Lingbo Wei

dblp:84/7868 · DBLP profile ↗
← Back
38ranked-venue papers
3as first author
25since 2021 · last 2026
0000-0003-1222-1006ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 25 · 1 first-author · 16 since 2021Security and privacy · 7 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
YearPublicationVenuePosition
2026 A High-Throughput, Cost-Free Covert Communication Scheme Based on the Bitcoin Lightning Network
Lingbo Wei
ICC3
2025 A High-Throughput Hybrid Covert Communication Scheme Integrating Blockchain with IPFS
Lingbo Wei
GLOBECOM3
2025 A Blockchain-Based Covert Communication Scheme Resilient to Internal Attacks
Chi Zhang 0001, Lingbo Wei, Yani Sun
ICC3
2025 Privacy-Preserving Credential Management for Blockchain-Based Self-sovereign Identity
Haixing Li, Chi Zhang 0001, Lingbo Wei
WASA (1)4
2025 Public data-enhanced multi-stage differentially private graph neural networks
Heyuan Huang, Lingbo Wei, Chi Zhang 0001
J. Inf. Secur. Appl.3
2024 AdvNets: Adversarial Attacks and Countermeasures for Model-level Neural Trojan Defenses
abstract
Neural trojans constitute a serious threat to systems that employ neural networks. In response to this threat, a multitude of trojan defense strategies have surfaced, with model-level measures, particularly those applied post-training, showcasing broader applicability. However, many such model-level defenses could be vulnerable because their robustness against adaptive attacks launched by sophisticated adversaries is unvalidated. In this paper, we introduce AdvNets, a general framework developed from the perspective of adversarial attacks, to demonstrate the vulnerability and enhance the robustness of model-level trojan defenses against adaptive attacks. Specifically, we implement feature-based and score-based attack modules that thoroughly circumvent multiple state-of-the-art defenses without modifying the so-called defendable backdoor patterns. To counteract these vulnerabilities, we craft an independent random decision envelopment mechanism where detections made by our detectors are mutually independent. The implementation of this mechanism markedly improves the AUC score for detecting adversarial models to over 80%. This presents a strong argument for designing a robust and dependable trojan defense system.
Chi Zhang 0001, Lingbo Wei, Qibin Sun
GLOBECOM3
2024 ParaEthereum: Private and Parallel Smart Contracts with Trusted Hardware
abstract
The last decade has witnessed unprecedented de-velopment in blockchain smart contracts. While smart contracts inherit the decentralization and other security properties of blockchain, they are hampered by the lack of privacy protection and poor performance of blockchain. In this paper, we propose a parallel contract execution framework, ParaEthereum, that combines blockchain and trusted execution environments (TEEs) to construct private, efficient, and scalable smart contracts. By introducing TEEs, ParaEthereum performs contract execution off the chain through enclave-enabled computing nodes and confirms the correctness of the execution results on the chain, achieving the decoupling of contract execution and consensus. To meet system availability requirements and enable concurrent exe-cution of transactions, each transaction is executed independently by a set of computing nodes determined by its execution set, and different computing nodes process transactions within the block concurrently based on the constructed transaction dependency graph. We also conducted extensive tests on our proposed scheme with respect to its efficiency and effectiveness.
Lingbo Wei, Chi Zhang 0001, Jianqing Liu
ICC2
2024 CVALLM: A Cloud Platform Security Assessment Framework Based on Large Language Models
abstract
Cloud computing has revolutionized computing and data storage by providing flexible resource management and on-demand services. However, the centralized nature of cloud computing results in significant security issues that pose significant threats to cloud services. The security threat can be alleviated to a certain extent through the cloud platform security assessment. However, the existing cloud platform security assessment framework mainly measures security from the enterprise perspective and lacks methods from the user perspective. For users, much information is internal to the enterprise and cannot be obtained. To address these challenges, we propose a framework called CVALLM to measure cloud platform security from the user’s perspective, which uses a large language model to automatically complete a cloud platform security assessment. First, we utilize a large language model to complete cloud platform information extraction and vulnerability collection from SLA agreements and product description documents that the user can access. Second, to solve the vulnerability assessment problem, we propose a vulnerability severity prediction method based on deep learning. This method considers both the textual description characteristics and the source code characteristics of the vulnerability. Finally, we propose an overall security assessment method for the cloud platform based on a large language model, design quantitative indicators to measure the security of the cloud platform, and automatically generate security reports to facilitate users’ ability to quickly compare and choose the right cloud service.
Wangyuan Jing, Chi Zhang 0001, Lingbo Wei
TrustCom4
2024 Privacy Leak Detection in LLM Interactions with a User-Centric Approach
abstract
In recent years, services based on Large Language Models (LLMs) have garnered increasing attention leading to more frequent interactions between users and LLMs. However, owing to the inherent characteristics of LLMs, user inputs are at risk of privacy leaks. While previous research has proposed methods for protecting user input privacy, many of these approaches face limitations, particularly in adapting to the dynamic and diverse nature of user interactions with LLMs. To address this challenge, our study approaches privacy protection from a user-centric perspective, employing detection methods to safeguard user inputs. Specifically, we compiled a comprehensive privacy list based on General Data Protection Regulation (GDPR) requirements, defined the detection scope, and developed the PA-BERT model for automatically detecting privacy leaks in LLMs. By utilizing the PA-BERT-BiLSTM-CRF architecture, our method effectively monitors private information in user inputs. In our experiments, we not only utilized real-world datasets but also constructed a user input privacy dataset containing 15,036 privacy entities. Experimental results on the constructed dataset show that our method significantly outperforms commonly used general detection models in privacy detection, with marked improvements in precision, recall, and F1 score, making it more effective for identifying privacy in user inputs.
Tan Su, Chi Zhang 0001, Lingbo Wei
TrustCom4
2024 Enhanced Privacy Policy Comprehension via Pre-trained and Retrieval-Augmented Models
abstract
Privacy policies are crucial for informing users about how their personal information is collected, stored, and used by organizations. However, privacy policies are lengthy, information-dense, and filled with legalese, making them difficult for users to comprehend. Although previous studies have attempted to improve the readability of privacy policies via traditional machine learning techniques, these methods overlook or oversimplify critical information or rely on predefined question-answers that cannot adapt to user personalized queries. Inspired by the fact that large language models perform well in terms of text comprehension and text question-answering, we propose a novel large language model-based privacy policy question-answering framework, which aims to help users understand privacy policies more intuitively and effectively. Specifically, our framework consists of two modules: the personal data practice disclosure module, which performs a pre-training and fine-tuning approach to extract structured information about data categories and corresponding data operations from privacy policies. The retrieval-augmented question-answering module integrates sparse and dense retrievers to find the most relevant evidence from the privacy policy and generate responses corresponding to user queries. The experimental results across two representative datasets demonstrate the superiority of our method over other prior methods.
Chi Zhang 0001, Lingbo Wei
TrustCom4
2024 A Monitoring-Free Bitcoin Payment Channel Scheme With Support for Real-Time Settlement
abstract
The Bitcoin blockchain enables users to conduct transactions securely, but its performance is restricted by the need for global consensus. Payment channels, as a promising solution to this issue, overcome this limitation through off-chain transactions. Instead of conducting each transaction on-chain, they only settle the final payment balances with the underlying blockchain. However, the most prominent scheme, the Lightning Network payment channel, requires participants to regularly monitor blockchain; otherwise, there is a potential risk of fund loss. Moreover, this scheme also fails to support participants in settling the final payment balances in real time, compromising the efficiency of fund utilization. Existing payment channel enhancing technologies are unable to overcome the above issues without compromising payment privacy. To solve the above issues, we apply the Intel Software Guard Extensions (SGX), which provides trusted execution environments with confidentiality and integrity guarantees, to design a novel Bitcoin payment channel scheme. The scheme can support real-time settlement yet guarantee the participants' fund security without monitoring the blockchain. Through a combination of the additive homomorphic property of keys, the secret sharing scheme, and customized punishments, our scheme can still guarantee fund security and off-chain transaction privacy, even if the confidentiality of SGX is compromised by side-channel attacks. Finally, security and performance analysis demonstrate that our scheme allows participants to construct a secure yet efficient payment channel to transfer value.
Yankai Xie, Ruian Li, Chi Zhang 0001, Lingbo Wei, Yani Sun
IEEE Trans. Serv. Comput.5
2023 Synthesizing High-Utility Tabular Data with Enhanced Privacy Via Split-and-Discard Pre-Training
abstract
Data sharing has led to the emergence of the deep generative model (DGM) with differential privacy for synthesizing tabular data. However, existing methods struggle to synthesize high-utility tabular data with enhanced privacy. One challenge is degraded data utility due to the limited number of training iterations available under strong privacy guarantees. The other challenge is that widely-used encoding schemes may leak the sensitive distribution of continuous features. To this end, we propose a novel pipeline incorporating split-and-discard pre-training and an embedding module to synthesize data. To reduce the impact of limited iterations, we employ the split-and-discard pre-training method. This method leverages the intrinsic structure of DGM, which can be split into discriminative and generative sub-models. By conducting pre-training and discarding specific sub-models of DGM on private data, we address these challenges while training models with differential privacy. To preserve the privacy of continuous features, we propose a piecewise linear one-hot encoding scheme followed by an embedding layer. We instantiate this pipeline using variational autoencoders and generative adversarial networks respectively and compare them against popular models and variants. Results show that our pipeline on private data effectively balances privacy and utility.
Liwei Luo, Heyuan Huang, Yankai Xie, Chi Zhang 0001, Lingbo Wei
GLOBECOM6
2023 Solving Multi-Task Offloading Problem in V2X with a Machine Learning-Based Online Algorithm
abstract
In Vehicle-to-Everything scenarios, the efficient and real-time offloading of multi-task from vehicles to roadside units with higher computing power presents a challenging endeavor. This challenge is amplified by the dynamic nature of computing power in roadside units, which fluctuates in real time due to resource sharing among multiple vehicles. Consequently, accurately determining the computing power of roadside units prior to offloading becomes a significant hurdle for vehicles. To overcome this challenge and enhance the performance of online algorithms used for task offloading, we propose a novel approach that leverages machine learning techniques. This approach utilizes historical data to predict the real-time computing power of roadside units. By incorporating machine learning predictions, our proposed approach aims to mitigate the uncertainty associated with the decision-making process of the online algorithm. This, in turn, enables vehicles to make more informed decisions regarding task offloading. Moreover, to enhance the robustness of the algorithm against potential prediction errors, our approach adopts a partial trust mechanism towards the predicted outcomes. By considering this partial trust, we aim to maintain the algorithm's reliability in real-world scenarios. Furthermore, we conduct theoretical analysis and comprehensive experiments to demonstrate the superiority of our proposed algorithm in terms of task offloading performance and robustness.
Yongwang Zhou, Dongbiao Li, Chi Zhang 0001, Lingbo Wei, Miao Pan
GLOBECOM5
2023 Private Status Retrieval for Blockchain-Based Certificate Revocation System
abstract
Blockchain is the most promising technology to tackle the security challenges of certificate revocation schemes, such as vulnerability to the single point of failure and lack of accountability systems. However, current blockchain-based certificate revocation systems suffer from privacy problems as the blockchain nodes can learn which website the client is going to connect with and infer the end-user's private information, such as identity, location, and health condition. In this paper, we propose a decentralized certificate revocation scheme that allows clients to securely and privately verify revocation information. We not only take advantage of blockchain to provide security guarantees but also further craft a novel multi-server offline/online private information retrieval (PIR) protocol named MOO-PIR to preserve query privacy for clients even if a subset of servers collude. Finally, we provide security analysis and performance evaluation, demonstrating that our scheme can protect client privacy without compromising efficiency.
Zhichao Ruan, Yankai Xie, Haixing Li, Chi Zhang 0001, Lingbo Wei
ICC6
2023 Private Transaction Retrieval for Lightweight Bitcoin Clients
abstract
Running a typical Bitcoin client (also called full node) needs more than 444 GB of disk space, considerable time, and computational resources to synchronize the entire blockchain, which is infeasible for resource-constrained devices. To address such concerns, the lightweight Bitcoin client proposed by Satoshi outsources most of computational and storage burdens to full nodes. Unfortunately, interacting with full nodes to query transactions leaks considerable information like addresses and transactions of lightweight client users. Thus, Bitcoin users that rely on lightweight clients are subject to de-anonymization, which defeats users privacy. Traditional schemes cannot support lightweight clients to query transactions from full nodes in an efficient yet privacy-preserving way. In this article, we propose a new efficient yet privacy-preserving transaction query scheme that specially targets the missing support for lightweight clients. We identify unique characteristics of the Bitcoin blockchain and craft a highly customized private information retrieval scheme called BIT-PIR to match the Bitcoin transaction query scenario and boost performances. Moreover, we customize a storage structure of the Bitcoin blockchain so that it further improves the query efficiency of our scheme. Finally, we develop a prototype implementation to demonstrate the feasibility of our proposed scheme.
Yankai Xie, Qingtao Wang, Ruoyue Li, Chi Zhang 0001, Lingbo Wei
IEEE Trans. Serv. Comput.5
2022 An Efficient Blockchain-Based Time-Stamping Scheme Using Commitment Signatures
abstract
Blockchain-based time-stamping services are widely used in file archiving systems, which can prove a file existed at a given time point by inserting the file hash into the blockchain. However, existing data insertion methods are not satisfactory in terms of efficiency, concealment, and scalability. Besides, to save the on-chain cost of inserting data, existing time-stamping services generate a Merkle tree to aggregate files and then utilize Merkle paths to verify the existence of files. However, as the number of files increases, the Merkle path grows in size, leading to a significant communication overhead for the file existence proof. To solve the above problems, we design a novel blockchain-based time-stamping scheme. First, we design a commitment signature scheme to embed data in the addresses and signatures of blockchain transactions, which can insert our data into public blockchains in an efficient, concealed, and scalable fashion without modifying the data structures and signature verifying schemes of the current public blockchains. Second, instead of using a Merkle tree to aggregate files, we utilize a bilinear pairing accumulator to achieve a constant communication overhead for the file existence proof. Finally, we implement a prototype on the Bitcoin blockchain to show that our scheme is more efficient without any security compromise compared with existing blockchain-based time-stamping schemes.
Sichao Zhang, Chi Zhang 0001, Lingbo Wei
GLOBECOM6
2022 Multi-Party Secure Computation with Intel SGX for Graph Neural Networks
abstract
The current privacy-preserving Graph Neural Networks (GNNs) cannot provide security and privacy guarantees against malicious adversaries without sacrificing accuracy and efficiency. For example, the Secure Multi-party Computation (MPC) can resist malicious adversaries while adding severe overhead. Trusted Execution Environment (TEE), such as Intel Software Guard Extension (SGX), can guarantee privacy and faithful execution without compromising efficiency. However, existing attacks can compromise the confidentiality of SGXs. Besides, the CPU-based structure of SGX restricts its extensibility that cannot perform collaborative computation with GPUs. To address the above issues, we propose a novel GNN training and inference framework to support data holders outsourcing their computation tasks to servers. First, we combine the advantage of MPC and the code integrity protection provided by SGXs to resist malicious adversaries without sacrificing efficiency. Second, we adopt a strategy that allows the servers to transfer the parallelizable computation task to the untrusted yet high-performance GPUs, further improving efficiency without hindering privacy. To the best of our knowledge, our proposal is the first privacy-preserving GNN framework against malicious adversaries without sacrificing accuracy and efficiency. Experiments on real-world citation datasets have demonstrated the performance of our framework regarding security, privacy, accuracy, and efficiency.
Yixin Jie, Yixuan Ren, Qingtao Wang, Yankai Xie, Chi Zhang 0001, Lingbo Wei, Jianqing Liu
ICC6
2022 Secure and Efficient Decentralized Bitcoin Mixing Scheme using Trusted Execution Environment
abstract
Mixing schemes have been applied by Bitcoin users to break their payment links in the blockchain to enhance privacy. However, most mixing schemes cannot provide secure mixing service without compromising efficiency since they are relying on complex cryptographic techniques or interactive protocols. To provide secure yet efficient mixing service, researchers introduce Intel SGX enclave, which provides Trusted Execution Environment (TEE) with confidentiality and integrity guarantees to execute mixing operations. Unfortunately, users will lose their mixing funds if a malicious service provider compromises the confidentiality guarantee of his/her enclave. Moreover, the scheme cannot scale to a large number of users in a single mixing round, that is, limited scalability. In this paper, we present a novel decentralized mixing scheme with multiple enclaves run by different service providers, which uses Shamir secret sharing scheme and additive homomorphic property of keys in Elliptic Curve Cryptography to tolerate a subset of enclaves to be compromised. Moreover, our scheme also provides stronger scalability so it achieves anonymity sets by orders of magnitude higher than the existing TEE-based mixing scheme. The experiment shows our scheme can provide stronger security and anonymity guarantees without compromising efficiency which outperforms existing mixing schemes.
Yankai Xie, Qingtao Wang, Ruiyang Xiao, Chi Zhang 0001, Lingbo Wei
ICC6
2022 Toward fine-grained access control and privacy protection for video sharing in media convergence environment
abstract
Video streaming applications are rapidly proliferating, allowing users to browse, download, and share videos through platforms such as YouTube, Netflix, and Amazon. Media content providers are required to register copyrights on digital platforms. With the existence of blockchain technology, users can manage their data using a smart contract, which allows them to define access and search policies and use an instant payment system without a third party in a decentralized network. We propose a secure and reliable video sharing scheme based on blockchain, using cryptographic primitives to secure the information of streamers and viewers. The use of blockchain ensures reliability and prevents the manipulating or forging of multimedia content. A smart contract system is implemented to represent contractual actions once a given access condition is satisfied. Analysis of the scheme's security and performance demonstrates that it is reliable and efficient.
Farooq Ahmed, Lingbo Wei, Yukun Niu, Wei Zhang 0307, Dong Zhang 0019, Wenxiang Dong
Int. J. Intell. Syst.2
2022 A blockchain-based privacy-preserving authentication system for ensuring multimedia content integrity
abstract
With the prevalence of digital cameras, multimedia data have been used to record facts and provide evidence of events. However, the integrity of multimedia data is vulnerable to attacks with the proliferation of data tampering tools. In fact, an effective multimedia content authentication system should support compliant editing (cropping, rotation, compression, and so forth) and have the ability to detect malicious data tampering. Data traceability is a feasible strategy to verify the integrity and provenance of multimedia data. Besides, the privacy of multimedia data needs to be protected to prevent unauthorized access. In this paper, we trace transformations of multimedia data privately by integrating a transparent and immutable blockchain with trusted hardware that provides the capability of private computation. Our system exploits a hybrid storage pattern that separately stores multimedia data off the blockchain and their hashes on the blockchain. With this, our system ensures data integrity and addresses the issue of blockchain's storage capability. Experimental results and analysis show that our solution is efficient and verifiable. A lightweight verifier merely needs to store block headers and is able to validate query results returned by full nodes.
Lingbo Wei, Chi Zhang 0001
Int. J. Intell. Syst.2
2021 Prediction-based UTXO Cache Optimization for Bitcoin Lightweight Full Nodes
abstract
Since version 0.11 of Bitcoin Core, a user can run a full node in pruning mode, i.e. a pruned node, in resource-limited devices. The pruned node is a lightweight full node as it can independently verify new transactions and blocks received from other peers in the Bitcoin network by only maintaining some recently verified blocks (not the complete blockchain) and the complete Unspent Transaction Output (UTXO) set. However, the rapid increase in the size of the UTXO set has caused the main part of the UTXO set to be stored in the low-speed disk, and thus slows down the verification speed of new blocks in lightweight full nodes. Existing verification schemes for pruned nodes do not take advantage of the fact that different UTXO-related transactions are included in a new block with different probabilities, resulting in poor verification performance. In this paper, we propose a prediction-based UTXO cache optimization mechanism to increase the verification speed of new blocks. In order to achieve higher prediction accuracy and reduce the memory requirements of UTXO set, we first design a method to synchronize unconfirmed transactions for lightweight full nodes to ensure that the local and miners' unconfirmed transaction sets are highly consistent. Then, a lightweight full node predicts which unconfirmed transactions will have a greater probability of appearing in the new block by utilizing the fact that most miners will prioritize unconfirmed transactions to maximize the total transaction fee when mining a new block. Based on this mechanism, we can pre-load the UTXOs required for new block verification into the memory, thereby greatly improving the verification performance. Experimental results show that the proposed mechanism can accelerate the block verification of lightweight full nodes with small memory requirements.
Yukun Niu, Haixing Li, Chi Zhang 0001, Lingbo Wei
GLOBECOM4
2021 HyperChannel: A Secure Layer-2 Payment Network for Large-Scale IoT Ecosystem
abstract
For the future large-scale IoT ecosystem, the number and frequency of micro-payments will increase dramatically. However, the mainstream of cryptocurrencies such as Bitcoin and Ethereum fail to meet the need for a large-scale IoT ecosystem due to limit transaction throughput and high transaction fee. Although Layer-2 solutions such as Lightning Network (LN) increases the throughput of cryptocurrencies by allowing participants to conduct off-chain transactions, LN still suffers from two main limitations: participants need to access the Blockchain within a short bounded time, and a payment channel can only accommodate two participants. To overcome these limitations, we propose HyperChannel, a novel distributed layer-2 payment network designed specifically for the IoT ecosystem which outsources the transaction processing task safely to a group of Intel Software Guard Extensions (SGXs) run by for-profit selfish third parties. Clients such as IoT devices and IoT service providers who often trade with each other will be assigned to a channel to conduct high-frequency in-channel transactions while being allowed to conduct crosschannel transactions in a fee-saving fashion. Compared with existing SGX-based layer-2 payment framework, HyperChannel achieves maximum throughput, addresses both limitations of LN, and further lightens the burden of participants so that IoT devices can conduct layer-2 transactions without running an SGX by themselves.
Qingtao Wang, Chi Zhang 0001, Lingbo Wei, Yankai Xie
ICC3
2021 A Secure and Efficient Bitcoin Payment Channel Using Intel SGX
abstract
Hardware trusted execution environment (TEE) provided by Intel SGX enclave has been introduced in existing payment channel schemes as a root-of-trust to enforce faithful protocol execution so that participants do not need to monitor Bitcoin blockchain anymore. However, the security of these schemes relies totally on enclaves. Since private keys of all channel funds are kept by both payment channel participants’ enclaves, a malicious participant can steal funds from the counterparty by defeating her own enclave. To solve the above problem, we present a novel TEE-based payment channel scheme that transfers the responsibility of running enclaves from participants to a third party committee, while relieving both participants from monitoring the blockchain at the same time. Furthermore, since committee members can try to steal funds by defeating their own enclaves, we exploit the additive homomorphic property of signature keys in Elliptic Curve Cryptography to design a novel secret sharing scheme to tolerate a subset of committee members to be malicious. By using the above secret sharing scheme, private keys of the channel funds are never constructed in any committee member’s enclave, so that a malicious committee member cannot steal funds by defeating his own enclave. Finally, experiment shows our scheme can ensure payment channel funds security without efficient compromises compared with existing TEE-based payment channel schemes.
Yankai Xie, Chi Zhang 0001, Lingbo Wei, Qingtao Wang
ICC3
2021 A Hybrid Secure Computation Framework for Graph Neural Networks
abstract
The Multi-party Secure Computation (MPC)-based methods for privacy-preserving Graph Neural Networks (GNNs) are still challenged by high communication overhead. Moreover, the security guarantee of most MPC-based methods can only defend against the semi-honest adversary, while a few methods which can defend against the malicious adversary will cause a further increase in communication overhead. Moreover, Software Guard Extensions (SGX), which can provide the data confidentiality and code integrity, has been considered as a novel solution to privacy-preserving GNN. Unfortunately, previous work has shown that SGX is vulnerable to side-channel attacks that deprive its confidentiality and preserve only its integrity. To solve the above problems, we propose an n-party secure computation framework for GNNs using SGX. This framework can reduce the communication overhead and improve the security guarantee without relying on the confidentiality of SGX. Specifically, both data holders and the server hold SGX. Data holders enrich the data and train the model by MPC efficiently with the assistance of the server. SGX ensures integrity, where data holders and the server must execute according to protocols, so malicious adversaries cannot deviate from the protocol to breach privacy and security. Even if the confidentiality of SGX was breached, the adversary could only access the ciphertext in MPC instead of the plaintext. We conduct experiments on public datasets to demonstrate that our framework has achieved comparable performance with traditional GNNs and perform security analysis to validate that our framework satisfies security and privacy requirements.
Yixuan Ren, Yixin Jie, Qingtao Wang, Chi Zhang 0001, Lingbo Wei
PST6
2021 A Privacy-Preserving Peer-to-Peer Accommodation System Based on a Credit Network
Zhen Wang 0053, Chi Zhang 0001, Lingbo Wei, Jianqing Liu, Yuguang Fang
WASA (2)4
2020 Protecting Access Privacy in Ethereum Using Differentially Private Information Retrieval
abstract
The last decade has witnessed fast development of blockchain techniques. However, the high cost of storage space and network bandwidth caused by data synchronization prevents many nodes from joining the network, and becomes a bottleneck impeding the development of blockchain. Traditional schemes typically attempt to transfer most of the storage and computation tasks from a light client to a full node. Nevertheless, they remain susceptible to privacy attacks because light clients need to query and retrieve blockchain data. In this paper, we first describe the privacy issues and challenges for Ethereum data retrieval and then propose a privacy-preserving scheme based on private information retrieval (PIR) to secure retrieval of blockchain data. The main idea is to achieve pointer based PIR search by keywords and introduce differential privacy to mitigate PIR's performance barrier. Hence we achieve a tradeoff between privacy and performance. The evaluations on the Ethereum dataset and analysis show that our scheme is both effective and practical in protecting blockchain access privacy.
Farooq Ahmed, Lingbo Wei, Chi Zhang 0001, Yuguang Fang
GLOBECOM3
2019 An Efficient Query Scheme for Privacy-Preserving Lightweight Bitcoin Client with Intel SGX
abstract
In Bitcoin, lightweight clients outsource most of storage and computation tasks to full nodes in order to run on resource-limited devices. In the interaction with the full node, the lightweight client leaks considerable information about which address or transaction is relevant to it. The existing schemes to solve this problem do not support efficient yet privacy-preserving transaction search due to the fact that the blockchain is inherently inefficient for transaction query and proposed schemes perform transaction search in a block-by-block manner. Therefore, we propose an efficient transaction query scheme for the privacy-preserving lightweight client with the Intel SGX enclave running on the full node. Our main idea is to leverage the secure enclave to serve transaction-query requests from lightweight clients. However, the usage of secure enclave alone does not achieve our goals. Our scheme reorganizes the blockchain and leverages prefix tree to increase transaction-search efficiency. Due to limited capacity, the secure enclave stores reorganized blockchain data in the untrusted full node. Thus, our scheme integrates prefix tree and oblivious searching technologies to simultaneously support efficient transaction search and protect access pattern of externally stored blockchain data for the secure enclave. Security analysis and performance evaluation show that our scheme provides efficient transaction search and verification functionalities for lightweight Bitcoin clients in a privacy-preserving way.
Yukun Niu, Chi Zhang 0001, Lingbo Wei, Yankai Xie, Yuguang Fang
GLOBECOM3
2019 DPSR: A Differentially Private Social Recommender System for Mobile Users
Xueling Zhou, Lingbo Wei, Yukun Niu, Chi Zhang 0001, Yuguang Fang
WASA2
2018 A Privacy-Preserving Networked Hospitality Service with the Bitcoin Blockchain
Hengyu Zhou, Yukun Niu, Jianqing Liu, Chi Zhang 0001, Lingbo Wei, Yuguang Fang
WASA5
2016 A Firewall of Two Clouds: Preserving Outsourced Firewall Policy Confidentiality with Heterogeneity
abstract
It is increasingly common for enterprises and other organizations to outsource firewalls to public clouds in order to reduce the cost and complexity in deploying and maintaining dedicated hardware middleboxes. However, this poses a serious threat to the enterprise network security because sensitive network policies, such as firewall rules, are revealed to cloud providers, which may be leaked and exploited by attackers. In this paper, we design and implement a SE- FWaaS, a secured system that enables cloud providers to support middlebox (e.g., firewall) outsourcing while preserving the network policy confidentiality. The key ingredients in our SE-FWaaS are the distribution of the firewall primitives, namely policy checking and verdict enforcing, to two independent public clouds, and the enabling techniques of efficient firewall rule obfuscation and oblivious rule-matching. Our SE-FWaaS provides the maximum achievable level of protection of network policies by enforcing the principle of the least privilege and removing the threat of offline probing attacks. We evaluate the proposed system over real-world firewall rules and demonstrate its effectiveness and feasibility.
Lingbo Wei, Chi Zhang 0001, Yanmin Gong 0001, Yuguang Fang, Kefei Chen
GLOBECOM1
2016 Attribute-based encryption scheme based on SIFF
abstract
Attribute-Based Encryption (ABE) is a public key encryption scheme that allows users to encrypt and decrypt messages based on user attributes. In this paper, we consider the problem of constructing a ciphertext-policy attribute-based encryption (CP-ABE) scheme in a setting where the attributes distributor is also the owner of messages that are to be encrypted and shared. The CP-ABE scheme we propose bases on the Sibling Intractable Function Family (SIFF) scheme. Compared to the existing ABE schemes, the decryption of our scheme in this setting is quite fast and the ciphertext size is rather small. Our ABE system also provides a high degree of compatibility with the messages that are already encrypted when our system is set up, namely, encrypted messages can be used directly in our scheme without being re-encrypted. We compare the efficiency of our scheme with Bethencourt's work in this paper.
Lingbo Wei, Chi Zhang 0001
ICC2
2016 TrInc-Based Secure and Privacy-Preserving Protocols for Vehicular Ad Hoc Networks
abstract
In vehicular ad hoc networks (VANETs), vehicles communicate with each other and with roadside units (RSUs) in order to enhance road safety, improve traffic management and provide infotainment services. Along with the growth of VANETs, some challenges are emerging. Although there are many research work on VANETs, cheating attacks are still not well resolved such as selective message relaying attack, faked information reporting attack and resource-consuming attack launched by selfish or malicious participants. To deal with this kind of attacks, we present two novel lightweight security mechanisms by equipped each vehicle's On-Board Unit (OBU) with a small elegant module called TrInc, which is a trusted hardware and composed of only a non-decreasing counter and a key. We observe that TrInc-based method not only can effectively resist against cheating attacks in safety- oriented, convenience-oriented, and commercial-oriented VANET applications, but also significantly defend various aspects of security and privacy in VANETs. Compared with previous works, our proposal features low communication and computation overhead, less memory requirements, and good network scalability.
Lingbo Wei, Chi Zhang 0001
VTC Spring1
2016 A Secure and Privacy-Preserving Billing Scheme for Online Electric Vehicles
abstract
The Online Electric Vehicle (OLEV) concept is introduced by Korea Advanced Institute of Science and Technology (KAIST) in South Korea. In OLEV system, an electric vehicle (EV) picks up electric energy remotely from power transmitters (PTs) which are buried under a certain route using its pick-up device while the EV is running. The OLEV uses wireless power transfer (WPT) technology which has been widely adopted to charge the batteries of EVs. However, there is not any billing systems for OLEV up to now. In this paper, we propose a secure and privacy-preserving billing scheme for OLEV. Users can buy electric energy from power supply company and charge their EVs anonymously and unlinkably. We assume that each PT transmits a fixed amount of energy to the EV and the energy supply company bills the EV a same amount of money for the electric energy from every PT. EVs can buy the energy according to the levels of their batteries.
Lingbo Wei, Chi Zhang 0001
VTC Spring2
2016 Piggybacking Lightweight Control Messages on Physical Layer for Multicarrier Wireless LANs
Bing Feng, Chi Zhang 0001, Lingbo Wei, Yuguang Fang
WASA3
2016 Optimal Task Recommendation for Mobile Crowdsourcing With Privacy Control
abstract
Mobile crowdsourcing (MC) is a transformative paradigm that engages a crowd of mobile users (i.e., workers) in the act of collecting, analyzing, and disseminating information or sharing their resources. To ensure quality of service, MC platforms tend to recommend MC tasks to workers based on their context information extracted from their interactions and smartphone sensors. This raises privacy concerns hard to address due to the constrained resources on mobile devices. In this paper, we identify fundamental tradeoffs among three metrics-utility, privacy, and efficiency-in an MC system and propose a flexible optimization framework that can be adjusted to any desired tradeoff point with joint efforts of MC platform and workers. Since the underlying optimization problems are NP-hard, we present efficient approximation algorithms to solve them. Since worker statistics are needed when tuning the optimization models, we use an efficient aggregation approach to collecting worker feedbacks while providing differential privacy guarantees. Both numerical evaluations and performance analysis are conducted to demonstrate the effectiveness and efficiency of the proposed framework.
Yanmin Gong 0001, Lingbo Wei, Yuanxiong Guo, Chi Zhang 0001, Yuguang Fang
IEEE Internet Things J.2
2015 A secure and privacy-preserving payment system for Electric vehicles
abstract
The Electric vehicle (EV) will become futuristic and promising for its advantages such as pro-environment, high energy efficiency and so forth. However, Due to the boundedness of batteries, EVs must be recharged very frequently. In this paper, we propose a secure and privacy-preserving payment system for EVs to charge their batteries with reservation service. A user can only reserve a limited number of charging stations simultaneously using our system so that he can not misuse it before charging their EVs. More importantly, our system can not only protect the privacy of users in order that the charging stations cannot know the identities of users, but also provide a lost-protection service to users so that users can find their stolen vehicles with the help of a trusted authorities. The price of charging and reservation is dynamic according to the charging time, the location of the charging station and some attributes of the users.
Chi Zhang 0001, Lingbo Wei
ICC3
2010 Threshold Password-Based Authenticated Group Key Exchange in Gateway-Oriented Setting
Chuankun Wu, Lingbo Wei
ISPEC3
2010 Shorter Verifier-Local Revocation Group Signature with Backward Unlinkability
Lingbo Wei, Jianwei Liu 0001
Pairing1