin 0001, Rongxing Lu, Pin-Han Ho, Xuemin Shen |
GLOBECOM | 2 |
| 2007 | ASRPAKE: An Anonymous Secure Routing Protocol with Authenticated Key Exchange for Wireless Ad Hoc NetworksabstractIn this paper, we present a novel anonymous secure routing protocol for mobile ad hoc networks (MANETs). The proposed protocol not only provides anonymity from all the intermediate nodes, but also integrates the authenticated key exchange mechanisms into the routing algorithm design. Furthermore, a new attack on anonymous services, called snare attack, is introduced, where a compromised node lures a very important node (VIN) into communicating with him and traces back to the VIN by following the route path. An adversary can then snare the VIN and launch decapitation strike on the VIN. Finally, we present a novel DECOY mechanism as a countermeasure to enhance anonymity of VINs and defeat snare attack. Xiaodong Lin 0001, Rongxing Lu, Haojin Zhu, Pin-Han Ho, Xuemin Shen, Zhenfu Cao |
ICC | 1 |
| 2007 | Two-Factor Localized Authentication Scheme for WLAN RoamingabstractIn the paper, we propose an efficient two-factor localized authentication scheme suitable for WLAN roaming. The proposed authentication scheme can greatly improve the security compared with the previously reported counterparts, where two independent factors, such as "what you know" and "what you have", are utilized in the authentication process for a mobile user (MO). Some important issues specific to the wireless environment are considered in the design of the scheme, such as limited computation power, memory space, and battery capacity of mobile stations (MSs), and ping-pong movement problem when roaming across WLANs. The detailed implementation of the proposed scheme is presented, where some of the key performance measures and security are analyzed. Numerical results demonstrate that the proposed scheme can significantly outperform the legacy authentication schemes in terms of signaling overhead, power consumption, and authentication latency without losing the capability of preserving the system security. Xiaodong Lin 0001, Haojin Zhu, Pin-Han Ho, Xuemin Shen |
ICC | 1 |
| 2007 | Secure Vehicular Communications Based on Group Signature and ID-Based Signature SchemeabstractVehicular communication networking is a promising approach of facilitating road safety, traffic management, and infotainment dissemination for drivers and passengers. However, it is subject to various malicious abuses and security attacks which hinder it from practical implementation. In this paper, we propose a novel security protocol based on group signature and identity-based signature scheme to meet the unique requirements of vehicular communication networks. The proposed protocol not only guarantees security and anonymity, but also provides easy traceability property when the identity of the sender of a message has to be revealed by the authority. To further enable Internet access, the network architecture incorporating with the proposed security protocol is introduced. Simulation is conducted to analyze the system performance which proves the feasibility of the proposed scheme. Xiaoting Sun, Xiaodong Lin 0001, Pin-Han Ho |
ICC | 2 |
| 2007 | Towards compromise-resilient localized authentication architecture for wireless mesh networksabstractIn this paper, a novel compromise-resilient localized authentication scheme is proposed for metropolitan-area wireless mesh networks (WMNs), which aims to mitigate the impact caused by a compromise event on one or multiple mesh access points (MAPs) before they are identified and removed from the network. As a proactive mechanism based on a "best practice" strategy - Defence in Depth, the proposed scheme can protect critical WMN functionalities, such as user authentication and handoff support, even in presence of compromised MAPs. Xiaodong Lin 0001, Pin-Han Ho, Xuemin Shen |
QSHINE | 1 |
| 2007 | A keyless facility access control system with wireless enabled personal devicesabstractNowadays, wireless personal devices, such as cell phones and Personal Data Assistants (PDAs), have gradually taken an important part of our daily lives. With two-factor authentication, the wireless personal devices can be further promoted to more security demanding and mission-critical applications, such as e-commerce, home surveillance, and medical monitoring, etc. Facility access is one of applications that have demonstrated a tremendous market potential for replacing the conventional physical key approach. In this paper, we present a novel keyless facility access control system by using wireless personal devices, where the devices serve as a second authentication factor to assure security. The proposed system is not only cost-efficient, but also capable of mitigating security threats existing in the traditional key control system. Furthermore, the proposed authentication protocol is featured in two different authentication processes for the first time and subsequent accesses by using a one-time authentication mechanism based on one-way hash chain while considering the resource constraints of the wireless personal devices and E-lock. Finally, a role-based access control (RBAC) system is adopted to reduce the complexity of key maintenance. Chenxi Zhang 0002, Xiaoting Sun, Xiaodong Lin 0001, Pin-Han Ho |
QSHINE | 3 |
| 2007 | A Novel Compromise-Resilient Authentication System for Wireless Mesh NetworksabstractUser authentication is essential in service-oriented communication networks to identify and reject any unauthorized network access. The state-of-the-art practice in securing wireless networks is based on the technique of authentication, authorization and accounting (AAA) framework where an AAA server is adopted to authenticate mobile users (MUs), handle authorization requests, and collect accounting data. However, the traditional AAA framework is by way of a single authentication server, and cannot tolerate AAA server failure due to various malicious attacks such as denial-of-service (DoS) attack, or any other failure event such that the authentication server is compromised due to misuse, misconfiguration and malicious access, etc. Thus, a more resilient approach is to adopt multiple authentication servers, where any authentication request is handled by more than one authentication servers in order to resist any compromise event of an authentication server. To meet this design objective, we introduce a novel compromise-resilient authentication system based on (t, n) threshold signature technique. With the proposed system, only t or more out of n authentication servers can cooperatively allow a MU to have network access, and any t-1 or less cannot. Case study of reliability analysis is conducted to demonstrate the effectiveness of the system. The proposed authentication system is expected to particularly contribute to wireless mesh networking (WMN) in metropolitan areas where thousands of nodes may coexist and are managed under a single control plane such that duplicated AAA servers are necessary. Xiaodong Lin 0001, Rongxing Lu, Pin-Han Ho, Xuemin Shen, Zhenfu Cao |
WCNC | 1 |
| 2007 | TTP Based Privacy Preserving Inter-WISP Roaming Architecture for Wireless Metropolitan Area NetworksabstractWe propose a novel inter-WISP roaming architecture based on trusted third party (TTP) and partially blind signature technique in wireless metropolitan area networks (WMAN). The proposed architecture aims to not only greatly improve user privacy and identity anonymity even in the presence of cooperation between the wireless Internet service provider (WISPs) and the TTP, but also dramatically reduce the required size of central database devised to minimize any possible service abuse. In addition, an efficient billing scheme among mobile users (MUs), WISPs and TTP, is introduced to address billing issues associated with roaming. Moreover, a localized inter-WISP authentication scheme is also proposed to support seamless handoff. Detailed analysis on a number of important performance metrics, such as computation time, handoff latency and power consumption, is conducted to verify the performance of the proposed schemes. Haojin Zhu, Xiaodong Lin 0001, Pin-Han Ho, Xuemin Shen, Minghui Shi |
WCNC | 2 |
| 2006 | A Novel Voting Mechanism for Compromised Node Revocation in Wireless Ad Hoc NetworksabstractDue to the nature of wireless ad hoc networks such as dynamic infrastructure and non-centralized management, the routing process has a huge exposure to malicious hacking and intrusions. This fact results in a likelihood of node compromise, leading to a disruption of the legitimate network functions/services. Most reported studies in coping with the problem have focused on the effort of protection on route discovery and data transmission against various attacks. In this paper, we solve the problem from a different perspective by targeting the node compromise revocation, i.e., isolating and breaking off the misbehaving nodes. To mitigate the security breaches from internal compromised nodes and eventually eliminate compromised nodes from the wireless ad hoc networks, we propose an energy efficient malicious node removal mechanism. Further, a new attack on routing service called entrap attack is introduced, where an innocent node is incriminated as a malicious node. Xiaodong Lin 0001, Haojin Zhu, Bin Lin 0001, Pin-Han Ho, Xuemin Shen |
GLOBECOM | 1 |