Wenmin Li 0001

dblp:60/2420-1 · DBLP profile ↗
← Back
37ranked-venue papers
6as first author
18since 2021 · last 2026
0000-0002-1278-1735ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 9 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 1 since 2021Security and privacy · 6 · 1 first-author · 4 since 2021Systems, architecture and hardware · 4 · 1 since 2021Computer networks · 4 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2
YearPublicationVenuePosition
2026 FedBRDO: A bias-aware and representation-decoupled dynamic optimization framework for federated long-tailed learning
Lujin Zhao, Pengfei Gong, Wenmin Li 0001, Yijie Shi, Zhengping Jin, Su-Juan Qin
Knowl. Based Syst.4
2026 SVA: Towards speech-Enabled vision-Language-Action model
Jiacheng Fan, Xiaohui Ni, Su-Juan Qin, Wenmin Li 0001, Fei Gao 0001
Pattern Recognit.5
2024 Comments on "VERSA: Verifiable Secure Aggregation for Cross-Device Federated Learning"
abstract
Recently, in IEEE Transactions on Dependable and Secure Computing (TDSC), the VERSA scheme proposed by Hahnet al. uses a double aggregation method for verifying the correctness of results returned from the server. The authors proposed that the correctness of the model aggregation can be verified with lower verification overhead by utilizing only a lightweight pseudorandom generator. To support verifiability of results returned from the server, a method of sharing a pair of vectors$(a,b)$by all clients is proposed, which is one of the most important work in VERSA. Unfortunately, in this paper, we show that the method is incorrect, which leads clients to consistently conclude that the aggregated results are incorrect. Furthermore, the model training process in federated learning is forced to abort. Finally, we demonstrate our view through theory analysis and instantiation verification.
Yanxin Xu, Hua Zhang 0001, Shaohua Zhao, Xin Zhang 0120, Wenmin Li 0001, Fei Gao 0001, Kaixuan Li 0007
IEEE Trans. Dependable Secur. Comput.5
2024 NUAT-GAN: Generating Black-Box Natural Universal Adversarial Triggers for Text Classifiers Using Generative Adversarial Networks
abstract
Recent works have demonstrated that text classifiers are vulnerable to universal adversarial triggers (UATs), which are concatenated to any original text from the dataset to mislead text classifiers. Existing methods for generating UATs are limited to a white-box setting, where the adversary needs access to the gradient information about the target model. In the more practical black-box setting, the adversary can only access the logit output of the target model, which increases the difficulty of crafting UATs. In this paper, we propose a framework for generating natural UATs using generative adversarial networks (NUAT-GAN) in the black-box setting. To update parameters of the generator in the black-box setting, we design a training generator algorithm with policy gradient (TGPG), in which the gradient of the target model is replaced with the policy gradient of reinforcement learning. On three text classification datasets, we evaluate the attack and the natural performance of UATs generated on LSTM, CNN and BERT models. Results show that UATs generated by NUAT-GAN can mislead the above models. The average values of the Attack Success Rate (ASR) and GPT-2 Loss of UATs are 0.81 and 9.10, respectively. The UATs can effectively attack online models, such as AllenNLP and ChatGPT. Moreover, we replace the reward given by the discriminator with GPT-2 Loss, the attack and the natural performance of UATs are close to those of NUAT-GAN. This shows that NUAT-GAN is extensible and can combined with the language model.
Hua Zhang 0001, Xin Zhang 0120, Huawei Wang 0001, Wenmin Li 0001, Tengfei Tu
IEEE Trans. Inf. Forensics Secur.6
2023 Privacy Protection Data Retrieval Scheme With Inverted Index for IoT Based on Blockchain
abstract
In the 6G era, Internet of Things (IoT) devices can form a blockchain network, which also faces the problems of data sharing. The data transmitted and stored through the network have the risk of privacy leaking. Encrypting the shared data can satisfy the need of the privacy, and retrieving the encrypted data can make the data used efficiently. However, to enable users to retrieve encrypted data and perform fine-grained authorization on their encrypted files is still a great challenge. Although attribute-based keyword search (ABKS) is a well-received solution to the challenge, there are still privacy and efficiency issues if the traditional ABKS schemes are directly used in blockchain data sharing. In order to solve the problems, this article proposes privacy protection data retrieval scheme with an inverted index, which is an application of attribute-based encryption. First, our scheme is proved secure against the outside keyword guessing attack (KGA) and chosen keyword attack (CKA) under the semitrusted model. Second, the scheme returns a multikeywords ranked result. Third, we analyze the efficiency of our scheme and verify it by simulation. The results show that our scheme has improvement in efficiency and can meet the data sharing needs of the blockchain network composed of IoT devices.
Wenmin Li 0001, Yang Chen 0042, Fei Gao 0001, Shuo Zhang 0008, Hua Zhang 0001, Qiaoyan Wen
IEEE Internet Things J.1
2023 Publishing locally private high-dimensional synthetic data efficiently
Hua Zhang 0001, Kaixuan Li 0007, Xin Zhang 0120, Wenmin Li 0001, Zhengping Jin, Fei Gao 0001, Minghui Gao
Inf. Sci.5
2023 Enhanced covertness class discriminative universal adversarial perturbations
Hua Zhang 0001, Xin Zhang 0120, Wenmin Li 0001, Fei Gao 0001
Neural Networks4
2023 Scalable Fuzzy Keyword Ranked Search Over Encrypted Data on Hybrid Clouds
abstract
Searchable encryption (SE) is a powerful technology that enables keyword-based search over encrypted data becomes possible. However, most SE schemes focus on exact keyword search which can not tolerate misspellings and typos. Existing fuzzy keyword search schemes only support fuzzy search within a limited similarity threshold$d$, the storage cost will grow exponentially or the precision of search results will greatly decrease as$d$increases. Moreover, the current fuzzy keyword ranked search schemes consider only the keyword weight, and disregard the influence of keyword morphology similarity on the ranking. In this article, we propose a scalable fuzzy keyword ranked search scheme over encrypted data under hybrid clouds architecture. We use the edit distance to measure the similarity of keywords and design an edit distance algorithm over encrypted data, in which our scheme achieves fuzzy keyword search for any similarity threshold$d$with a constant storage size and accurate search results. Furthermore, we design a two-factor ranking function combining keyword weight with keyword morphology similarity, which is utilized to rank the search results and enhance system usability. Extensive experiments are performed to demonstrate the trade-off of efficiency and security of the proposed scheme.
Hua Zhang 0001, Shaohua Zhao, Ziqing Guo, Qiaoyan Wen, Wenmin Li 0001, Fei Gao 0001
IEEE Trans. Cloud Comput.5
2022 Secure and Differentiated Fog-Assisted Data Access for Internet of Things
abstract
Abstract The ability of Fog computing to admit and process huge volumes of heterogeneous data is the catalyst for the fast expansion of Internet of things (IoT). The critical challenge is secure and differentiated access to the data, given limited computation capability and trustworthiness in typical IoT devices and Fog servers, respectively. This paper designs and develops a new approach for secure, efficient and differentiated data access. Secret sharing is decoupled to allow the Fog servers to assist the IoT devices with attribute-based encryption of data while preventing the Fog servers from tampering with the data and the access structure. The proposed encryption supports direct revocation and can be decoupled among multiple Fog servers for acceleration. Based on the decisional $q$-parallel bilinear Diffie–Hellman exponent assumption, we propose a new extended $q$-parallel bilinear Diffie–Hellman exponent (E$q$-PBDHE) assumption and prove that the proposed approach provides ‘indistinguishably chosen-plaintext attacks secure’ data access for legitimate data subscribers. As numerically and experimentally verified, the proposed approach is able to reduce the encryption time by 20% at the IoT devices and by 50% at the Fog network using parallel computing as compared to the state of the art .
Wei Ni 0001, Hua Zhang 0001, Ren Ping Liu 0001, Qiaoyan Wen, Wenmin Li 0001, Fei Gao 0001
Comput. J.6
2022 KRTunnel: DNS channel detector for mobile devices
abstract
Nowadays, DNS channel attacks on mobile devices have become a challenging threat. Attackers usually attack mobile devices and steal information with the help of DNS channel. It is difficult for users to detect this kind of attack, especially when attackers covert sensitive information in the DNS response. In this paper, we proposed a method for DNS tunnel detection based on isolated forest for Android. We constructed a framework for mobile devices to collect DNS tunnel traffic. Based on the analysis of DNS tunnel traffic generated on mobile devices, we extracted features based on DNS request and response and constructed the feature set. We proposed a DNS tunnel detector, KRTunnel, for mobile devices. Experiments showed that KRTunnel can identify unseen DNS tunnel traffic with the accuracy of 98.1%.
Senmiao Wang, Luli Sun, Su-Juan Qin, Wenmin Li 0001
Comput. Secur.4
2022 A rORAM scheme with logarithmic bandwidth and logarithmic locality
abstract
Oblivious Random Access Machine (ORAM) is a kind of cryptographic primitive that allows a client to access its private data from the server without disclosing the access pattern. To deal with consecutive requested blocks at a time efficiently, range ORAM (rORAM) is presented. In the previous rORAM scheme, the locality, namely, the number of discontinuous seeks to complete a request, is reduced to O(log2 N), nevertheless, the bandwidth cost is increased to the poly-logarithmic level. Hence, there exists an open question, that is, whether rORAM can be constructed with the same bandwidth efficiency as a regular ORAM, that is, O(log N)-block? In this paper, we propose a new rORAM scheme, called L2-rORAM. In our scheme, a compatible superblock technique is proposed, and it is combined together with an eviction technique for range blocks, so that it avoids duplication of multiple copies and extra dummy access. As a result, it obtains O(log N)-block bandwidth cost, which affirmatively answers the above open question. Meanwhile, the data locality is reduced to O(log N). In addition, the client storage is maintained at the small level of O(log N)-block, and the server storage is maintained at the unexpanded level of O(N)-block. Finally, experimental results show that the average response time of our L2-rORAM is reduced by one order of magnitude over the state-of-the-art rORAM scheme.
Yunping Gong, Fei Gao 0001, Wenmin Li 0001, Hua Zhang 0001, Zhengping Jin, Qiaoyan Wen
Int. J. Intell. Syst.3
2022 Forward privacy multikeyword ranked search over encrypted database
abstract
Dynamic searchable encryption (SE) aims at achieving varied search function over encrypted database in dynamic setting, which is a trade-off in efficiency, security, and functionality. Recent work proposes a file-injection attack which can successfully attack by utilizing some information leaked in the update process. To mitigate this attack, some SE schemes with forward privacy are proposed. However, these schemes are designed to achieve single keyword or conjunctive keyword search, which cannot support multikeyword search. Moreover, these schemes do not consider the function of results ranking. In this paper, we propose a forward privacy multikeyword ranked search scheme over encrypted database. We design a forward privacy multikeyword search scheme based on the classic MRSE scheme. Our scheme makes the cloud cannot obtain the actual match results of the past query with the newly updated files by adding the well-chosen dummy elements to the original index and query vectors. We rank the search results based on the matched keyword number and the T F × I D F $TF\times IDF$ rule in the dynamic setting. Our scheme uses only the symmetric encryption primitive. We implement our scheme for COVID-19 data set and the experimental evaluation results show that the proposed scheme is secure and efficient.
Shaohua Zhao, Hua Zhang 0001, Xin Zhang 0120, Wenmin Li 0001, Fei Gao 0001, Qiaoyan Wen
Int. J. Intell. Syst.4
2022 Generating natural adversarial examples with universal perturbations for text classification
Hua Zhang 0001, Xingguo Yang, Wenmin Li 0001, Fei Gao 0001, Qiaoyan Wen
Neurocomputing4
2022 KRProtector: Detection and Files Protection for IoT Devices on Android Without ROOT Against Ransomware Based on Decoys
abstract
Nowadays, cryptographic ransomware on Android has become one of the most serious threat. They extort users by means of encrypting private data on their devices. Even worse, there exists little files protection solution on IoT devices without ROOT. In light of this, there is an urgent need for countermeasure solutions on IoT devices without ROOT. In this article, we analyze characteristics of cryptographic ransomware. We propose the strategy of files protection against ransomware based on decoys. In order to satisfy the need of files protection on devices without root, we design and implement KRProtector to detect ransomware and protect files based on decoys.
Senmiao Wang, Hua Zhang 0001, Su-Juan Qin, Wenmin Li 0001, Tengfei Tu, Ana Shen
IEEE Internet Things J.4
2022 Practical Attribute-Based Multi-Keyword Ranked Search Scheme in Cloud Computing
abstract
Attribute-based keyword search (ABKS) has a broad developing prospect in providing search service for users and realizing fine-grained access control over ciphertext in the background of cloud computing. However, two open problems prevent further development and application of ABKS. First, most of ABKS schemes suffer from inside keyword guessing attack (KGA) inherently, which is a great threat to the security of the scheme. Second, the existing ABKS schemes focus on single or conjunctive keyword search, these inflexible retrieval modes may lead to efficiency loss caused by inaccurate positioning of user’s interest and greatly reduce user search experience. In this article, we introduce a semi-trusted server and build a dual server model. Based on the dual server model and our proposed techniques, we are the first to put forward an attribute-based multi-keyword ranked search scheme against inside keyword guessing attack (ABKRS-KGA) to solve the mentioned two problems simultaneously. In our scheme, the queries of users contain weighted keywords and the returned files can be ranked according to user’s query interest. We provide strict security definitions for two types of adversaries and we are the first to prove that the construction is adaptively secure against both chosen-keyword attack (CKA) and KGA. Finally, all-side simulation with real-world data set is implemented for the proposed scheme, and the simulation results show that the efficiency of the proposed scheme is acceptable.
Yang Chen 0042, Wenmin Li 0001, Fei Gao 0001, Qiaoyan Wen, Hua Zhang 0001, Huawei Wang 0001
IEEE Trans. Serv. Comput.2
2022 Dynamic Proof of Data Possession and Replication With Tree Sharing and Batch Verification in the Cloud
abstract
Cloud storage attracts a lot of clients to join the paradise. For a high data availability, some clients require their files to be replicated and stored on multiple servers. Because clients are generally charged based on the redundancy level required by them, it is critical for clients to obtain convincing evidence that all replicas are stored correctly and are updated to the up-to-date version. In this article, we propose a dynamic proof of data possession and replication (DPDPR) scheme, which is proved to be secure in the defined security model. Our scheme shares a single authenticated tree across multiple replicas, which reduces the tree's storage cost significantly. Our scheme allows for batch verification for multiple challenged leaves and can verify multiple replicas in a single batch way, which considerably save bandwidth and computation resources during audit process. We also evaluate the DPDPR's performance and compare it with the most related scheme. The evaluation results show that our scheme saves almost 66 percent tree's storage cost for three replicas, and obtains almost 60 and 80 percent efficiency improvements in terms of the overall bandwidth and computation costs, respectively, when three replicas are checked and each challenged with 460 blocks.
Wei Guo 0042, Su-Juan Qin, Fei Gao 0001, Hua Zhang 0001, Wenmin Li 0001, Zhengping Jin, Qiaoyan Wen
IEEE Trans. Serv. Comput.5
2021 Cost-Sensitive Approach to Improve the HTTP Traffic Detection Performance on Imbalanced Data
abstract
Aim. The purpose of this study is how to better detect attack traffic in imbalance datasets. The deep learning technology has played an important role in detecting malicious network traffic in recent years. However, it suffers serious imbalance distribution of data if the traffic model skews towards the modeling in the benign direction, because only a small portion of traffic is malicious, while most network traffic is benign. That is the reason why the authors wrote this manuscript. Methods. We propose a cost-sensitive approach to improve the HTTP traffic detection performance with imbalanced data and also present a character-level abstract feature extraction approach that can provide features with clear decision boundaries in addition. Finally, we design a spark-based HTTP traffic detection system based on these two approaches. Results. The methods proposed in this paper work well in imbalanced datasets. Compared to other methods, the experiment results indicate that our system has F1-score in a high precision. Conclusion. For imbalanced HTTP traffic detection, we confirmed that the method of feature extraction and the cost function is very effective. In the future, we may focus on how to use the cost function to further improve detection performance.
Wenmin Li 0001, Sanqi Sun, Shuo Zhang 0008, Hua Zhang 0001, Yijie Shi
Secur. Commun. Networks1
2021 PPFilter: Provider Privacy-Aware Encrypted Filtering System
abstract
Filtering refers to an operation to determine whether the concerned data should be accepted and transferred, or be blocked and marked as a malicious traffic flow. It mitigates the inter-domain bandwidth overhead, local computational cost and storage cost for data identification. In many sensitive applications, the identity of the data provider needs to be hidden. This creates challenges how to filter the transmitted data packet with an encrypted form. It is non-trivial to hide this data provider's identity while enabling filtering, as the policy used as a matching criteria will need to determine whether the data needs to be transferred or not without knowing the origin of that data. In this work, we designPPFilter, a privacy-aware encrypted filtering mechanism which allows the filtering to be conducted without the need to know the identity of the data provider. PPFilter achieves the integrity protection of the data packets and the provider privacy Level 3. PPFilter is built on top of a novel notion calledidentity-based encryption with sender search (IESS), which supports anonymous sender identity in an encrypted searching. We present a provably secure IESS instantiation, and apply it to achieve a PPFilter protocol. PPFilter allows the data provider's identity to be hidden from both the transferred data and policy while enabling the filtering capability, which solves the aforementioned problem. The analysis and evaluation show that PPFilter maintains cost-reasonable filtering while preserving provider privacy, and hence it guarantees its practicality.
Peng Jiang 0007, Fuchun Guo, Willy Susilo, Man Ho Au, Jianchang Lai, Wenmin Li 0001
IEEE Trans. Serv. Comput.6
2020 Practical Attribute-Based Conjunctive Keyword Search Scheme
abstract
Abstract To date cloud computing may provide considerable storage and computational power for cloud-based applications to support cryptographic operations. Due to this benefit, attribute-based keyword search (ABKS) is able to be implemented in cloud context in order to protect the search privacy of data owner/user. ABKS is a cryptographic primitive that can provide secure search services for users but also realize fine-grained access control over data. However, there have been two potential problems that prevent the scalability of ABKS applications. First of all, most of the existing ABKS schemes suffer from the outside keyword guessing attack (KGA). Second, match privacy should be considered while supporting multi-keyword search. In this paper, we design an efficient method to combine the keyword search process in ABKS with inner product encryption and deploy several proposed techniques to ensure the flexibility of retrieval mode, the security and efficiency of our scheme. We later put forward an attribute-based conjunctive keyword search scheme against outside KGA to solve the aforementioned problems. We provide security notions for two types of adversaries and our construction is proved secure against chosen keyword attack and outside KGA. Finally, all-side simulation with real-world data set is implemented for the proposed scheme, and the results of the simulation show that our scheme achieves stronger security without yielding significant cost of storage and computation.
Yang Chen 0042, Wenmin Li 0001, Fei Gao 0001, Kaitai Liang, Hua Zhang 0001, Qiaoyan Wen
Comput. J.2
2020 New Blind Filter Protocol: An Improved Privacy-Preserving Scheme for Location-Based Services
abstract
Abstract Location-based services have attracted much attention in both academia and industry. However, protecting user’s privacy while providing accurate service for users remains challenging. In most of the existing research works, a semi-trusted proxy is employed to act on behalf of a user to minimize the computation and communication costs of the user. However, user privacy, e.g. location privacy, cannot be protected against the proxy. In this paper, we design a new blind filter protocol where a user can employ a semi-trusted proxy to determine whether a point of interest is within a circular area centered at the user’s location. During the protocol, neither the proxy nor the location-based service provider can obtain the location of the user and the query results. Moreover, each type of query is controlled by an access tree and only the users whose attributes satisfy this access tree can complete the specific type of query. Security analysis and efficiency experiments validate that the proposed protocol is secure and efficient in terms of the computation and communication overhead.
Wenmin Li 0001, Fei Gao 0001, Hua Zhang 0001, Zhengping Jin, Qiaoyan Wen
Comput. J.2
2020 Adaptively secure broadcast encryption with authenticated content distributors
Dianli Guo, Qiaoyan Wen, Wenmin Li 0001, Hua Zhang 0001, Zhengping Jin
Multim. Tools Appl.3
2020 KNN search-based trajectory cloaking against the Cell-ID tracking in cellular network
Yuanbo Cui, Fei Gao 0001, Hua Zhang 0001, Wenmin Li 0001, Zhengping Jin
Soft Comput.4
2020 Comments on "Provable Multicopy Dynamic Data Possession in Cloud Computing Systems"
abstract
Replication is a fundamental solution for the cloud service provider (CSP) to guarantee data availability. To provide users with convincing evidence that the copies required by them are all stored correctly, a number of multi-copy integrity auditing schemes were presented. Recently, Barsoum and Hasan proposed a map-based provable multi-copy dynamic data possession scheme (IEEE Transactions on Information Forensics and Security, vol. 10, no. 3, pp. 485-497, 2015), which was claimed to be secure and can ensure that the CSP possesses all copies required by the contract. However, in this letter, we show that the scheme is easily subject to a copy-summation attack and a single-copy attack, by which a cheating CSP only needs to invest a storage cost of a single copy-while can still pass the verifier's challenge at all times. Therefore, the scheme is no longer secure in this case. Furthermore, we propose some simple but effective countermeasures and give a repaired scheme which is free from the above two attacks.
Wei Guo 0042, Su-Juan Qin, Fei Gao 0001, Hua Zhang 0001, Wenmin Li 0001, Zhengping Jin, Qiaoyan Wen
IEEE Trans. Inf. Forensics Secur.5
2019 Efficient Attribute-Based Data Sharing Scheme with Hidden Access Structures
abstract
Abstract Online data sharing has become a research hotspot while cloud computing is getting more and more popular. As a promising encryption technique to guarantee the security shared data and to realize flexible fine-grained access control, ciphertext-policy attribute-based encryption (CP-ABE) has drawn wide attentions. However, there is a drawback preventing CP-ABE from being applied to cloud applications. In CP-ABE, the access structure is included in the ciphertext, and it may disclose user’s privacy. In this paper, we find a more efficient method to connect ABE with inner product encryption and adopt several techniques to ensure the expressiveness of access structure, the efficiency and security of our scheme. We are the first to present a secure, efficient fine-grained access control scheme with hidden access structure, the access structure can be expressed as AND-gates on multi-valued attributes with wildcard. We conceal the entire attribute instead of only its values in the access structure. Besides, our scheme has obvious advantages in efficiency compared with related schemes. Our scheme can make data sharing secure and efficient, which can be verified from the analysis of security and performance.
Yang Chen 0042, Wenmin Li 0001, Fei Gao 0001, Wei Yin 0004, Kaitai Liang, Hua Zhang 0001, Qiaoyan Wen
Comput. J.2
2019 Outsourced dynamic provable data possession with batch update for secure cloud storage
Wei Guo 0042, Hua Zhang 0001, Su-Juan Qin, Fei Gao 0001, Zhengping Jin, Wenmin Li 0001, Qiaoyan Wen
Future Gener. Comput. Syst.6
2019 An efficient blind filter: Location privacy protection and the access control in FinTech
Wenmin Li 0001, Qiaoyan Wen, Jiageng Chen, Wei Yin 0004, Kaitai Liang
Future Gener. Comput. Syst.2
2019 Authenticated public key broadcast encryption with short ciphertexts
Dianli Guo, Qiaoyan Wen, Zhengping Jin, Hua Zhang 0001, Wenmin Li 0001
Multim. Tools Appl.5
2018 A New Insight - Proxy Re-encryption Under LWE with Strong Anti-collusion
Wei Yin 0004, Qiaoyan Wen, Wenmin Li 0001, Hua Zhang 0001, Zhengping Jin
ISPEC3
2018 Secure multi-keyword ranked search over encrypted cloud data for multiple data owners
Ziqing Guo, Hua Zhang 0001, Caijun Sun, Qiaoyan Wen, Wenmin Li 0001
J. Syst. Softw.5
2018 Attribute-based fuzzy identity access control in multicloud computing environments
Wenmin Li 0001, Qiaoyan Wen, Xuelei Li, Debiao He
Soft Comput.1
2018 An Anonymous Authentication Protocol Based on Cloud for Telemedical Systems
abstract
Telecare medical information systems (TMIS) enable patients to access healthcare delivery services conveniently. With the explosive development occurring in cloud computing and services, storage of personal medical and health information outsourcing to cloud infrastructure has been a potential alternative. However, this has entailed many considerable security and privacy issues. In order to address the security loopholes, we propose a promising solution satisfying the requirements of cloud computing scenarios for telemedical systems. The proposed scheme could provide both data confidentiality and message authenticity while preserving anonymity. Furthermore, the formal security proof demonstrates that the proposed scheme is resistant to various attacks. The performance comparisons show the proposal’s workability and it is well suited to adoption in telemedical services.
Wenmin Li 0001, Shuo Zhang 0008, Qiaoyan Wen, Yang Chen 0042
Wirel. Commun. Mob. Comput.1
2017 Flexible CP-ABE Based Access Control on Encrypted Data for Mobile Users in Hybrid Cloud System
Wenmin Li 0001, Xuelei Li, Qiaoyan Wen, Shuo Zhang 0008, Hua Zhang 0001
J. Comput. Sci. Technol.1
2017 Succinct multi-authority attribute-based access control for circuits with authenticated outsourcing
Jie Xu 0038, Qiaoyan Wen, Wenmin Li 0001, Jian Shen 0001, Debiao He
Soft Comput.3
2016 A strongly secure pairing-free certificateless authenticated key agreement protocol under the CDH assumption
Haiyan Sun, Qiaoyan Wen, Wenmin Li 0001
Sci. China Inf. Sci.3
2016 Circuit Ciphertext-Policy Attribute-Based Hybrid Encryption with Verifiable Delegation in Cloud Computing
abstract
In the cloud, for achieving access control and keeping data confidential, the data owners could adopt attribute-based encryption to encrypt the stored data. Users with limited computing power are however more likely to delegate the mask of the decryption task to the cloud servers to reduce the computing cost. As a result, attribute-based encryption with delegation emerges. Still, there are caveats and questions remaining in the previous relevant works. For instance, during the delegation, the cloud servers could tamper or replace the delegated ciphertext and respond a forged computing result with malicious intent. They may also cheat the eligible users by responding them that they are ineligible for the purpose of cost saving. Furthermore, during the encryption, the access policies may not be flexible enough as well. Since policy for general circuits enables to achieve the strongest form of access control, a construction for realizing circuit ciphertext-policy attribute-based hybrid encryption with verifiable delegation has been considered in our work. In such a system, combined with verifiable computation and encrypt-then-mac mechanism, the data confidentiality, the fine-grained access control and the correctness of the delegated computing results are well guaranteed at the same time. Besides, our scheme achieves security against chosen-plaintext attacks under the k-multilinear Decisional Diffie-Hellman assumption. Moreover, an extensive simulation campaign confirms the feasibility and efficiency of the proposed solution.
Jie Xu 0038, Qiaoyan Wen, Wenmin Li 0001, Zhengping Jin
IEEE Trans. Parallel Distributed Syst.3
2015 An anonymous and efficient remote biometrics user authentication scheme in a multi server environment
Peng Jiang 0007, Qiaoyan Wen, Wenmin Li 0001, Zhengping Jin, Hua Zhang 0001
Frontiers Comput. Sci.3
2012 An efficient and secure mobile payment protocol for restricted connectivity scenarios in vehicular ad hoc network
Wenmin Li 0001, Qiaoyan Wen, Zhengping Jin
Comput. Commun.1