EDBT 2026 Demo / reviewers in the wild / expert
Xu Yang 0002
dblp:63/1534-2
· DBLP profile ↗
41ranked-venue papers
13as first author
27since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 3 first-author · 9 since 2021Computer networks · 11 · 2 first-author · 7 since 2021Systems, architecture and hardware · 8 · 5 first-author · 4 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | eBPF-Guard: a detection method for container escape via multi-level monitoring and enhanced analysis model
Xiaotang Lin, Zhide Chen, Wencheng Yang, Xuechao Yang, Xu Yang 0002 |
Empir. Softw. Eng. | 6 |
| 2026 | Quantum-Based Two-Factor Authentication Protocol for Blockchain-Aided Internet-of-Medical-Things
Zhaofeng Huang, Yuhong Ke, Xu Yang 0002, Xuechao Yang, Jer Shyuan Ng, Jingqiang Lin 0001 |
IEEE Internet Things J. | 3 |
| 2026 | Smart Lock Cybersecurity: A Comprehensive Review of Cross-Layer Threats and Defense Mechanisms
Zhide Chen, Chao Lin 0003, Xu Yang 0002, Wencheng Yang, Xuechao Yang |
IEEE Internet Things J. | 4 |
| 2026 | Transferable adversarial attacks on human pose estimation: A regularization and pruning frameworkabstractHuman Pose Estimation (HPE) is a core component in real-time decision systems, supporting critical applications such as healthcare monitoring, autonomous driving, and sports analytics. While deep learning models—particularly CNNs and Transformer-based architectures—have significantly improved HPE accuracy, they remain vulnerable to adversarial perturbations that subtly distort keypoint localization, thereby undermining system reliability. To address this challenge, we propose regularization and pruning transferable adversarial attack (RPA), a novel framework designed to enhance the transferability of adversarial samples in Transformer-based HPE models. RPA integrates two synergistic strategies: gradient regularization, which suppresses dominant feature correlations to reduce overfitting, and adaptive weight pruning, which removes redundant parameters to reduce model-specific noise. This dual mechanism enables the generation of transferable adversarial attacks that are effective across diverse model architectures. Extensive experiments on state-of-the-art HPE networks demonstrate that RPA consistently outperforms existing attack methods. In white-box settings, RPA reduces average precision (AP) by 0.05-0.30; in black-box scenarios, it yields AP drops of 0.01-0.04. These findings expose critical vulnerabilities in IoT-enabled HPE applications and establish a new benchmark for evaluating adversarial robustness in real-time perception systems. Renguang Chen, Xuechao Yang, Xun Yi, Zhide Chen, Chen Feng 0036, Xu Yang 0002, Iqbal Gondal |
Inf. Sci. | 6 |
| 2026 | A lightweight privacy-preserving fingerprint authentication system for IoT devices via pruned and secured minutia cylinder codeabstractFingerprint authentication is extensively adopted due to its ease of capture, low cost sensors and high recognition accuracy. The Minutia Cylinder Code (MCC) is a high-quality feature representation widely used in fingerprint authentication. However, there are two main limitations in the direct use of MCC: redundancy in the feature representation due to overlap between minutiae vicinities, which can lead to inefficient resource utilization; and vulnerability to template inversion attacks, which may expose the original fingerprint data and threaten user privacy. In this paper, we propose a lightweight privacy-preserving fingerprint authentication system that overcomes these limitations through two novel algorithms. The first algorithm, P-MCC, uses the Pearson correlation coefficient to prune MCC features to effectively reduce redundancy and improve resource utilisation, yielding a lightweight design. The second algorithm, S-MCC, applies a secure Boolean function which transforms the pruned MCC features non-invertibly to ensure privacy, thus preventing the reconstruction of original fingerprint data. Together, P-MCC and S-MCC provide a lightweight privacy-preserving fingerprint authentication system, which is well suited to resource-constrained environments, such as the Internet of Things (IoT). Experimental results demonstrate the effectiveness of the proposed system and its practicality in IoT applications. Wencheng Yang, Song Wang 0003, Yan Li 0002, Di Wu 0050, Ji Zhang 0001, Xu Yang 0002 |
J. Inf. Secur. Appl. | 6 |
| 2026 | Toward Personalized Federated Meta-Learning With Constrained Hypernetwork on Non-IID DataabstractPersonalized Federated Learning (pFL) tailors models to each client’s local data distribution in heterogeneous federated learning settings. Federated Meta-Learning (FML) is a branch of pFL that uses meta-learning to achieve fast adaptation, where clients start with a meta-model and personalize it by fine-tuning it with local data. Since a single global meta-model has limitations when the data distribution of clients varies significantly, meta-model personalization should be considered in FML. However, most benchmark pFL methods lack meta-model personalization, and usually lack meta-learning or relying on a single global meta-model. Besides, these methods can neither provide meta-model personalization nor guarantee generalization and convergence, due to the challenges in measuring the distance between the meta-model and the client model in FML. To address these issues, we combine FML with hypernetwork and propose a constrained hypernetwork-based FML framework called FMLH, which innovatively utilizes hypernetwork to capture the differences in fine-tuned models, thereby providing personalized meta-models for each client. We provide rigorous mathematical proofs illustrating how the hypernetwork affects the convergence and generalization bounds of FMLH. Experimental results demonstrate that FMLH significantly improves the generalization of the model in cross-client shifts, with the lowest decile accuracy improved by up to 18.71%. FMLH also outperforms representative pFL algorithms by up to 5.6% in terms of maximum accuracy improvement. Lizhao Wu, Xiaoding Wang 0001, Hui Lin 0007, Xu Yang 0002, Jiwu Shu, Xun Yi, Ibrahim Khalil 0001, Albert Y. Zomaya |
IEEE Trans. Computers | 4 |
| 2026 | Privacy-Preserving Multi-Modal Object Fusion for Connected Autonomous Vehicles: Resilience Against Malicious Third-Party AttacksabstractConnected autonomous vehicles (CAVs) utilize multi-modal sensors, such as LiDAR and high-definition cameras, to collect diverse types of sensing data. Fusing object detection information from these two modalities facilitates more accurate environmental perception. In this context, lightweight secret sharing techniques are employed to protect information privacy, enabling further calculation while effectively alleviating the computational resource constraints of CAVs. Meanwhile, such techniques require an additional third-party to generate some necessary random numbers. Addressing the challenges of privacy disclosure of multi-modal object information and the reliability of random numbers, we propose a malicious third-party-resistant privacy-preserving multi-modal object fusion model, termed MPOF. First, we develop a series of secure computation protocols that do not rely on time-consuming cryptographic primitives, including secure multiplication, secure sharing conversion, and secure comparison. Leveraging the idea of sacrificial verification, we can effectively detect malicious behavior by the third-party during the random number generation process. Second, we construct a secure object bounding-box matching module based on arithmetic secret sharing (ASS), enabling similarity calculation and matching of bounding-boxes between point cloud and image modalities. Additionally, we design a secure object score fusion module that achieves fusion and updating through secure implementations of convolution, ReLU, and Maxout operations. Detailed theoretical analysis and experimental results demonstrate that, compared to secure computation protocols using homomorphic encryption for random number generation, the proposed protocols reduce computational overhead by five orders of magnitude. Furthermore, the MPOF model constructed by integrating these protocols is secure, accurate, and efficient. Renwan Bi, Jinbo Xiong, Xu Yang 0002, Yuanyuan Zhang 0009, Zhiqiang Ruan, Xun Yi |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Enhancing Privacy in Face Recognition With Dual-Path Feature Compression and Homomorphic EncryptionabstractFace recognition offers seamless human-machine interaction and efficiency. However, its widespread adoption has heightened security and privacy concerns due to the risks associated with compromised biometric data, such as spoofing and unauthorized tracking. To mitigate these concerns, this paper introduces a novel privacy-preserving face recognition framework that integrates an enhanced dual-path feature compression approach with homomorphic encryption (HE) for secure and efficient authentication. We leverage the robust deep neural network model FaceNet to extract discriminative 512-dimensional feature vectors and propose two significantly improved complementary feature compression methods tailored specifically for encrypted biometric systems: (1) Partitioned Principal Component Analysis (P-PCA), which employs a novel segment-wise PCA transformation, preserving localized discriminative information and supporting revocable biometric templates; and (2) Segment-wise Locality-Sensitive Hashing (S-LSH), introducing segment-specific hashing optimized for efficient binary representation and privacy-preserving encrypted-domain computations. Both compressed real-valued and binary features are securely encrypted using HE, enabling direct encrypted-domain similarity computations without exposing sensitive biometric data. Extensive experiments demonstrate that our method achieves competitive authentication performance while maintaining computational efficiency and practical feasibility. Wencheng Yang, Song Wang 0003, Di Wu 0050, Xu Yang 0002, Hui Cui 0001, Michael N. Johnstone, Yan Li 0002 |
IJCB | 5 |
| 2025 | TurboCache: Empowering Switch-Accelerated Key-Value Caches with Accurate and Fast Cache UpdatesabstractRecent key-value (KV) caches are offloaded to programmable switches to offer high query processing performance. However, they suffer from both low accuracy in hot key detection and high latency in cache updates due to the strict limitations on switch registers. We propose TurboCache, a switch-accelerated KV cache with accurate hot key detection and fast cache updates. Our key idea is to leverage the switch recirculation capability to build a novel data structure that caches hot KV pairs. With this hardware-compatible cache data structure, TurboCache designs efficient data plane algorithms that accurately detects new hot keys and quickly updates its cache entirely within switch ASIC pipelines. We have implemented TurboCache on a${64}\times {100}$Gbps Tofino switch. Testbed results indicate that TurboCache improves the hot key detection accuracy and decreases the cache update latency of existing KV caches by several orders of magnitude. Xiang Chen 0017, Longlong Zhu, Linying Zheng, Lingfei Cheng, Jianshan Zhang, Xu Yang 0002, Dong Zhang 0010, Xuan Liu 0006, Xiaoming Lu, Xun Yi, Ibrahim Khalil 0001, Albert Y. Zomaya, Haifeng Zhou, Chunming Wu 0001 |
INFOCOM | 6 |
| 2025 | Cryptocurrency Transaction Anomaly Detection Based on Semi-supervised Learning and Graph Neural Network
Renguang Chen, Zhide Chen, Xu Yang 0002, Zhiqiang Ruan, Chen Feng 0036, Xuechao Yang |
SecureComm (5) | 5 |
| 2025 | Remote sensing revolutionizing agriculture: Toward a new frontier
Xiaoding Wang 0001, Haitao Zeng, Xu Yang 0002, Jiwu Shu, Qibin Wu, Youxiong Que, Xuechao Yang, Xun Yi, Ibrahim Khalil 0001, Albert Y. Zomaya |
Future Gener. Comput. Syst. | 3 |
| 2025 | Bilinear-Pairing-Free Universal Designated Verifier Signatures for Private Access in Zero Trust NetworkabstractZero Trust networks provide an innovative cybersecurity architecture that effectively incorporates “never trust, always verify" principles to address traditional network security threats. Universal Designated Verifier Signature (UDVS) can protect the clients’ privacy in Zero Trust networks, preventing malicious gateways from leaking clients access information to third parties. However, existing UDVS schemes suffer from computational overhead due to their reliance on bilinear pairing operations. This paper primarily focuses on the general transformation method from Identity-Based Key Encapsulation Mechanism (ID-KEM) to UDVS proposed by Steinfeld et al. We first propose ID-KEM based on the SM2 algorithm and prove that it satisfies the EK and Separable properties required by the transformation. Then, we obtain the first UDVS scheme without bilinear pairing through transformation. In terms of performance analysis, the computational overhead of our scheme is 144.36 milliseconds, which is at least 74.39% lower than the previous UDVS schemes. The communication cost is 96 bytes, which is at least 88.89% lower than other schemes, including the first UDVSP scheme without bilinear pairing. To show the utility of our UDVS scheme, we finally apply it into a Zero Trust-based Software Defined Perimeter (SDP) environment, which reaps privacy-preserving authentication for single packet authorization. Chao Lin 0003, Wei Wu 0001, Xu Yang 0002, Yudi Zhang 0001 |
IEEE Internet Things J. | 4 |
| 2025 | Towards auditing gradient privacy risks in image reconstruction attacks on deep learning modelsabstractAs artificial intelligence continues to drive advancements in computer vision, particularly in areas such as image analysis, object detection, and facial recognition, the ability to accurately recognize patterns in visual data has become a central focus of research. However, alongside these advances, concerns about the privacy risks associated with the training data used in AI models have also gained prominence. Deep learning models, frequently employed in computer vision tasks, can unintentionally expose sensitive information from the data they are trained on, raising the need for comprehensive research into privacy-preserving techniques. This paper explores the intersection of AI-driven pattern recognition and the privacy risks involved in training models on image data. Existing studies show that attackers can exploit the gradients from deep learning processes to reconstruct original image data, including personal and identifiable information, such as facial features. By iteratively adjusting input data, attackers can minimize the difference between the gradients of the random and stolen data, leading to the full reconstruction of private images. Current privacy protection methods fall short of explaining the relationship between an attacker’s capacity to recover visual data and the structure of the targeted model. This paper introduces a novel privacy auditing framework that directly assesses the extent to which gradient-based attacks can reconstruct sensitive data. Unlike traditional methods, which mainly focus on mitigating privacy risks through model regularization or data obfuscation, our approach provides a systematic and quantitative evaluation of gradient leakage, filling a critical gap in existing privacy protection techniques. This paper investigates the relationships among reconstructed data, model gradients, and the original input data in the context of computer vision. By formalizing the connection between gradient similarity and data similarity, we propose a novel methodology that quantifies the vulnerability of deep learning models to data reconstruction attacks. Building on these insights, we propose a novel privacy auditing method aimed at evaluating the privacy risks associated with deep learning models used in pattern recognition for image data. Qingyu Huang, Chenhuang Wu, Guolong Zheng, Xu Yang 0002, Wencheng Yang |
Discov. Comput. | 8 |
| 2025 | FedPA: Generator-Based Heterogeneous Federated Prototype Adversarial LearningabstractFederated Learning is an emerging distributed algorithm that is designed to collaboratively train the global model without accessing clients’ private data. However, heterogeneity of data among clients leads to significant degradation in model performance. Some studies suggest adopting model regularization and using generators to enrich datasets with diverse features can effectively enhance model performance. But current research focuses on regularizing specific modules of the model, failing to achieve regularization across the entire model, and offering limited mitigation of bias from heterogeneous data. Moreover, few methods consider that generators often produce samples with simple features, and the direct use for generating raw data can raise privacy concerns. To solve these challenges, we propose a generator-based heterogeneous Federated Prototype Adversarial Learning framework, named FedPA, which combines prototype learning and lightweight generators to achieve regularization of the entire model. Our generators are designed to generate features rather than raw data, and use prototype learning to find the hard features in an adversarial learning manner, thereby improving model performance. Experimental results show that FedPA improves test accuracy by 3.7% compared to state-of-the-art methods, validating that FedPA can effectively mitigate model bias. Xiaoding Wang 0001, Xu Yang 0002, Jiwu Shu, Hui Lin 0007, Xun Yi |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Secure Reputation-Based Authentication With Malicious Detection in VANETsabstractReputation-based authentication is a mechanism used to establish trust and ensure the reliability of vehicle communication in vehicular ad hoc networks (VANETs). However, existing schemes ignore the importance of privacy protection and face issues such as malicious vehicles spreading false or duplicate messages. To address these issues, this paper proposes a secure and anonymous reputation-based authentication scheme based on the ElGamal cryptosystem for the vehicular communication system, which promotes cooperative behavior and encourages vehicles' positive contribution to the network. In particular, we design an efficient duplicate detection mechanism based on the technique of Bloom filter to aid in identifying and isolating malicious vehicles. Security analysis is conducted to demonstrate the robust security of the proposed scheme. The results of performance evaluation highlight the superiority of the proposed scheme in addressing the identified shortcomings while maintaining reasonable computation and communication costs. Xu Yang 0002, Xuechao Yang, Xun Yi, Jianting Ning, Xinyi Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Lightweight Privacy-Friendly Aggregation Scheme Against Internal Attacks for Smart GridsabstractWhile real-time electricity consumption data of users in smart grids can enable value-added services, such as Big Data analytics, each individual user's privacy needs to be protected. How to balance data utility and privacy protection is a significant issue, of which privacy-preserving data aggregation (PPDA) is a viable solution. Prior to this, researchers have proposed a number of PPDA schemes to address the above challenge. Unluckily, most of them suffer from security and privacy drawbacks, while others are inappropriate for resource-limited smart meters due to high cost of cryptographic operations. To tackle this issue, in this article, we propose a pairing-free and exponentiation-free certificateless PPDA scheme named CL-PPDA for smart grids. We prove the security of our design and analyze its performance. Comparative analyses with state-of-the-art work in theory and experiment show that our design not only has better security properties, but also has competitive computation overhead, especially on the resource-constrained smart meter side. Besides, we present an extension of our CL-PPDA scheme to support multidimensional data aggregation, which further enriches the functionality of our design. Wei Wu 0001, Alsharif Abuadbba, Saru Kumari, Xu Yang 0002, Ibrahim Khalil 0001, Xun Yi |
IEEE Trans. Ind. Informatics | 5 |
| 2024 | Estimation of realized volatility of cryptocurrencies using CEEMDAN-RF-LSTM
Yongrong Huang, Zhide Chen, Xu Yang 0002, Xun Yi, Hai Dong 0001, Xuechao Yang |
Future Gener. Comput. Syst. | 4 |
| 2024 | A Robust and Secure Data Access Scheme for Satellite-Assisted Internet of Things With Content Adaptive AddressingabstractThis paper investigates data communication and access control in satellite-assisted Internet of Things. In particular, given the characteristics of an open communication environment, a multi-layer heterogeneous network, and a time-varying topology in the Space-Air-Ground-Sea Integrated Network (SAGSIN), traditional data communication and security mechanisms built upon the TCP/IP architecture may not fully leverage their potential. Current networks are primarily responsible for end-to-end transmission of binary data, lacking the capability to semantically perceive and handle dynamic and decentralized content. This leads to significant performance gaps in the network. In other words, it is better to retrieve expected information directly from the network and perform content protection on it with low dependency. We propose DARS, a Data Access scheme with Robust and Secure content communication for Satellite-assisted Internet of Things (S-IoT), leveraging the architectural benefits of content centric networks and rich attributes of IoT. DARS enables automatic data retrieval and access control without additional mechanisms, such as online certificate distribution, homogeneous network, and other presuppositions, which facilitates DARS to be applied in various environments. Additionally, DARS integrates a combination of techniques, including semantic representation, cryptographic technologies, and content caching, from a network-centric perspective. Theoretical analysis and experimental simulations show that DARS simplifies system operations and offers a viable solution for satellite-assisted IoT-based applications. Zhiqiang Ruan, Xu Yang 0002, Xuechao Yang, Yuan Miao 0001, Xinyi Huang 0001, Xun Yi |
IEEE Internet Things J. | 2 |
| 2024 | SemantiChain: A Trust Retrieval Blockchain Based on Semantic ShardingabstractSince its inception, blockchain technology has found wide-ranging applications in various fields including agriculture, energy, and so on, owing to its immutable and decentralized nature. However, existing blockchains encounter significant challenges in scenarios that demand efficient retrieval of big data. This is primarily because current blockchains cannot directly store and process diverse types of rich media information. Additionally, the semantic relationships between data within the blockchains are weak, complicating the categorization and retrieval of data and transactions. Moreover, the scalability of current blockchains is limited, with the capacity of full nodes continually increasing. Although some semantic-based blockchain solutions that combine off-chain scalability have been proposed, they are limited in effectiveness and applications. To address these issues, this paper introduces a brand-new blockchain sharding technique called Semantic Sharding, which enhances blockchain scalability through a hybrid on/off-chain approach. Building on this, we propose a semantic sharding blockchain architecture, SemantiChain, which enables the on-chain storage and retrieval of transaction semantic features. Furthermore, through the Po2RW consensus protocol, we balance the scalability and security of SemantiChain. Security analysis proves that SemantiChain can resist security risks such as man-in-the-middle attacks, malicious node attacks and on/off-chain data inconsistency. Experimental results demonstrate that SemantiChain can reduce search time and memory usage by at least 32.29% and 77.97% respectively under the same retrieval performance, compared to mainstream approximate nearest neighbour retrieval algorithms. Furthermore, compared to the SOTA semantic blockchain, SemantiChain achieves a retrieval performance improvement of at least 45.88% and reduces retrieval memory usage by 95.76%. Zihang Zhen, Xiaoding Wang 0001, Xu Yang 0002, Jiwu Shu, Jia Hu 0001, Hui Lin 0007, Xun Yi |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Towards Sustainable Trust: A Practical SGX Aided Anonymous Reputation SystemabstractReputation systems are widely used to provide a trustworthy environment and improve the sustainability of online discussions. They help users understand and evaluate the quality of information by collecting and counting feedback from different users. However, a common issue in most reputation systems is how to maintain users’ reputation and protect their anonymity simultaneously. In this paper, we introduce a new practical anonymous reputation system based on SGX. The establishment of an anonymous reputation system has a positive effect on sustainable trust in reputation-based online applications. Our system achieves the combination of reputation and anonymity by utilizing Intel SGX and the Bloom filter. The Path ORAM algorithm is also implemented to resist side-channel attacks. The experiments demonstrate that our system achieves high performance in terms of computation and storage costs. When compared to two state-of-the-art anonymous reputation systems, our system has better computation performance with at least three orders of magnitude. Xu Yang 0002, Xuechao Yang, Xun Yi, Ibrahim Khalil 0001, Shangqi Lai, Wei Wu 0001, Albert Y. Zomaya |
IEEE Trans. Sustain. Comput. | 1 |
| 2022 | An Efficient Clustering-Based Privacy-Preserving Recommender System
Xun Yi, Fengling Han, Xuechao Yang, Xu Yang 0002 |
NSS | 5 |
| 2022 | Secure and Lightweight Authentication for Mobile-Edge Computing-Enabled WBANsabstractWireless body area networks (WBANs) technology nowadays has become a promising networking paradigm in the Internet of Things (IoT) as it can provide people with high quality of life and high level of medical service. In order to ensure the security and privacy of patients’ sensitive biomedical data and the efficiency of message processing across different devices, it is critical to provide a secure and lightweight authentication scheme for WBANs. In this article, we propose an extra lightweight authentication scheme for mobile-edge computing-enabled WBANs. Two different authentication phases based on the modular square roots technique are designed: one is the intra-BAN authentication between the sensor node and edge node (EN), and the other is the inter-BAN authentication between EN and application provider. The proposed scheme offers robust security by providing comprehensive security analysis. Performance is also evaluated in terms of computation, communication, and storage costs. The evaluation results demonstrate that the proposed scheme achieves a reduction of at least 90% in computation cost and at least 30% in communication cost when compared to four other related schemes. Xu Yang 0002, Xun Yi, Ibrahim Khalil 0001, Elisa Bertino, Surya Nepal, Xinyi Huang 0001 |
IEEE Internet Things J. | 1 |
| 2022 | Blockchain-Based Secure and Lightweight Authentication for Internet of ThingsabstractOver the past decade, the Internet of Things (IoT) is widely adopted in various domains, including education, commerce, government, and healthcare. There are also many IoT-based applications drawn significant attentions in recent years. With the increasing numbers of the connected devices in the IoT system, one of the challenging tasks is to ensure devices’ authenticity, which allows users to have a high confidence in the decision. In addition, due to the heterogeneity of the IoT system and the resource-constrained devices, how to efficiently manage such system and guarantee the security and privacy for devices is concerned. In this article, we proposed a new blockchain-based authentication scheme to meet the challenges. Our proposed framework combines the blockchain technique and the modular square root algorithm to achieve an effective authentication process. Besides, we demonstrate the security and utility of the proposed scheme by providing the security analysis and the detailed experiment. Xu Yang 0002, Xuechao Yang, Xun Yi, Ibrahim Khalil 0001, Xiaotong Zhou, Debiao He, Xinyi Huang 0001, Surya Nepal |
IEEE Internet Things J. | 1 |
| 2022 | Cryptanalysis and improvements of an efficient certificate-based proxy signature scheme for IIoT environments
Feihong Xu, Xu Yang 0002, Xun Yi, Alsharif Abuadbba |
Inf. Process. Lett. | 3 |
| 2022 | Efficient and Anonymous Authentication for Healthcare Service With Cloud Based WBANsabstractAs a promising technology in the development of human healthcare services, the wireless body area networks (WBANs) technology has attracted widespread attention in recent years from both industry and academia. However, due to the sensitiveness of the medical system and the capability limitation of the wearable devices, security, privacy, and efficiency of the healthcare services in WBANs are remained as major challenges. Although different authentication mechanisms have been designed to meet the challenges in recent years, most of them suffer from some functional defects or security problems. In this article, we firstly provide a review and cryptanalysis on the state-of-the-art authentication scheme. In order to meet the challenges and address the drawbacks in previous works, we then propose a new efficient and anonymous authentication scheme for cloud based WBANs. Through the security analysis, we show that our scheme could overcome the weaknesses in previous schemes and meet all the security requirements. Besides, we show the advantages of the proposed scheme through performance evaluation in terms of functionality features, computation overhead, communication overhead and storage overhead, which shows our scheme is more appropriate for practical applications on healthcare services. Xu Yang 0002, Xun Yi, Surya Nepal, Ibrahim Khalil 0001, Xinyi Huang 0001, Jian Shen 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | Efficient and Anonymous Authentication for Healthcare Service With Cloud Based WBANsabstractWireless body area networks (WBANs) technology nowadays has become a promising networking paradigm in the Internet of Things (IoT) as it can provide people with high quality of life and a high level of medical service. Specifically, to make sure those people with a high incidence of chronic diseases, including hypertension, diabetes, and cardiovascular diseases, are taking care of which further reduces social costs. Thus, both industry and academia in recent years pay widely attention to WBANs technology. After years of research, security, privacy, and efficiency of the healthcare services in WBANs have remained as major challenges. Although different authentication mechanisms have been designed to meet the challenges in recent years, most of them suffer from some functional defects or security problems. To ensure the security and privacy of patients’ sensitive biomedical data and the efficiency of message processing across different devices, it is critical to provide a secure and lightweight authentication scheme for WBANs. Xu Yang 0002, Xun Yi, Surya Nepal, Ibrahim Khalil 0001, Xinyi Huang 0001, Jian Shen 0001 |
SERVICES | 1 |
| 2021 | Verifiable image revision from chameleon hashesabstractAbstract In a digital society, the rapid development of computer science and the Internet has greatly facilitated image applications. However, one of the public network also brings risks to both image tampering and privacy exposure. Image authentication is the most important approaches to verify image integrity and authenticity. However, it has been challenging for image authentication to address both issues of tampering detection and privacy protection. One aspect, image authentication requires image contents not be changed to detect tampering. The other, privacy protection needs to remove sensitive information from images, and as a result, the contents should be changed. In this paper, we propose a practical image authentication scheme constructed from chameleon hashes combined with ordinary digital signatures to make tradeoff between tampering detection and privacy protection. Our scheme allows legitimate users to modify contents of authenticated images with a privacy-aware purpose (for example, cover some sensitive areas with mosaics) according to specific rules and verify the authenticity without interaction with the original authenticator. The security of our scheme is guaranteed by the security of the underlying cryptographic primitives. Experiment results show that our scheme is efficient and practical. We believe that our work will facilitate image applications where both authentication and privacy protection are desirable. Junpeng Xu, Haixia Chen, Xu Yang 0002, Wei Wu 0001, Yongcheng Song |
Cybersecur. | 3 |
| 2020 | Privacy-Preserving Authentication for Tree-Structured Data with Designated Verification in Outsourced Environments
Xun Yi, Alsharif Abuadbba, Ibrahim Khalil 0001, Xu Yang 0002, Surya Nepal, Xinyi Huang 0001 |
ProvSec | 5 |
| 2020 | Lightweight privacy preservation for secondary users in cognitive radio networks
Yali Zeng, Li Xu 0002, Xu Yang 0002, Xun Yi, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 3 |
| 2019 | An efficient privacy-preserving protocol for database-driven cognitive radio networks
Yali Zeng, Li Xu 0002, Xu Yang 0002, Xun Yi |
Ad Hoc Networks | 3 |
| 2019 | A new privacy-preserving authentication protocol for anonymous web browsingabstractSummary Anonymous authentication technique receives wide attention in recent years since it can protect users' privacy. Anonymous web browsing refers to utilization of the World Wide Web that hides a user's personally identifiable information from the websites visited. Even if a user can hide the IP address and other physical information with anonymity programs such as Tor, the web server can always monitor the user on the basis of the identity. In this paper, we firstly give an overview and cryptanalysis on the protocol of Yang et al and point out the security weaknesses of their protocol. Then, we propose a new authentication protocol for anonymous web browsing. In the proposed protocol, we take the advantages of a pseudo identity mechanism and an identity‐based elliptic curve cryptography algorithm to achieve user anonymity, robust security, and high efficiency. The result of security analysis and performance evaluation indicate the feasibility and practicality of our proposed anonymous authentication protocol. Xu Yang 0002, Xun Yi, Ibrahim Khalil 0001, Hui Cui 0001, Xuechao Yang, Surya Nepal, Xinyi Huang 0001, Yali Zeng |
Concurr. Comput. Pract. Exp. | 1 |
| 2019 | Privacy-preserving aggregation for cooperative spectrum sensing
Yali Zeng, Li Xu 0002, Xu Yang 0002, Xun Yi, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 3 |
| 2018 | A Practical Privacy Preserving Protocol in Database-Driven Cognitive Radio Networks
Yali Zeng, Xu Yang 0002, Qikui Xu, Dongcheng Wang |
ACISP | 3 |
| 2018 | An Improved Lightweight RFID Authentication Protocol for Internet of Things
Xu Yang 0002, Xun Yi, Yali Zeng, Ibrahim Khalil 0001, Xinyi Huang 0001, Surya Nepal |
WISE (1) | 1 |
| 2017 | A Practical Authentication Protocol for Anonymous Web Browsing
Xu Yang 0002, Xun Yi, Hui Cui 0001, Xuechao Yang, Surya Nepal, Xinyi Huang 0001, Yali Zeng |
ISPEC | 1 |
| 2017 | Towards secure and cost-effective fuzzy access control in mobile cloud computing
Wei Wu 0001, Shun Hu, Xu Yang 0002, Joseph K. Liu, Man Ho Au |
Soft Comput. | 3 |
| 2016 | Improved handover authentication and key pre-distribution for wireless mesh networksabstractSummary Ticket‐based authentication is a critical technology to secure wireless mesh networks (WMN), which enable efficient communication among laptops, cell phones and other wireless devices. In this paper, we provide a new design of handoff authentication for WMN to reduce the delay caused by handoff. Our major improvement is on the key pre‐distribution for handoff authentication. We apply the attribute‐based encryption to encrypt key pre‐distribution messages for neighbor mesh routers. As a result, key pre‐distribution has constant computation and communication costs, which are independent of the number of neighbor mesh routers. Another advantage of our design is that it can perform immediate handoff authentication once the login authentication is complete, even before key pre‐distribution messages reach the foreign mesh router. The security of our handoff authenticator protocol is also improved by employing home mesh router's digital signature in the handoff ticket and key pre‐distribution messages. Our scheme can efficiently thwart forgery attacks. The proposed scheme provides an efficient and secure solution that meets the requirements of WMN in the era of Big Data. Copyright © 2015 John Wiley & Sons, Ltd. Xu Yang 0002, Xinyi Huang 0001, Jinguang Han, Chunhua Su |
Concurr. Comput. Pract. Exp. | 1 |
| 2016 | Efficient handover authentication with user anonymity and untraceability for Mobile Cloud Computing
Xu Yang 0002, Xinyi Huang 0001, Joseph K. Liu |
Future Gener. Comput. Syst. | 1 |
| 2016 | Self-healing and energy-efficient restoration in machine-to-machine networksabstractMachine‐to‐machine (M2M) networks often serve mission‐critical applications in our daily life. Maintaining nodes connectivity is crucial for M2M networks to accomplish their tasks effectively. The fault of a critical node may break the network into several blocks, and thus hinders the operation. Rapid recovery is highly required in such a case. In this study, the authors focus on designing an effective algorithm for restoring damaged network topologies by moving available nodes. Unlike contemporary algorithms that only consider network connectivity or coverage, the proposed algorithm not only takes into account network connectivity, coverage and energy consumption, but also concerns about the shortest path between any pair of nodes. Simulation results demonstrate that the proposed algorithm outperforms the existing scheme in terms of network lifetime. Yali Zeng, Zhide Chen, Xu Yang 0002 |
IET Commun. | 3 |
| 2015 | PEVTS: Privacy-Preserving Electric Vehicles Test-Bedding SchemeabstractElectric Vehicle (EV) infrastructure is relatively new in many countries. Due to the recency of an EV infrastructure, it is important to carry out a series of testing programs. Furthermore, authenticity for collection of data is necessary for testing programs in order to provide accurate results. At the same time, user privacy should not cease since tracing one's daily logistic movements or behaviour from the EV testing programs means breaching one's privacy. In this paper, we propose a novel solution PEVTS for enabling both data authenticity and user privacy concurrently. Our proposed system provides great flexibility to the authority to choose any arbitrary set of authenticated users for testing in every time period. At the same time, it provides anonymity for all participating users. Yet it can trace any vehicle within a time period for statistical purpose. We give a detailed description of our system. We also implement the prototype of our system to show its practicality. Xu Yang 0002, Joseph K. Liu, Wei Wu 0001, Man Ho Au, Willy Susilo |
ICPADS | 1 |
| 2015 | Lightweight Anonymous Authentication for Ad Hoc Group: A Ring Signature Approach
Xu Yang 0002, Wei Wu 0001, Joseph K. Liu, Xiaofeng Chen 0001 |
ProvSec | 1 |