Yanping Li 0001

dblp:77/2109-1 · also Yan-Ping Li 0001 · DBLP profile ↗
← Back
28ranked-venue papers
3as first author
23since 2021 · last 2025
0000-0002-2395-6000ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 1 first-author · 9 since 2021Systems, architecture and hardware · 8 · 2 first-author · 7 since 2021Security and privacy · 6 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2025 ADPFL: Adaptive Differential Privacy-Enhanced Federated Learning
Xiuli Xu, Yanping Li 0001, Laifeng Lu
IEEE Internet Things J.2
2025 RAFL: Reputation-Aware Federated Learning with hierarchical aggregation in LEO satellite networks
Xiuli Xu, Yanping Li 0001, Laifeng Lu
J. Syst. Archit.2
2024 A Lightweight and Robust Multidimensional Data Aggregation Scheme for IoT
abstract
Data aggregation technology plays a very important role in improving the efficiency of data collection of the Internet of Things (IoT). Most data collected by sensor nodes (SNs) in IoT is multi-dimensional. However, there are a few existing multi-dimensional data aggregation schemes, which are almost based on homomorphic encryption and not suitable for resource-constrained IoT smart devices. In addition, when SNs cannot upload in time for some reason, such as device error or network interruption, control center cannot get the correct aggregation result, i.e., robustness is not considered in most schemes. Therefore, we propose a lightweight and robust multi-dimensional data aggregation scheme for IoT. First, multi-dimensional data is packaged into one-dimensional data based on the Chinese Remainder Theorem, which greatly reduces communication and storage overhead. Second, the encryption in our scheme only uses addition operations without the costly additive homomorphic encryption. At the same time, our proposed scheme supports batch verification, which reduces the computation complexity of bilinear pairs by nearly half. Third, our scheme also supports dynamic SNs management and fault tolerance, enabling scalability and robustness. Finally, performance evaluation shows that our scheme has lower communication overhead and is more suitable for resource-constrained IoT scenarios.
Yanping Li 0001, Yong Ding 0005, Bo Yang 0003
IEEE Internet Things J.2
2024 EHFL: Efficient Horizontal Federated Learning With Privacy Protection and Verifiable Aggregation
abstract
As a recently distributed machine learning framework, federated learning (FL) has garnered attention for its privacy protection. However, recent researches in recent years have shown malicious entities may still acquire the clients’ privacy in FL. Moreover, factors, such as the verifiability of the aggregation model and the huge computational and communication overheads, also make existing solutions less practical. To this end, we design a novel FL architecture named EHFL. First of all, EHFL protects data privacy by concealing the clients’ data using a single mask and group key encryption. Second, combined with symmetric balanced incomplete block design (SBIBD), our EHFL dramatically reduces client computational and communication overhead to approximately$(k+1)/(k^{2}+k+1)$compared to traditional FL (e.g., FedAvg). Third, EHFL designs an ingenious verification mechanism to ensure the correctness of the aggregation server’s results via the Hamiltonian graph formed by the SBIBD. Finally, sufficient theoretical analyses prove the reliability of EHFL and lots of experiments demonstrate the effectiveness of EHFL.
Zehu Zhang, Yanping Li 0001, Kai Zhang 0044
IEEE Internet Things J.2
2024 A Blockchain-Based Anonymous Attribute-Based Searchable Encryption Scheme for Data Sharing
abstract
Attribute-based searchable encryption (ABSE) is a promising encryption mechanism for sharing outsourced encrypted data in clouds, allowing fine-grained access control over data while searching for encrypted data. However, the access policy in the most existing ABSE schemes exists in plaintext, which could expose sensitive information about legitimate data users. Moreover, such schemes delegate complex search operations to a cloud server, which can lead to data tampering and even untrusted results, and single point of failure. In this article, we propose a blockchain (BC)-based anonymous ABSE scheme for data sharing (BADS). First, attributes of the access policy are hidden, thus, providing confidentiality to the set of attributes that satisfy the access policy. Then combining ABSE with BC have features of tamper-proof, integrity verification, and nonrepudiation. In particular, information, such as secure index is stored in BC, while encrypted data is stored in a distributed system called the interplanetary file system (IPFS) to avoid single point of failure. Finally, BADS supports the matching algorithm that perform a fixed number of pairing operations before searching algorithm. We analysis security and evaluate performance to show the efficiency and practicability of BADS.
Kai Zhang 0044, Yan Zhang 0107, Yanping Li 0001, Ximeng Liu, Laifeng Lu
IEEE Internet Things J.3
2024 A Physician's Privacy-Preserving Authentication and Key Agreement Protocol Based on Decentralized Identity for Medical Data Sharing in IoMT
abstract
As well known, Internet of medical things (IoMT) produces large amounts of medical data and promotes the medical data sharing which serves the data user (i.e., physicians) to boost the clinical treatment and medical research. To protect data user’s privacy and data security during the sharing of medical data, data user must have a self-sovereign decentralized identity (DID) and data access authority. In existing solutions, data user’s privacy protection and authenticated-key-agreement (AKA) for protecting data security are worked independently, which easily results in typical security attacks (e.g., phishing inquiry attacks, ephemeral secret leakage attacks) during data access and system computing overload. To solve the challenge, a new credential-embedded authentication and key agreement scheme (CAKA) is proposed, which can seamlessly combine DID-credentials into AKA. First, CAKA supports bilateral authentication by allowing a digital user to authenticate its service provider, which can enhance the security of unilateral scheme (such as CanDID, IEEE S&P, 2021) and prevent phishing query attacks. Second, for secure data session communication, the user’s DID-credentials are used as the kernel of the session key (SK) generation. In security analysis and performance metrics comparisons, the results indicate that CAKA holds a significant advantage, especially, the storage costs, communication costs and computation costs consumed in CAKA are at least 43% reduction, compared to alternatives. In simulation experiments of CAKA, the results show that decentralized identity authentication and session key agreement are both less than 15 ms, that means CAKA is a practical and promising solution to medical data sharing.
Shihong Zou, Qiang Cao 0006, Chonghui Huangqi, Anpeng Huang, Yanping Li 0001, Chenyu Wang 0002, Guoai Xu
IEEE Internet Things J.5
2024 NSPFL: A Novel Secure and Privacy-Preserving Federated Learning With Data Integrity Auditing
abstract
Federated learning (FL) is a new distributed machine learning framework that emerged in recent years, which can protect the participants’ data privacy to a certain extent without exchanging the participants’ original data. Unfortunately, it can still be vulnerable to privacy attacks (e.g. membership inference attacks) or security attacks (e.g. model poisoning attacks), which can compromise participants’ data or corrupt the trained model. Inspired by previous works, we propose a novel federated learning framework with data integrity auditing called NSPFL. First, NSPFL protects against privacy attacks by using a single mask to hide the participants’ original data. Second, NSPFL constructs a novel reputation evaluation method to resist security attacks by measuring the distance between the previous and current aggregated gradients. Third, NSPFL utilizes the data stored on the cloud to prevent malicious Byzantine participants from denying behaviors. Finally, sufficient theoretical analysis proves the reliability of the scheme, and a large of experiments demonstrate the effectiveness of the NSPFL.
Zehu Zhang, Yanping Li 0001
IEEE Trans. Inf. Forensics Secur.2
2024 Lightweight and Decentralized Cross-Cloud Auditing With Data Recovery
abstract
Cloud storage has benefited millions of users with its remarkable advantages of economy and flexibility. Since a single cloud service provider is not always reliable and prone to a single point of failure, multi-cloud storage is proposed to enhance data availability. However, cross multiple clouds (cross-cloud) auditing to provide users with the integrity verification of outsourced data also faces many challenges, such as the fact that a large quantity of existing schemes rely heavily on the trusted third-party. Therefore, we propose a decentralized data storage and integrity auditing scheme for multi-cloud scenarios to eliminate the dependence on the third-party, namely BDDR, and an improved version iBDDR with stronger security. First, both BDDR and iBDDR adopt multi-cloud data storage and support batch auditing to greatly save computation costs. Second, our schemes not only get rid of a third-party, but also do not require a dispute arbitration since the outsourced data can be verified by cloud server providers via the homomorphic verifiable tags published on the blockchain. Third, locating the corrupted cloud server providers and accurately recovering the corrupted data at a lower communication and computation costs are supported. Finally, security and performance analyses demonstrate the security and effectiveness of our schemes.
Liping Qiao, Yanping Li 0001, Yong Ding 0005, Bo Yang 0003
IEEE Trans. Serv. Comput.2
2023 PTAP: A novel secure privacy-preserving & traceable authentication protocol in VANETs
Yichuan Wang 0003, Yanping Li 0001
Comput. Networks3
2023 VMSE: Verifiable multi-keyword searchable encryption in multi-user setting supporting keywords updating
Yanrong Liang, Yanping Li 0001, Kai Zhang 0044, Zhenqiang Wu
J. Inf. Secur. Appl.2
2023 Blockchain-based auditing with data self-repair: From centralized system to distributed storage
Yanping Li 0001, Laifeng Lu, Yong Ding 0005
J. Syst. Archit.2
2023 Algebraic Signature-Based Public Data Integrity Batch Verification for Cloud-IoT
abstract
With the rapid development of Internet of Things, the related data are growing explosively. However, IoT devices have limited storage and computing capabilities so that they cannot deal with massive data storage and computing locally. The integration of IoT and cloud is regarded as an effective solution to the above issue, i.e., IoT devices outsource collected data to cloud to enjoy powerful storage and computing resources. Because the data stored in cloud are out of the control of IoT users, some security risks need to be addressed in advance. In this paper, we propose a public data integrity verification scheme, called AIVCI, to check the data integrity for Cloud-IoT scenarios. Firstly, based on algebraic signature and homomorphic hash function, AIVCI can efficiently complete data auditing. Secondly, AIVCI adopts blind technology to prevent the privacy leakage of IoT data and further protect the privacy of IoT users. Thirdly, batch auditing is implemented to improve auditing efficiency and meet realistic demands for Cloud-IoT scenarios. And a new data structure named Improved Divide and Conquer Table (ID&CT) is designed to realize efficient data dynamics. Finally, the security and performance analysis demonstrates that AIVCI is more secure and efficient.
Yanping Li 0001, Bo Yang 0003, Yong Ding 0005
IEEE Trans. Cloud Comput.1
2023 Edge-Enabled: A Scalable and Decentralized Data Aggregation Scheme for IoT
abstract
The data aggregation technique has been widely adopted in the Internet of Things (IoT) to protect data privacy while ensuring data availability. Homomorphic encryption is a typical technique that guarantees accurate computing results. However, it brings heavy computation overhead for edge nodes and exposes the aggregated results to the central server, which significantly threatens the confidentiality of results. This article gets rid of the server-centric style existing in most data aggregation schemes and proposes a scalable and decentralized data aggregation scheme for edge-enabled IoT. In the proposed scheme, edge nodes can freely form, join, and exit from the data aggregation group to aggregate data correctly, securely, and efficiently. Besides, two structure-based data aggregation methods are proposed to reduce the aggregation overhead to$O(n\sqrt{n})$with constant rounds, as opposed to$O(n\log n)$with$O(n)$round. Symmetric encryption and online/offline signature computation are adopted to mitigate the online computation burden. Moreover, the proposed scheme can rigorously defend against forgery attack, eavesdropping attack, and collusion attack. The performance evaluation and experiment results show that the proposed scheme improves the efficiency of communication with affordable computation costs for edge nodes.
Yuan Su, Yanping Li 0001, Zhou Su 0001
IEEE Trans. Ind. Informatics3
2022 Lightweight integrity auditing of edge data for distributed edge computing scenarios
Liping Qiao, Yanping Li 0001, Bo Yang 0003
Ad Hoc Networks2
2022 Edge data integrity verification scheme supporting data dynamics and batch auditing
Yanping Li 0001, Kai Zhang 0044
J. Syst. Archit.2
2022 A faster outsourced medical image retrieval scheme with privacy preservation
abstract
With the rapid development of computer technology and medical imaging technology, medical images present an explosive growth. To save storage and computation overhead, hospitals often choose to outsource digital medical images to cloud server. Since medical images are a major auxiliary means for doctors’ diagnosis or medical researchers’ study, the secure retrieval of outsourced medical images is especially important. To address this problem, we propose a Faster outsourced Medical Image Retrieval scheme with privacy preservation (FMIR) in this paper. FMIR first makes a simple classification to outsourced medical images, which narrows the retrieval range and improves the retrieval efficiency compared with the existing unclassified retrieval schemes. Second, FMIR implements a lightweight access control for each class using polynomial-based access control strategy , which provides the fine-grained access control for better privacy protection of medical images. Third, FMIR reduces the interference of random numbers on relevant score to 0, which further improves the accuracy of the retrieval. Finally, the security and performance analysis show that FMIR is secure, accurate and efficient.
Yating Duan, Yanping Li 0001, Laifeng Lu, Yong Ding 0005
J. Syst. Archit.2
2022 Decentralized Self-Auditing Scheme With Errors Localization for Multi-Cloud Storage
abstract
With the popularity of cloud storage, increasing users begin to outsource data to the cloud. In order to resist possible data analysis for centralized outsourced data and improve the fault tolerance, users prefer to distribute data to cloud servers of different cloud service providers. However, once the data have been outsourced, it will be out of user’s control and many security issues may occur, such as outsourced data being illegally tamper with, or rarely accessed data being secretly deleted. In this article, we propose a decentralized self-auditing scheme for multi-cloud storage, called DSAS. First, based on the symmetric balanced incomplete block design, DSAS achieves integrity verification for outsourced data via the interactions of cloud servers and the auditing costs are shared by the participating CSs. Second, DSAS can locate misbehavior cloud server with low computation costs, and resist denial of service attack initiated by malicious cloud servers which attempts to destroy the audit. Third, DSAS can recover the corrupted data without fetching data, and support the revocation of cloud servers and batch auditing. Finally, security proof and function evaluation show that DSAS has comprehensive security and functionality, and performance simulations and experiment results show that DSAS is efficient.
Yuan Su, Yanping Li 0001, Bo Yang 0003, Yong Ding 0005
IEEE Trans. Dependable Secur. Comput.2
2021 Robust and auditable distributed data storage with scalability in edge computing
Yanping Li 0001, Bo Yang 0003
Ad Hoc Networks2
2021 LCEDA: Lightweight and Communication-Efficient Data Aggregation Scheme for Smart Grid
abstract
Secure data aggregation for smart grid aims to protect the privacy of individual data and guarantee the utility of big data. To protect user’s privacy in data aggregation, public-key-based homomorphic encryption and masking-value-based methods are adopted in existing works. However, public-key-based homomorphic encryption causes unaffordable computation costs for smart meters (SMs), while the masking-value-based works suffer from inefficient communication. Therefore, we propose a lightweight and communication efficient data aggregation (LCEDA) scheme for smart grid. First, LCEDA allows SMs to freely form the aggregation zone at lower communication and computation costs. Second, in order to ensure forward security of individual data, LCEDA achieves efficient update of masking value share, which greatly saves the complexity and computation costs compared with the existing schemes. Third, LCEDA supports dynamic enrollment and revocation of SMs to solve the malfunction and migration of SMs and improve the scalability of the LCEDA scheme. Finally, the security of LCEDA is analyzed, and extensive performance evaluations and experiments demonstrate that LCEDA is more efficient and practical.
Yuan Su, Yanping Li 0001, Kai Zhang 0044
IEEE Internet Things J.2
2021 A privacy-preserving public integrity check scheme for outsourced EHRs
Yuan Su, Yanping Li 0001, Kai Zhang 0044, Bo Yang 0003
Inf. Sci.2
2021 A secure index resisting keyword privacy leakage from access and search patterns in searchable encryption
Yanping Li 0001, Qiang Cao 0006, Kai Zhang 0044
J. Syst. Archit.1
2021 DMSE: Dynamic Multi-keyword Search Encryption based on inverted index
Yanrong Liang, Yanping Li 0001, Kai Zhang 0044
J. Syst. Archit.2
2021 Privacy-Preserving Attribute-Based Keyword Search with Traceability and Revocation for Cloud-Assisted IoT
abstract
With the rapid development of cloud computing and Internet of Things (IoT) technology, it is becoming increasingly popular for source-limited devices to outsource the massive IoT data to the cloud. How to protect data security and user privacy is an important challenge in the cloud-assisted IoT environment. Attribute-based keyword search (ABKS) has been regarded as a promising solution to ensure data confidentiality and fine-grained search control for cloud-assisted IoT. However, due to the fact that multiple users may have the same retrieval permission in ABKS, malicious users may sell their private keys on the Internet without fear of being caught. In addition, most of existing ABKS schemes do not protect the access policy which may contain privacy information. Towards this end, we present a privacy-preserving ABKS that simultaneously supports policy hiding, malicious user traceability, and revocation. Formal security analysis shows that our scheme can not only guarantee the confidentiality of keywords and access policies but also realize the traceability of malicious users. Furthermore, we provide another more efficient construction for public tracing.
Kai Zhang 0044, Yanping Li 0001, Laifeng Lu
Secur. Commun. Networks2
2020 VPAMS: Verifiable and practical attribute-based multi-keyword search over encrypted cloud data
Yanrong Liang, Yanping Li 0001, Qiang Cao 0006
J. Syst. Archit.2
2020 A Traceable and Revocable Multiauthority Attribute-Based Encryption Scheme with Fast Access
abstract
Multiauthority ciphertext-policy attribute-based encryption (MA-CP-ABE) is a promising technique for secure data sharing in cloud storage. As multiple users with same attributes have same decryption privilege in MA-CP-ABE, the identity of the decryption key owner cannot be accurately traced by the exposed decryption key. This will lead to the key abuse problem, for example, the malicious users may sell their decryption keys to others. In this paper, we first present a traceable MA-CP-ABE scheme supporting fast access and malicious users’ accountability. Then, we prove that the proposed scheme is adaptively secure under the symmetric external Diffie–Hellman assumption and fully traceable under the q -Strong Diffie–Hellman assumption. Finally, we design a traceable and revocable MA-CP-ABE system for secure and efficient cloud storage from the proposed scheme. When a malicious user leaks his decryption key, our proposed system can not only confirm his identity but also revoke his decryption privilege. Extensive efficiency analysis results indicate that our system requires only constant number of pairing operations for ciphertext data access.
Kai Zhang 0044, Yanping Li 0001, Yun Song, Laifeng Lu, Tao Zhang 0029, Qi Jiang 0001
Secur. Commun. Networks2
2020 Privacy-preserving conjunctive keyword search on encrypted data with enhanced fine-grained access control
Qiang Cao 0006, Yanping Li 0001, Zhenqiang Wu, Yinbin Miao, Jianqing Liu
World Wide Web2
2016 NCLAS: a novel and efficient certificateless aggregate signature scheme
abstract
Aggregate signature algorithms combine n signatures on n different messages from n distinct users into one aggregated signature. The aggregated signature allows the verifier to authenticate the n signatures simultaneously. Because the total signature length and authentication costs are significantly reduced, aggregate signature algorithms are attractive to applications with resource constraints and applications requiring efficient batch authentications. In this paper, we propose a novel aggregate signature scheme based on certificateless-PKC. Under this novel scheme, the length of the aggregated signature and the pairing computation cost in the aggregate signature verification process are independent of the number of signatures being aggregated. We also prove that the proposed scheme is existentially unforgeable against adaptive chosen-message and chosen-identity attacks, based on the hardness assumption of the computational Diffie-Hellman problem. The new scheme will be suitable for resource-constrained applications. Copyright © 2016 John Wiley & Sons, Ltd.
Haohao Nie, Yanping Li 0001, Weifeng Chen 0001, Yong Ding 0005
Secur. Commun. Networks2
2016 CAKA: a novel certificateless-based cross-domain authenticated key agreement protocol for wireless mesh networks
Yanping Li 0001, Weifeng Chen 0001, Zhiping Cai, Yuguang Fang
Wirel. Networks1