Fei Chen 0003

dblp:81/4345-3 · DBLP profile ↗
← Back
48ranked-venue papers
21as first author
20since 2021 · last 2025
0000-0001-8132-539XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 4 first-author · 7 since 2021Systems, architecture and hardware · 10 · 6 first-author · 3 since 2021Security and privacy · 7 · 4 first-author · 5 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 4 · 1 since 2021Theory of computation · 3 · 3 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 SWICE: Towards Connection-Free Transmission in Wireless Distributed Edge Environment
abstract
The rapid evolution of wireless edge computing faces fundamental limitations from connection-oriented protocols, particularly in dynamic scenarios with distributed edge environments. In this paper, we present SWICE, a novel transmission system with modified frame injection techniques that eliminates connection establishment overhead while ensuring reliable data delivery in wireless distributed edge environments. Our system introduces a connection-free measurement strategy that uses minimal packets to assess communication status while keeping device identities private. We formulate an edge node selection problem for efficiency and develop a heuristic algorithm for optimal data delivery. Additionally, we implement a reliability mechanism that combines adaptive retransmission to enhance communication stability. We conduct real-world experiments with commercially available Wi-Fi devices and modified wireless radios. The results show that SWICE achieves up to a 36.88 % increase in goodput compared to conventional transmission methods, demonstrating its effectiveness through real-world experiments.
Changkang Mo, Yaodong Huang, Biying Kong, Hengzhi Wang, Fei Chen 0003, Laizhong Cui
IWQoS7
2025 An efficient encrypted search with owner-level and attribute-level access controls
Yang Yang 0022, Yanjiao Chen, Fei Chen 0003, Jing Chen 0003
Comput. Networks5
2025 Decentralized Self-Auditing Multiple Cloud Storage in Compressed Provable Data Possession
abstract
As cloud storage becomes popular, more and more users tend to outsource their data to powerful cloud severs. To prevent a single point of failure, users prefer to store data on multiple cloud servers from different cloud service providers. However, after outsourcing data to cloud servers, users lose the control of their data, which may incur many serious security issues, such as abnormal data tampering and deleting. It is necessary for users to audit multiple cloud storage aperiodically. In this article, we aim to design a decentralized self-auditing solution for multiple cloud storage, in which cloud servers can audit the integrity of each other, and thus no third-party entity is required. First, based on basic algebra, our protocol realizes decentralized self-auditing multiple cloud storage that only involves encrypted user data. Second, we design a proof exchanging mechanism, making any number of cloud servers form the same final integrity proof with a linear number of interactions. Third, our solution can achieve cloud dynamics, which can freely enable and disable a cloud server to provide storage service. At last, security proof and performance evaluation show that the proposed protocol has provable security and high efficiency.
Yang Yang 0022, Yanjiao Chen, Ping Xiong 0001, Fei Chen 0003, Jing Chen 0003
IEEE Trans. Dependable Secur. Comput.4
2024 Practical cloud storage auditing using serverless computing
Fei Chen 0003, Jianquan Cai, Tao Xiang 0001, Xiaofeng Liao 0001
Sci. China Inf. Sci.1
2024 Public cloud object storage auditing: Design, implementation, and analysis
Fei Chen 0003, Fengming Meng, Tao Xiang 0001
J. Parallel Distributed Comput.1
2024 BBS: A secure and autonomous blockchain-based big-data sharing system
Shan Wang 0008, Ming Yang 0001, Shan Jiang 0005, Fei Chen 0003, Yue Zhang 0025, Xinwen Fu
J. Syst. Archit.4
2024 A Two-Stage Approach for Fair Data Trading Based on Blockchain
Fei Chen 0003, Haohui Zhang, Tao Xiang 0001, Joseph K. Liu
IEEE Trans. Inf. Forensics Secur.1
2023 Protecting Vaccine Safety: An Improved, Blockchain-Based, Storage-Efficient Scheme
abstract
In recent years, vaccine safety incidents have occurred frequently. To protect vaccine safety, researchers have proposed to use blockchain to secure the vaccine circulation process. Technically, blockchain has some limitations in solving vaccine and other supply chain problems, such as large on-chain storage consumption and low throughput. To better alleviate these restrictions, we propose an improved, blockchain-based, storage-efficient vaccine safety protection scheme in this work. Specifically, we first model the vaccine circulation process. We then design a system to protect vaccine circulation using blockchain, cloud, and cryptographic mechanisms. The proposed system leverages the cloud to implement the vaccine circulation model. Correspondingly, it uses the blockchain to store circulating data certificates and signatures. We evaluated the proposed conceptual model using a consortium blockchain. The experimental results show that the proposed system is efficient.
Laizhong Cui, Fei Chen 0003, Hua Dai 0003, Jianqiang Li 0001
IEEE Trans. Cybern.3
2023 A Full Lifecycle Authentication Scheme for Large-Scale Smart IoT Applications
abstract
The rapid development of IoT (Internet of Things) brings great convenience to people through the utilization of IoT applications, but also brings huge security challenges. Existing IoT security breaches show that many IoT devices have authentication flaws. Although many IoT authentication schemes were proposed, they are not applicable to recent smart IoT applications covering IoT device, back-end sever, and user-end mobile applications. To build the first line of defense for trending IoT systems, this paper proposes a new authentication scheme. The proposed scheme first models the entire life cycle of the IoT device for real-world scenarios of smart IoT systems, which contains factory manufacturing, daily usage, and system resetting. For each stage in the life cycle, the proposed scheme employs efficient symmetric key mechanisms to achieve the authentication between IoT device, back-end server, and mobile application. The proposed scheme supports both server-free local area network communication and sever-involved remote public area communication. Formal security verification shows that the proposed scheme resists existing attacks. The open-source experimental evaluations also show that the proposed scheme is efficient and promising for practical usage.
Fei Chen 0003, Zixing Xiao, Tao Xiang 0001, Junfeng Fan, Hong Linh Truong 0001
IEEE Trans. Dependable Secur. Comput.1
2023 XBound-Former: Toward Cross-Scale Boundary Modeling in Transformers
abstract
Skin lesion segmentation from dermoscopy images is of great significance in the quantitative analysis of skin cancers, which is yet challenging even for dermatologists due to the inherent issues, i.e., considerable size, shape and color variation, and ambiguous boundaries. Recent vision transformers have shown promising performance in handling the variation through global context modeling. Still, they have not thoroughly solved the problem of ambiguous boundaries as they ignore the complementary usage of the boundary knowledge and global contexts. In this paper, we propose a novel cross-scale boundary-aware transformer, XBound-Former, to simultaneously address the variation and boundary problems of skin lesion segmentation. XBound-Former is a purely attention-based network and catches boundary knowledge via three specially designed learners. First, we propose an implicit boundary learner (im-Bound) to constrain the network attention on the points with noticeable boundary variation, enhancing the local context modeling while maintaining the global context. Second, we propose an explicit boundary learner (ex-Bound) to extract the boundary knowledge at multiple scales and convert it into embeddings explicitly. Third, based on the learned multi-scale boundary embeddings, we propose a cross-scale boundary learner (X-Bound) to simultaneously address the problem of ambiguous and multi-scale boundaries by using learned boundary embedding from one scale to guide the boundary-aware attention on the other scales. We evaluate the model on two skin lesion datasets and one polyp lesion dataset, where our model consistently outperforms other convolution- and transformer-based models, especially on the boundary-wise metrics. All resources could be found in https://github.com/jcwang123/xboundformer.
Jiacheng Wang 0002, Fei Chen 0003, Liansheng Wang 0002, Zhaodong Fei, Jianwei Shuai, Xiangdong Tang, Qichao Zhou, Harry Qin
IEEE Trans. Medical Imaging2
2022 Blockchain Based Non-repudiable IoT Data Trading: Simpler, Faster, and Cheaper
abstract
Next-generation wireless technology and machine-to-machine technology can provide the ability to connect and share data at any time among IoT smart devices. However, the traditional centralized data sharing/trading mechanism lacks trust guarantee and cannot satisfy the real-time requirement. Distributed systems, especially blockchain, provide us with promising solutions. In this paper, we propose a blockchain based non-repudiation scheme for IoT data trading to resolve the credibility and real-time limits. The proposed scheme has two parts, i.e., a trading scheme and an arbitration scheme. The trading scheme employs a divide-and-conquer method and two commitment methods to support efficient IoT data trading, which runs in a two-round manner. The arbitration scheme first leverages a smart contract to solve disputes on-chain in real time. In case of on-chain arbitration dissatisfaction, the arbitration scheme also employs an off-line arbitration to make a final resolution. Short-term and long-term analysis show that the proposed scheme enforces non-repudiation among the data trading parties and runs efficiently for rational data owners and buyers. We implemented the proposed scheme. Experimental results confirm that the proposed scheme has an orders-of-magnitude performance speedup than the state-of-the-art scheme.
Fei Chen 0003, Changkun Jiang, Tao Xiang 0001, Yuanyuan Yang 0001
INFOCOM1
2022 TrustBuilder: A non-repudiation scheme for IoT cloud applications
Fei Chen 0003, Jianqiang Li 0001, Yang Xu 0013, Cheng Zhang 0035, Tao Xiang 0001
Comput. Secur.1
2022 Identity-Based Cloud Storage Auditing for Data Sharing With Access Control of Sensitive Information
abstract
Remote data integrity auditing ensures the integrity of cloud storage. In practice, cloud users may not want their sensitive data to be exposed to others. Thus, it is meaningful to investigate how to realize data sharing with sensitive information hiding in cloud storage auditing. Up to now, cloud storage has been proven to achieve the sensitive information hiding property through a third-party sanitizer dedicated to sanitize user data, which leads to high outlays on purchasing and maintaining a special server. To meet this challenge, we design a novel cloud storage auditing protocol to support sensitive information hiding without the need of a third-party sanitizer. In addition, our scheme allows data owners to enable or disable other users to access their sensitive information with the help of the cloud that dose not deviate from the agreement during access control. To be specific, only after receiving the delegations from the data owner, the users can compute the valid warrants that can pass the access verification of the cloud. The proposed protocol is built on identity-based cryptography, thus avoiding the complex certificate management. We validate the advantages of the proposed protocol through massive theoretical analysis and experimental results.
Yang Yang 0022, Yanjiao Chen, Fei Chen 0003, Jing Chen 0003
IEEE Internet Things J.3
2022 An Efficient Identity-Based Provable Data Possession Protocol With Compressed Cloud Storage
abstract
Cloud storage is more and more prevalent in practice, and thus how to check its integrity becomes increasingly essential. A classical solution is identity-based (ID-based) provable data possession (PDP), which supports certificateless cloud storage auditing without entire user data. However, existing ID-PDP protocols always require that cloud users outsource data blocks, authenticators and a small-sized file tag to the cloud, and make use of the heavy elliptic curve cryptography over bilinear pairing. These disadvantages would result in vast storage, communication, and computation costs, which is unexpected, especially for resource-limited cloud users. To improve the performance, this paper proposes a novel cryptographic primitive: ID-based PDP with compressed cloud storage. In this model, cloud storage auditing can be achieved by using only encrypted data blocks in a self-verified way, and original data blocks can be reconstructed from the outsourced data. Thus, data owners no longer need to store original data blocks on the cloud. We also use some basic algebraic operations to realize a concrete ID-based PDP protocol with compressed cloud storage, which is quite efficient due to no heavy cryptographic operations involved. The proposed protocol can easily be extended to support the other practical functions by using the primitive replacement technique. The proposed protocol is strictly proven to have the properties of correctness, privacy, unforgeability and detectability. Finally, we give plenty of theoretical analysis and experimental results to validate the efficiency of the proposed protocol.
Yang Yang 0022, Yanjiao Chen, Fei Chen 0003, Jing Chen 0003
IEEE Trans. Inf. Forensics Secur.3
2022 Cloud Object Storage Synchronization: Design, Analysis, and Implementation
abstract
Cloud storage synchronization among different computing terminals has attracted large-scale uses among enterprise and individual users. It enables users to maintain the same copy of data in real time, which eases users the tedious yet error-prone data management burden. However, existing cloud storage synchronization systems are in a closed form. Users are fixed to a certain cloud service provider, which makes it hard to transfer from one provider to another when balancing factors such as performance, cost, security, etc. To bridge this gap, this article proposes a new synchronization system based on standard cloudobjectstorage. Specifically, we first formulate the cloud object storage synchronization problem by defining some useful concepts. We then use the idea of state encoding and a push-pull paradigm to propose a cloud object storage synchronization system. The proposed system supports real-time, multiple-terminal, and cloud-independent storage synchronization. We also prototyped the proposed system. The experimental results show that the proposed system is promising for practical usages.
Fei Chen 0003, Changkun Jiang, Tao Xiang 0001, Yuanyuan Yang 0001
IEEE Trans. Parallel Distributed Syst.1
2021 On Designing a Lesser Obtrusive Authentication Protocol to Prevent Machine-Learning-Based Threats in Internet of Things
abstract
In the era of the Internet of Things (IoT), people access many applications through smartphones for controlling smart devices. Therefore, such a centralized node must follow a robust access control mechanism so that an intruder cannot control the connected devices. Recent reports suggest that password can be used as an authentication factor for accessing the smart setups. However, this static information can be compromised under the light of different machine learning (ML)-empowered attack mechanisms. Alarmingly, different sensors used in the IoT setup can also expose this static information to the adversaries. Password-based authentication that uses a challenge-response strategy is an effective solution for handling such threat scenarios. In this article, at first, we show that no existing usable challenge-response protocol is safe to be used in the public area network. Following this, we propose a challenge-response protocol that is more secure to use in the public domain. By using eight classifiers, we show that a learning-based threat specific to our protocol has a marginal impact on the method's security standard. The discussion in this article also suggests that the proposed protocol has usability and security advantages compared to the existing state of the art (e.g., reduces the number of interactions between the user and verifier by a factor of 0.5).
Nilesh Chakraborty, Jianqiang Li 0001, Samrat Mondal, Chengwen Luo 0001, Huihui Wang 0001, Mamoun Alazab, Fei Chen 0003, Yi Pan 0001
IEEE Internet Things J.7
2021 Towards Dynamic Verifiable Pattern Matching
abstract
Verifiable pattern matching enables users to obtain authenticated query results over outsourced data on an untrusted remote server. It is a fundamental problem in many security-critical big data applications, including big database search, human genome data search, text search, etc., especially when these applications are outsourced to third-party clouds. However, the state-of-the-art schemes do not yet support efficient data updates. In this work, we propose the first dynamic verifiable pattern matching scheme to support efficient data updates. The proposed scheme is built on two ideas: one is to embed unique randomness to decouple the character and its index in the outsourced data, enabling efficient data updates; the other is to reduce the verifiable pattern matching problem to a discrete set membership testing problem, which relies on the decoupling introduced in the first idea. Based on these two ideas, the proposed scheme first employs the suffix array index structure to search pattern matching queries. The scheme then authenticates the outsourced text using a newly designed authenticated data structure based on the RSA accumulator, which guarantees the verifiability of pattern matching query results. Data update is naturally supported using the RSA accumulator working on discrete sets. Based on the proposed design, we have prototyped a proof-of-concept for the proposed scheme and have conducted an extensive experimental evaluation. In addition to supporting efficient data update, our experimental results show that the proposed scheme incurs reduced verification cost in comparison with the baseline state-of-the-art scheme.
Fei Chen 0003, Donghong Wang, Qiuzhen Lin, Jianyong Chen, Zhong Ming 0001, Wei Yu 0002, Harry Qin
IEEE Trans. Big Data1
2021 Computation Outsourcing Meets Lossy Channel: Secure Sparse Robustness Decoding Service in Multi-Clouds
abstract
This paper addresses the problem of lossy outsourcing, i.e., clients outsource computation needs to the cloud side through lossy channels, which is very common in practice. We focus on the case that the clients transmit 2D sparse signals to the semi-trusted clouds over packet-loss networks, and the clouds provide sparse robustness decoding service (SRDS) for the users. In order to achieve high level of efficiency and security, we propose to jointly exploit parallel compressive sensing for robust signal encoding and employ multiple cloud servers for SRDS. Specifically, prior to encoding, a signal is encrypted by only altering the indices and amplitudes of its non-zero entries. The encrypted signal is sensed using a Gaussian measurement matrix and the generated compressive measurements are then sent to multi-clouds for SRDS, along with the occurrence of packet loss. Each column in compressive measurements can be regarded as a packet and each description consists of a certain number of packets. Each description together with a small portion of support set is distributed to a cloud. When receiving the request from a user, each cloud performs SRDS using the acquired description, where the reconstructed signal is still in encrypted form so that the signal privacy is well preserved. After receiving the reconstructed signal, the user accomplishes the decryption operation. Experimental results show that the encryption algorithm improves compressibility and reconstruction performance compared with the case of no encryption, and the proposed privacy-assured outsourcing of SRDS is highly robust and efficient.
Yushu Zhang 0001, Jiantao Zhou 0001, Yong Xiang 0001, Leo Yu Zhang, Fei Chen 0003, Shaoning Pang 0001, Xiaofeng Liao 0001
IEEE Trans. Big Data5
2021 Improving Vaccine Safety Using Blockchain
abstract
In recent years, vaccine incidents occurred around the world, which endangers people’s lives. In the technical respect, these incidents are partially due to the fact that existing vaccine management systems are distributively managed by different entities in the vaccine supply chain. This architecture makes it relatively easy to modify or even delete the vaccine circulation data maliciously, which makes tracing problematic vaccine hard and identifying the responsibility for a vaccine accident hard. To solve these issues, this article presents a blockchain-based solution to protect the whole process of vaccine circulation. We first propose a model to supervise the vaccine circulation process by incorporating existing regulatory practices. Then, we propose a blockchain-based tracing system to implement this model. The proposed system takes the blockchain as a global, unique, and verifiable database to store all the circulation data. Through data insertions and queries on the global and unique database, the proposed system achieves the protection of vaccine circulation. We also implement a proof-of-concept prototype of the proposed system. Experimental results confirm that the proposed system is beneficial.
Laizhong Cui, Fei Chen 0003, Yi Pan 0001, Hua Dai 0003, Harry Qin
ACM Trans. Internet Techn.4
2021 A Compressive Integrity Auditing Protocol for Secure Cloud Storage
abstract
With the widespread application of cloud storage, ensuring the integrity of user outsourced data catches more and more attention. To remotely check the integrity of cloud storage, plenty of protocols have been proposed, implemented by checking the equation constructed by the aggregated blocks, tags, and indices. However, the verifier only has the knowledge of the indices of the audited blocks and tags, which thus requires the cloud to store both data blocks and tags for integrity verification. In this article, we present a compressive secure cloud storage protocol inspired by Goldreich-Goldwasser-Halevi (GGH) cryptosystem. Since the aggregated blocks can be reconstructed from the aggregated tags without the help of data indices, the cloud can only store data tags for providing the verifiable integrity proof. In this way, communication and storage costs can be hugely reduced and user private information can be hidden from the cloud. Furthermore, the proposed protocol only contains a few basic algebraic operations, making it highly efficient. We also provide formal security proof of the proposed protocol regarding forge, replay and replace attacks. In addition, we explore a new technique to support data dynamics. Furthermore, we establish a generic framework of compressive secure cloud storage protocols. Finally, we provide the theoretical analysis and experimental results, which further validate the effectiveness of the proposed protocol.
Yang Yang 0022, Yanjiao Chen, Fei Chen 0003
IEEE/ACM Trans. Netw.3
2020 Secure and efficient outsourcing computation on large-scale linear regressions
Yang Yang 0022, Ping Xiong 0001, Fei Chen 0003
Inf. Sci.4
2020 Blockchain for Internet of things applications: A review and open issues
Fei Chen 0003, Laizhong Cui, Qiuzhen Lin, Jianqiang Li 0001, Shui Yu 0001
J. Netw. Comput. Appl.1
2020 Towards Usable Cloud Storage Auditing
abstract
Cloud storage security has gained considerable research efforts with the wide adoption of cloud computing. As a security mechanism, researchers have been investigating cloud storage auditing schemes that enable a user to verify whether the cloud keeps the user's outsourced data undamaged. However, existing schemes have usability issues in compatibility with existing real world cloud storage applications, error-tolerance, and efficiency. To mitigate this usability gap, this article proposes a new general cloud storage auditing scheme that is more usable. The proposed scheme uses the idea of integrating linear error correcting codes and linear homomorphic authentication schemes together. This integration uses only one additional block to achieve error tolerance and authentication simultaneously. To demonstrate the power of the general construction, we also propose one detailed scheme based on the proposed general construction using the Reed Solomon code and the universal hash based MAC authentication scheme, both of which are implemented over the computation-efficient Galois field GF(28). We also show that the proposed scheme is secure under the standard definition. Moreover, we implemented and open-sourced the proposed scheme. Experimental results show that the proposed scheme is orders of magnitude more efficient than the state-of-the-art scheme.
Fei Chen 0003, Fengming Meng, Tao Xiang 0001, Hua Dai 0003, Jianqiang Li 0001, Harry Qin
IEEE Trans. Parallel Distributed Syst.1
2019 Secure and efficient parallel hash function construction and its application on cloud audit
Fei Chen 0003, Shulan Wang, Jianqiang Li 0001, Jianyong Chen, Zhong Ming 0001
Soft Comput.2
2018 Identity-Based Proofs of Storage with Enhanced Privacy
Miaomiao Tian 0001, Shibei Ye, Hong Zhong 0001, Lingyan Wang, Fei Chen 0003, Jie Cui 0004
ICA3PP (4)5
2018 Efficient biometric identity-based encryption
Xiaoguo Li, Tao Xiang 0001, Fei Chen 0003, Shangwei Guo
Inf. Sci.3
2018 An adaptive immune-inspired multi-objective algorithm with multiple differential evolution strategies
Qiuzhen Lin, Yueping Ma, Jianyong Chen, Qingling Zhu, Carlos A. Coello Coello, Ka-Chun Wong, Fei Chen 0003
Inf. Sci.7
2018 Achieving verifiable, dynamic and efficient auditing for outsourced database in cloud
Tao Xiang 0001, Xiaoguo Li, Fei Chen 0003, Yuanyuan Yang 0001, Shengyu Zhang 0002
J. Parallel Distributed Comput.3
2018 Secure Hashing-Based Verifiable Pattern Matching
abstract
Verifiable pattern matching is the problem of finding a given pattern verifiably from the outsourced textual data, which is resident in an untrusted remote server. This problem has drawn much attention due to a large number of applications. The state-of-the-art method for this problem suffers from low efficiency. To enable fast verifiable pattern matching, we propose a novel scheme in this paper. Our scheme is based on an ordered set accumulator data structure and a newly developed verifiable suffix array structure, which only involves fast cryptographic hash computations. Our scheme also supports fast multiple-occurrence pattern matching. A striking feature of our proposed scheme is that our scheme works even with no secret keys, which ensures public verifiability. We conduct extensive experiments to evaluate the proposed scheme using Java. The results show that our scheme is orders of magnitude faster than the state-of-the-art work. Specifically, our scheme with public verifiability only costs a preprocessing time of 47 s (merely one-time off-line cost during outsourcing), a search time of 30 μs, a verification time of 149 μs, and a proof size of 2760 bytes for a verifiable pattern matching query with pattern length 200 on 10-million long textual data which consists of sequences of two-byte, Unicode characters in Java.
Fei Chen 0003, Donghong Wang, Rong-Hua Li 0001, Jianyong Chen, Zhong Ming 0001, Alex X. Liu, Huayi Duan, Cong Wang 0001, Harry Qin
IEEE Trans. Inf. Forensics Secur.1
2018 User Differentiated Verifiable File Search on the Cloud
abstract
Cloud storage security has been gaining research interest in recent years. Although considerable work has been conducted on verifying the integrity of the outsourced data in the cloud, how to efficiently verify the file search results returned from the cloud is still a challenge to be resolved. Towards this direction, we tackle the verifiable file search problem in this paper. We formulate and solve this problem by proposing two protocols. The first protocol enables verifying the correctness of the file search result when all users have the same security privilege in accessing the outsourced data. The second protocol, which builds on the first protocol, further enables user differentiation, i.e., different users can only access files that fit their security privileges. In our protocols, we employ two key strategies in enabling file search verifiability. One is to separate all possible filenames into two finite sets and the other is to embed some secret information in the outsourced data. Further, we leverage the key chaining and recursion mechanisms to enable user differentiation. We have conducted experiments to validate the effectiveness of our proposed protocols. Our results show that both protocols are efficient in terms of computation, storage, and communication cost.
Fei Chen 0003, Tao Xiang 0001, Xinwen Fu, Wei Yu 0002
IEEE Trans. Serv. Comput.1
2017 A secure cloud storage system based on discrete logarithm problem
abstract
With the development of cloud storage, data owners no longer physically possess their data and thus how to ensure the integrity of their outsourced data becomes a challenging task. Several protocols have been proposed to audit cloud storage, all of which rely mainly on data block tags to check data integrity. However, their block tag constructions employ cryptographic operations, which makes them computationally complex. In this paper, we investigate a secure cloud storage protocol based on the classic discrete logarithm problem. Our protocol generates data block tags with only basic algebraic operations, which brings substantial computation savings compared with previous work. We also strictly prove that the proposed protocol is secure under a definition which captures the real-world uses of cloud storage. In order to fit more application scenarios, we extend the proposed protocol to support data dynamics by employing an index vector and third-party public auditing by using a random masking number, both of which are efficient and provably secure. At last, theoretical analysis and experimental evaluation are provided to validate the superiority of the proposed protocol.
Jian Zhang 0010, Yang Yang 0022, Yanjiao Chen, Fei Chen 0003
IWQoS4
2017 Securing Outsourced Data in the Multi-Authority Cloud with Fine-Grained Access Control and Efficient Attribute Revocation
abstract
Data outsourcing is a promising service for data owners, where their data are stored on a cloud storage provider. Since the cloud is not fully trusted, data access control has become a challenging issue in the Cloud Storage System (CSS). Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is a feasible technique for ensuring access control in the CSS, where an attribute authority is responsible to manage attributes and distribute keys. In this paper, we propose a novel revocable Multi-Authority CP-ABE scheme, in which the access policy can be constructed as an arbitrary tree rather than a matrix used by existing schemes. The tree-like policy makes our scheme more flexible. Consequently, the encryption, decryption and attribute revocation operations are also more efficient. Our scheme is also proved to be secure under the standard assumption. It can resist user collusion attack, while the attribute revocation operation also achieves both forward security and backward security. Simulation results show that our scheme is highly efficient.
Junwei Zhou 0002, Hui Duan, Kaitai Liang, Qiao Yan, Fei Chen 0003, F. Richard Yu, Jieming Wu, Jianyong Chen
Comput. J.5
2016 Bilateral-secure Signature by Key Evolving
abstract
In practice, the greatest threat against the security of a digital signature scheme is the exposure of signing key, since the forward security of past signatures and the backward security of future signatures could be compromised. There are some attempts in the literature, addressing forward-secure signature for preventing forgeries of signatures in the past time; however, few studies addressed the backward-security of signatures, which prevents forgeries in the future time. In this paper, we introduce the concept of key-evolving signature with bilateral security, i.e., both forward security and backward security. We first define the bilateral security formally for preventing the adversaries from forging a valid signature of the past and the future time periods in the case of key exposure. We then provide a novel construction based on hub-and-spoke updating structure and the random oracle model, and show that the construction achieves bilateral security and unbounded number of time periods. Finally, we compare our scheme with the existing work by rigorous analysis and experimental evaluation, and demonstrate that our construction is more secure and efficient for practical applications.
Tao Xiang 0001, Xiaoguo Li, Fei Chen 0003, Yi Mu 0001
AsiaCCS3
2016 Embedding cryptographic features in compressive sensing
Yushu Zhang 0001, Jiantao Zhou 0001, Fei Chen 0003, Leo Yu Zhang, Kwok-Wo Wong, Xing He 0001, Di Xiao 0001
Neurocomputing3
2016 Processing secure, verifiable and efficient SQL over outsourced database
Tao Xiang 0001, Xiaoguo Li, Fei Chen 0003, Shangwei Guo, Yuanyuan Yang 0001
Inf. Sci.3
2016 Secure Cloud Storage Meets with Secure Network Coding
abstract
This paper reveals an intrinsic relationship between secure cloud storage and secure network coding for the first time. Secure cloud storage was proposed only recently while secure network coding has been studied for more than ten years. Although the two areas are quite different in their nature and are studied independently, we show how to construct a secure cloud storage protocol given any secure network coding protocol. This gives rise to a systematic way to construct secure cloud storage protocols. Our construction is secure under a definition which captures the real world usage of the cloud storage. Furthermore, we propose two specific secure cloud storage protocols based on two recent secure network coding protocols. In particular, we obtain the first publicly verifiable secure cloud storage protocol in the standard model. We also enhance the proposed generic construction to support user anonymity and third-party public auditing, which both have received considerable attention recently. Finally, we prototype the newly proposed protocol and evaluate its performance. Experimental results validate the effectiveness of the protocol.
Fei Chen 0003, Tao Xiang 0001, Yuanyuan Yang 0001, Sherman S. M. Chow
IEEE Trans. Computers1
2015 Secure cloud storage hits distributed string equality checking: More efficient, conceptually simpler, and provably secure
abstract
Cloud storage has gained a remarkable success in recent years with an increasing number of consumers and enterprises outsourcing their data to the cloud. To assure the availability and integrity of the outsourced data, several protocols have been proposed to audit cloud storage. Despite the formally guaranteed security, the constructions employed heavy cryptographic operations as well as advanced concepts (e.g., bilinear maps over elliptic curves and digital signatures), and thus are inefficient to admit wide applicability in practice. In this paper, we design a novel secure cloud storage protocol, which is conceptually and technically simpler and significantly more efficient than previous constructions. Inspired by a classic string equality checking protocol in distributed computing, our protocol uses only basic integer arithmetic (without advanced techniques and concepts). As simple as the protocol is, it supports both randomized and deterministic auditing to fit different applications. We further extend the proposed protocol to support data dynamics, i.e., adding, deleting and modifying data, using a novel technique. As a further contribution, we find a systematic way to design secure cloud storage protocols based on verifiable computation protocols. Theoretical and experimental analyses validate the efficacy of our protocol.
Fei Chen 0003, Tao Xiang 0001, Yuanyuan Yang 0001, Cong Wang 0001, Shengyu Zhang 0002
INFOCOM1
2014 A verifiable PSO algorithm in cloud computing
abstract
In this paper, we study the verification problem of particle swarm optimization (PSO) when it is outsourced to the cloud, i.e. making sure that the cloud executes PSO algorithm as requested. A verifiable PSO algorithm and its verification algorithm are proposed. The proposed scheme does not involve expensive cryptography, and it is efficient and effective to verify the honesty of the cloud.
Tao Xiang 0001, Fei Chen 0003
IEEE Congress on Evolutionary Computation3
2014 Secure cloud storage meets with secure network coding
abstract
This paper investigates the intrinsic relationship between secure cloud storage and secure network coding for the first time. Secure cloud storage was proposed only recently while secure network coding has been studied for more than ten years. We show in general how to construct a secure cloud storage protocol given any secure network coding protocol. Our construction suggests a systematic way to construct various secure cloud storage protocols. We also show that it is secure under a definition which captures the real world uses of the cloud storage. From our general construction, we propose a secure cloud storage protocol based on a recent secure network coding protocol. The protocol is the first publicly verifiable secure cloud storage protocol in the standard model, while the previous work is either not publicly verifiable, or security argument is only argued heuristically in the random oracle model. We also enhance the proposed protocol to support third-party public auditing, which has received considerable attention recently. Finally, we prototype the proposed protocol and evaluate its performance. Experimental results validate the effectiveness of the protocol.
Fei Chen 0003, Tao Xiang 0001, Yuanyuan Yang 0001, Sherman S. M. Chow
INFOCOM1
2014 Privacy-preserving and verifiable protocols for scientific computation outsourcing to the cloud
Fei Chen 0003, Tao Xiang 0001, Yuanyuan Yang 0001
J. Parallel Distributed Comput.1
2014 Secure MQ coder: An efficient way to protect JPEG 2000 images in wireless multimedia sensor networks
Tao Xiang 0001, Chenyun Yu, Fei Chen 0003
Signal Process. Image Commun.3
2014 Highly Efficient Linear Regression Outsourcing to a Cloud
abstract
With cloud computing and mobile computing becoming more and more popular, there are a lot potential applications for computation outsourcing to the cloud. This paper investigates the linear regression outsourcing problem, which is a quite common engineering task and employed in various applications, as a case study to find out the possible problems that need to be solved. We propose two protocols which can enable secure and efficient outsourcing of linear regression problems to the cloud. The protocols can protect the client’s data privacy well and at the same time have good efficiency. We show all subtleties and the techniques in designing such protocols. The main idea to protect the privacy is employing some transformations to the original linear regression problem to get a new problem which is sent to the cloud; and then transforming the answer returned back from the cloud to get the true solution to the original problem. Experimental results validate the practical usability of our protocols.
Fei Chen 0003, Tao Xiang 0001, Jianyong Chen
IEEE Trans. Cloud Comput.1
2014 Period distribution of generalized discrete Arnold cat map
Fei Chen 0003, Kwok-Wo Wong, Xiaofeng Liao 0001, Tao Xiang 0001
Theor. Comput. Sci.1
2013 Fast Encryption of JPEG 2000 Images in Wireless Multimedia Sensor Networks
Tao Xiang 0001, Chenyun Yu, Fei Chen 0003
WASA3
2013 Period Distribution of the Generalized Discrete Arnold Cat Map for $N = 2^{e}$
abstract
The Arnold cat map is employed in various applications where chaos is utilized, especially chaos-based cryptography and watermarking. In this paper, we study the problem of period distribution of the generalized discrete Arnold cat map over the Galois ring \BBZ2e. Full knowledge of the period distribution is obtained analytically by adopting the Hensel lift approach. Our results have impact on both chaos theory and its applications as they not only provide design strategy in applications where special periods are required, but also help to identify unstable periodic orbits of the original chaotic cat map. The method in our paper also shows some ideas how to handle problems over the Galois ring \BBZ2e.
Fei Chen 0003, Kwok-Wo Wong, Xiaofeng Liao 0001, Tao Xiang 0001
IEEE Trans. Inf. Theory1
2012 Period Distribution of Generalized Discrete Arnold Cat Map for N=pe
abstract
In this paper, we analyze the period distribution of the generalized discrete cat map over the Galois ring where is a prime. The sequences generated by this map are modeled as 2-dimensional LFSR sequences. Employing the generation function and the Hensel lifting approaches, full knowledge of the detail period distribution is obtained analytically. Our results not only characterize the period distribution of the cat map, which gives insights to various applications, but also demonstrate some approaches to deal with the period of a polynomial in the Galois ring.
Fei Chen 0003, Kwok-Wo Wong, Xiaofeng Liao 0001, Tao Xiang 0001
IEEE Trans. Inf. Theory1
2011 Security analysis of the public key algorithm based on Chebyshev polynomials over the integer ring ZN
Fei Chen 0003, Xiaofeng Liao 0001, Tao Xiang 0001, Hongying Zheng
Inf. Sci.1
2010 On the Security of Public-Key Algorithms Based on Chebyshev Polynomials over the Finite Field $Z_N$
abstract
In this paper, the period distribution of sequences generated by Chebyshev polynomials over the finite field ZNis analyzed. It is found that the distribution is unsatisfactory if N (the modulus) is not chosen properly. Based on this finding, we present an attack on the public-key algorithm based on Chebyshev polynomials over ZN. Then, we modify the original algorithm to make it suitable for practical purpose. Its security under some existing models is also discussed in detail.
Xiaofeng Liao 0001, Fei Chen 0003, Kwok-Wo Wong
IEEE Trans. Computers2