Chengzhe Lai

dblp:74/11196 · DBLP profile ↗
← Back
48ranked-venue papers
25as first author
27since 2021 · last 2026
0000-0002-4603-3380ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 36 · 20 first-author · 18 since 2021Security and privacy · 6 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021
YearPublicationVenuePosition
2026 FGPAM: Fine-Grained Privacy-Preserving User Attribute Matching in Mobile Social Networks
Chengzhe Lai
IEEE Internet Things J.1
2026 A Lightweight Privacy-Preserving Scheme With Efficient Reputation Management for Vehicular Crowdsensing
Chengzhe Lai, Kaihuan Deng
IEEE Internet Things J.3
2026 WLCHAT-PDP: Provable Data Possession Based on Weighted Link-List Chameleon Hash Authentication Tree in Edge Computing
abstract
In Internet of Things (IoT) scenarios, the integrity audit of massive amounts of data uploaded from Edge Nodes (ENs) to the cloud poses significant challenge to researchers. Existing Provable Data Possession (PDP) schemes suffer from low communication and computational efficiency, as well as the issue of Third-Party Auditors (TPAs) not being completely trustworthy, especially in dynamic data update scenarios. This paper designs an efficient authentication structure, named the Weighted Link-list Chameleon Hash Authentication Tree (WLCHAT), to reduce cloud storage overhead and improve dynamic update efficiency. Based on this, the paper further proposes the WLCHAT-PDP scheme, which is built upon the WLCHAT structure. Building on the PDP model, the proposed scheme introduces the ENs to proxy user operations for tag generation and to participate in the audit process. By combining this with a user authorization signature mechanism, the proposed scheme not only alleviates terminal computational load but also guarantees that all operations are authorized. To enhance the credibility of the audit process, the proposed scheme incorporates blockchain-anchored log records to effectively prevent collusive behavior between cloud service providers and TPAs. Theoretical analyses and comparative evaluation demonstrate that the scheme achieves a balance between security and computational overhead, rendering it suitable for dynamic and trusted IoT cloud storage environments.
Youjun Xu, Yiyu Yang, Dengqi Yang, Chengzhe Lai
Peer Peer Netw. Appl.6
2026 Splight: A Lightweight Block Cipher for Resource-Constrained Embedded Devices
Chengzhe Lai, Yong Yu 0002
IEEE Trans. Computers3
2026 SRAA: A Secure and Revocable Access Authentication Scheme in Cross-Domain Vehicular Twin Networks
abstract
Vehicular twin networks (VTN) create virtual agents of vehicular entities through digital twin (DT) technology, replacing physical counterparts in connecting and exchanging traffic information in cyberspace, overcoming physical range constraints and extending information sources for enhanced vehicular decision support. However, the inherent openness of VTN renders communication between DTs, vulnerable to security threats, such as tampering and impersonation, especially in scenarios where DTs are distributed across multiple cloud domains. These issues result in erroneous decisions to threaten vehicular safety because DTs may receive compromised information. To address these challenges, this article proposes a secure and revocable access authentication scheme in the cross-domain VTN. In the scheme, DTs should be authorized first to obtain identity-bound symmetric functions before joining the VTN, and then perform secure access authentication and key agreement with others based on chameleon hash functions for both intradomain and cross-domain communication. Moreover, a dynamic revocation mechanism is introduced to remove malicious DTs from VTN. Formal verification using the Tamarin tool demonstrates that the proposed scheme achieves diverse security properties. Performance evaluation further shows that the proposed scheme outperforms most related schemes in terms of computational and communication overhead.
Guanjie Li, Jin Cao 0001, Jinkai Zheng, Chengzhe Lai, Tom H. Luan, Zehui Xiong
IEEE Trans. Ind. Informatics4
2026 Cloud-Assisted Privacy-Preserving Safety Monitoring Scheme for Online Ride-Hailing Services
Chengzhe Lai, Jiping Ma, Zhiquan Liu 0001
IEEE Trans. Mob. Comput.1
2025 MOA-RHS: Maximized Order Acceptance Ride-Hailing Scheme with Collusion Resistance
abstract
Ride-hailing services provide convenient transportation and contribute to urban traffic efficiency, but they also introduce security and privacy challenges. A major concern is collusion between ride-hailing service providers (RHSPs) and drivers, which can compromise passengers’ location privacy through repeated matching. Additionally, existing solutions often fail to consider drivers’ profit-oriented nature, leading to low order acceptance rates and inefficient resource allocation. To address these issues, we propose a privacy-preserving ride-matching scheme utilizing Multi-Party Secure Computation (MPC) and homomorphic encryption. Our approach prevents RHSPs from accessing sensitive user data while ensuring fair ride allocation. By incorporating drivers’ expected earnings into the matching process, our solution enhances order acceptance rates and reduces resource waste. Furthermore, an efficient decentralized matching algorithm offloads computation to Roadside Units (RSUs), minimizing reliance on centralized servers. Our scheme ensures secure, efficient, and accountable ride-hailing services while protecting user privacy.
Chengzhe Lai
VTC2025-Fall1
2025 Efficient and secure cross-domain data sharing scheme with traceability for Industrial Internet
Wei Luo 0003, Ziyi Lv, Chengzhe Lai
Comput. Networks3
2025 Two-phase authentication for secure vehicular digital twin communications
Xinwei Zhang 0008, Chengzhe Lai, Guanjie Li, Dong Zheng 0001
Comput. Networks2
2025 SECR: A Secure and Efficient Charging Reservation Scheme Based on Digital Twin in Vehicular Network
abstract
Despite the rapid growth of electric vehicles (EVs), charging remains a time-consuming issue that requires effective management. An important solution uses digital twin (DT) technology, which acts as a virtual agent for EVs in the digital space. DT can analyze real-time vehicle data to develop optimal charging schedules and reserve charging providers in advance through the vehicular network, leading to more efficient charging processes. However, the vehicular network exposes the automated reservation process of the DT to security attacks. Additionally, there is a risk that the actual charging process may deviate from the scheduled requirements set by the DT, resulting in wasted charging resources. To address these issues, this article proposes a secure and efficient charging reservation scheme based on DT technology. To prevent malicious attacks, we first design a secure and privacy-preserving reservation authentication protocol using the extended Chebyshev chaotic maps, taking into account the computational resources of the EV. Furthermore, we develop a reputation mechanism to evaluate and incentivize the charging behavior of EVs. Formal verification and further discussions are conducted to show diverse security functionalities of the proposed scheme can be achieved. We evaluate that the proposed scheme outperforms existing schemes in terms of computation and communication overheads, while also assessing the impact of EV charging behavior on reputation and charging level.
Guanjie Li, Tom H. Luan, Jinkai Zheng, Chengzhe Lai, Kuan Zhang 0001, Shui Yu 0001
IEEE Internet Things J.4
2025 LAPMS: A lightweight and privacy-preserving management scheme for secure vehicle platoons
Chengzhe Lai, Guanjie Li, Lingchen Li
Peer Peer Netw. Appl.2
2025 DTHA: A Digital Twin-Assisted Handover Authentication Scheme for 5G and Beyond
abstract
With the rapid development and extensive deployment of the fifth-generation wireless system (5G), it has achieved ubiquitous high-speed connectivity and improved overall communication performance. Additionally, as one of the promising technologies for integration beyond 5G, digital twin in cyberspace can interact with the core network, transmit essential information, and further enhance the wireless communication quality of the corresponding mobile device (MD). However, the utilization of millimeter-wave, terahertz band, and ultra-dense network technologies presents urgent challenges for MD in 5G and beyond, particularly in terms of frequent handover authentication with target base stations during faster mobility, which can cause connection interruption and incur malicious attacks. To address such challenges in 5G and beyond, in this paper, we propose a secure and efficient handover authentication scheme by utilizing digital twin. Acting as an intelligent intermediate, the authorized digital twin can handle computations and assist the corresponding MD in performing secure mutual authentication and key negotiation in advance before attaching the target base stations in both intra-domain and inter-domain scenarios. In addition, we provide the formal verification based on BAN logic, RoR model, and ProVerif, and informal analysis to demonstrate that the proposed scheme can offer diverse security functionality. Performance evaluation shows that the proposed scheme outperforms most related schemes in terms of signaling, computation, and communication overheads.
Guanjie Li, Tom H. Luan, Chengzhe Lai, Jinkai Zheng, Rongxing Lu
IEEE Trans. Dependable Secur. Comput.3
2025 Traceable Access Control Encryption With Parallel Multiple Sanitizers
abstract
Access control encryption (ACE) is an innovative cryptographic primitive that realizes fine-grained read/write control of data and protects data privacy and security while facilitating the effective flow of information. However, existing ACE schemes face several limitations: 1) Inability to adequately mitigate the risks of a single point of failure in the sanitizer. 2) Lack of an effective accountability mechanism for disputes arising during the sanitization process. To solve these problems, this paper proposes the notion of traceable access control encryption with parallel multiple sanitizers for the first time and designs a specific structure of traceable parallel ACE to prevent the single point of failure, effectively deter abnormal sanitizer behaviors, and optimize system performance. Additionally, computationally intensive operations in the encryption and decryption processes are outsourced to third-party servers, resulting in a significant reduction of computational overhead. Furthermore, theoretical analysis and experimental simulations validate the effectiveness of the proposed scheme. Comprehensive security analysis demonstrates its no-read security under the decisional q-parallel Bilinear Diffie-Hellman Exponent (BDHE) assumption and its no-write security under the Discrete Logarithm (DL) assumption, ensuring its reliability in practical applications.
Wei Luo 0003, Qinghe Duan, Chengzhe Lai
IEEE Trans. Inf. Forensics Secur.3
2024 GAN Augmentation-Based Continuous Authentication for Vehicular Digital Twin
abstract
In this paper, to secure the communication between autonomous vehicle and its digital representative in the vehicular digital twin system, we propose a GAN augmentation-based continuous authentication scheme. Specifically, in the proposed scheme, we first introduce a data augmentation technique based Generative Adversarial Network (GAN) that provides the augmentation of raw data from vehicle sensors. We then present the efficient authentication: 1) We train a Convolutional Neural Network (CNN) using raw and augmented data; 2) Deep features are extracted through a combination of Principal Component Analysis (PCA) and CNN; 3) We train the OC-SVM classifier during the registration to ensure the legality of vehicle in the authentication phase. Performance evaluations via extensive simulations demonstrate the efficiency and effectiveness of the proposed scheme in terms of GAN loss and accuracy.
Chengzhe Lai, Xinwei Zhang 0008, Guanjie Li, Yong Yu 0002, Dong Zheng 0001
ICC1
2024 Privacy-Preserving Medical Data Sharing Scheme Based on Two-Party Cloud-Assisted PSI
abstract
The conflict between data privacy and sharing among healthcare institutions creates data silos, causing wasteful duplication, incomplete information, and potential hindrances to scientific research. In this article, we present a privacy-preserving medical data sharing scheme based on cloud-assisted private set intersection (PSI) and aggregate signature technique. First, we propose a novel authenticated cloud-assisted PSI, named AC-PSI, which can achieve client authentication and randomized processing of private data by using Diffie–Hellman-based oblivious pseudorandom function (DH-OPRF) and vector oblivious linear-function evaluation-based oblivious pseudorandom function (VOLE-OPRF), respectively. Second, based on the AC-PSI and locally verifiable signature (LVS), we design a privacy-preserving and secure medical data sharing scheme, which can provide enhanced security features by enabling access control of computing resources and resist precomputation attacks from external sources. Our approach has been proven through a rigorous analysis of security. Finally, through comparative analysis with the existing schemes, it is demonstrated that the proposed AC-PSI and medical data sharing scheme has low communication and computation overhead while achieving a higher level of privacy preservation and security.
Chengzhe Lai, Hanyue Zhang, Rongxing Lu, Dong Zheng 0001
IEEE Internet Things J.1
2023 A Secure and Efficient Handover Authentication Based on Digital Twin in 5G-V2X
abstract
In recent years, 5G-V2X has promoted the advancement of autonomous vehicles, enabling the latter to obtain more information via 5G networks. However, fast-moving vehicles have to perform frequent handover authentication with base stations in vulnerable wireless channels, which can cause access failures and affect smooth driving. The digital twin is the virtual agent in cyberspace to reliably provide real-time decisions and added-value services to improve the quality of communication for vehicles by analyzing raw data and interacting with the 5G core network. Based on the capabilities of digital twin, in this paper, we propose digital twin-assisted handover authentication scheme that uses the digital twin as the bridge to exchange necessary parameters in 5G-V2X, thereby intelligently assisting in completing mutual authentication and key negotiation between the vehicle and the target base station in advance and reducing the complexity of the handover process. Furthermore, the security and performance analysis demonstrates that our proposed scheme is secure and efficient.
Guanjie Li, Tom H. Luan, Jinkai Zheng, Chengzhe Lai, Zhou Su 0001, Haixia Peng
GLOBECOM4
2023 A PUF-based Authentication and Key Distribution Scheme for In-Vehicle Network
abstract
With the increasing connectivity between and within vehicles, in-vehicle network security has received considerable attention. As the most widely used protocol in in-vehicle network, Controller Area Network (CAN) bus lacks security mechanisms by design, and is vulnerable to various attacks. Although many frameworks have been proposed to solve the security issues of CAN buses, spoofing attacks by compromised Electronic Control Units (ECUs) and reducing message latency while ensuring security remains a challenge. In this paper, we propose an authentication and key distribution scheme for the CAN bus. Specifically, the scheme includes ECU identity authentication, key distribution, and authentication of data frames. By utilizing physically unclonable functions (PUF) technique, each ECU avoids the risk of long-term key leakage, simplifies the key distribute process, and reduces the communication overhead of vehicles. Compared with the state-of-the-art group-based schemes, the proposed scheme has lower computational and communication overhead.
Chengzhe Lai, Dong Zheng 0001
ICC1
2023 A Group-oriented Authentication Scheme for IoT Devices in 5G Networks
abstract
One of the 5G support for IoT is Massive Machine Type Communication (mMTC). However, it also poses a great challenge to the IoT network, which cannot cope with the massive number of devices accessing at the same time. In this paper, we propose a group-oriented authentication scheme which supports a large number of devices accessing. In particular, the proposed scheme enables lightweight intra-group authentication and leader election through collaborative filtering techniques. In addition, our solution enables secure and efficient key agreement and mutual authentication by using Round-Efficient and Sender-Unrestricted Dynamic Group Key Agreement (RESUD-GKA), aggregate signature with forward security and proxy signature. We also introduce software-defined networking (SDN) and combine mobile edge computing (MEC) and network function virtualization (NFV) to fully utilize the links and greatly reduce the time cost. Ultimately, multiple security objectives of the protocol are assessed through the utilization of security analysis and the formal verification tool Scyther. Performance evaluation shows that the proposed scheme has lower bandwidth and transmission overhead compared to existing schemes.
Qili Guo, Chengzhe Lai, Haoyan Ma, Dong Zheng 0001
MSN2
2023 A blockchain-based traceability system with efficient search and query
Chengzhe Lai, Yinzhen Wang, Dong Zheng 0001
Peer Peer Netw. Appl.1
2023 Searchable Encryption With Autonomous Path Delegation Function and Its Application in Healthcare Cloud
abstract
Outsourcing medical data to healthcare cloud has become a popular trend. Since medical data of patients contain sensitive personal information, they should be encrypted before outsourcing. However, information retrieval methods based on plaintext cannot be directly applied to encrypted data. In this article, we present a new cryptographic primitive named conjunctive keyword search with secure channel free and autonomous path delegation function (AP-SCF-PECKS), which can be applied in scenarios where patients want to search for and autonomous delegate their private medical information without revealing their private key. Particularly, the proposed solution allows patients to set up multi-hop delegation path with their preferences, and the delegated doctors in the path can search for and access the patient’s private medical information with priority from high to low. Patients can ensure that authorized doctors are always trustworthy, and unauthorized users cannot obtain the private medical information of patients. Moreover, the scheme supports the conjunctive keyword search, secure channel free, and is secure against chosen keyword attack, chosen ciphertext attack, and keyword guessing attack. The security of proposed scheme has been formally proved in the standard model. Finally, the performance evaluations demonstrate that the overhead of proposed scheme are modest for healthcare cloud scenarios.
Qian Wang 0033, Chengzhe Lai, Rongxing Lu, Dong Zheng 0001
IEEE Trans. Cloud Comput.2
2023 A Novel Authentication Scheme Supporting Multiple User Access for 5G and Beyond
abstract
The deployment of ultra-dense networks in the fifth-generation (5 G) network architecture can significantly improve the quality of wireless links, but this will cause frequent handovers of mobile users and increase authentication delays. Furthermore, the simultaneous influx of a large number of mobile users may cause serious network congestion. Aiming at these problems, this article proposes a novel authentication scheme supporting multi-user access, which fully considers the scenarios of intra-domain handover and inter-domain handover across AMF. Using the characteristics of the network architecture integrated with mobile edge computing (MEC) and software-defined networks (SDN), the user's moving path can be predicted in advance to speed up the handover process. Most importantly, the proposed scheme can perform secure, efficient and flexible mutual authentication and key agreement between the group and the core network by using aggregated message authentication codes with detecting functionality (AMAD) and contributory broadcast encryption technique. Through the use of BAN Logic and Scyther tool verification, the proposed scheme can not only realize multiple user authentication and key agreement, but also fulfill various security goals. Performance evaluations demonstrate that the proposed scheme has moderate computational and communication overhead, and lower transmission overhead compared with existing schemes, which can effectively reduce authentication delay.
Chengzhe Lai, Rongxing Lu, Yinghui Zhang 0002, Dong Zheng 0001
IEEE Trans. Dependable Secur. Comput.1
2023 pdRide: Privacy-Preserving Distributed Online Ride-Hailing Matching Scheme
abstract
Privacy-preserving online ride-hailing (ORH) service enables riders and drivers to conveniently establish optimized ride-hailing through mobile applications without disclosing their location information. In order to alleviate the load of central server and unnecessary increased response latency caused by centralized schemes, we investigate the privacy-preserving ORH matching service in distributed deployment environment. In this paper, we first design three secure outsourced calculation protocols based on Distributed Two-Trapdoor Public-Key Cryptosystem (DT-PKC), including ciphertext packing, blinding and decryption protocol across domains (CPBD), secure Euclidean square distance calculation protocol across domains (SESDC) and secure minimum distance selection protocol (SMDS). Then, we apply the protocols to construct a privacy-preserving distributed ORH matching scheme named pdRide. Geographically distributed road-side unit (RSU) and computation service provider (CSP) collaborate to securely select the matching driver for the requesting rider within a range. Specifically, SESDC can effective calculate the Euclidean square distances between multiple drivers and requesting rider over the encrypted location information with different keys. SMDS can select the driver with the minimum distance for the requesting rider on the encrypted distances. Finally, experiment results demonstrate its effectiveness in terms of communication overhead, computation overhead and transmission latency.
Qian Wang 0033, Chengzhe Lai, Dong Zheng 0001
IEEE Trans. Intell. Transp. Syst.2
2022 Achieving Efficient and Secure Query in Blockchain-based Traceability Systems
abstract
With the rapid development of blockchain technology, it provides a new technical solution for secure storage of data and trusted computing. However, in the actual application of data traceability, blockchain technology has an obvious disadvantage: the large amount of data stored in the blockchain system will lead to a long response time for users to query data. Higher query delay severely restricts the development of block chain technology in the traceability system. In order to solve this problem, we propose an efficient, secure and low storage overhead blockchain query scheme. Specifically, we design an index structure independent of Merkle tree to support efficient intra-block query, and create new fields in the block header to optimize inter-block query. Compared with several existing schemes, our scheme ensures the security of data. Finally, we simulate and evaluate our proposed scheme. The results show that the proposed scheme has better execution efficiency while reducing additional overhead.
Chengzhe Lai, Yinzhen Wang
PST1
2022 Secure medical data sharing scheme based on traceable ring signature and blockchain
Chengzhe Lai, Rui Guo 0005, Dong Zheng 0001
Peer-to-Peer Netw. Appl.1
2021 Group-based Handover Authentication for Space-Air-Ground Integrated Vehicular Networks
abstract
Space-air-ground integrated vehicular networks (SAGIVN) integrate satellite networks, aerial networks (UAVs) and vehicular networks into a complete network system, which has been attracting a lot of attention and exploration. SAGIVN can make vehicular platoon to keep connected and accessing the network of some areas with lack of infrastructure. However, satellites, UAVs and vehicular platoon accessing the SAGIVN will bring a huge security and efficiency challenges. In this paper, we propose an efficient and secure handover authentication scheme, along with the batch verification mechanism, for vehicular platoon in SAGIVN. The proposed scheme can enhance handover efficiency when vehicular platoon switches from the current UAV to the new UAV. Finally, the security analysis shows that our scheme can satisfy a variety of security requirements. The performance evaluation shows that our scheme has a better effect on both signaling overhead and handover latency than existing schemes.
Chengzhe Lai
ICC1
2021 SRSP: A Secure and Reliable Smart Parking Scheme With Dual Privacy Preservation
abstract
Finding an empty parking lot in a downtown or busy area is difficult and time consuming. Smart parking services enable vehicles to obtain real-time parking information, which has great potential to mitigate the parking problem. Compared with the existing parking methods, the cooperative parking information sharing based on vehicular crowdsourcing has lower cost and higher accuracy. However, vehicles face the threat of identity and trajectory privacy leakage. In order to provide secure and reliable parking service, we propose a secure and reliable smart parking scheme (SRSP) with dual privacy preservation. Specifically, a novel group signature technique can be equipped to achieve anonymous authentication among vehicles, parking server, and fog node. Meanwhile, the mix zone method combined with differential privacy can be utilized to hide the vehicles' trajectory. Moreover, message-lock encryption technique enables fog node to detect and delete duplicated reports to reduce the computational overhead of parking server. An incentive mechanism is proposed, which can not only reward contributing vehicles but also prevent the same vehicle from getting multiple rewards. In addition, the trust model is designed to evaluate the reliability of vehicles based on direct trust and recommendation trust. Finally, security analysis demonstrates that SRSP can achieve security objectives. Performance evaluation shows that SRSP has lower computational overhead compared with the existing schemes.
Chengzhe Lai, Qian Li 0054, Dong Zheng 0001
IEEE Internet Things J.1
2021 A trust-based privacy-preserving friend matching scheme in social Internet of Vehicles
Chengzhe Lai, Yangyang Du, Qili Guo, Dong Zheng 0001
Peer-to-Peer Netw. Appl.1
2020 A Bilingual Multi-type Spam Detection Model Based on M-BERT
abstract
Spam has harassed Internet users for a long time, and how to detect spam accurately and efficiently is a critical problem. As yet, there are lots of research works proposed to detect spam, e.g., black and white lists, machine learning methods, and deep learning content-level measures, etc. Based on previous works, we find that most of methods' accuracy can reach 0.95 when they focus on one type and one language spam. Nevertheless, nowadays, people will receive spam messages of different types, different sources, and even different languages. Toward this, we develop a novel model, which is based on Google multilingual bidirectional encoder representations from transformers (M-BERT). Meanwhile, we design a brand new bilingual multi-type spam dataset to train our model. Particularly, we utilize optical character recognition (OCR) to extract text from image-based spam. Through the experiment, we find that the proposed model's accuracy can reach 0.9648, which outperforms the comparison models. In terms of time overhead, the proposed model only costs 0.3168 seconds per training step, which is an acceptable overhead. Therefore, these analysis results demonstrate that our approach can detect bilingual multi-type spam effectively.
Jie Cao 0009, Chengzhe Lai
GLOBECOM2
2020 SPIR: A Secure and Privacy-Preserving Incentive Scheme for Reliable Real-Time Map Updates
abstract
The high-precision maps can provide additional information on roads and conditions, which plays an important role in autonomous vehicles (AVs) navigation. Compared with the existing map update methods, the real-time map updates based on crowdsensing have lower cost and higher accuracy. However, in the process of map update, the map service platform (MSP) cannot recruit enough vehicle users to obtain the sensing data due to a lack of incentive mechanism. Therefore, how to motivate more vehicle users to provide high-quality sensing data is the key for real-time map updates. In this article, we propose a secure and privacy-preserving incentive scheme for reliable real-time map updates, named SPIR. Specifically, under the condition of limited service platform budget and limited vehicle user's ability, an effective incentive mechanism based on reverse auction is presented, which can solve two core problems: i.e., payment control for MSP and completion quality for vehicle users. Meanwhile, a credit management and payment system based on the blockchain technique are designed. In addition, the partially blind signature technique is applied to guarantee the security of the incentive mechanism and protect the privacy of vehicle users. Both theoretical analysis and simulation results indicate that the proposed SPIR achieves near-optimal benefits, which can provide the fair reward for vehicle users and reasonable budget for the MSP. In the real-time map update services, SPIR can guarantee the computational efficiency and data reliability.
Chengzhe Lai, Jie Cao 0009, Dong Zheng 0001
IEEE Internet Things J.1
2020 A provably secure aggregate authentication scheme for unmanned aerial vehicle cluster networks
Hong Wang 0017, Chengzhe Lai
Peer-to-Peer Netw. Appl.3
2018 SEIP: Secure and seamless IP communications for group-oriented machine to machine communications
Chengzhe Lai, Dong Zheng 0001
Peer-to-Peer Netw. Appl.1
2018 The Improved Hill Encryption Algorithm towards the Unmanned Surface Vessel Video Monitoring System Based on Internet of Things Technology
abstract
Depending on the actual demand of maritime security, this paper analyzes the specific requirements of video encryption algorithm for maritime monitoring system. Based on the technology of Internet of things, the intelligent monitoring system of unmanned surface vessels (USV) is designed and realized, and the security technology and network technology of the Internet of things are adopted. The USV are utilized to monitor and collect information on the sea, which is critical to maritime security. Once the video data were captured by pirates and criminals during the transmission, the security of the sea will be affected awfully. The shortcomings of traditional algorithms are as follows: the encryption degree is not high, computing cost is expensive, and video data is intercepted and captured easily during the transmission process. In order to overcome the disadvantages, a novel encryption algorithm, i.e., the improved Hill encryption algorithm, is proposed to deal with the security problems of the unmanned video monitoring system in this paper. Specifically, the Hill algorithm of classical cryptography is transplanted into image encryption, using an invertible matrix as the key to realize the encryption of image matrix. The improved Hill encryption algorithm combines with the process of video compression and regulates the parameters of the encryption process according to the content of the video image and overcomes the disadvantages that exist in the traditional encryption algorithm and decreases the computation time of the inverse matrix so that the comprehensive performance of the algorithm is optimal with different image information. Experiments results validate the favorable performance of the proposed improved encryption algorithm.
Tingting Yang 0001, Chengzhe Lai, Minghua Xia
Wirel. Commun. Mob. Comput.3
2017 Achieving Secure and Seamless IP Communications for Group-Oriented Software Defined Vehicular Networks
Chengzhe Lai, Rongxing Lu, Dong Zheng 0001
WASA1
2017 SIRC: A Secure Incentive Scheme for Reliable Cooperative Downloading in Highway VANETs
abstract
In this paper, we propose a secure incentive scheme to achieve fair and reliable cooperative (SIRC) downloading in highway vehicular ad hoc networks (VANETs). SIRC can stimulate vehicle users to help download-and-forward packets for each other and consists of cooperative downloading and forwarding phase. During the cooperative downloading phase, SIRC utilizes “virtual checks” associated with the designated verifier signature to ensure fair and secure cooperation. Meanwhile, to minimize the payment risk of the client vehicle, partial prepayment strategy is adopted, i.e., the vehicles involved in downloading packets can only obtain part of the check before the client vehicle confirms the packet reception. During the cooperative forwarding phase, a profit-sharing model associated with an aggregating Camenisch-Lysyanskaya (CL) signature can stimulate cooperation and reduce the authentication overhead. In addition, we develop a reputation system to encourage cooperation and punish malicious vehicles. The aggregating CL signature and the symmetric cryptosystem are applied to resist various attacks, including injection/removing attack, free riding attack, submission refusal attack, and denial of service attacks. Extensive simulation results are given to show that the proposed SIRC can achieve a high download success rate and low average download delay with moderate cryptographic computation and communication overhead.
Chengzhe Lai, Kuan Zhang 0001, Nan Cheng 0001, Hui Li 0006, Xuemin Shen
IEEE Trans. Intell. Transp. Syst.1
2016 GLARM: Group-based lightweight authentication scheme for resource-constrained machine to machine communications
Chengzhe Lai, Rongxing Lu, Dong Zheng 0001, Hui Li 0006, Xuemin Shen
Comput. Networks1
2016 Optimal Workload Allocation in Fog-Cloud Computing Toward Balanced Delay and Power Consumption
abstract
Mobile users typically have high demand on localized and location-based information services. To always retrieve the localized data from the remote cloud, however, tends to be inefficient, which motivates fog computing. The fog computing, also known as edge computing, extends cloud computing by deploying localized computing facilities at the premise of users, which prestores cloud data and distributes to mobile users with fast-rate local connections. As such, fog computing introduces an intermediate fog layer between mobile users and cloud, and complements cloud computing toward low-latency high-rate services to mobile users. In this fundamental framework, it is important to study the interplay and cooperation between the edge (fog) and the core (cloud). In this paper, the tradeoff between power consumption and transmission delay in the fog-cloud computing system is investigated. We formulate a workload allocation problem which suggests the optimal workload allocations between fog and cloud toward the minimal power consumption with the constrained service delay. The problem is then tackled using an approximate approach by decomposing the primal problem into three subproblems of corresponding subsystems, which can be, respectively, solved. Finally, based on simulations and numerical results, we show that by sacrificing modest computation resources to save communication bandwidth and reduce transmission latency, fog computing can significantly improve the performance of cloud computing.
Ruilong Deng, Rongxing Lu, Chengzhe Lai, Tom H. Luan, Hao Liang 0002
IEEE Internet Things J.3
2016 SPGS: a secure and privacy-preserving group setup framework for platoon-based vehicular cyber-physical systems
abstract
Recently, the platoon-based vehicular cyber-physical system (VCPS) has attracted significant attention because the platoon based driving pattern can bring many benefits. In the platoon-based VCPS, the platoon members may change quite dynamically because vehicles can join or leave the platoon at any time. Therefore, how to securely and efficiently set up and maintain a platoon is a challenge. To address this issue, in this paper, we propose a secure and privacy-preserving group setup framework, called SPGS, for platoon-based VCPS. The key components of SPGS are two group setup policies that can be developed based on two kinds of techniques: attribute-based encryption and contributory key agreement. Based on these group setup policies, we propose two authentication protocols, respectively. The first one can authenticate all vehicles in the platoon simultaneously. The second one can guarantee anonymous authentication with traceability. With SPGS, a temporary platoon can be securely set up and maintained, and platoon merging/splitting can also be flexibly supported. Finally, we carry out extensive analysis to show the security and efficiency of our proposed SPGS. Copyright © 2016 John Wiley & Sons, Ltd.
Chengzhe Lai, Rongxing Lu, Dong Zheng 0001
Secur. Commun. Networks1
2016 Secure machine-type communications in LTE networks
abstract
Abstract With a great variety of potential applications, machine‐type communications (MTC) is gaining a tremendous interest from mobile network operators and research groups. MTC is standardized by the 3rd Generation Partnership Project (3GPP), which has been regarded as the promising solution facilitating machine‐to‐machine communications. In the latest standard, 3GPP proposes a novel architecture for MTC, in which the MTC server is located outside the operator domain. However, the connection between the 3GPP core network and MTC server in this scenario is insecure; consequently, there are distrustful relationships among MTC device, core network, and MTC server. If the security issue is not well addressed, all applications involved in MTC cannot be put into the market. To address this problem, we propose an end‐to‐end security scheme for MTC based on the proxy‐signature technique, called E2SEC. Specifically, both the MTC device and MTC server can establish strong trustful relationships with each other by using the proxy signatures issued by the 3GPP core network. Moreover, we present some implementation considerations of E2SEC and analyze the performance during authentication by comparing the operational cost of three cases that apply three different signature algorithms, that is, ElGamal, Schnorr, and DSA. Through security analysis by using Automatic Cryptographic Protocol Verifier (ProVerif), we conclude that the proposed E2SEC scheme can achieve the security goals and prevent various security threats. Copyright © 2015 John Wiley & Sons, Ltd.
Chengzhe Lai, Rongxing Lu, Hui Li 0006, Dong Zheng 0001, Xuemin Shen
Wirel. Commun. Mob. Comput.1
2015 Towards power consumption-delay tradeoff by workload allocation in cloud-fog computing
abstract
Fog computing, characterized by extending cloud computing to the edge of the network, has recently received considerable attention. The fog is not a substitute but a powerful complement to the cloud. It is worthy of studying the interplay and cooperation between the edge (fog) and the core (cloud). To address this issue, we study the tradeoff between power consumption and delay in a cloud-fog computing system. Specifically, we first mathematically formulate the workload allocation problem. After that, we develop an approximate solution to decompose the primal problem into three subproblems of corresponding subsystems, which can be independently solved. Finally, based on extensive simulations and numerical results, we show that by sacrificing modest computation resources to save communication bandwidth and reduce transmission latency, fog computing can significantly improve the performance of cloud computing.
Ruilong Deng, Rongxing Lu, Chengzhe Lai, Tom H. Luan
ICC3
2015 SGSA: Secure Group Setup and Anonymous Authentication in Platoon-Based Vehicular Cyber-Physical Systems
Chengzhe Lai, Rongxing Lu, Dong Zheng 0001
WASA1
2015 EAPSG: Efficient authentication protocol for secure group communications in maritime wideband communication networks
Tingting Yang 0001, Chengzhe Lai, Rongxing Lu, Rong Jiang 0001
Peer-to-Peer Netw. Appl.2
2015 Efficient self-healing group key management with dynamic revocation and collusion resistance for SCADA in smart grid
abstract
Abstract In this paper, in order to simultaneously resolve the transmission security and availability in Supervisory Control And Data Acquisition (SCADA) group communications, we propose a robust and efficient group key management scheme, called LiSH+, which is characterized by developing a secure self‐healing mechanism witht‐revocation and collusion resistance capability. A dual direction hash chain is utilized to guarantee the backward secrecy and forward secrecy of group key. A novel self‐healing mechanism is constructed to ensure availability of the group member in case of devices failure and prevent the collusive users from exploiting the group key in the proposed scheme. In addition, the compromised users can be revoked from the group dynamically by broadcasting message. Detailed security analysis shows that the proposed LiSH+ scheme meets the requirements of group communication and is secure in terms oftuser collusion‐free. Performance evaluation also demonstrates its efficiency in terms of low storage requirement and communication overheads. Copyright © 2014 John Wiley & Sons, Ltd.
Rong Jiang 0001, Rongxing Lu, Jun Luo 0011, Chengzhe Lai, Xuemin Shen
Secur. Commun. Networks4
2014 SEGR: A secure and efficient group roaming scheme for machine to machine communications between 3GPP and WiMAX networks
abstract
With extensive promising applications, machine to machine (M2M) communications or machine-type communication (MTC) have attached a tremendous interest among mobile network operators and research groups. Supporting multiple MTC devices has been considered as an essential requirement in M2M communications. How to achieve a secure and efficient access authentication for a group of MTC devices during roaming is a challenging issue. In this paper, in order to simultaneously resolve the access security and efficiency in MTC, we propose a secure and efficient group roaming scheme for MTC between 3GPP and WiMAX networks, named SEGR, which is characterized by authenticating all MTC devices in a group simultaneously and speeding up the process of authentication through adopting a novel certificateless aggregate signature technique. Through security analysis, the proposed SEGR can provide robust security, especially overcome the drawback of key escrow in identity-based (ID-based) aggregate signature schemes. In addition, performance evaluations in terms of communication overhead and computation complexity demonstrate that SEGR is more efficient than those traditional schemes.
Chengzhe Lai, Hui Li 0006, Rongxing Lu, Rong Jiang 0001, Xuemin Shen
ICC1
2014 CPAL: A Conditional Privacy-Preserving Authentication With Access Linkability for Roaming Service
abstract
The roaming service enables mobile subscribers to access the internet service anytime and anywhere, which can fulfill the requirement of ubiquitous access for the emerging paradigm of networking, e.g., the Internet of Things (IoT). In this paper, we propose a conditional privacy-preserving authentication with access linkability (CPAL) for roaming service, to provide universal secure roaming service and multilevel privacy preservation. CPAL provides an anonymous user linking function by utilizing a novel group signature technique, which can not only efficiently hide users’ identities but also enables the authorized entities to link all the access information of the same user without knowing the user’s real identity. Specifically, by using the master linking key possessed by the trust linking server, the authorized foreign network operators or service providers can link the access information from the user to improve its service, while preserving user anonymity, e.g., using individual access information to analyze user preferences without revealing user’s identity. Furthermore, the subscribers can also use this functionality to anonymously query their usage of service. In addition, CPAL has an efficient revocation function, which revokes a group of users at the same time. Through extensive analysis, we demonstrate that CPAL resists various security threats and provides more flexible privacy preservation compared to the existing schemes. Meanwhile, performance evaluations demonstrate its efficiency in terms of communication and computation overhead.
Chengzhe Lai, Hui Li 0006, Xiaohui Liang 0002, Rongxing Lu, Kuan Zhang 0001, Xuemin Shen
IEEE Internet Things J.1
2013 Robust group key management with revocation and collusion resistance for SCADA in smart grid
abstract
Supevisory Control And Data Acquisition (SCADA) systems are vital for operation and control of critical infrastructures in smart grid. Availability is one of the most important security objectives in SCADA communications, unavailability of which may further undermine the power delivery, and a reliable key management is essential to address this problem. In this paper, in order to simultaneously resolve the transmission security and availability in SCADA group communications, we propose a robust and efficient group key management scheme, called LiSH, which is characterized by developing a secure self-healing mechanism with t-revocation capability using one-way function to protect current session keys from being attacked by intruders. Detailed security analysis shows that the proposed LiSH scheme is secure in terms of collusion-free, and t-wise forward and backward security. In addition, performance evaluation also demonstrates its efficiency in terms of low storage and communication overheads.
Rong Jiang 0001, Rongxing Lu, Chengzhe Lai, Jun Luo 0011, Xuemin Shen
GLOBECOM3
2013 LGTH: A lightweight group authentication protocol for machine-type communication in LTE networks
abstract
Supporting a massive number of machine-type communication (MTC) devices has been considered as an essential requirement in machine to machine (M2M) communications. Meanwhile, cyber security is of paramount importance in MTC; if MTC devices cannot securely access the networks through efficient authentication, all applications involving MTC cannot be widely accepted. One of research challenges in MTC is group authentication. A large number of MTC devices accessing the network simultaneously will cause a severe authentication signaling congestion. To solve this problem and reduce authentication overhead of the previous schemes based on public key cryptosystems, we propose a novel lightweight group authentication protocol for MTC in the long term evolution (LTE) networks based on aggregate message authentication codes (MACs), called LGTH, which can not only authenticate all MTC devices simultaneously, but also minimize the authentication overhead. Through security analysis, we conclude that the proposed LGTH can provide robust security, and avoid the authentication signaling congestion in the LTE networks. In addition, performance evaluations in terms of communication and computation overhead demonstrate that LGTH is more efficient than previous schemes.
Chengzhe Lai, Hui Li 0006, Rongxing Lu, Rong Jiang 0001, Xuemin Shen
GLOBECOM1
2013 SE-AKA: A secure and efficient group authentication and key agreement protocol for LTE networks
Chengzhe Lai, Hui Li 0006, Rongxing Lu, Xuemin Shen
Comput. Networks1
2012 A simple and robust handover authentication between HeNB and eNB in LTE networks
Jin Cao 0001, Hui Li 0006, Maode Ma, Yueyu Zhang, Chengzhe Lai
Comput. Networks5