EDBT 2026 Demo / reviewers in the wild / expert
Rui Zhang 0016
dblp:60/2536-16
· DBLP profile ↗
28ranked-venue papers
7as first author
15since 2021 · last 2026
0000-0003-0002-5593ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 1 first-author · 7 since 2021Software engineering, systems software and programming languages · 7 · 4 first-author · 3 since 2021Computer networks · 5 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Survey of Consensus Protocol's Formal VerificationabstractAbstract As blockchain technology is increasingly being applied to various aspects of actual production, higher requirements are being placed on its stability and correctness. As the core logical structure of the blockchain system, the consensus protocol bears the pressure of coordinating, exchanging, and processing information among all parties in the system, and it also requires further improvement. Currently, the improvement and development of the consensus protocol have reached a level that can effectively cope with the pressures and requirements of the current situation. However, with the development of computing technology, the computing power of all parties will continue to improve, and the threat to the consensus protocol will also increase simultaneously. Traditional simulation verification methods may no longer be able to meet existing requirements. More scientific verification methods should be employed when designing protocols to ensure accuracy and reliability. Additionally, a unified induction of the current verification level for each protocol is necessary to facilitate a more comprehensive analysis of future research ideas. This paper begins with an overview of consensus protocols, gathering and summarizing extensive research on the use of formal methods to verify protocol formulas. It analyzes the common properties of these verification protocols, along with their definitions and formal expressions. The paper then examines the methods and tools commonly employed for formal verification, discussing the characteristics of each approach, current research trends, and the challenges that remain to be addressed. Through the analysis of specific case studies, we outline the historical context and current achievements in this area, providing valuable references for future research. Zelin Feng, Rui Zhang 0016 |
Cybersecur. | 2 |
| 2024 | Demo: Enhancing Smart Contract Security Comprehensively through Dynamic Symbolic ExecutionabstractThe frequent security incidents of contracts indicate a pressing need to ensure contract security from deployment to running stages, but the state-of-the-art (SOTA) analysis methods cannot work well for three requirements.(i) Identify contract defective code snippets, while generating exploit call sequences to help developers fix them.(ii) Monitor abnormal call behaviors, especially for multiple continuous transactions.(iii) Validate numerous unexploitable detection results automatically because manual verification is labor-intensive.To tackle these problems, we propose SymX, a symbolic executionbased security analysis art accounting for contract development and running stages.The experiment results demonstrate that it can accurately identify 90.22% of contracts and 98.04% of call transactions, as well as validate misreports as intended, which is superior to SOTAs, thereby protecting contracts better during the contract lifecycle.Currently, SymX is available at https://github.com/Secbrain/SymX. Zhaoxuan Li, Ziming Zhao 0008, Wenhao Li 0005, Rui Zhang 0016, Rui Xue 0001, Siqi Lu, Fan Zhang 0010 |
CCS | 4 |
| 2024 | metaNet: Interpretable unknown mobile malware identification with a novel meta-features mining algorithm
Zhaoxuan Li, Ziming Zhao 0008, Rui Zhang 0016, Wenhao Li 0005, Fan Zhang 0010, Siqi Lu, Rui Xue 0001 |
Comput. Networks | 3 |
| 2024 | DDoS family: A novel perspective for massive types of DDoS attacks
Ziming Zhao 0008, Zhaoxuan Li, Jiongchi Yu, Zhuoxue Song, Xiaofei Xie, Fan Zhang 0010, Rui Zhang 0016 |
Comput. Secur. | 8 |
| 2024 | FOSS: Towards Fine-Grained Unknown Class Detection Against the Open-Set Attack Spectrum With Variable Legitimate TrafficabstractAnomaly-based network intrusion detection systems (NIDSs) are essential for ensuring cybersecurity. However, the security communities realize some limitations when they put most existing proposals into practice. The challenges are mainly concerned with (i) fine-grained unknown attack detection and (ii) ever-changing legitimate traffic adaptation. To tackle these problem, we present three key design norms. The core idea is to construct a model to split the data distribution hyperplane and leverage the concept of isolation, as well as advance the incremental model update. We utilize the isolation tree as the backbone to design our model, named FOSS, to echo back three norms. By analyzing the popular dataset of network intrusion traces, we show that FOSS significantly outperforms the state-of-the-art methods. Further, we perform an initial deployment of FOSS by working with the Internet Service Provider (ISP) to detect distributed denial of service (DDoS) attacks. With real-world tests and manual analysis, we demonstrate the effectiveness of FOSS to identify previously-unseen attacks in a fine-grained manner. Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Xie, Jiongchi Yu, Fan Zhang 0010, Rui Zhang 0016, Binbin Chen 0001, Xiangyang Luo 0001, Ming Hu 0003, Wenrui Ma |
IEEE/ACM Trans. Netw. | 6 |
| 2023 | Poster: Detecting Adversarial Examples Hidden under Watermark Perturbation via Usable Information TheoryabstractImage watermark is a technique widely used for copyright protection. Recent studies show that the image watermark can be added to the clear image as a kind of noise to realize fooling deep learning models. However, previous adversarial example (AE) detection schemes tend to be ineffective since the watermark logo differs from typical noise perturbations. In this poster, we propose Themis, a novel AE detection method against watermark perturbation. Different from prior methods, Themis neither modifies the protected classifier nor requires knowledge of the process for generating AEs. Specifically, Themis leverages usable information theory to calculate the pointwise score, thereby discovering those instances that may be watermark AEs. The empirical evaluations involving 5 different logo watermark perturbations demonstrate the proposed scheme can efficiently detect AEs, and significantly (over 15% accuracy) outperforms five state-of-the-art (SOTA) detection methods. The visualization results display our detection metric is more distinguishable between AEs and non-AEs. Meanwhile, Themis realizes a larger Area Under Curve (AUC) in a threshold-resilient manner, while only introducing ∼0.04s overhead. Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Zhuoxue Song, Fan Zhang 0010, Rui Zhang 0016 |
CCS | 6 |
| 2023 | BPMS: Blockchain-Based Privacy-Preserving Multi-Keyword Search in Multi-Owner SettingabstractSearchable encryption (SE) has emerged as a cryptographic primitive that allows data users to search on encrypted data. Most existing SE schemes usually delegate search operations to an intermediary such as a cloud server, which would inevitably result in single-point failure, privacy leakage, and even untrustworthy results. Several blockchain-based SE schemes have been proposed to alleviate these issues; however, they suffer from some issues, such as the support for multi-keyword multi-owner model, query privacy and data storage availability. In this paper, we propose BPMS, blockchain-based privacy-preserving multi-keyword search in multi-owner setting, which supports searching over encrypted data in trustworthy, private and efficient manners. The attribute Bloom filter has been introduced into our BPMS to build indexes, which protects query privacy and improves index generation performance. To guarantee data storage availability, our BPMS leverages the advantages of IPFS (InterPlanetary File System) to store large scale of encrypted data. Security proof and comparative analysis in theory indicate that our BPMS is more secure and efficient. A series of experiments conducted on a real-world dataset further demonstrate that our BPMS is feasible in practice. Sheng Gao 0002, Yuqi Chen 0022, Jianming Zhu 0002, Zhiyuan Sui, Rui Zhang 0016, XinDi Ma |
IEEE Trans. Cloud Comput. | 5 |
| 2023 | SAGE: Steering the Adversarial Generation of Examples With AccelerationsabstractTo generate image adversarial examples, state-of-the-art black-box attacks usually require thousands of queries. However, massive queries will introduce additional costs and exposure risks in the real world. Towards improving the attack efficiency, we carefully design an acceleration framework SAGE for existing black-box methods, which is composed of sLocator (initial point optimization) and sRudder (search process optimization). The core idea of SAGE in terms of 1) saliency map can guide the perturbations towards the most adversarial direction and 2) exploiting bounding box (bbox) to capture those salient pixels in the black-box attack. Meanwhile, we provide a series of observations and experiments that demonstrate bbox holds model invariance and process invariance. We extensively evaluate SAGE on four state-of-the-art black-box attacks involving three popular datasets (MNIST, CIFAR10, and ImageNet). The results show that SAGE could present fundamental improvements even against robust models that use adversarial training. Specifically, SAGE could reduce >20% of queries and improve the success rate of attacks to 95%~100%. Compared with the other acceleration framework, SAGE fulfills the more significant effect in a flexible, stable, and low-overhead manner. Moreover, our practical evaluation (Google Cloud Vision API) shows SAGE can be applied to real-world scenarios. Ziming Zhao 0008, Zhaoxuan Li, Fan Zhang 0010, Tingting Li 0004, Rui Zhang 0016, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2023 | Distributed Attribute-Based Signature With Attribute Dynamic Update for Smart GridabstractSmart grid is gaining more and more attention as one of the typical applications of Internet of Things. However, in a distributed environment, how to guarantee the privacy of users in electricity trading while ensuring the efficiency of the transactions is one of the urgent issues to be solved. In this article, we propose a distributed attribute-based signature (DABS) scheme for distributed electricity trading, which can support users' free choice of trade objects without revealing their real identities. We construct a signature generation and verification method by taking advantage of the open and hard-to-tamper properties of blockchain to achieve signature verifiability independent of dynamic changes in attributes.To improve the update efficiency, we propose an improved scheme that enables the update complexity to be reduced from$O(n)$to$O(\log n)$, where$n$is the number of users. Finally, performance analysis and simulation experiments demonstrate the security and practicality of the DABS. Qianqian Su, Rui Zhang 0016, Rui Xue 0001, You Sun, Sheng Gao 0002 |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | VulHunter: Hunting Vulnerable Smart Contracts at EVM Bytecode-Level via Multiple Instance LearningabstractWith the economic development of Ethereum, the frequent security incidents involving smart contracts running on this platform have caused billions of dollars in losses. Consequently, there is a pressing need to identify the vulnerabilities in contracts, while the state-of-the-art (SOTA) detection methods have been limited in this regard as they cannot overcome three challenges at the same time. (i) Meet the requirements of detecting the source code, bytecode, and opcode of contracts simultaneously; (ii) reduce the reliance on manual pre-defined rules/patterns and expert involvement; (iii) assist contract developers in completing the contract lifecycle more safely,e.g., vulnerability repair and abnormal monitoring. With the development of machine learning (ML), using it to detect the contract runtime execution sequences (called instances) has made it possible to address these challenges. However, the lack of datasets with fine-grained sequence labels poses a significant obstacle, given the unreadability of bytecode/opcode. To this end, we propose a method named VulHunter that extracts the instances by traversing the Control Flow Graph built from contract opcodes. Based on the hybrid attention and multi-instance learning mechanisms, VulHunter reasons the instance labels and designs an optional classifier to automatically capture the subtle features of both normal and defective contracts, thereby identifying the vulnerable instances. Then, it combines the symbolic execution to construct and solve symbolic constraints to validate their feasibility. Finally, we implement a prototype of VulHunter with 15K lines of code and compare it with 9 SOTA methods on five open source datasets including 52,042 source codes and 184,289 bytecodes. The results indicate that VulHunter can detect contract vulnerabilities more accurately (90.04% accurate rate and 85.60% F1 score), efficiently (only took 4.4 seconds per contract), and robustly (0% analysis failed rate) than the SOTA methods. Also, it can focus on specific metrics such as precision and recall by employing different baseline models and hyperparameters to meet the various user requirements,e.g., vulnerability discovery and misreport mitigation. More importantly, compared with the previous ML-based arts, it can not only provide classification results, defective contract source code statements, key opcode fragments, and vulnerable execution paths, but also eliminate misreports and facilitate more operations such as vulnerability repair and attack simulation during the contract lifecycle. Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Ziming Zhao 0008, Rujin Liang, Rui Xue 0001, Wenhao Li 0005, Fan Zhang 0010, Sheng Gao 0002 |
IEEE Trans. Software Eng. | 3 |
| 2022 | SR-MuSig2: A Scalable and Reconfigurable Multi-signature Scheme and Its Applications
Wenqiu Ma, Rui Zhang 0016 |
Inscrypt | 2 |
| 2022 | SmartFast: an accurate and robust formal analysis tool for Ethereum smart contracts
Zhaoxuan Li, Siqi Lu, Rui Zhang 0016, Rui Xue 0001, Wenqiu Ma, Rujin Liang, Ziming Zhao 0008, Sheng Gao 0002 |
Empir. Softw. Eng. | 3 |
| 2022 | Security and Privacy for Healthcare BlockchainsabstractHealthcare blockchains provide an innovative way to store healthcare information, execute healthcare transactions, and build trust for healthcare data sharing and data integration in a decentralized open healthcare network environment. Although the healthcare blockchain technology has attracted broad interests and attention in industry, government and academia, the security and privacy concerns remain the focus of debate when deploying blockchains for information sharing in the healthcare sector from business operation to research collaboration. This article focuses on the security and privacy requirements for medical data sharing using blockchain, and provides a comprehensive analysis of the security and privacy risks and requirements, accompanied by technical solution techniques and strategies. First, we discuss the security and privacy requirements and attributes required for electronic medical data sharing by deploying the healthcare blockchain. Second, we categorize existing efforts into three reference blockchain usage scenarios for electronic medical data sharing, and discuss the technologies for implementing these security and privacy properties in the three categories of usage scenarios for healthcare blockchain, such as anonymous signatures, attribute-based encryption, zero-knowledge proofs, verification techniques for smart contract security. Finally, we discuss other potential blockchain application scenarios in healthcare sector. We conjecture that this survey will help healthcare professionals, decision makers, and healthcare service developers to gain technical and intuitive insights into the security and privacy of healthcare blockchains in terms of concepts, risks, requirements, development and deployment technologies and systems. Rui Zhang 0016, Rui Xue 0001, Ling Liu 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | A Privacy-Preserving Identity Authentication Scheme Based on the BlockchainabstractTraditional identity authentication solutions mostly rely on a trusted central entity, so they cannot handle single points of failure well. In addition, most of these traditional schemes need to store a large amount of identity authentication or public key information, which makes the schemes difficult to expand and use in distributed situations. In addition, the user prefers to protect the privacy of their information during the identity verification process. Due to the open and decentralized nature of the blockchain, the existing identity verification schemes are difficult to apply well in the blockchain. To solve this problem, in this article, we propose a privacy protection identity authentication scheme based on the blockchain. The user independently generates multiple-identity information, and these identities can be used to apply for an identity certificate. Authorities use the ECDSA signature algorithm and the RSA encryption algorithm to complete the distribution of the identity certificate based on the identity information and complete the registration of identity authentication through the smart contract on the blockchain. On the one hand, it can realize the protection of real identity information; on the other hand, it can avoid the storage overhead caused by the need to store a large number of certificates or key pairs. Due to the use of the blockchain, there is no single point of failure in the authentication process, and it can be applied to distributed scenarios. The security and performance analysis show that the proposed scheme can meet security requirements and is feasible. Sheng Gao 0002, Qianqian Su, Rui Zhang 0016, Jianming Zhu 0002, Zhiyuan Sui |
Secur. Commun. Networks | 3 |
| 2021 | RTChain: A Reputation System with Transaction and Consensus Incentives for E-commerce BlockchainabstractBlockchain technology, whose most successful application is Bitcoin, enables non-repudiation and non-tamperable online transactions without the participation of a trusted central party. As a global ledger, the blockchain achieves the consistency of replica stored on each node through a consensus mechanism. A well-designed consensus mechanism, on one hand, needs to be efficient to meet the high frequency of online transactions. For example, the existing electronic payment systems can handle over 50,000 transactions per second (TPS), while Bitcoin can only handle an average of about 3TPS. On the other hand, it needs to have good security and high fault tolerance; that is, in the case when some nodes are captured by adversaries, the network can still operate normally. In this article, we establish a reputation system, called RTChain, to be integrated into the e-commerce blockchain to achieve a distributed consensus and transaction incentives. The proposed scheme has the following advantages. First, an incentive mechanism is used to influence the consensus behavior of nodes and the transaction behavior of users, which in turn influence the reputation scores of both nodes and users. That is, when a node correctly processes a transaction, it will receive the corresponding reputation value as a reward, and the reputation value will be reduced as punishment not only when the node is dishonest and violates the consensus agreement but also the transaction is not completed as required. Just like electronic transactions in the real world, the higher the reputation of the user, the more likely it is to be selected as the transaction partner. A user with a low reputation will be gradually eliminated in our system because it is difficult to complete the transaction. Second, RTChain uses a verifiable random function to generate the leader in each round, which guarantees fairness for all participants and, unlike PoW, does not consume a large amount of computing resources. Then our consensus mechanism selects the nodes with high reputation scores to reduce the number of nodes participating in the consensus, thus improving the consensus efficiency, so that RTChain’s throughput can reach 4,000TPS. Third, we built a reputation chain to implement the distributed storage and management of reputation. Finally, our consensus mechanism is secure against existing attacks, such as flash attacks, selfish mining attacks, eclipse attacks, and double spending attacks, and allows nodes that participate in the consensus to fail, as long as the reputation of the failure node does not exceed one-third of the total reputation. We build a prototype of RTChain, and the experimental results show that RTChain is promising and deployable for e-commerce blockchains. You Sun, Rui Xue 0001, Rui Zhang 0016, Qianqian Su, Sheng Gao 0002 |
ACM Trans. Internet Techn. | 3 |
| 2020 | Secure Outsourcing Algorithms for Composite Modular Exponentiation Based on Single Untrusted CloudabstractAbstract Modular exponentiation, as a fundamental operation used in many public-key cryptosystems, has always be considered to be very time-consuming. It is difficult for some devices with limited computation capability, such as mobile devices and low-cost radio frequency identification (RFID) tags, to perform large-scale modular exponentiations. In cryptosystems, one typical case of modular exponentiation is that the modulus is a composite number. For instance, in RSA algorithm, the modulus is the product of two distinct prime numbers. In this paper, we investigate how to securely and efficiently outsource composite modular exponentiations and put forward two secure outsourcing algorithms for composite modular exponentiations based on single untrusted cloud. The first algorithm, named MCExp, is designed for outsourcing single composite modular exponentiation, i.e. $u^a$ mod $N$. The second algorithm, named SMCExp, is designed for outsourcing simultaneous composite modular exponentiation, i.e. $\prod ^{n}_{i=1}u^{a_i}_{i}$ mod $N$. Different from algorithms based on two untrusted servers, the proposed algorithms are very practical because they avoid the strong assumption that there must exist two servers without collusion. The proposed algorithms not only protect the privacy of the exponent and the base simultaneously, but also enable users to verify the correctness of the result returned by the cloud with high probability. Compared with using the square-and-multiply algorithm, the user can achieve higher efficiency by using the proposed algorithms. Besides, we prove the security of our algorithms and conduct several experiments to demonstrate the efficiency of the proposed algorithms. Finally, we show that the proposed algorithms can be used to construct the secure outsourcing algorithms for Shamir’s identity-based signature and identity-based multi-signature. Qianqian Su, Rui Zhang 0016, Rui Xue 0001 |
Comput. J. | 2 |
| 2018 | A Decentralizing Attribute-Based Signature for Healthcare BlockchainabstractBlockchain is one of the technology innovations for sharing data across organizations through a peer to peer overlay network. Many blockchain- based data sharing applications, such as sharing Electronic Health Records (EHRs) among different Care Delivery Organizations (CDOs), require privacy preserving verification services with dual capabilities. On one hand, the users want to verify the authenticity of EHR data as well as the identity of the signer. On the other hand, the signer wants to keep his real identity private such that others cannot trace and infer his identity information. However, typical blockchain systems that use pseudonyms as public keys, such as Bitcoin's blockchain, cannot support such privacy-preserving verification. In such systems, it is hard to verify the authenticity of signer's identity, and adversaries or curious parties can guess the real identity from the series of statements and actions taken with a specific pseudonym through inference attacks, such as by transaction graph analysis. In this paper, we propose a decentralized attribute- based signature scheme for healthcare blockchain, which provides efficient privacy-preserving verification of authenticity of EHR data and signer's identity. We also describe a holistic on-chain and off- chain collaborative storage system for efficient storage and verification EHR data. The analysis and experiments show that our scheme is effective and deployable. You Sun, Rui Zhang 0016, Kaiqiang Gao, Ling Liu 0001 |
ICCCN | 2 |
| 2018 | Attribute-based multi-function verifiable computation
Ying Wu 0008, Muhua Liu, Rui Xue 0001, Rui Zhang 0016 |
Future Gener. Comput. Syst. | 4 |
| 2018 | A new audio steganalysis method based on linear prediction
Chunling Han, Rui Xue 0001, Rui Zhang 0016 |
Multim. Tools Appl. | 3 |
| 2018 | Searchable Encryption for Healthcare Clouds: A SurveyabstractOutsourcing medical data and their search services to a third party cloud have been a popular trend for many medical practices, because using healthcare cloud services can help cut down the cost of Electronic Health Records (EHR) systems in terms of front-end ownership cost and IT maintenance burdens. Healthcare cloud applications need searchable encryption with the following two capabilities for protecting data privacy and access privacy: (1) the healthcare providers need to share the encrypted data with authorized users and enable querying over encrypted data, and (2) they also need to keep the query keywords and associated search operations private such that healthcare data hosting service providers cannot gain access to unauthorized content or trace and infer sensitive data stored in the healthcare cloud. This survey paper describes the notion of searchable encryption (SE) in the context of healthcare applications and characterize the SE use cases into four scenarios in healthcare. Then we provide a comprehensive overview of the four representative SE techniques: searchable symmetric encryption (SSE), public key encryption with keyword search (PEKS), attribute-based encryption with keyword search (ABKS), and proxy re-encryption with keyword search (PRES) according to different EHR retrieving scenarios and requirements. We categorize and compare the different SE schemes in terms of their security, efficiency, and functionality. The survey is designed to benefit both experienced researchers in the computer science (CS) field and non-specialists who are domain scientists or healthcare professionals with limited CS and information security background. Thus, we are in favor of technological overview of the state of art searchable encryption models and the underlying key techniques, instead of detailed proofs and constructions of the respective SE algorithms. We describe how the existing SE schemes relate to and differ from one another, and point out the connections between the SE techniques and the security and privacy requirements of healthcare applications and the open research problems. Rui Zhang 0016, Rui Xue 0001, Ling Liu 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2017 | Multi-Client Verifiable Computation Service for Outsourced DataabstractThe introduction of verifiable computation came as a result of the increasingly common phenomenon of "outsourcing" computation to untrusted servers and also to the growing desire of weak clients to outsource computational tasks to more powerful computation services like in cloud computing. Verifiable computation enables a computer to offload the computation of some function, to other perhaps untrusted cloud servers, while maintaining verifiable results. The servers evaluate the function and return the result with a proof that the computation of the function was carried out correctly. In the previous setting of verifiable computation, there is only one data provider. But in practice, there exist scenarios such as a network of sensors where each sensor collects data (e.g. air temperature in a certain area of a city) and stores them on servers. A control unit performs computation (e.g. the average air temperature of the city in certain period) on the outsourced data on the cloud (e.g. Amazon Cloud). When the control unit receives the results, it wants to verify the correctness of the computation results returned by the servers. For this scenario, we define a novel two-server multiclient verifiable computation service framework for outsourced data. An efficient construction is proposed, whose security is based on the existence of one-way functions. There are two advantages in our construction: (1) The size of the proof vouching for the correctness of computation result is independent with the number of data providers. (2) The verification only needs two equality tests executed by one who wants to get the computation result. We also experimentally analyze our construction and show our construction is very efficient in practice. Ying Wu 0008, Rui Zhang 0016, Rui Xue 0001, Ling Liu 0001 |
ICWS | 2 |
| 2017 | Oblivious Multi-Keyword Search for Secure Cloud Storage ServiceabstractOutsource encrypted data has attracted attentions from industry and academics for storing sensitive data in third party clouds. Many cloud applications need privacy preserving multiple keywords search services over encrypted data with dual capabilities. On one hand, they need to keep the query keywords and associated search operations private such that data hosting service providers cannot trace and infer sensitive data stored in the third party data hosting servers. On the other hand, they need to support multiple keywords search to significantly improve the search efficiency. However, current keyword search protocols for encrypted data are not practical with poor privacy and low efficiency. In this paper, we propose a new oblivious multiple keywords search (OMKS) service, which provides privacy for both users and cloud storage service provider and supports efficient multiple keywords search. Compared to previous oblivious keyword search (OKS) protocols, our protocols maintain strong privacy, i.e., database security and query privacy, and effectively support disjunctive and conjunctive keywords search. The analysis and experiments show that OMKS protocols significantly reduce the storage and communication overhead. Moreover, the computation overhead of conjunctive search is not increased with the number of query keywords such that it can performs highly efficient conjunctive keywords search. Rui Zhang 0016, Rui Xue 0001, Ling Liu 0001, Lijuan Zheng |
ICWS | 1 |
| 2017 | Homomorphic MAC from Algebraic One-Way Functions for Network Coding with Small Key SizeabstractNetwork coding is a routing technique that differs from traditional ‘store-and-forward’ mechanisms. It allows intermediate nodes to modify packets in transit. It is well known that network coding can increase throughput and improve robustness in network. However, it is the messages mixing feature that makes network coding susceptive to pollution attacks. To address this problem, homomorphic message authentication codes (MACs) have been proposed. The existing homomorphic MAC schemes adopt inner product to authenticate a message with a tag over a field Fq. In practical instantiations, the size of the field Fq is normally chosen (or desired) to be small (typically set as 28) to limit computational and communication overheads. In these settings, an adversary will break the schemes with probability at least 1/q (typically 1/28). The security is not guaranteed in this case. To waver the limitations and enhance the security, multiple tags are adopted for each message, that certainly incurs large key size overhead and is not preferred in applications. A scheme of homomorphic MAC with preferring security and shorter keys is much expected, and till now, to our knowledge, is not successfully constructed. This work solves this problem by presenting a new homomorphic MAC scheme for authentication in network coding. The proposed scheme allows us to authenticate a message in a linear space over a field of moderate size and at the same time, achieves a reliable security with a short key. The construction is based on a recently invented somewhat public-key notion: algebraic one-way function, by Catalano et al. (TCC 2013). Compared to the existing schemes, our scheme possesses the advantages that it achieves stronger security with much shorter keys, and is practical in applications. Hence resolve the longstanding problem. Ying Wu 0008, Jinyong Chang, Rui Xue 0001, Rui Zhang 0016 |
Comput. J. | 4 |
| 2016 | PVSAE: A Public Verifiable Searchable Encryption Service Framework for Outsourced Encrypted DataabstractOutsource encrypted data is a popular trend for storing sensitive data in third party clouds. Many cloud applications need privacy preserving data encryption services with two capabilities: On one hand, they need querying over encrypted data in Web based data hosting services. On the other hand, they also need to keep the query keywords and associated search operations private such that data hosting service providers cannot gain access to unauthorized content or trace and infer sensitive data stored in the third party data hosting servers. In this paper we present a novel service oriented framework for verifiable searchable asymmetric encryption, called PVSAE. PVSAE offers strong support for outsourced encrypted data with two formal security properties in terms of IND-CKA security and search pattern privacy. Our framework supports two concrete PVSAE schemes. The first scheme l-PVSAE is based on the l-dimensional vectors and achieves strong security notions, namely statistical IND-CKA security and statistical search pattern privacy. The second scheme 3-PVSAE is a light-weight version based on 3-dimensional vectors. 3-PVSAE maintains the strong security properties and offers higher efficiency for search over encrypted data compared with existing verifiable searchable asymmetric encryption schemes. We experimentally evaluate the proposed PVSAE schemes and show that they not only offer strong security but also are practical and deployable. Rui Zhang 0016, Rui Xue 0001, Ting Yu 0001, Ling Liu 0001 |
ICWS | 1 |
| 2016 | Dynamic and Efficient Private Keyword Search over Inverted Index-Based Encrypted DataabstractQuerying over encrypted data is gaining increasing popularity in cloud-based data hosting services. Security and efficiency are recognized as two important and yet conflicting requirements for querying over encrypted data. In this article, we propose an efficient private keyword search (EPKS) scheme that supports binary search and extend it to dynamic settings (called DEPKS ) for inverted index--based encrypted data. First, we describe our approaches of constructing a searchable symmetric encryption (SSE) scheme that supports binary search. Second, we present a novel framework for EPKS and provide its formal security definitions in terms of plaintext privacy and predicate privacy by modifying Shen et al.’s security notions [Shen et al. 2009]. Third, built on the proposed framework, we design an EPKS scheme whose complexity is logarithmic in the number of keywords. The scheme is based on the groups of prime order and enjoys strong notions of security, namely statistical plaintext privacy and statistical predicate privacy. Fourth, we extend the EPKS scheme to support dynamic keyword and document updates. The extended scheme not only maintains the properties of logarithmic-time search efficiency and plaintext privacy and predicate privacy but also has fewer rounds of communications for updates compared to existing dynamic search encryption schemes. We experimentally evaluate the proposed EPKS and DEPKS schemes and show that they are significantly more efficient in terms of both keyword search complexity and communication complexity than existing randomized SSE schemes. Rui Zhang 0016, Rui Xue 0001, Ting Yu 0001, Ling Liu 0001 |
ACM Trans. Internet Techn. | 1 |
| 2015 | An Approach for Mitigating Potential Threats in Practical SSO Systems
Liang Yang 0002, Zimu Yuan, Rui Zhang 0016, Rui Xue 0001 |
Inscrypt | 4 |
| 2014 | Role-based and time-bound access and management of EHR dataabstractABSTRACT Security and privacy are widely recognized as important requirements for access and management of electronic health record (EHR) data. In this paper, we argue that EHR data need to be managed with customizable access control in both spatial and temporal dimensions. We present a role‐based and time‐bound access control (RBTBAC) model that provides more flexibility in both roles (spatial capability) and time (temporal capability) dimensions to control the access of sensitive data. Through algorithmic combination of role‐based access control and time‐bound key management, our RBTBAC model has two salient features. First, we have developed a privacy‐aware and dynamic key structure for role‐based privacy aware access and management of EHR data, focusing on the consistency of access authorization (including data and time interval) with the activated role of user. In addition to role‐based access, a path‐invisible EHR structure is built for preserving privacy of patients. Second, we have employed a time tree method for generating time granule values, offering fine granularity of time‐bound access authorization and control. Our initial experimental results show that tree‐like time structure can improve the performance of the key management scheme significantly, and RBTBAC model is more suitable than existing solutions for EHR data management because it offers high‐efficiency and better security and privacy. Copyright © 2013 John Wiley & Sons, Ltd. Rui Zhang 0016, Ling Liu 0001, Rui Xue 0001 |
Secur. Commun. Networks | 1 |
| 2010 | Security Models and Requirements for Healthcare Application CloudsabstractWith the widespread use of electronic health record (EHR), building a secure EHR sharing environment has attracted a lot of attention in both healthcare industry and academic community. Cloud computing paradigm is one of the popular healthIT infrastructure for facilitating EHR sharing and EHR integration. In this paper we discuss important concepts related to EHR sharing and integration in healthcare clouds and analyze the arising security and privacy issues in access and management of EHRs. We describe an EHR security reference model for managing security issues in healthcare clouds, which highlights three important core components in securing an EHR cloud. We illustrate the development of the EHR security reference model through a use-case scenario and describe the corresponding security countermeasures and state of art security techniques that can be applied as basic security guards. Rui Zhang 0016, Ling Liu 0001 |
IEEE CLOUD | 1 |