Lanxiang Chen

dblp:80/6074 · DBLP profile ↗
← Back
38ranked-venue papers
14as first author
23since 2021 · last 2026
0000-0002-5232-7801ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 4 first-author · 8 since 2021Systems, architecture and hardware · 9 · 5 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 1 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Theory of computation · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
YearPublicationVenuePosition
2026 An accurate, generalized, and efficient detection framework for steel surface defect inspection
Lanxiang Chen, Shikun Chen, Shunwu Xu, Zhaowen Chen
Eng. Appl. Artif. Intell.2
2026 Dynamic Hub Labeling for Shortest Distance Queries on Structured Encrypted Graphs
Mengdi Hu, Lanxiang Chen, Yi Mu 0001
VLDB J.2
2025 Privacy-Enhanced Role-Based Access Control for IoT Systems
abstract
Unauthorized accessing private information poses a significant security risk in IoT. Although role-based access control can partially address the problem, there is a lack of studies on protecting the privacy of roles. This work proposes a novel privacy-enhanced role-based access control (PE-RBAC) scheme for resource-limited cloud-based IoT systems. Our PE-RBAC scheme enhances the privacy of traditional RBAC by allowing the cloud platform (CP) to learn only the necessary roles of IoT devices rather than their entire role sets. IoT devices remain unaware of the cloud platform’s roles through the incorporation of the authorized private set intersection (APSI) protocol. Our scheme enables role authorization to prevent unauthorized requests by integrating an authorization center (AC) with an authentication scheme. It achieves lightweight computation and communication overhead using a garbled Bloom filter (GBF), independent of IoT roles. It requires only XOR operations and random number generation, making it ideal for IoT devices with limited computing capacity and bandwidth. Through formal security model definitions and rigorous security analysis, it achieves unlinkability and ciphertext indistinguishability for IoT device privacy and unforgeability for both the cloud platform and IoT devices. It demonstrates high practicality through real-world-like experiments considering varying role sizes and the number of concurrent IoT devices. Experimental results show a throughput of 1,100 requests per second, with storage overhead remaining linear with the number of devices.
Lanxiang Chen, Yizhao Zhu, Xiangqian Kong
IEEE Internet Things J.2
2025 Laconic updatable private set intersection
Xiangqian Kong, Lanxiang Chen, Yizhao Zhu, Yi Mu 0001
J. Inf. Secur. Appl.2
2025 Efficient and privacy-preserving butterfly counting on encrypted bipartite graphs
Xin Pang, Lanxiang Chen
J. Inf. Secur. Appl.2
2025 Authenticable Distributed Homomorphic Private Counter and its application in data analysis of edge computing
abstract
The rapid proliferation of advanced technologies, including the Internet of Things (IoT), cloud computing , and edge computing , has led to an exponential growth in structured and unstructured data, generated and collected across diverse applications. It is important to develop secure techniques that can efficiently process large volumes of data while preserving privacy. Privacy-preserving data analytics on encrypted data have gained popularity for performing essential calculations within cloud storage servers . However, applying these techniques to fully homomorphic encryption introduces inefficiencies and computational overheads. While homomorphic encryption allows for delegated execution of arithmetic operations directly on ciphertexts via cloud services, ensuring both efficiency and correctness in data computations remains a challenging endeavor. Most existing studies overlook simultaneous data aggregation while maintaining integrity and privacy for analytical purposes. In response, we propose an Authenticable Distributed Homomorphic Private Counter Scheme (ADHPC) for privacy-preserving data analysis in cloud computing. Our scheme securely and efficiently aggregates encrypted data within distributed edge computing environments, subsequently allowing authorized parties to decrypt and validate it. To authenticate the encrypted data, we employ an authenticable additive homomorphic encryption scheme based on online and offline setup stages. We demonstrate the applicability and efficiency of our proposed approach through implementation results and a comprehensive security analysis.
Fatemeh Rezaeibagha, Leyou Zhang, Ke Huang 0002, Lanxiang Chen
J. Inf. Secur. Appl.4
2025 Leakage Reduced Searchable Symmetric Encryption for Multi-Keyword Queries
abstract
Conjunctive keyword queries on untrusted cloud servers represent one of the most common forms of search in encrypted environments. Extensive research has been devoted to developing efficient schemes that support multi-keyword queries. In particular, the Oblivious Cross-Tags (OXT) protocol has received significant attention and is widely regarded as a benchmark in this domain. However, existing schemes fail to simultaneously hide the Keyword-Pair Result Pattern (KPRP) and the conditional Intersection Pattern (IP), potentially leaking additional information to the server. In this work, we propose a novel searchable symmetric encryption (SSE) scheme, referred to asResult Hiding Search (RHS), which aims to minimize result pattern leakage and achieve query result hiding during the index retrieval phase by integrating Private Set Intersection (PSI) techniques. Our scheme enhances privacy by employing PSI for secure membership testing. To improve query efficiency, we shift the expensive complex computation to the offline phase, and utilize efficient pseudorandom functions and hash functions during the online phase. Moreover, we propose a variant of RHS, called vRHS, designed to reduce client-side storage overhead. A simulation-based security proof demonstrates that our scheme is robust against non-adaptive adversaries. Comprehensive experimental evaluation further shows that our approach achieves better security and efficiency trade-offs compared to existing SSE schemes.
Qinghua Deng, Lanxiang Chen, Yizhao Zhu, Yi Mu 0001
IEEE Trans. Cloud Comput.2
2025 Private Reachability Queries on Structured Encrypted Temporal Bipartite Graphs
abstract
A temporal bipartite graph is a graph model that incorporates time-related information into its edges, making it suitable for modeling real-world phenomena like disease outbreaks. However, this temporal information is often sensitive. To protect the privacy of graph data, researchers have explored various approaches to preserve privacy in graph queries, with reachability queries being popular and fundamental as they determine the possibility of reaching one node from others in a graph. While privacy-preserving reachability queries have been extensively studied, existing efforts often overlook the valuable attribute information present in both edges and nodes of the graphs. Moreover, reachability queries on temporal bipartite graphs have not received sufficient attention in the literature. To bridge this gap, we propose a novel approach to achieve various privatereachabilityqueries onstructured encryptedtemporalbipartitegraphs ($\mathsf{RQ}$-$\mathsf{STBG}$) through a real-world scenario. Specifically, we construct a minimal index using hierarchical 2-hop labels and integrate structured encryption, order-revealing encryption, and garbled Bloom filters to support reachability queries with different label constraints. The proposed scheme is flexible and can cater to the query requirements of diverse users. Security analysis and experimental evaluations demonstrate that the proposed scheme achieves both preferable security and efficiency.
Lanxiang Chen, Gaolin Chen, Yi Mu 0001, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.2
2025 Keyword-Pair Result Pattern Hiding Structured Encryption for Boolean Queries
abstract
Cash et al. [CRYPTO2013] proposed the oblivious cross-tags (OXT) protocol to enable highly scalable searchable symmetric encryption (SSE) with support for Boolean queries. More recently, Lai et al. [CCS2018] introduced the hidden cross-tags (HXT) protocol, an enhancement of OXT designed to eliminate “keyword-pair result pattern” (KPRP) leakage in conjunctive queries. However, while HXT prevents KPRP leakage in conjunctive queries, it suffers from low efficiency and remains vulnerable to KPRP leakage in disjunctive queries. In this paper, we propose the first efficient structured encryption scheme for Boolean queries (STE-BQ) that eliminates KPRP leakage for both disjunctive and conjunctive multi-keyword queries. Our approach introduces a novel index construction method based on prime number aggregation, which significantly reduces the number of comparisons required in multi-keyword searches, thereby improving efficiency. Security analysis confirms that STE-BQ satisfies CQA2-security. Experimental evaluations further demonstrate that STE-BQ achieves optimal performance in conjunctive query processing. While its disjunctive query time is slightly slower than that of OXT, STE-BQ is the only scheme that fully eliminates KPRP leakage for both conjunctive and disjunctive queries.
Lanxiang Chen, Yi Mu 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.1
2024 Using private set intersection to achieve privacy-preserving authorization for IoT systems
Rongsheng Cai, Lanxiang Chen, Yizhao Zhu
J. Inf. Secur. Appl.2
2024 Practical and malicious private set intersection with improved efficiency
Yizhao Zhu, Lanxiang Chen, Yi Mu 0001
Theor. Comput. Sci.2
2024 A Pruned Pendant Vertex Based Index for Shortest Distance Query Under Structured Encrypted Graph
abstract
The shortest distance query is used to determine the shortest distance between two vertices. Various graph encryption schemes have been proposed to achieve accurate, efficient and secure shortest distance queries for encrypted graphs. However, the majority of these schemes are inefficient or lack scalability due to the time-consuming index construction and large index storage. Moreover, none of them consider the trade-off between query efficiency and accuracy. To better trade off the query efficiency and accuracy, we propose a Pruned Pendant Vertex based Index for Shortest Distance Query ($\mathsf { PPVI}$-$\mathsf { SDQ}$) under structured encryption. The proposed scheme utilizes the structured encryption technique to encrypt a graph and build indexes. The main idea is to use the recursive method to repeatedly prune the pendant vertex, and thereby reducing the index size and construction time by minimizing the redundant data storage and graph traversal. The proposed scheme achieves accurate, efficient and secure shortest distance query with privacy-preserving for encrypted graph. The security analysis demonstrates that the proposed scheme satisfies CQA2-security. Experimental results with real datasets show that the scheme achieves the optimal accuracy and efficiency.
Mengdi Hu, Lanxiang Chen, Gaolin Chen, Yi Mu 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.2
2024 Efficient Public-Key Searchable Encryption Scheme From PSI With Scalable Proxy Servers
abstract
Public-key Encryption with Keyword Search (PEKS) enables secure keyword searches within encrypted data. At the same time, Public-key Authenticated Encryption with Keyword Search (PAEKS) enhances security by permitting authorized users to search specific keyword sets, protecting against Internal Keyword Guessing Attacks (IKGA). However, to the best of our knowledge, existing PEKS and PAEKS schemes typically require to generate a distinct set of keyword ciphertext for each data user, leading to storage, computation, and communication costs and the lack of support for multiple-keyword search. In this article, we introduce a novel, efficient public-key searchable encryption scheme from the private set intersection (PSI) with scalable proxy servers, using a PSI protocol with multiple proxy server settings, which achieves sub-linear complexity. Our scheme is secure against IKGA and supports multiple keyword searches and sharing one encrypted keyword set by multiple users. We introduce an efficient system model with scalable proxy servers, significantly reducing computational overhead through a divide-and-conquer approach. Our proposed scheme supports multiple data users, and multiple keyword searches, utilizing a single set of keyword ciphertext for multiple data users. We formally define a security model and present a comprehensive security proof to demonstrate that our scheme maintains ciphertext-indistinguishability and trapdoor-indistinguishability.
Xiangqian Kong, Lanxiang Chen, Yizhao Zhu, Yi Mu 0001
IEEE Trans. Serv. Comput.2
2023 Enhanced Public-Key Searchable Encryption Scheme for Cloud-Based EHR Systems
abstract
Due to the swift development of cloud computing technology, an increasing number of healthcare organizations tend to store electronic health records (EHR) on cloud storage servers. To ensure patient privacy, sensitive information within EHR data must undergo encryption prior to being uploaded to the cloud server. Nonetheless, this encryption process alters the data's original structural characteristics, presenting a significant challenge in achieving effective and flexible EHR utilization, such as plaintext keyword search. Considering the privacy and practicality of EHR. This paper introduces a new cloud-based EHR system that integrates public-key encryption with the keyword search (PEKS) scheme. This system enables authorized users to conduct searches for specific keywords on encrypted EHR data, all while maintaining the highest level of data security. Compared to existing PEKS-based EHR system solutions, our approach is not limited by a secure channel, reducing communication overhead while taking full advantage of the large storage space and high computational performance of the cloud server to realize flexible and effective search capabilities. Furthermore, our solution effectively prevents online keyword guessing attacks from outside adversaries.
Xiangqian Kong, Lanxiang Chen
HealthCom2
2023 Structured encryption for triangle counting on graph data
Lanxiang Chen
Future Gener. Comput. Syst.2
2023 Toward Secure Data Computation and Outsource for Multi-User Cloud-Based IoT
abstract
Cloud computing has promoted the success of Internet of Things (IoT) with offering abundant storage and computation resources where the data from IoT sensors can be remotely outsourced to the cloud servers, whereas storing, exchanging and processing data collected through IoT sensors via centralised or decentralised cloud servers make cloud-based IoT systems prone to internal or external attacks. To protect IoT data against potential malicious users and adversaries, some cryptographic schemes have been applied to ensure confidentiality and integrity of IoT data. It is however a challenging task to perform any arithmetical computations once data items are encrypted. Fully-homomorphic encryption which is based on lattices can, in principle, provide a solution, but it is unfortunately inefficient in computation and hence cannot be applied to IoT. Fully-homomorphic encryption is feasible when we allow the involvement of a semi-trusted server. However, it is challenging to provide such a system in the situation of distributed environments for shared IoT data. We solve this problem and provide a fully-homomorphic encryption scheme for cloud-based IoT applications. We introduce a new method with the aid of a semi-trusted server that can help compute the homomorphic multiplications without gaining any useful information of the encrypted data. We show how our scheme is applied to multi-user IoT security and prove its semantic security. We also conduct experiments to justify its efficiency and applicability to multi-user cloud-based IoT systems.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang
IEEE Trans. Cloud Comput.4
2023 Authenticable Data Analytics Over Encrypted Data in the Cloud
abstract
Statistical analytics on encrypted data requires a fully-homomorphic encryption (FHE) scheme. However, heavy computation overheads make FHE impractical. In this paper we propose a novel approach to achieve privacy-preserving statistical analysis on an encrypted database. The main idea of this work is to construct a privacy-preserving calculator to calculate attributes’ count values for later statistical analysis. To authenticate these encrypted count values, we adopt an authenticable additive homomorphic encryption scheme to construct the calculator. We formalize the notion of an authenticable privacy-preserving calculator that has properties of broadcasting and additive homomorphism. Further, we propose a cryptosystem based on binary vectors to achieve complex logic expressions for statistical analysis on encrypted data. With the aid of the proposed cryptographic calculator, we design several protocols for statistical analysis including conjunctive, disjunctive and complex logic expressions to achieve more complicated statistical functionalities. Experimental results show that the proposed scheme is feasible and practical.
Lanxiang Chen, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.1
2023 Global Combination and Clustering Based Differential Privacy Mixed Data Publishing
abstract
With the rapid advancement of information technology, a large amount of high-value data have been generated. To exploit the potential value of big data and at the same time to protect individuals' sensitive information, a global combination and clustering based differential privacy (DP) mixed data publishing method is proposed in this paper. The main idea of the proposed method is to improve the truthfulness of the published data as well as to enhance the utility by shifting the sensitivity of query function from a single record to a group of records using$k$-median clustering algorithm. Specifically, to improve the accuracy and utility of categorical attributes, a global combination method is proposed to take the correlation among categorical attributes into account. The proposed combination method takes all categorical attributes as a unit and then applies the exponential mechanism to improve the data utility. Then we combine it with the$k$-median clustering with differential privacy to publish the mixed data. Theoretical analysis shows that the proposed method satisfies$\varepsilon$-differential privacy. Experimental results on real datasets illustrate that the proposed method has a much lower information loss and time overhead than the state-of-the-art approach for the same parameters.
Lanxiang Chen, Lingfang Zeng, Yi Mu 0001, Leilei Chen
IEEE Trans. Knowl. Data Eng.1
2023 CASE-SSE: Context-Aware Semantically Extensible Searchable Symmetric Encryption for Encrypted Cloud Data
abstract
Traditional searchable symmetric encryption (SSE) schemes rarely support context-aware semantic extension, and then lead to the searched results being incomplete or deviating from the user’s query intention. To address this problem, a new context-aware semantically extensible searchable symmetric encryption based on Word2vec model (CASE-SSE) is proposed to achieve context-aware semantic extension in this article. The proposed scheme utilizes outsourced datasets as corpora to extract all keywords for training the Word2vec model, and the trained results is the ontology knowledge base that can be used to extend the semantics of query keywords directly. Further, to facilitate multi-keyword search using the extended query vector, we use the$k$-means clustering algorithm to classify outsourced datasets. We then construct an AVL-tree index and an inverted index based on the classified results, thereby achieving efficient context-aware semantically extensible SSE. The security analysis indicates it is secure and effective. The experimental results show that our scheme is superior in both efficiency and accuracy.
Lanxiang Chen, Yujie Xue, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng
IEEE Trans. Serv. Comput.1
2023 Authenticable Additive Homomorphic Scheme and its Application for MEC-Based IoT
abstract
The integration of Internet of Things (IoT) and cloud computing are always seen as promising technologies to enhance streamlined data collection, share and exchange. Although the advances in edge computing, particularly mobile edge computing (MEC), could enhance the performance of data collection and computation via computing offloading, security and privacy impediments have made new challenges to data integrity and confidentiality, in particular when multiple edges or nodes at different locations collect IoT data. Homomorphic encryption therefore has shown promising advantages for cloud computing, offering arithmetic operations to be carried out on the encrypted data without revealing the secret key. While fully homomorphic encryption introduced by Gentry, in 2009, allows both additive and multiplicative operations, it has shown significant implementation drawbacks due to the parameters generation and memory consumption. In this work, we focus on partially homomorphic encryption, which can be efficiently computed. However, it is challenging to add authentication feature for the verification and aggregation capability. We propose a novel secure and privacy preserving authenticable homomorphic encryption (AHEC) scheme. We demonstrate an application of our AHEC scheme for MEC-based IoT systems and provide security analysis to prove that our scheme is secure against chosen plaintext attack (IND-CPA) and unforgeability (UNF) under DDH-ZN2 and Lift-DH-ZN2 assumptions. Experimental results show that our proposed scheme is efficient for practical applications.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen, Leyou Zhang
IEEE Trans. Serv. Comput.4
2022 Blockchain-based random auditor committee for integrity verification
Lanxiang Chen, Qingxiao Fu, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Min-Shiang Hwang
Future Gener. Comput. Syst.1
2022 Structured encryption for knowledge graphs
Yujie Xue, Lanxiang Chen, Yi Mu 0001, Lingfang Zeng, Fatemeh Rezaeibagha, Robert H. Deng
Inf. Sci.2
2021 Secure and Efficient Data Aggregation for IoT Monitoring Systems
abstract
The proliferation of Internet of Things (IoT) as a promising paradigm has contributed enormously to modern technology design. The wireless body sensor network (WBSN) technology is an application of IoT in healthcare, whereas data security and privacy impediments have raised some concerns. The collected data via IoT wireless body sensors is vulnerable to a variety of internal and external attacks. One solution is to encrypt or sign the collected data to provide confidentiality and integrity, but the computational complexity hinders the application in the real IoT-based healthcare devices. Although there have been some attempts to provide secure and efficient IoT schemes, there is a lack of achieving secure data analysis in modern healthcare. The aggregated data statistics about the patient's medical status is useful to doctors and healthcare providers. However, the dynamic data continually updating over time is challenging. In this article, we present an efficient and provably secure scheme, which is the first step toward secure data analysis for handling the data collection and analysis for IoT wireless body sensors. The main contribution of our work is a novel cryptographic accumulator based on our novel authenticated additive homomorphic encryption which can collect and accumulate data from IoT wireless wearable devices. These encrypted data can be used for analysis in an encrypted form so that the information is not revealed. To validate security and efficiency, we present security analysis and performance evaluations of our proposed scheme for IoT wireless body sensors.
Fatemeh Rezaeibagha, Yi Mu 0001, Ke Huang 0002, Lanxiang Chen
IEEE Internet Things J.4
2020 On Reliability of Multiprocessor System Based on Star Graph
abstract
As a critical parameter in evaluating the reliability of a multiprocessor system when processors malfunction, the \boldmath h-extra connectivity (h-EC) of a multiprocessor system modeled by a graph G, denoted by κo(h)(G), is an h-extra vertex-cut with minimum cardinality. Both of the h-extra conditional diagnosability (h-ECD) and the t/h-diagnosability of the multiprocessor system are vital to tolerate and diagnose faulty processors. These two parameters rely on the resolving of hEC. For the multiprocessor system based on star graph Sn, we show that the 5-EC κo(5)(Sn) of Sn(n ≥ 5) is 6n - 18. As a by-product, we present a novel proof of κo(2)(Sn) = 3n - 7 (resp., κo(4)(Sn) = 5n - 14) by relaxing the restriction n ≥ 10 (resp., n ≥ 7) to n ≥ 5 (resp., n ≥ 5). Furthermore, we determine that the h-ECD of Sn(n ≥ 5) under the preparata, metze, and chien (PMC) model is (h + 1)n - 2h - 1 for 1 ≤ h ≤ 3 and (h + 1)n - 3h + 2 for 4 ≤ h ≤ 5. In addition, we show that Snis [(h + 1)n - 4h + 2]/h-diagnosable for 4 ≤ h ≤ 5, which extends the result that Snis [(h + 1)n - 3h - 1]/h-diagnosable for 1 ≤ h ≤ 3 by [Zhou et al. “The t/k-diagnosability of star graph networks,” IEEE Trans. Comput., vol. 64, no. 2, pp. 547-555, Feb. 2015].
Mengjie Lv, Shuming Zhou, Gaolin Chen, Lanxiang Chen, Jiafei Liu 0001, Chin-Chen Chang 0001
IEEE Trans. Reliab.4
2019 Practical, Dynamic and Efficient Integrity Verification for Symmetric Searchable Encryption
Lanxiang Chen, Zhenchao Chen
CANS1
2019 Blockchain based searchable encryption for electronic health record sharing
Lanxiang Chen, Wai-Kong Lee, Chin-Chen Chang 0001, Kim-Kwang Raymond Choo
Future Gener. Comput. Syst.1
2019 Enhanced secure data backup scheme using multi-factor authentication
abstract
Remote data backup technology facilitates data storage for users. However, an attacker may intercept some sensitive data on transfer. To solve this problem, sensitive data should be encrypted before uploading to the remote storage. Thus, protecting the secret encryption key is very important. Liu et al . have designed a scheme to protect the secret key using the secret‐sharing method and multi‐factor authentication. Unfortunately, the authors find some security weaknesses of Liu et al .’s scheme. Liu et al .’s scheme cannot resist offline password guessing attack, the server impersonation attack, the user impersonation attack and an attacker updating password/biometrics attack. They present an enhanced secure data backup scheme using multi‐factor authentication to overcome all above‐mentioned security threats. The user first divided a secret used to encrypt sensitive data into three shares using Shamir's secret sharing. Moreover, then the user uses the own password and biometrics to hide the true shares, and stores the pseudo three shares in the smart card, the laptop and the server, separately. Furthermore, the proposed scheme is illustrated in detail, and they give a security comparison of their scheme with Liu et al .’s scheme and computational costs.
Huidan Hu, Changlu Lin, Chin-Chen Chang 0001, Lanxiang Chen
IET Inf. Secur.4
2018 Improving file locality in multi-keyword top-k search based on clustering
Lanxiang Chen, Kuanching Li, Shuibing He, Linbing Qiu
Soft Comput.1
2017 DMRS: an efficient dynamic multi-keyword ranked search over encrypted cloud data
Lanxiang Chen, Linbing Qiu, Kuanching Li
Soft Comput.1
2016 On conditional fault tolerance and diagnosability of hierarchical cubic networks
Shuming Zhou, Sulin Song, Xiaoxue Yang, Lanxiang Chen
Theor. Comput. Sci.4
2015 Remote data possession checking with enhanced security for cloud storage
Yong Yu 0002, Yafang Zhang, Jianbing Ni, Man Ho Au, Lanxiang Chen
Future Gener. Comput. Syst.5
2014 Improvement of a Remote Data Possession Checking Protocol from Algebraic Signatures
Yong Yu 0002, Jianbing Ni, Jian Ren 0001, Wei Wu 0001, Lanxiang Chen, Qi Xia 0001
ISPEC5
2014 A hill cipher-based remote data possession checking in cloud storage
abstract
ABSTRACT Cloud storage enables users to access their data at any time anywhere. It has the advantages of high scalability, ease of use, cost effectiveness, and so on. However, the server that stores users' data may not be fully trustworthy. When users store their data in cloud storage, they concern much about data intactness. This is the goal of remote data possession checking schemes. This paper proposes a Hill cipher‐based remote data possession checking scheme. The main idea of the scheme comes from the homomorphism of Hill cipher, namely the tags computed from plaintext blocks can be used to compare with the tags computed from ciphertext blocks. It has several advantages as follows. First, it is efficient in terms of computation and communication. Second, it allows verification without the need for the challenger to compare against the original data. Third, the scheme only needs to store a small amount of metadata and use only small challenges and responses. Finally, it performs data possession checking at the same time it provides confidentiality of data. The security and performance analysis illustrates that the scheme is feasible and effective. Copyright © 2013 John Wiley & Sons, Ltd.
Lanxiang Chen, Gongde Guo
Secur. Commun. Networks1
2013 Using algebraic signatures to check data possession in cloud storage
Lanxiang Chen
Future Gener. Comput. Syst.1
2009 Using Session Identifiers as Authentication Tokens
abstract
As authentication provides crucial online identity, it is the basis of data security. In this paper, a session based authentication is proposed and the long unique un-guessable session identifier is used as a parameter of an authentication token. It has the advantages of one-timeness, short-lived and no prior knowledge requirement. The session model is established with detailed implementation of communication protocol. The security of this protocol is then analyzed formally and the results show that the protocol can resist various attacks, e.g. session hijacking, message replay and pharming attacks etc. Finally, a case is studied and the performance of the application is evaluated, which indicates that the proposed scheme is simpler and more efficient than the existing schemes.
Lanxiang Chen, Dan Feng 0001, Zhan Shi 0001
ICC1
2007 FPGA/ASIC based Cryptographic Object Store System
abstract
avoid re-encryption in cryptographic storage system when revoking users, Field Programmable Gate Array (FPGA) and Application Specific Integrated Circuit (ASIC) hardware module have been introduced to a cryptographic object store system, let private key never leave the hardware module and symmetric key only exist in hardware module in plaintext. Anyone doesn 7 know private or symmetric key, so when revoking users, it just needs to modify access control list (A CL) to delete the privileges of the users. To facilitate file sharing and key management, group is adopted. In our system, almost all computationally expensive cryptographic operations are through FPGA/ASIC hardware module. Once creator revokes some users, objects don't need re- encryption. How to use ACL and FPGA/ASIC hardware module to authenticate and authorize are described. And the procedure of object store and the distribution of meta-data are detailed. Finally, a cryptographic object store prototype system is implemented with tested and effective performance.
Dan Feng 0001, Lanxiang Chen, Lingfang Zeng, Zhongying Niu
IAS2
2007 The Security Threats and Corresponding Measures to Distributed Storage Systems
Lanxiang Chen, Dan Feng 0001, Liang Ming
APPT1
2007 A Direction to Avoid Re-encryption in Cryptographic File Sharing
Lanxiang Chen, Dan Feng 0001, Lingfang Zeng
NPC1